So I ran GMER on my test bench machine just for ha ha's...and it found this:
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-05-12 13:46:29
Windows 6.1.7600
Running: nr7knxxh.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{C941EA10-6499-4293-ABBE-823E71A6FB60}?\Device\{8A7DF796-2B36-47A5-9FF7-6054DA4D5AC7}?\Device\{5226AEFD-382A-43D7-AE76-D66A12518BB4}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{C941EA10-6499-4293-ABBE-823E71A6FB60}"?"{8A7DF796-2B36-47A5-9FF7-6054DA4D5AC7}"?"{5226AEFD-382A-43D7-AE76-D66A12518BB4}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{C941EA10-6499-4293-ABBE-823E71A6FB60}?\Device\TCPIP6TUNNEL_{8A7DF796-2B36-47A5-9FF7-6054DA4D5AC7}?\Device\TCPIP6TUNNEL_{5226AEFD-382A-43D7-AE76-D66A12518BB4}?
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch@Epoch 585
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch 477
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{14A4C815-30A4-487B-A65C-B991E0733348}@LeaseObtainedTime 1336844439
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{14A4C815-30A4-487B-A65C-B991E0733348}@T1 -810639210
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{14A4C815-30A4-487B-A65C-B991E0733348}@T2 1873715350
Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{08fe8736-b5be-4326-8391-b8df0917ff84}@Dhcpv6State 0
Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{2ad5242c-6a7b-4071-ac2a-53df72bb0f90}@Dhcpv6State 0
---- EOF - GMER 1.0.15 ----
Not sure what to make of it, if anything.
UPDATE: Interestingly, when I run it on my C: drive alone it finds nothing. All the above seems to be from my clone of the machine, on B:. Also, none of the entries are in red.
GMER 1.0.15.15641 - http://www.gmer.net
Rootkit scan 2012-05-12 13:46:29
Windows 6.1.7600
Running: nr7knxxh.exe
---- Registry - GMER 1.0.15 ----
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Bind \Device\{C941EA10-6499-4293-ABBE-823E71A6FB60}?\Device\{8A7DF796-2B36-47A5-9FF7-6054DA4D5AC7}?\Device\{5226AEFD-382A-43D7-AE76-D66A12518BB4}?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Route "{C941EA10-6499-4293-ABBE-823E71A6FB60}"?"{8A7DF796-2B36-47A5-9FF7-6054DA4D5AC7}"?"{5226AEFD-382A-43D7-AE76-D66A12518BB4}"?
Reg HKLM\SYSTEM\CurrentControlSet\Control\Network\{4d36e975-e325-11ce-bfc1-08002be10318}\{2B07FAA1-8217-4E30-B5EC-FD4501E773BB}\Linkage@Export \Device\TCPIP6TUNNEL_{C941EA10-6499-4293-ABBE-823E71A6FB60}?\Device\TCPIP6TUNNEL_{8A7DF796-2B36-47A5-9FF7-6054DA4D5AC7}?\Device\TCPIP6TUNNEL_{5226AEFD-382A-43D7-AE76-D66A12518BB4}?
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch@Epoch 585
Reg HKLM\SYSTEM\CurrentControlSet\services\SharedAccess\Epoch2@Epoch 477
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{14A4C815-30A4-487B-A65C-B991E0733348}@LeaseObtainedTime 1336844439
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{14A4C815-30A4-487B-A65C-B991E0733348}@T1 -810639210
Reg HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{14A4C815-30A4-487B-A65C-B991E0733348}@T2 1873715350
Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{08fe8736-b5be-4326-8391-b8df0917ff84}@Dhcpv6State 0
Reg HKLM\SYSTEM\CurrentControlSet\services\TCPIP6\Parameters\Interfaces\{2ad5242c-6a7b-4071-ac2a-53df72bb0f90}@Dhcpv6State 0
---- EOF - GMER 1.0.15 ----
Not sure what to make of it, if anything.
UPDATE: Interestingly, when I run it on my C: drive alone it finds nothing. All the above seems to be from my clone of the machine, on B:. Also, none of the entries are in red.
Last edited: