Hello!
Here I go. Got that strange thing that redirects me back to Google search. Is there a name for this virus?
Protection is Microsoft Security Essentials and Lavasoft Ad-aware
--------------------------------------------------------------------------
MALWAREBYTES (Yes, the malwarebytes scan is the latest one in time. But the first one was in my local language and not english. That's why I rescanned, same output though)
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7393
Windows 6.1.7600
Internet Explorer 9.0.8112.16421
2011-08-06 22:20:24
mbam-log-2011-08-06 (22-20-24).txt
Scan type: Quick scan
Objects scanned: 201420
Time elapsed: 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
----------------------------------------------------------------------------------------------------------
GMER
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-06 18:09:35
Windows 6.1.7600
Running: htubqnw6.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export ???w?????|???????????????????????????????e???????????????????????????????????????%?????e?%??255.0.0.0???text????????????????? ???????v???????????f??????????????????????system32\DRIVERS\intelsmb.sys????????v?????????????????????????????????????????????????v??????<??v????????h?????failover????Modem???????????text????tunnel?F-4??????????????????????????????????????????????? ???????n?????v?????v?0????????J???????s?????J??v?????????e????@%SystemRoot%\system32\samsrv.dll,-1??????4??v??????p???MS_WindowsLocalValidation??????v??????@??v????????h??????v??????????????%SystemRoot%\system32\lsass.exe???????J??v?????????n????@%SystemRoot%\system32\samsrv.dll,-2????RPCSS???????? ???v??????????????LocalSystem??????????????????????????????v??????????????????????t??????? ????????????v?v?v?v?v?v?v?v?v???????v???????????e??? ???????v???????????v?0????????????????????????????0????????????????`???????????????????? ????????????????????? ???????????????????? ???????n???????????u??????????T???????????????????????t??????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158315a1ef
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158315a1ef@00254869473f 0xBF 0x1C 0x5A 0x07 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158315a1ef@3cf72a2b0849 0x66 0x84 0x61 0xB5 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????????Microsoft 6to4 Adapter Driver???? ???????????????????m??????????"??? ???????????? ??????? ??????????? "????????????8B4??ndis5_ip6_tunnel?3???????????}???????????????????h??????????*6to4mp??E??? ????????????????????????????????????????????s?????? ??!???????????x?????6?????????????16??Microsoft 6to4 Adapter #33?6?2???????????3???????0??? ?? ????????????8????6??????T??????3???Microsoft 6to4 Adapter #32?t#*???????????#???????8??????????????????????????????nettun.inf??????? ?????????????????????0??L????????? ???????????? ?????????????????????0????????????&???????????????????????? ?????????????????????0????????????????????????????? ???????????????????o?0?????????????????????????????????????l??wn??????????????????????machine.inf??C???????????????????????????????????????????????_?????????????Z?????????????????????????????????5??????????? ???????????????????k?0??????*?8??? ???????? ??????????????????????????Local Area Connection* 1080??D???????????d??????6_?????????????????????????????????j??????l?????`????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ????????????????????????? ???w???e?????p????? ???y???t??????????Net?????????????????????????USB?e??????????????????????????????????????????{???{????v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=41|App=System|Name=@FirewallAPI.dll,-25352|Desc=@FirewallAPI.dll,-25358|EmbedCtxt=@FirewallAPI.dll,-25000|??????????????*6to4mp??&??????????tunnel?:6.????????????N?????? ????D?????*6to4mp??e???????a??????????????????????????*6to4mp??o????X?????????????v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=58|ICMP6=143:*|RA6=LocalSubnet|Name=@FirewallAPI.dll,-25076|Desc=@FirewallAPI.dll,-25081|EmbedCtxt=@FirewallAPI.dll,-25000|?????????????ATDT*99#?????????????????????????????????????????B??????????????????????????????????????????tunnel?8}???????????????????? ???z???????????????z??????????????v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=546|RPort=547|App=%SystemRoot%\system32\svchost.exe|Svc=dhcp|Name=@FirewallAPI.dll,-25304|Desc=@FirewallAPI.dll,-25306|EmbedCtxt=@FirewallAPI.dll,-25000|???v2.10|Action=Allow|Acti
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????????input.inf???? ???????n?????s?????s????????$?`?????????????H??s?????????e????@%SystemRoot%\system32\kmsvc.dll,-6???????Z??s????????h?????%SystemRoot%\System32\svchost.exe -k netsvcs??????H??s?????????n????@%SystemRoot%\system32\kmsvc.dll,-7?????? ???s??????????????????????????????????????????????t??????s?????s?s?s?????? ????????????????s???????????e????,??s????????????????????????????????????`??s??????????????????SeChangeNotifyPrivilege?SeImpersonatePrivilege???????s?s?s?s?s?s?s?s?s?s?s??????????????????????????? ???????s???????????s?,??????,?@??? ???????????? @??s??????????????%SystemRoot%\system32\kmsvc.dll?????????????????????????????? ???????n?????s?????s????$???$???????????????r??????????s????????h?????%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted?????P??s?????????n????@%SystemRoot%\System32\ListSvc.dll,-101??????????????????????????s???????????e???s?s?s?s?s??@%SystemRoot%\System32\ListSvc.dll,-100????????????????????????????? ????????????s?s?s??????????LanmanServer????? ???s?
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ??????????6??????1??????3?????X??????e??????????????????????????????int??????????????????????????????z???????e??????????Net?????tunnel??? ??8&109f0e1c&0?3????X??????????t????N???????????D??|???????_???s???????????????????????????????????????????????????????????????????????????????????W??????s????????????$???????n???????????????????????$????????????????????????????????N?????????????????{4d36e972-e325-11ce-bfc1-08002be10318}??????Type?:????????????????????X??????????t??? ???????????????????????????y????????:????????g????????????sb??????so???????k???7??s}??????90??????? ??????{745a17a0-74d3-11d0-b6fe-00a0c90f57da}\0009??????????????????????????????6??.7??{4d36e972-e325-11ce-bfc1-08002be10318}??????????????????$???4????? ??????? ??????????????????????????????????????????????????????? ??????????? ??????????? ??????????????? ???&????C???????B??????`????????????????????H???????????????????????????B???????????K???B?????????????????????????? ????F???F?????????? ??????????? ????????????F??????F??????,?????????n???????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ????t?????@??{??? ????h?????viahduaa.sys?????????e???????e??????????Bluetooth????????????????????.???????????????????????z??????????????P???????????????z????{?{?{?{?????z??????????????v2.10|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|Profile=Domain|App=%SystemRoot%\system32\svchost.exe|Svc=Msiscsi|Name=@FirewallAPI.dll,-29007|Desc=@FirewallAPI.dll,-29010|EmbedCtxt=@FirewallAPI.dll,-29002|????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Domain|LPort=135|App=%SystemRoot%\system32\svchost.exe|Svc=rpcss|Name=@FirewallAPI.dll,-34252|Desc=@FirewallAPI.dll,-34253|EmbedCtxt=@FirewallAPI.dll,-34251|?????????????????t????z???????????????0???z???????|??*6to4mp?????????????MBRES???*PNP0600?????z??????S????????????z??????????????????????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|Profile=Public|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\system32\svchost.exe|Svc=Msiscsi|Name=@FirewallAPI.dll,-29003|Desc=@FirewallAPI.dll,-29006|EmbedCtxt=@FirewallAPI.dll,-29002|??????????z?????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ?????????????????????????I???O????2?????????????????????sun_VBoxNetFltmp????????????????????????????????????????ar????????????????????>????????g?????????????????????????0???????????g??????????? $??????"?????C32??9&aaa7c05&0??????????????????????????????????????????????f???????????????????n???e????x???????????h??????????????????????????k???????e???????????T?????s_{???????????????????????????????k????????X??????0???e??Logitech??????????????????*?????????????? &??????1?????7f6??????????????????????????????????????????eu?????f??????????????????N??????4?????D,4????????????????????N?????????????????????????????????????????????-5??? f?????????????????????6A????2??????????????????????1??????????????a???????6A????????????????????????????????2?????????????????????????????????????????????????????????.NT??????????????????????????????????????????|???????????????????e???????????v???\??????????????????????????????????????????????????????????????????????01???????????????????????????????f???????????????????-??d0?????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Bind ????????? ??????????????x?H??????????2??12(?6.1.7600.16385??13 ??????????D??-AH??????????-??77(?6.1.7600.16385?13E???????-??77??Microsoft 6to4 Adapter????(?6.1.7600.16385????????????????????@???N??????????? ?????????????????Logitech????????l?????????????????????????????????????????????~??????7??77 ??????????????? ??????????8??3A ???.??????????????????????????????}????????????????????????????????????????????????????8?Microsoft 6to4 Adapter????H??????????2??12(?nettun.inf??????12??????????? ?????????????????????0????????????????????? ?????????????????????0?????????????????? ?????????? ??????????????? ?????????????????????0???????????????????????????????????e?e??? ?????????????????????0??????????????????@?Microsoft 6to4 Adapter??????ed??????????? ?????????????????????0????????????&???????????????????????? ?????????????????????0????????????????????????????? ?????????????????????0??????????????????@???~??????2??5D ??????????6??64??????????? ?????????????????????0????????????????????? ?????????????????????0???????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Route ???2?3???????????,????????????<??,?????????? ???? ???????:???????????:???????????????????e?????,???:?????&??NetBIOS?????5532?????????????????????????????(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ???????P???????W???????P???????W??????????:?,???????????????? ??(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ????(??????P????????????(??????P????????????????????????????????,?????????????????????????? ??????????? ????????????????????????????????????????????(??????P????????????(??????P????????????????????????????????,???(??????P???gsrvctr.ini?????5660???????,?,???????????????? ??(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ????(??????P????????????(??????P???????????????P???????W???????P???????W??????????,?,???????????????????(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ??????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Export ???????????????????????????6TO4 Adapteronnection* 15????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????,Microsoft 6to4 Adapter????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Bind ???k?s???????????D??????\i???f?k?k?k?????????????????????6&??????l?l????? ???????j?????d?????k????????????/? ???????I???????????????????????? ???????k??????????????????????N????????????? ??e???p???e???l?los???k???????????????3???k???????k???????????l?l???????????????????k?&??DiskDrive???????????? ???????????k??????s???LegacyDriver????????????????????????rdbss????????????????????????????????????k???k?k?k?k?????????k???k???????????????????k??Btcsrusb?????????????e??|N??mrxsmb???????????????o??In???k???k?????????????g???????????????????s`????l?l?k????????????>??k?????g?????????????????0????6??o??????????????????S????k?????????????????????????s?????????k???????e??Network?????????CC????????????X??????????}???????????????????????????????????????k????N??n???p?????Dev??.NT??g???k?k?k?k????????Ndi-Mp-Bh???? ???????j?????k?????k????????????0????????S????????????????????????? ???????k??????????????????????N???????????mrxsmb??????SbieDrv??????k???k??????????????????????????0????k?k?k?k?k???k???????????l?l???????k?&??tap
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Route ????2D????????????????????????8?????????????16??????????????s5???l????????N??????????????;??{4d36e96a-e325-11ce-bfc1-08002be10318}\0010??????h?W?r?w???h????????????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????Microsoft 6to4 Adapter???????????????n??sm??????er????????????N??????4?????D"????h?h?i?w???z?w??????????Microsoft 6to4 Adapter #76?6?2??????????????????????????PNP_TDI?????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?pi??@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter??f??? p?????????????????????????????????????????????????????????Microsoft???*6to4mp??2??nettun.inf???E??{4d36e972-e325-11ce-bfc1-08002be10318}?nst???????2??????????????7.??????ct???????????????u???????????????????E??????C9??@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????????????.N??????????????????????????????????? ???|??????????????????so??????????????????16????????????:??????|?g?????????????????????????????3?????s57???????????"???e??????29??????????????????*isatap???????????????N??????C?????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Export ?????????????w???????????????????????????e??????????????v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|Profile=Public|RPort=137|RA4=LocalSubnet|RA6=LocalSubnet|App=System|Name=@FirewallAPI.dll,-32773|Desc=@FirewallAPI.dll,-32776|EmbedCtxt=@FirewallAPI.dll,-32752|?????v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|LPort=138|RA4=LocalSubnet|RA6=LocalSubnet|App=System|Name=@FirewallAPI.dll,-32777|Desc=@FirewallAPI.dll,-32780|EmbedCtxt=@FirewallAPI.dll,-32752|??????????????????????????????? ??????????????????????????????????????????????????usb.inf?31???????????????????s??????? ???????9?????}"?????????????????????????e?????????????????????????Type?????????????:?w?????????????????????????.??????@oem147.inf,%realtek%;Realtek?????*???????????????????????????????????????????????N???????????????????????X??????????e??????????? ?????????????????|???????????HIDClass?????????????????????????????????????e??????????????????????????????????????\\?\HDAUDIO#FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1
Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Bind ???k????? ???????i?????i??????????(????????????????????.?&??? ???????i?????i??????????4?????????????????????????? ???????i??????????????????????????????????????? ???????i???????????i????????"??????????f???????i ???????????rsas????????????????????????@???????????????@???????????????????????????????D???????????????D?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ???????? ??????????????? ? ????????????.??? ???i?????????????????????????@?????????D????????????????????? ??????? ????????? ???? ????? ? ????????????i????????? ???????i?????????????0??L????????? ??????EV_?????i???i???i????????? ???????i?????i???????0????????????&???????????????????????? ???????i?????????????0????????????????????? ???????i?????????????0????????????????????????md??????? ???????i?????????????0???????????????????????i???i???i???i????? ???????i?????????????0????????????????????? ???????i?????i???????0????????????&????????????????????8??? ???????i?????i???????0???????????
Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Route ????!???6.1.7600.16385???????f?i?i?j?????t????????????????N??????F?????DE-????X?????????????????192.168.1.2??????????????????????????e??????Microsoft????????????????f?Z?i?z????????????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}??????? p?????????????????????????????????*6to4mp?????????????????????????????@nettun.inf,%msft%;Microsoft????????????????????????????.NT?????*6to4mp????????i????????????????????? p??????1?????}?\??????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?039????????????????????????????????N??????C?????Dni??{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?vic??????????????????????@nettun.inf,%msft%;Microsoft?C??????????? ??????????????x????????????????????????????1??????-A??Microsoft 6to4 Adapter #73?61D????8?????????????16?????????????????s15??????????????????????????????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?64F??{4d36e972-e325-11ce-bfc1-08002be10318}????????:??????l?gs_??????6C??????????????????????????????????????????????????????????????????????????????????15????N??????_?????D_{??? ???????|?????s?|?
Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Export ??????????B??????T???????????????e??oem80.inf???????????? ??????????????? ??????????????????????????????????????????????? ?????????????????????????????????? ???????&0??? ??????????????????????????????????????????????? ?????????????????????????????????? ???????&0??? ??????????????????????????????????????????????Generic USB Hub?????*6to4mp?????????????????????????????? ???????5????????????????"?????X???g????????????????????????????????????????????????????#??????????????????{00000000-0000-0000-0000-000000000000}??????4????????????r??????\M??6.1.7600.16385??????????????????????????????????? ?????????????????????0??????????????????????:??????&??????????????????????????????????? ?????????????????????0?????????????????????(N?????????????????????????????????????????? ???????-??????nC????:??????????????????????????????????????????e??????????????? ??????1???????????????????(0???????????????????????????????N?????????D???? ?????????????????????0????????????&????????????????????5??? ?????????????????????0???????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xBD 0xF1 0x76 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC4 0x50 0xD1 0x7E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3C 0x7C 0x42 0xC8 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Linkage@Export ??????????????????????????????N?????????????????{CA7DBBF7-AFFC-4810-AB71-8CF8FF6FCE1D}?1?????????????????????????????????????s??@nettun.inf,%msft%;Microsoft??????6???????????????????:???????????????N???????????D??????????????????????????????????????s?u?y???????????????????????????????e???????l???"???e??Intel(R) 82801 PCI Bridge - 244E?????h?Z?i?i??????????????????8?????????????16??Microsoft?????N??????_?????D14??14??vpcbus???????????????}??01???????j??{4d36e972-e325-11ce-bfc1-08002be10318}?25C???????????????????????????????o????????N????????????D????????????Microsoft????????????????????5??????{4d36e96a-e325-11ce-bfc1-08002be10318}???????????????s???s??? ???????i?????nf:???t?t????????????ar??Microsoft 6to4 Adapter #24??????*6to4mp??|???????_??????????????????????????tunnel?1-0????????????????????:????????g??????:??????o?g?o??????????? ???????????????????????????s?????s.1???????????????????-??????02??MONITOR\DEL3016?????? ???s???7????????????N???????????D?X????????e??text?e??????????????????????9.??? ???_???,?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export ???/?&????????????"???????????c????????? ????~??????????1???????????????intelppm???????????????? ???????????????0????t??Fi????N??/?????????????g????midi8?????p? V???????????/???????/?/?/???b?b?V??????????? ???????0?????/???????0???????????????????????7????1:Brightness=0.0,Contrast=1.0,Saturation=1.0,Gamma=0.0,Hue=0.0;2:Brightness=-3.0,Contrast=1.16,Saturation=1.25,Gamma=0.0,Hue=0.0;3:Brightness=-3.0,Contrast=1.07,Saturation=1.10,Gamma=0.0,Hue=0.0;4:Brightness=7.0,Contrast=1.25,Saturation=0.96,Gamma=0.0,Hue=0.0??????/?/?/???????????7?????????????g????MEDIA???????0???????????????100?????NO?64?????????????????????9??????:?:?????????????????.??????????? ???????.???????????.????????"?????????????? ?x?????????????????.?,??*??? ????? ??????????????? ??????????????/????????????????????????????? ?w?????/???????????.?,?????? ????? ???????ES?????? ????S??y???? ?x?????/?????/?????.?,?????? ?????????????????T-?????? ???????y??????? ??????????????? ???????y????????????????????????????n???/?????????????????e???????????????
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158315a1ef (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158315a1ef@00254869473f 0xBF 0x1C 0x5A 0x07 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158315a1ef@3cf72a2b0849 0x66 0x84 0x61 0xB5 ...
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ???o?????????????&???o????????????????????????????4??o?????????e????RPCSS???????@%SystemRoot%\system32\qmgr.dll,-1000?????????????<??s????????h?????speedfan????@%SystemRoot%\system32\qmgr.dll,-1001????????????????????????????????e???????y??? ???????o?????o???????????????????? ???????????? ???????o????????'???????????L?????????????????????????t???????????????????????@%systemroot%\system32\browser.dll,-102?????????????????t????????????+???+???}?}?}???s?r?p????&??????????????e??NTDS????????????@%systemroot%\system32\browser.dll,-103?????CD/DVD File System Reader???cdrom.inf_amd64_neutral_8363d00ecae4322d?????????????p????2??o????????h???????????????????????"??o??????p???????????????Boot File System??????8??o????????h????????????????g??????R??o???????????d?????????????g?????????????????????o???????????????????????????????o?o?o?o?o?o??????4??o????????h??????????????????????????????????????????????????????????????????????p??????????????t???11???????q???q??Internal????????t??????????????????n????system32\DRIVERS\cd
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???o????eF??6-21-2006????????t????D??o????????h???????????????????????????????????????????@??o?????????e????Disk Driver???????8??t???????????????????????{??System32\Drivers\dfsc.sys?????>??o?????????e??????"??s??????p????????????????s??system32\DRIVERS\CompositeBus.sys?siteBus.sys?????b??o?????????e??????4??o????????????????????(?????????p???????????????????????????????????t????????????g??????sy??????????????*6to4mp?????@%systemroot%\system32\drivers\dfsc.sys,-101????@%systemroot%\system32\drivers\dfsc.sys,-102????Brother RemovableDisk(U)?????????????????????????????????????????????{??????????????????COM25??????????o???o???o??????P??o?????????n????????????????e???system32\DRIVERS\cdfs.sys???????????????????system32\drivers\csc.sys??????????????????????????????D??p???????????e???????o???:???????????????????{??????????system32\DRIVERS\bowser.sys???????"??o??????p????????????i??t????????????????????????????????????????????????????????????????????????????????????o???????y???????????????????????????????&???o?????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ???k????????eF????0??s?????????e?????????????????????????????????q??????????????????????????????????disk?????k?k?o?s?s?l?o???????s???????????????????????????????{???y???q??????j????????u???q?q????? ???????p???????????q?,?????? ?F????????????????????????????????????q????F??q??????????????%systemroot%\system32\sdengin2.dll???????q?q????? ???????p???????????q???????? ?<????????????????g????<??q??????????????%SystemRoot%\System32\wer.dll????????????????????????q?q????? ???????p???????????q?,??????&?N?????????????????????N??q??????????????{CA4E628D-8567-4896-AB6B-835B221F373F}???????????????????????????q?q?q??? ??????????????t?????B??q?????????????e????%systemroot%\system32\tquery.dll?????q?q?q?q?q????B??q??????????????%systemroot%\system32\tquery.dll????? ???????p???????????q?,?????? ?N???+??????????????????????n??????N??q??????????????{FC6F77DD-769A-470E-BCF9-1B6555A118BE}????????????????????????????B??q??????????????%SystemRoot%\system32\wsepno.dll????? ???????p???????????q???????? ?N????????t????D??q?????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ???k??????N??j????????????????X??k???&???&???j???m?m?k??fltmgr??????edit????{533c5b84-ec70-11d2-9505-00c04f79deaf}??????{533c5b84-ec70-11d2-9505-00c04f79deaf}\0000?????@volsnap.inf,%msft%;Microsoft???SW\{eeab7790-c514-11d1-b42b-00805fc1270e}???????? ??????????????s???{00000000-0000-0000-ffff-ffffffffffff}???????????????????j??????????? V??j??????????????enum??????N??j?????????D??????????????????????????N??k???p?????D????? ??W???????????o????????\??????s????????????:??????????????????{4d36e972-e325-11ce-bfc1-08002be10318}???????????????????j???n???k???????j???:???:??? l??m???????????????????j???????e??DiskDrive????????u??{00000000-0000-0000-0000-000000000000}????????????????<??k?????????e????????????????????????????? ???????-?????B5F??? ???????fs???????????????8??????? ?????????? ???????j?????j???????????????????????????????k?&??? ???????j?????j?? ???????"?????f????????????k?k?????????????????????k?k?????j?????j?&???????j??????????6.1.7600.16385??????????????????? ????2??j??????????Composite Bus Enumerator? ?
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ???n?????k???????????l?lNd?????k?&????t????????g????????????ms_agilevpnminiport?????{4d36e972-e325-11ce-bfc1-08002be10318}\0006??????????k???3????????????????????????????h??????????????k?l????@netavpna.inf,%msft%;Microsoft???????????e???????m???????????????????????????l??? ???????j?????k?????k????????????F??????????P???????????v??????|???? ???????k???????????k??????????b????????????????????????-??machine.inf??????-?????k?&??usbccgp??????????????????k???1???1??usbccgp??????l???????????????????k???????????????????????????????????3???????????????????????????k??????????7&3396f9b0&0?????????k???-??-2??????????6.1.7600.16385??6.????*??l???????????????????????l??????????Microsoft?????N??l????????D????????????????????s????? h??l???1?????1?1???k?l?????????????3??????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}???????k?f?k?k?i?k?l?l?k?l?l?????????m?????????#??? ???????l?????l???????0????????????&???????????????????????? ???????l?????l???????0????????????????????? ???????l???????????k?0?????????????????????????????5??????net
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???o?o???????????????<????????X?????????????????????????????????????????????????????????????? h??????B??????ot???????????????????????o??????p???????????????????????????????????system32\DRIVERS\HDAudBus.sys?DAudBus.sys?????<??s????????h??????????????????????????????????????????????????????????s?gro??*6to4mp?????????????????????????????t???Extended Base?????P??t?????????n????????????????????????????t???????????????????.NT?????????????{A05DABCF-DABF-4F82-8EC3-376408E16AEF}?ity??? ??????? ?????o?????g?5?????? ?N? ?????????????????????? ??W????:??????????????????????????????????????? ???????o?????o???????5???????????????i????? ???????o?????????????5???????????? ??????o?o??{AA4E204D-855B-4F95-9617-94C55270C8F6}?? ???? ?????????????9?????*??????????N?????????????X??????????e??? h??????:???????????o??? ???????n???????????o?,????????6?w?????4???system32\DRIVERS\EIO64.sys???????&???????p??????????????????????wpdfs.inf????????s??????????s????????????????o?????????e????????? ??????? ?????o?????f?5?????? ?N??????????????
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind ???q?q??*6to4mp??|???????????????q???????:?????k????????eF????0??s?????????e?????????????????????????????????q??????????????????????????????????disk?????k?k?o?s?s?l?o???????s???????????????????????????????{???y???q??????j????????u???q?q????? ???????p???????????q?,?????? ?F????????????????????????????????????q????F??q??????????????%systemroot%\system32\sdengin2.dll???????q?q????? ???????p???????????q???????? ?<????????????????g????<??q??????????????%SystemRoot%\System32\wer.dll????????????????????????q?q????? ???????p???????????q?,??????&?N?????????????????????N??q??????????????{CA4E628D-8567-4896-AB6B-835B221F373F}???????????????????????????q?q?q??? ??????????????t?????B??q?????????????e????%systemroot%\system32\tquery.dll?????q?q?q?q?q????B??q??????????????%systemroot%\system32\tquery.dll????? ???????p???????????q?,?????? ?N???+??????????????????????n??????N??q??????????????{FC6F77DD-769A-470E-BCF9-1B6555A118BE}????????????????????????????B??q??????????????%SystemRoot%\system32\wsepno.dll????? ???????p?????
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route ????????{bf49bdee-48bb-11e0-aacb-806e6f6e6963}??st???????k??????????????????????? ????????????X??????D???t???????????????????????????????l??????????????{4d36e96b-e325-11ce-bfc1-08002be10318}\0010?????????????????????? p??????\?????t#*????B?????????????Microsoft????????????????????????????B??????????@bth.inf,%microsoft%;Microsoft??????????????? ???????b?????????????*??L???????????????????????tba???C:\ProgramData\Microsoft\Microsoft Security Client\Support\Application.etl??????{ebb5d2d1-897c-483c-a28d-0b02b8e5f4a5}?????????????????????e? ???????????????I???????????s??t????????????????????????????????????~?????b???b???b???b???b???c???c???????????d???d???d???d???d???d???d???d???d???d???d???d???d???d?C?????d???d???d????????????????????????????????????????????????????????????????????????????????????????????????????@oem61.inf,%intel%;Intel?;(Standard system devices)?????@machine.inf,%gendev_mfg%;(Standard system devices)???????:?????????????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????Microsoft 6to4
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export ????????????? ???????Z?????????????0????????????&???????????????????????? ?????????????????????0??????*?8??? ???????{4??Local Area Connection* 1103?10????????????4Local Area Connection* 845???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????4Microsoft 6to4 Adapter #10????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Bind ???f?s??????????? .??f??????????????? ???h?????????yst???h?h?/???? ??e???M???????f?f?????????s??????????????????monitor?Wi???????h???/?????????n?/???????i???s?????????n-1???????????????????????????d???4???e???????????????????n??|A??????????????????????$???4????? ??????? ????H?????????? ??????????????????????????$|??e???????????????????????????$|??e??????????????????????????GenCdRom?????f?f????????????????????Base?????????????????????????7??{00000000-0000-0000-ffff-ffffffffffff}????????N??g????????D???????N??h???r?????DTh????N???????????D?????????????????????????????????Video????????????????????????d???????????e?e??????`??~???????v???????????$|??e??????????????????????????{4d36e97d-e325-11ce-bfc1-08002be10318}???????????????????????????A???9??????srv2?????????e??????s4??Net?oo?????????????????????g????????????? ?????????????????????,??L???.??????????????????????????????????8??? ???????f?????f?????????????????????????????????????-??25???f?f??????n??????????????????????????????????????f??? ???????f?????d???????
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Route ????N???????????VBoxNetFlt.ndi????????????????J??????t???????????????;??f???Modem?????????h?????H???@???????@???????H???????????????????????????? h??????0??????o???oem43.inf???????????????????Root\*6TO4MP\0063???????????????????????????\\?\Root#*6TO4MP#0058#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{969CCED3-61BB-4F28-9CD9-0B6262C9238C}?3E??Root\*6TO4MP\0062???????????Root\*6TO4MP\0061????????_???n??sm???????@???@??????\\?\USB#VID_058F&PID_6387#89BF6A3B#{a5dcbf10-6530-11d2-901f-00c04fb951ed}???\\?\PCI#VEN_10EC&DEV_8168&SUBSYS_83A31043&REV_03#4&61613ac&0&00E7#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8E06BBE3-6C44-4D10-8ED4-81FB96D9F2B1}?9-??\\?\Root#*6TO4MP#0052#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{0B6D52E7-FB9F-48EC-A113-A0FB3AEB45BD}?B1??\\?\Root#*6TO4MP#0061#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{27E35669-ECC4-4A7B-8EB9-CC3CF0D744FB}?3B???????????6??????_{??Root\*6TO4MP\0066????????????E??????35??? ???????????????????0??????????h?????????????h?????H???@???????@???????H???????????????????????????? ??W??????
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Export ?????????????????A??????nd??@nettun.inf,%msft%;Microsoft?d??@nettun.inf,%msft%;Microsoft?2??????lt???????????i??ev??????????????????????????????????????? p?????????????????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0143?? ??{4d36e972-e325-11ce-bfc1-08002be10318}\0147???????6??????7??????1E???????????????????A??19??tunnel???B??6-21-2006?????????????????????~?????????6A??{4d36e972-e325-11ce-bfc1-08002be10318}?008??@nettun.inf,%msft%;Microsoft????Microsoft 6to4 Adapter #82????????6??????D??????{D??{D??????????????5.0.15.0?r??*6to4mp?0???????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?mor??Microsoft 6to4 Adapter #84??????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}?-bf??? p??????9????????????????????????????????????????????????????????????N?????????????????????16??{4d36e972-e325-11ce-bfc1-08002be10318}\0088???????X??????????t??????????????????@nettun.inf,%msft%;Microsoft?|???????????w?????s?w??? ???????a??????ct???????t??*6to4mp??????????????s??????????dy????????????:??????o?ga???? p
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Bind ???k?v???g?g?f???f?f?f???g?on?????t??????????????????f????N??h???M?????D-1???h?h?i???t?v?v??????????????????? ???h???.??????????? ???????f?????f?????f????(???$? ?????????????s??????????f???????????????????????????????f???????????f?f????Microsoft???? ???????f?????f???????,??4?????????????????????0;?????f????? ???????f?????????????,?????????????????????y?????f????? ???????f???????????f????????"??????????f???f?fos??t????f????????????????L??????6??????????????????????????????? ???h??????????????*6to4mp?????? ???????f???????????f????????$?????????????????????????????? ??????????????? ???????f???????????e????????"??????????f?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ??????????????????????????????????????????????????????????????????????????????????????????? ????????????f??????????????????????????MBRES???t???? ???????f?????f???????0??L????????? ??????.76?????f???f???f?????????????f???????????????f??????????? ???????f?????f???????????????
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Route ???v??????<??v????????h?????failover????Modem???????????text????tunnel?F-4??????????????????????????????????????????????? ???????n?????v?????v?0????????J???????s?????J??v?????????e????@%SystemRoot%\system32\samsrv.dll,-1??????4??v??????p???MS_WindowsLocalValidation??????v??????@??v????????h??????v??????????????%SystemRoot%\system32\lsass.exe???????J??v?????????n????@%SystemRoot%\system32\samsrv.dll,-2????RPCSS???????? ???v??????????????LocalSystem??????????????????????????????v??????????????????????t??????? ????????????v?v?v?v?v?v?v?v?v???????v???????????e??? ???????v???????????v?0????????????????????????????0????????????????`???????????????????? ????????????????????? ???????????????????? ???????n???????????u??????????T???????????????????????t????????????????????v?v?v????????????????????????T??v????????h???????P??v???????????d??o???????????PlugPlay????\SystemRoot\system32\DRIVERS\sbp2port.sys???sbp2.inf_amd64_neutral_2fff12561375e45f???????????????????????X??????????t??????????????????????? ???????n?????v???
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Export ???m?v??? ??l???c?????6-4??????????????t?????X??????????t??? ???????l???????????????????????????????f??? ???????l?????l???????0??L????????? ??????????????l???l????? ???????l?????l???????0????????????&???????????????????????? ???????l?????l???????0????????????????????? ???????l???????????j?0????????????????????usbhub??????WAN Miniport (PPPOE)???????????l?????????l???r???e??6.1.7600.16385??6.???l??????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0003?????????????????????Tcpip???????? ???????l?????l???????0????????????????????? ???????l???????????k?0????????????????????root\umbus??cr?????l????? ???????l?????l???????0???????????????????????l???l???l????????? ???????l???????????k?0????????????????????Microsoft????????????l?l?????????l???&?????l????? ???????l?????l???????0????????????&??????????????????????????l???l????? ???????l?????l???????0????????????????????? ???????l???????????k?0?????????????????????????l???????e???????g?????????????????????????????l????? ???????l?????l???????0?????????????????????m?mos?
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xBD 0xF1 0x76 0x6C ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC4 0x50 0xD1 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3C 0x7C 0x42 0xC8 ...
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Export ???l?y??????????????2????????????????????????????????????????????v???????????????????T?????? "??????????*6to4mp?????????????????? ???????n???????? ?????????????V???????????Intel(R) SMBus 2.0 Driver????????????4???????????y???????v???????y??????????????n???????????????????????????RapiMgr??E??disk.inf?????????????????????????v?????????? ????????????????????????????????B???????????????????????????????????????y???????????6??????????1.17.62.0????????????4?g-4??????of??????????????????????????*6to4mp??3??????????????t???5952?,??????????????t???????????????????????.NT??m??? ???????n???????????v??????????V?????????????????????????????????????????????????T??v????????h?????\SystemRoot\system32\DRIVERS\sermouse.sys?????(??v?????????e????Serial Mouse Driver??????????v??????p???Pointer Port?????v???????????????v?v?v?v?v?v?v????V??v???????????d??msmouse.inf_amd64_neutral_7a5f47d3150cc0eb??????? ???????n?????t????????????????????????????????????????? ???????v???????????v?????????????????????e?????????????????????s??? ???v?
---- EOF - GMER 1.0.15 ----
Here I go. Got that strange thing that redirects me back to Google search. Is there a name for this virus?
Protection is Microsoft Security Essentials and Lavasoft Ad-aware
--------------------------------------------------------------------------
MALWAREBYTES (Yes, the malwarebytes scan is the latest one in time. But the first one was in my local language and not english. That's why I rescanned, same output though)
Malwarebytes' Anti-Malware 1.51.1.1800
www.malwarebytes.org
Database version: 7393
Windows 6.1.7600
Internet Explorer 9.0.8112.16421
2011-08-06 22:20:24
mbam-log-2011-08-06 (22-20-24).txt
Scan type: Quick scan
Objects scanned: 201420
Time elapsed: 52 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
----------------------------------------------------------------------------------------------------------
GMER
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2011-08-06 18:09:35
Windows 6.1.7600
Running: htubqnw6.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export ???w?????|???????????????????????????????e???????????????????????????????????????%?????e?%??255.0.0.0???text????????????????? ???????v???????????f??????????????????????system32\DRIVERS\intelsmb.sys????????v?????????????????????????????????????????????????v??????<??v????????h?????failover????Modem???????????text????tunnel?F-4??????????????????????????????????????????????? ???????n?????v?????v?0????????J???????s?????J??v?????????e????@%SystemRoot%\system32\samsrv.dll,-1??????4??v??????p???MS_WindowsLocalValidation??????v??????@??v????????h??????v??????????????%SystemRoot%\system32\lsass.exe???????J??v?????????n????@%SystemRoot%\system32\samsrv.dll,-2????RPCSS???????? ???v??????????????LocalSystem??????????????????????????????v??????????????????????t??????? ????????????v?v?v?v?v?v?v?v?v???????v???????????e??? ???????v???????????v?0????????????????????????????0????????????????`???????????????????? ????????????????????? ???????????????????? ???????n???????????u??????????T???????????????????????t??????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158315a1ef
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158315a1ef@00254869473f 0xBF 0x1C 0x5A 0x07 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\00158315a1ef@3cf72a2b0849 0x66 0x84 0x61 0xB5 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Bind ????????Microsoft 6to4 Adapter Driver???? ???????????????????m??????????"??? ???????????? ??????? ??????????? "????????????8B4??ndis5_ip6_tunnel?3???????????}???????????????????h??????????*6to4mp??E??? ????????????????????????????????????????????s?????? ??!???????????x?????6?????????????16??Microsoft 6to4 Adapter #33?6?2???????????3???????0??? ?? ????????????8????6??????T??????3???Microsoft 6to4 Adapter #32?t#*???????????#???????8??????????????????????????????nettun.inf??????? ?????????????????????0??L????????? ???????????? ?????????????????????0????????????&???????????????????????? ?????????????????????0????????????????????????????? ???????????????????o?0?????????????????????????????????????l??wn??????????????????????machine.inf??C???????????????????????????????????????????????_?????????????Z?????????????????????????????????5??????????? ???????????????????k?0??????*?8??? ???????? ??????????????????????????Local Area Connection* 1080??D???????????d??????6_?????????????????????????????????j??????l?????`????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Route ????????????????????????? ???w???e?????p????? ???y???t??????????Net?????????????????????????USB?e??????????????????????????????????????????{???{????v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=41|App=System|Name=@FirewallAPI.dll,-25352|Desc=@FirewallAPI.dll,-25358|EmbedCtxt=@FirewallAPI.dll,-25000|??????????????*6to4mp??&??????????tunnel?:6.????????????N?????? ????D?????*6to4mp??e???????a??????????????????????????*6to4mp??o????X?????????????v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=58|ICMP6=143:*|RA6=LocalSubnet|Name=@FirewallAPI.dll,-25076|Desc=@FirewallAPI.dll,-25081|EmbedCtxt=@FirewallAPI.dll,-25000|?????????????ATDT*99#?????????????????????????????????????????B??????????????????????????????????????????tunnel?8}???????????????????? ???z???????????????z??????????????v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|LPort=546|RPort=547|App=%SystemRoot%\system32\svchost.exe|Svc=dhcp|Name=@FirewallAPI.dll,-25304|Desc=@FirewallAPI.dll,-25306|EmbedCtxt=@FirewallAPI.dll,-25000|???v2.10|Action=Allow|Acti
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanServer\Linkage@Export ????????input.inf???? ???????n?????s?????s????????$?`?????????????H??s?????????e????@%SystemRoot%\system32\kmsvc.dll,-6???????Z??s????????h?????%SystemRoot%\System32\svchost.exe -k netsvcs??????H??s?????????n????@%SystemRoot%\system32\kmsvc.dll,-7?????? ???s??????????????????????????????????????????????t??????s?????s?s?s?????? ????????????????s???????????e????,??s????????????????????????????????????`??s??????????????????SeChangeNotifyPrivilege?SeImpersonatePrivilege???????s?s?s?s?s?s?s?s?s?s?s??????????????????????????? ???????s???????????s?,??????,?@??? ???????????? @??s??????????????%SystemRoot%\system32\kmsvc.dll?????????????????????????????? ???????n?????s?????s????$???$???????????????r??????????s????????h?????%SystemRoot%\System32\svchost.exe -k LocalSystemNetworkRestricted?????P??s?????????n????@%SystemRoot%\System32\ListSvc.dll,-101??????????????????????????s???????????e???s?s?s?s?s??@%SystemRoot%\System32\ListSvc.dll,-100????????????????????????????? ????????????s?s?s??????????LanmanServer????? ???s?
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Bind ??????????6??????1??????3?????X??????e??????????????????????????????int??????????????????????????????z???????e??????????Net?????tunnel??? ??8&109f0e1c&0?3????X??????????t????N???????????D??|???????_???s???????????????????????????????????????????????????????????????????????????????????W??????s????????????$???????n???????????????????????$????????????????????????????????N?????????????????{4d36e972-e325-11ce-bfc1-08002be10318}??????Type?:????????????????????X??????????t??? ???????????????????????????y????????:????????g????????????sb??????so???????k???7??s}??????90??????? ??????{745a17a0-74d3-11d0-b6fe-00a0c90f57da}\0009??????????????????????????????6??.7??{4d36e972-e325-11ce-bfc1-08002be10318}??????????????????$???4????? ??????? ??????????????????????????????????????????????????????? ??????????? ??????????? ??????????????? ???&????C???????B??????`????????????????????H???????????????????????????B???????????K???B?????????????????????????? ????F???F?????????? ??????????? ????????????F??????F??????,?????????n???????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Route ????t?????@??{??? ????h?????viahduaa.sys?????????e???????e??????????Bluetooth????????????????????.???????????????????????z??????????????P???????????????z????{?{?{?{?????z??????????????v2.10|Action=Allow|Active=FALSE|Dir=Out|Protocol=6|Profile=Domain|App=%SystemRoot%\system32\svchost.exe|Svc=Msiscsi|Name=@FirewallAPI.dll,-29007|Desc=@FirewallAPI.dll,-29010|EmbedCtxt=@FirewallAPI.dll,-29002|????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Domain|LPort=135|App=%SystemRoot%\system32\svchost.exe|Svc=rpcss|Name=@FirewallAPI.dll,-34252|Desc=@FirewallAPI.dll,-34253|EmbedCtxt=@FirewallAPI.dll,-34251|?????????????????t????z???????????????0???z???????|??*6to4mp?????????????MBRES???*PNP0600?????z??????S????????????z??????????????????????v2.10|Action=Allow|Active=FALSE|Dir=In|Protocol=6|Profile=Private|Profile=Public|RA4=LocalSubnet|RA6=LocalSubnet|App=%SystemRoot%\system32\svchost.exe|Svc=Msiscsi|Name=@FirewallAPI.dll,-29003|Desc=@FirewallAPI.dll,-29006|EmbedCtxt=@FirewallAPI.dll,-29002|??????????z?????????
Reg HKLM\SYSTEM\CurrentControlSet\services\LanmanWorkstation\Linkage@Export ?????????????????????????I???O????2?????????????????????sun_VBoxNetFltmp????????????????????????????????????????ar????????????????????>????????g?????????????????????????0???????????g??????????? $??????"?????C32??9&aaa7c05&0??????????????????????????????????????????????f???????????????????n???e????x???????????h??????????????????????????k???????e???????????T?????s_{???????????????????????????????k????????X??????0???e??Logitech??????????????????*?????????????? &??????1?????7f6??????????????????????????????????????????eu?????f??????????????????N??????4?????D,4????????????????????N?????????????????????????????????????????????-5??? f?????????????????????6A????2??????????????????????1??????????????a???????6A????????????????????????????????2?????????????????????????????????????????????????????????.NT??????????????????????????????????????????|???????????????????e???????????v???\??????????????????????????????????????????????????????????????????????01???????????????????????????????f???????????????????-??d0?????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Bind ????????? ??????????????x?H??????????2??12(?6.1.7600.16385??13 ??????????D??-AH??????????-??77(?6.1.7600.16385?13E???????-??77??Microsoft 6to4 Adapter????(?6.1.7600.16385????????????????????@???N??????????? ?????????????????Logitech????????l?????????????????????????????????????????????~??????7??77 ??????????????? ??????????8??3A ???.??????????????????????????????}????????????????????????????????????????????????????8?Microsoft 6to4 Adapter????H??????????2??12(?nettun.inf??????12??????????? ?????????????????????0????????????????????? ?????????????????????0?????????????????? ?????????? ??????????????? ?????????????????????0???????????????????????????????????e?e??? ?????????????????????0??????????????????@?Microsoft 6to4 Adapter??????ed??????????? ?????????????????????0????????????&???????????????????????? ?????????????????????0????????????????????????????? ?????????????????????0??????????????????@???~??????2??5D ??????????6??64??????????? ?????????????????????0????????????????????? ?????????????????????0???????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Route ???2?3???????????,????????????<??,?????????? ???? ???????:???????????:???????????????????e?????,???:?????&??NetBIOS?????5532?????????????????????????????(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ???????P???????W???????P???????W??????????:?,???????????????? ??(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ????(??????P????????????(??????P????????????????????????????????,?????????????????????????? ??????????? ????????????????????????????????????????????(??????P????????????(??????P????????????????????????????????,???(??????P???gsrvctr.ini?????5660???????,?,???????????????? ??(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ????(??????P????????????(??????P???????????????P???????W???????P???????W??????????,?,???????????????????(??????P???????W????(??????P???????W??????????????????????????????? ??????????? ??????????? ??????????? ??????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBIOS\Linkage@Export ???????????????????????????6TO4 Adapteronnection* 15????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????,Microsoft 6to4 Adapter????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Bind ???k?s???????????D??????\i???f?k?k?k?????????????????????6&??????l?l????? ???????j?????d?????k????????????/? ???????I???????????????????????? ???????k??????????????????????N????????????? ??e???p???e???l?los???k???????????????3???k???????k???????????l?l???????????????????k?&??DiskDrive???????????? ???????????k??????s???LegacyDriver????????????????????????rdbss????????????????????????????????????k???k?k?k?k?????????k???k???????????????????k??Btcsrusb?????????????e??|N??mrxsmb???????????????o??In???k???k?????????????g???????????????????s`????l?l?k????????????>??k?????g?????????????????0????6??o??????????????????S????k?????????????????????????s?????????k???????e??Network?????????CC????????????X??????????}???????????????????????????????????????k????N??n???p?????Dev??.NT??g???k?k?k?k????????Ndi-Mp-Bh???? ???????j?????k?????k????????????0????????S????????????????????????? ???????k??????????????????????N???????????mrxsmb??????SbieDrv??????k???k??????????????????????????0????k?k?k?k?k???k???????????l?l???????k?&??tap
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Route ????2D????????????????????????8?????????????16??????????????s5???l????????N??????????????;??{4d36e96a-e325-11ce-bfc1-08002be10318}\0010??????h?W?r?w???h????????????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????Microsoft 6to4 Adapter???????????????n??sm??????er????????????N??????4?????D"????h?h?i?w???z?w??????????Microsoft 6to4 Adapter #76?6?2??????????????????????????PNP_TDI?????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?pi??@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter??f??? p?????????????????????????????????????????????????????????Microsoft???*6to4mp??2??nettun.inf???E??{4d36e972-e325-11ce-bfc1-08002be10318}?nst???????2??????????????7.??????ct???????????????u???????????????????E??????C9??@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????????????.N??????????????????????????????????? ???|??????????????????so??????????????????16????????????:??????|?g?????????????????????????????3?????s57???????????"???e??????29??????????????????*isatap???????????????N??????C?????
Reg HKLM\SYSTEM\CurrentControlSet\services\NetBT\Linkage@Export ?????????????w???????????????????????????e??????????????v2.10|Action=Allow|Active=TRUE|Dir=Out|Protocol=17|Profile=Public|RPort=137|RA4=LocalSubnet|RA6=LocalSubnet|App=System|Name=@FirewallAPI.dll,-32773|Desc=@FirewallAPI.dll,-32776|EmbedCtxt=@FirewallAPI.dll,-32752|?????v2.10|Action=Allow|Active=TRUE|Dir=In|Protocol=17|Profile=Public|LPort=138|RA4=LocalSubnet|RA6=LocalSubnet|App=System|Name=@FirewallAPI.dll,-32777|Desc=@FirewallAPI.dll,-32780|EmbedCtxt=@FirewallAPI.dll,-32752|??????????????????????????????? ??????????????????????????????????????????????????usb.inf?31???????????????????s??????? ???????9?????}"?????????????????????????e?????????????????????????Type?????????????:?w?????????????????????????.??????@oem147.inf,%realtek%;Realtek?????*???????????????????????????????????????????????N???????????????????????X??????????e??????????? ?????????????????|???????????HIDClass?????????????????????????????????????e??????????????????????????????????????\\?\HDAUDIO#FUNC_01&VEN_1002&DEV_AA01&SUBSYS_00AA0100&REV_1
Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Bind ???k????? ???????i?????i??????????(????????????????????.?&??? ???????i?????i??????????4?????????????????????????? ???????i??????????????????????????????????????? ???????i???????????i????????"??????????f???????i ???????????rsas????????????????????????@???????????????@???????????????????????????????D???????????????D?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ???????? ??????????????? ? ????????????.??? ???i?????????????????????????@?????????D????????????????????? ??????? ????????? ???? ????? ? ????????????i????????? ???????i?????????????0??L????????? ??????EV_?????i???i???i????????? ???????i?????i???????0????????????&???????????????????????? ???????i?????????????0????????????????????? ???????i?????????????0????????????????????????md??????? ???????i?????????????0???????????????????????i???i???i???i????? ???????i?????????????0????????????????????? ???????i?????i???????0????????????&????????????????????8??? ???????i?????i???????0???????????
Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Route ????!???6.1.7600.16385???????f?i?i?j?????t????????????????N??????F?????DE-????X?????????????????192.168.1.2??????????????????????????e??????Microsoft????????????????f?Z?i?z????????????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}??????? p?????????????????????????????????*6to4mp?????????????????????????????@nettun.inf,%msft%;Microsoft????????????????????????????.NT?????*6to4mp????????i????????????????????? p??????1?????}?\??????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?039????????????????????????????????N??????C?????Dni??{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?vic??????????????????????@nettun.inf,%msft%;Microsoft?C??????????? ??????????????x????????????????????????????1??????-A??Microsoft 6to4 Adapter #73?61D????8?????????????16?????????????????s15??????????????????????????????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?64F??{4d36e972-e325-11ce-bfc1-08002be10318}????????:??????l?gs_??????6C??????????????????????????????????????????????????????????????????????????????????15????N??????_?????D_{??? ???????|?????s?|?
Reg HKLM\SYSTEM\CurrentControlSet\services\Smb\Linkage@Export ??????????B??????T???????????????e??oem80.inf???????????? ??????????????? ??????????????????????????????????????????????? ?????????????????????????????????? ???????&0??? ??????????????????????????????????????????????? ?????????????????????????????????? ???????&0??? ??????????????????????????????????????????????Generic USB Hub?????*6to4mp?????????????????????????????? ???????5????????????????"?????X???g????????????????????????????????????????????????????#??????????????????{00000000-0000-0000-0000-000000000000}??????4????????????r??????\M??6.1.7600.16385??????????????????????????????????? ?????????????????????0??????????????????????:??????&??????????????????????????????????? ?????????????????????0?????????????????????(N?????????????????????????????????????????? ???????-??????nC????:??????????????????????????????????????????e??????????????? ??????1???????????????????(0???????????????????????????????N?????????D???? ?????????????????????0????????????&????????????????????5??? ?????????????????????0???????????????
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s1 771343423
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@s2 285507792
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg@h0 1
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xBD 0xF1 0x76 0x6C ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC4 0x50 0xD1 0x7E ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0
Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3C 0x7C 0x42 0xC8 ...
Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Linkage@Export ??????????????????????????????N?????????????????{CA7DBBF7-AFFC-4810-AB71-8CF8FF6FCE1D}?1?????????????????????????????????????s??@nettun.inf,%msft%;Microsoft??????6???????????????????:???????????????N???????????D??????????????????????????????????????s?u?y???????????????????????????????e???????l???"???e??Intel(R) 82801 PCI Bridge - 244E?????h?Z?i?i??????????????????8?????????????16??Microsoft?????N??????_?????D14??14??vpcbus???????????????}??01???????j??{4d36e972-e325-11ce-bfc1-08002be10318}?25C???????????????????????????????o????????N????????????D????????????Microsoft????????????????????5??????{4d36e96a-e325-11ce-bfc1-08002be10318}???????????????s???s??? ???????i?????nf:???t?t????????????ar??Microsoft 6to4 Adapter #24??????*6to4mp??|???????_??????????????????????????tunnel?1-0????????????????????:????????g??????:??????o?g?o??????????? ???????????????????????????s?????s.1???????????????????-??????02??MONITOR\DEL3016?????? ???s???7????????????N???????????D?X????????e??text?e??????????????????????9.??? ???_???,?
Reg HKLM\SYSTEM\ControlSet002\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export ???/?&????????????"???????????c????????? ????~??????????1???????????????intelppm???????????????? ???????????????0????t??Fi????N??/?????????????g????midi8?????p? V???????????/???????/?/?/???b?b?V??????????? ???????0?????/???????0???????????????????????7????1:Brightness=0.0,Contrast=1.0,Saturation=1.0,Gamma=0.0,Hue=0.0;2:Brightness=-3.0,Contrast=1.16,Saturation=1.25,Gamma=0.0,Hue=0.0;3:Brightness=-3.0,Contrast=1.07,Saturation=1.10,Gamma=0.0,Hue=0.0;4:Brightness=7.0,Contrast=1.25,Saturation=0.96,Gamma=0.0,Hue=0.0??????/?/?/???????????7?????????????g????MEDIA???????0???????????????100?????NO?64?????????????????????9??????:?:?????????????????.??????????? ???????.???????????.????????"?????????????? ?x?????????????????.?,??*??? ????? ??????????????? ??????????????/????????????????????????????? ?w?????/???????????.?,?????? ????? ???????ES?????? ????S??y???? ?x?????/?????/?????.?,?????? ?????????????????T-?????? ???????y??????? ??????????????? ???????y????????????????????????????n???/?????????????????e???????????????
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158315a1ef (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158315a1ef@00254869473f 0xBF 0x1C 0x5A 0x07 ...
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\00158315a1ef@3cf72a2b0849 0x66 0x84 0x61 0xB5 ...
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Bind ???o?????????????&???o????????????????????????????4??o?????????e????RPCSS???????@%SystemRoot%\system32\qmgr.dll,-1000?????????????<??s????????h?????speedfan????@%SystemRoot%\system32\qmgr.dll,-1001????????????????????????????????e???????y??? ???????o?????o???????????????????? ???????????? ???????o????????'???????????L?????????????????????????t???????????????????????@%systemroot%\system32\browser.dll,-102?????????????????t????????????+???+???}?}?}???s?r?p????&??????????????e??NTDS????????????@%systemroot%\system32\browser.dll,-103?????CD/DVD File System Reader???cdrom.inf_amd64_neutral_8363d00ecae4322d?????????????p????2??o????????h???????????????????????"??o??????p???????????????Boot File System??????8??o????????h????????????????g??????R??o???????????d?????????????g?????????????????????o???????????????????????????????o?o?o?o?o?o??????4??o????????h??????????????????????????????????????????????????????????????????????p??????????????t???11???????q???q??Internal????????t??????????????????n????system32\DRIVERS\cd
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Route ???o????eF??6-21-2006????????t????D??o????????h???????????????????????????????????????????@??o?????????e????Disk Driver???????8??t???????????????????????{??System32\Drivers\dfsc.sys?????>??o?????????e??????"??s??????p????????????????s??system32\DRIVERS\CompositeBus.sys?siteBus.sys?????b??o?????????e??????4??o????????????????????(?????????p???????????????????????????????????t????????????g??????sy??????????????*6to4mp?????@%systemroot%\system32\drivers\dfsc.sys,-101????@%systemroot%\system32\drivers\dfsc.sys,-102????Brother RemovableDisk(U)?????????????????????????????????????????????{??????????????????COM25??????????o???o???o??????P??o?????????n????????????????e???system32\DRIVERS\cdfs.sys???????????????????system32\drivers\csc.sys??????????????????????????????D??p???????????e???????o???:???????????????????{??????????system32\DRIVERS\bowser.sys???????"??o??????p????????????i??t????????????????????????????????????????????????????????????????????????????????????o???????y???????????????????????????????&???o?????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanServer\Linkage@Export ???k????????eF????0??s?????????e?????????????????????????????????q??????????????????????????????????disk?????k?k?o?s?s?l?o???????s???????????????????????????????{???y???q??????j????????u???q?q????? ???????p???????????q?,?????? ?F????????????????????????????????????q????F??q??????????????%systemroot%\system32\sdengin2.dll???????q?q????? ???????p???????????q???????? ?<????????????????g????<??q??????????????%SystemRoot%\System32\wer.dll????????????????????????q?q????? ???????p???????????q?,??????&?N?????????????????????N??q??????????????{CA4E628D-8567-4896-AB6B-835B221F373F}???????????????????????????q?q?q??? ??????????????t?????B??q?????????????e????%systemroot%\system32\tquery.dll?????q?q?q?q?q????B??q??????????????%systemroot%\system32\tquery.dll????? ???????p???????????q?,?????? ?N???+??????????????????????n??????N??q??????????????{FC6F77DD-769A-470E-BCF9-1B6555A118BE}????????????????????????????B??q??????????????%SystemRoot%\system32\wsepno.dll????? ???????p???????????q???????? ?N????????t????D??q?????????
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Bind ???k??????N??j????????????????X??k???&???&???j???m?m?k??fltmgr??????edit????{533c5b84-ec70-11d2-9505-00c04f79deaf}??????{533c5b84-ec70-11d2-9505-00c04f79deaf}\0000?????@volsnap.inf,%msft%;Microsoft???SW\{eeab7790-c514-11d1-b42b-00805fc1270e}???????? ??????????????s???{00000000-0000-0000-ffff-ffffffffffff}???????????????????j??????????? V??j??????????????enum??????N??j?????????D??????????????????????????N??k???p?????D????? ??W???????????o????????\??????s????????????:??????????????????{4d36e972-e325-11ce-bfc1-08002be10318}???????????????????j???n???k???????j???:???:??? l??m???????????????????j???????e??DiskDrive????????u??{00000000-0000-0000-0000-000000000000}????????????????<??k?????????e????????????????????????????? ???????-?????B5F??? ???????fs???????????????8??????? ?????????? ???????j?????j???????????????????????????????k?&??? ???????j?????j?? ???????"?????f????????????k?k?????????????????????k?k?????j?????j?&???????j??????????6.1.7600.16385??????????????????? ????2??j??????????Composite Bus Enumerator? ?
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Route ???n?????k???????????l?lNd?????k?&????t????????g????????????ms_agilevpnminiport?????{4d36e972-e325-11ce-bfc1-08002be10318}\0006??????????k???3????????????????????????????h??????????????k?l????@netavpna.inf,%msft%;Microsoft???????????e???????m???????????????????????????l??? ???????j?????k?????k????????????F??????????P???????????v??????|???? ???????k???????????k??????????b????????????????????????-??machine.inf??????-?????k?&??usbccgp??????????????????k???1???1??usbccgp??????l???????????????????k???????????????????????????????????3???????????????????????????k??????????7&3396f9b0&0?????????k???-??-2??????????6.1.7600.16385??6.????*??l???????????????????????l??????????Microsoft?????N??l????????D????????????????????s????? h??l???1?????1?1???k?l?????????????3??????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}???????k?f?k?k?i?k?l?l?k?l?l?????????m?????????#??? ???????l?????l???????0????????????&???????????????????????? ???????l?????l???????0????????????????????? ???????l???????????k?0?????????????????????????????5??????net
Reg HKLM\SYSTEM\ControlSet002\services\LanmanWorkstation\Linkage@Export ???o?o???????????????<????????X?????????????????????????????????????????????????????????????? h??????B??????ot???????????????????????o??????p???????????????????????????????????system32\DRIVERS\HDAudBus.sys?DAudBus.sys?????<??s????????h??????????????????????????????????????????????????????????s?gro??*6to4mp?????????????????????????????t???Extended Base?????P??t?????????n????????????????????????????t???????????????????.NT?????????????{A05DABCF-DABF-4F82-8EC3-376408E16AEF}?ity??? ??????? ?????o?????g?5?????? ?N? ?????????????????????? ??W????:??????????????????????????????????????? ???????o?????o???????5???????????????i????? ???????o?????????????5???????????? ??????o?o??{AA4E204D-855B-4F95-9617-94C55270C8F6}?? ???? ?????????????9?????*??????????N?????????????X??????????e??? h??????:???????????o??? ???????n???????????o?,????????6?w?????4???system32\DRIVERS\EIO64.sys???????&???????p??????????????????????wpdfs.inf????????s??????????s????????????????o?????????e????????? ??????? ?????o?????f?5?????? ?N??????????????
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Bind ???q?q??*6to4mp??|???????????????q???????:?????k????????eF????0??s?????????e?????????????????????????????????q??????????????????????????????????disk?????k?k?o?s?s?l?o???????s???????????????????????????????{???y???q??????j????????u???q?q????? ???????p???????????q?,?????? ?F????????????????????????????????????q????F??q??????????????%systemroot%\system32\sdengin2.dll???????q?q????? ???????p???????????q???????? ?<????????????????g????<??q??????????????%SystemRoot%\System32\wer.dll????????????????????????q?q????? ???????p???????????q?,??????&?N?????????????????????N??q??????????????{CA4E628D-8567-4896-AB6B-835B221F373F}???????????????????????????q?q?q??? ??????????????t?????B??q?????????????e????%systemroot%\system32\tquery.dll?????q?q?q?q?q????B??q??????????????%systemroot%\system32\tquery.dll????? ???????p???????????q?,?????? ?N???+??????????????????????n??????N??q??????????????{FC6F77DD-769A-470E-BCF9-1B6555A118BE}????????????????????????????B??q??????????????%SystemRoot%\system32\wsepno.dll????? ???????p?????
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Route ????????{bf49bdee-48bb-11e0-aacb-806e6f6e6963}??st???????k??????????????????????? ????????????X??????D???t???????????????????????????????l??????????????{4d36e96b-e325-11ce-bfc1-08002be10318}\0010?????????????????????? p??????\?????t#*????B?????????????Microsoft????????????????????????????B??????????@bth.inf,%microsoft%;Microsoft??????????????? ???????b?????????????*??L???????????????????????tba???C:\ProgramData\Microsoft\Microsoft Security Client\Support\Application.etl??????{ebb5d2d1-897c-483c-a28d-0b02b8e5f4a5}?????????????????????e? ???????????????I???????????s??t????????????????????????????????????~?????b???b???b???b???b???c???c???????????d???d???d???d???d???d???d???d???d???d???d???d???d???d?C?????d???d???d????????????????????????????????????????????????????????????????????????????????????????????????????@oem61.inf,%intel%;Intel?;(Standard system devices)?????@machine.inf,%gendev_mfg%;(Standard system devices)???????:?????????????@nettun.inf,%6to4mp.displayname%;Microsoft 6to4 Adapter?????Microsoft 6to4
Reg HKLM\SYSTEM\ControlSet002\services\NetBIOS\Linkage@Export ????????????? ???????Z?????????????0????????????&???????????????????????? ?????????????????????0??????*?8??? ???????{4??Local Area Connection* 1103?10????????????4Local Area Connection* 845???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????4Microsoft 6to4 Adapter #10????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Bind ???f?s??????????? .??f??????????????? ???h?????????yst???h?h?/???? ??e???M???????f?f?????????s??????????????????monitor?Wi???????h???/?????????n?/???????i???s?????????n-1???????????????????????????d???4???e???????????????????n??|A??????????????????????$???4????? ??????? ????H?????????? ??????????????????????????$|??e???????????????????????????$|??e??????????????????????????GenCdRom?????f?f????????????????????Base?????????????????????????7??{00000000-0000-0000-ffff-ffffffffffff}????????N??g????????D???????N??h???r?????DTh????N???????????D?????????????????????????????????Video????????????????????????d???????????e?e??????`??~???????v???????????$|??e??????????????????????????{4d36e97d-e325-11ce-bfc1-08002be10318}???????????????????????????A???9??????srv2?????????e??????s4??Net?oo?????????????????????g????????????? ?????????????????????,??L???.??????????????????????????????????8??? ???????f?????f?????????????????????????????????????-??25???f?f??????n??????????????????????????????????????f??? ???????f?????d???????
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Route ????N???????????VBoxNetFlt.ndi????????????????J??????t???????????????;??f???Modem?????????h?????H???@???????@???????H???????????????????????????? h??????0??????o???oem43.inf???????????????????Root\*6TO4MP\0063???????????????????????????\\?\Root#*6TO4MP#0058#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{969CCED3-61BB-4F28-9CD9-0B6262C9238C}?3E??Root\*6TO4MP\0062???????????Root\*6TO4MP\0061????????_???n??sm???????@???@??????\\?\USB#VID_058F&PID_6387#89BF6A3B#{a5dcbf10-6530-11d2-901f-00c04fb951ed}???\\?\PCI#VEN_10EC&DEV_8168&SUBSYS_83A31043&REV_03#4&61613ac&0&00E7#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{8E06BBE3-6C44-4D10-8ED4-81FB96D9F2B1}?9-??\\?\Root#*6TO4MP#0052#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{0B6D52E7-FB9F-48EC-A113-A0FB3AEB45BD}?B1??\\?\Root#*6TO4MP#0061#{ad498944-762f-11d0-8dcb-00c04fc3358c}\{27E35669-ECC4-4A7B-8EB9-CC3CF0D744FB}?3B???????????6??????_{??Root\*6TO4MP\0066????????????E??????35??? ???????????????????0??????????h?????????????h?????H???@???????@???????H???????????????????????????? ??W??????
Reg HKLM\SYSTEM\ControlSet002\services\NetBT\Linkage@Export ?????????????????A??????nd??@nettun.inf,%msft%;Microsoft?d??@nettun.inf,%msft%;Microsoft?2??????lt???????????i??ev??????????????????????????????????????? p?????????????????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0143?? ??{4d36e972-e325-11ce-bfc1-08002be10318}\0147???????6??????7??????1E???????????????????A??19??tunnel???B??6-21-2006?????????????????????~?????????6A??{4d36e972-e325-11ce-bfc1-08002be10318}?008??@nettun.inf,%msft%;Microsoft????Microsoft 6to4 Adapter #82????????6??????D??????{D??{D??????????????5.0.15.0?r??*6to4mp?0???????????{00000000-0000-0000-FFFF-FFFFFFFFFFFF}?mor??Microsoft 6to4 Adapter #84??????????????????????????{4d36e972-e325-11ce-bfc1-08002be10318}?-bf??? p??????9????????????????????????????????????????????????????????????N?????????????????????16??{4d36e972-e325-11ce-bfc1-08002be10318}\0088???????X??????????t??????????????????@nettun.inf,%msft%;Microsoft?|???????????w?????s?w??? ???????a??????ct???????t??*6to4mp??????????????s??????????dy????????????:??????o?ga???? p
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Bind ???k?v???g?g?f???f?f?f???g?on?????t??????????????????f????N??h???M?????D-1???h?h?i???t?v?v??????????????????? ???h???.??????????? ???????f?????f?????f????(???$? ?????????????s??????????f???????????????????????????????f???????????f?f????Microsoft???? ???????f?????f???????,??4?????????????????????0;?????f????? ???????f?????????????,?????????????????????y?????f????? ???????f???????????f????????"??????????f???f?fos??t????f????????????????L??????6??????????????????????????????? ???h??????????????*6to4mp?????? ???????f???????????f????????$?????????????????????????????? ??????????????? ???????f???????????e????????"??????????f?????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????? ??????????????????????????????????????????????????????????????????????????????????????????? ????????????f??????????????????????????MBRES???t???? ???????f?????f???????0??L????????? ??????.76?????f???f???f?????????????f???????????????f??????????? ???????f?????f???????????????
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Route ???v??????<??v????????h?????failover????Modem???????????text????tunnel?F-4??????????????????????????????????????????????? ???????n?????v?????v?0????????J???????s?????J??v?????????e????@%SystemRoot%\system32\samsrv.dll,-1??????4??v??????p???MS_WindowsLocalValidation??????v??????@??v????????h??????v??????????????%SystemRoot%\system32\lsass.exe???????J??v?????????n????@%SystemRoot%\system32\samsrv.dll,-2????RPCSS???????? ???v??????????????LocalSystem??????????????????????????????v??????????????????????t??????? ????????????v?v?v?v?v?v?v?v?v???????v???????????e??? ???????v???????????v?0????????????????????????????0????????????????`???????????????????? ????????????????????? ???????????????????? ???????n???????????u??????????T???????????????????????t????????????????????v?v?v????????????????????????T??v????????h???????P??v???????????d??o???????????PlugPlay????\SystemRoot\system32\DRIVERS\sbp2port.sys???sbp2.inf_amd64_neutral_2fff12561375e45f???????????????????????X??????????t??????????????????????? ???????n?????v???
Reg HKLM\SYSTEM\ControlSet002\services\Smb\Linkage@Export ???m?v??? ??l???c?????6-4??????????????t?????X??????????t??? ???????l???????????????????????????????f??? ???????l?????l???????0??L????????? ??????????????l???l????? ???????l?????l???????0????????????&???????????????????????? ???????l?????l???????0????????????????????? ???????l???????????j?0????????????????????usbhub??????WAN Miniport (PPPOE)???????????l?????????l???r???e??6.1.7600.16385??6.???l??????????????{4d36e972-e325-11ce-bfc1-08002be10318}\0003?????????????????????Tcpip???????? ???????l?????l???????0????????????????????? ???????l???????????k?0????????????????????root\umbus??cr?????l????? ???????l?????l???????0???????????????????????l???l???l????????? ???????l???????????k?0????????????????????Microsoft????????????l?l?????????l???&?????l????? ???????l?????l???????0????????????&??????????????????????????l???l????? ???????l?????l???????0????????????????????? ???????l???????????k?0?????????????????????????l???????e???????g?????????????????????????????l????? ???????l?????l???????0?????????????????????m?mos?
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xBD 0xF1 0x76 0x6C ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xC4 0x50 0xD1 0x7E ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0xA0 0x02 0x00 0x00 ...
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet)
Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x3C 0x7C 0x42 0xC8 ...
Reg HKLM\SYSTEM\ControlSet002\services\TCPIP6\Linkage@Export ???l?y??????????????2????????????????????????????????????????????v???????????????????T?????? "??????????*6to4mp?????????????????? ???????n???????? ?????????????V???????????Intel(R) SMBus 2.0 Driver????????????4???????????y???????v???????y??????????????n???????????????????????????RapiMgr??E??disk.inf?????????????????????????v?????????? ????????????????????????????????B???????????????????????????????????????y???????????6??????????1.17.62.0????????????4?g-4??????of??????????????????????????*6to4mp??3??????????????t???5952?,??????????????t???????????????????????.NT??m??? ???????n???????????v??????????V?????????????????????????????????????????????????T??v????????h?????\SystemRoot\system32\DRIVERS\sermouse.sys?????(??v?????????e????Serial Mouse Driver??????????v??????p???Pointer Port?????v???????????????v?v?v?v?v?v?v????V??v???????????d??msmouse.inf_amd64_neutral_7a5f47d3150cc0eb??????? ???????n?????t????????????????????????????????????????? ???????v???????????v?????????????????????e?????????????????????s??? ???v?
---- EOF - GMER 1.0.15 ----