Edit C:\Windows\System32\rasauto.dll
MZ? ÿÿ ¸ @ è º ´ Í!¸LÍ!This program cannot be run in DOS mode. $ °?*´ôýDçôýDçôýDç)?çöýDçôýEçIýDç)?çíýDç)?çúýDç)?çõýDç)?çìýDç)?çõýDç)?çõýDçRichôýDç PE d? BRPT ð " d \ \ ? Q `A Ps i °Ô ð À ì P À ðk ? Ð ¨ pr @ .text ¹c d `.data h2 ? h @ À.pdata ì À j @ @.idata Ú Ð r @ @.didat ( ð ? @ À.rsrc ? @ @.reloc P ? @ B pY? `? ð? ? ? p? @? ¡ `¦ µ ¹ pà ÐÄ àé ì ðí î ?" & P. à. °3 Ð3 0U `U pY \ _ b °b Ðb Pc pc ?c °c ðc BRPT $ ?l ?` p?? ?? TAPI32.dll STó±Ð?× ÀOÃ5?ìá<nó±Ð?× ÀOÃ5?}-?ó±Ð?× ÀOÃ5?~-?ó±Ð?× ÀOÃ5? CopyNetbiosName: wks %15.15s (0x%x) CopyNetbiosName: iWks=%d CopyNetbiosName: srv %15.15s (0x%x), cmp=%d IpAddressToNetbiosName: adapter type=%d, name=%S, xport=%S \ D e v i c e \ N e t b t _ T c p i p _ IpAddressToNetbiosName: NtCreateFile failed (status=0x%x) IpAddressToNetbiosName: LocalAlloc failed IpAddressToNetbiosName: Unable to allocate packet IpAddressToNetbiosName: results (status=0x%x, dwcNames=%d) StringToNodeNumber: bad node number length StringToNodeNumber: bad digit %02x:%02x:%02x:%02x:%02x:%02x \ D e v i c e \ N w l n k n b IpxAddressToNetbiosName: NtCreateFile failed (status=0x%x) IpxAddressToNetbiosName: LocalAlloc failed IpxAddressToNetbiosName: Node=%02x:%02x:%02x:%02x:%02x:%02x IpxAddressToNetbiosName: Unable to allocate packet IpxAddressToNetbiosName: results (status=0x%x, dwcNames=%d) NetbiosFindName: arithmetic overflow NetbiosFindName: LocalAlloc failed NetbiosFindName: address=%s NetbiosFindName: CreateEvent failed NetbiosFindName: NtCreateFile failed (status=0x%x) NetbiosFindName: Unable to allocate packet NetbiosFindName: checking for STATUS_SUCCESS NetbiosFindName: %S: status=%d NetbiosFindName: %S: dwcNames=%d NetbiosFindName: dwcWait=%d NetbiosFindName: WaitForMultipleObjects returned 0x%x NetbiosFindName: WaitForMultipleObjects failed (status=0x%x) NetbiosFindName: WaitForMultipleObjects returned STATUS_ABANDONED? NetbiosFindName: %S returned status 0x%x from wait NetbiosFindName: pIoStatusBlock[%d]=0x%x, pBuffer[%d]=0x%x PingIpAddress: IP address=(%s, 0x%x) PingIpAddress: icmp.dll not loaded! PingIpAddress: IcmpCreateFile failed PingIpAddress: LocalAlloc failed PingIpAddress: shutting down PingIpAddress: ping reply status[%d]=%d i c m p IcmpCreateFile IcmpSendEcho IcmpCloseHandle 0 . 0 . 0 . 0 2 5 5 . 2 5 5 . 2 5 5 . 2 5 5 1 2 7 . 0 . 0 . 0 1 2 7 . 0 . 0 . 1 d i a l i n _ g a t e w a y NewAddressMapEntry: LocalAlloc failed GetAddressMapEntry: NewAddressMapEntry failed GetAddressMapEntry: PutTableEntry failed ResetDriver: NtDeviceIoControlFile failed (status=0x%x) EnableDriver: fEnable=%d ResetAddressMapAddress(%S) ResetAddressMapAddress: NewAddressMapEntry failed ( n u l l ) ResetAddressMap: inserting pszAddress=%S ResetAddressMapAddress: PutTableEntry failed ResetAddressMapAddress: AddressToNetwork(%S) failed ResetAddressMapAddress: LocalAlloc failed ResetAddressMapAddress: inserting dwLocationID=%d ResetAddressMapAddress: updating dwLocationID=%d with %S ResetAddressMapAddress: no changes for dwLocationID=%d ResetAddressMap: RasEnumAutodialAddresses failed (dwErr=%d) ResetAddressMap: LocalAlloc failed InitializeAddressMap: NewTable failed WriteRegistryFields: writing %S=%d/%S WriteRegistryFields: AddressToNetwork(%S) failed BuildAddressList: %S has no location info MarkAddressList: RASADP_SavedAddressesLimit=%d PruneAddressList: NEED TO DELETE ADDRESS %S in the driver! WriteAddressMap: WriteRegistryFields failed w p a d p n p t r i a g e n t t r i a g e n t c o r e 2 l i v e r a i d SetAddressDisabled: GetAddressMapEntry failed SetAddressDisabledEx: ioctl failed w w w FindSimilarAddress: fIsWww=1, %S FindSimilarAddress: dialing location %d not found FindSimilarAddress: returning FALSE GetSimilarDialingLocationEntry: %S is not www and has no organization GetSimilarDialingLocationEntry: %S: fWww=%d, fOrg=%d, org is %S GetSimilarDialingLocationEntry: TapiCurrentDialingLocation failed (dwErr=%d) GetSimilarDialingLocationEntry: %S: did not find matching org GetSimilarDialingLocationEntry: %S: matching address is %S SetAddressLastFailedConnectTime: GetAddressMapEntry failed GetAddressLastFailedConnectTime: GetAddressMapEntry failed SetAddressWeight: GetAddressMapEntry failed SetAddressDialingLocationEntry: GetAddressMapEntry failed SetAddressDialingLocationEntry: LocalAlloc failed resetting disabled addresses S o f t w a r e \ M i c r o s o f t \ R A S A u t o d i a l \ C o n t r o l ResetDisabledAddresses: RegCreateKey failed (dwErr=%d) D i s a b l e d A d d r e s s e s ResetDisabledAddresses: adding %S as a disabled address ResetDisabledAddresses: RegSetValue failed (dwErr=%d) AcsHandleNewUser: new user came active AcsHandleNewUser: RefreshImpersonation failed AcsHandleNewUser: ResetAddressMap failed AcsHandleNewUser: UpdateNetworkMap failed AcsHandleNewUser: CreateAutoDialChangeEvent failed (dwErr=%d) AcsHandleNewUser: EnableDriver failed! AcsAddressMapThread: NewTable failed AcsAddressMapThread: LoadRasDlls failed AcsAddressMapThread: waiting for events..dwcEvents = %d AcsAddressMapThread: WaitForMultipleObjects returned %d AcsAddressMapThread: status=%d: shutting down AcsAddressMapThread: pnp event signaled AcsAddressMapThread: ResetAddressMap failed AcsAddressMapThread: UpdateNetworkMap failed AcsAddressMapThread: EnableDriver failed! AcsAddressMapThread: RAS connection change AcsAddressMapThread: TAPI changed AcsAddressMapThread: registry changed AcsAddressThread: user is logging out AcsAddressMapThread: exiting è ? ø ? ? 0 ? H ? AcsRequestWorkerThread: waiting... AcsRequestWorkerThread: status=%d: shutting down AcsRequestWorkerThread: shared-autodial disabled! AcsRequestWorkerThread: no currently logged-on user! AcsRequestWorkerThread: shutting down AcsRequestWorkerThread: AddressToUnicodeString failed AcsRequestWorkerThread: pszAddress=%S, ulFlags=0x%x AcsRequestWorkerThread: CreateConnection returned %d AcsRequestWorkerThread: NtDeviceIoControlFile(IOCTL_ACD_COMPLETION) failed (status=0x%x) s v c h o s t . e x e s e r v i c e s . e x e l l s s r v . e x e AcsDoService: CreateEvent failed (error=0x%x) AcsDoService: CreateThread failed (error=0x%x) AcsDoService: waiting for notification AcsDoService: WaitForMultipleObjects returned 0x%x AcsDoService: NtDeviceIoControlFile(IOCTL_ACD_NOTIFICATION) failed (status=0x%x) AcsDoService: AddressToUnicodeString failed AcsDoService: ignoring null address AcsDoService: got notification: address: %S, ulFlags=0x%x AcsDoService: no currently logged-on user! AcsDoService: %S: is disabled AcsDoService: connections disabled for this login session AcsDoService: connections disabled for this dialing location AcsDoService: %S: address disabled AcsDoService: notif.ulFlags=0x%x AcsDoService: Autodial is disabled for process 0x%lx AcsDoService: process 0x%lx is not disabled AcsDoService: LocalAlloc failed AcsDoService: NtDeviceIoControlFile(IOCTL_ACD_COMPLETION) failed (status=0x%x) AcsDoService: signaling worker thread to shutdown AcsDoService: worker thread shutdown done AcsDoService: exiting AcsDialSharedConnection AcsDialSharedConnection: Could not load RAS DLLs. AcsDialSharedConnection: unable to refresh impersonation! AcsDialSharedConnection: RasQuerySharedConnection=%d AcsDialSharedConnection: shared connection is LAN adapter AcsDialSharedConnectionNoUser AcsDialSharedConnectionNoUser: Could not load RAS DLLs. AcsDialSharedConnectionNoUser: RasQuerySharedConnection=%d AcsDialSharedConnectionNoUser: shared connection is LAN AcsDialSharedConnectionNoUser: RasGetCredentials=%d AcsDialSharedConnectionNoUser: RasDial AcsDialSharedConnectionNoUser: RasDial=%d R A S D L G . D L L RasDialDlgW AcsDialSharedConnectionNoUser: lpfnRasDialDlg returns %d AcsDialSharedConnectionNoUser: Failed to get procaddress for RasDialDlgW AcsDialSharedConnectionNoUser: Failed to load RASDLG.dll AcsDialSharedConnectionNoUser: Wrong type. RASENTRY.dwType=%d AcsDialSharedConnectionNoUser: lpfnRasGetEntryPropertiesG=%d AcsDialSharedConnectionNoUser: RasHangUp=%d ResetEntryName: SetAddressEntryName failed fRequestToSelf. lpRemoteName=%S CreateConnection: lpRemoteName=%S CreateConnection: Could not load RAS DLLs. CreateConnetion: Request to self. Bailing. CreateConnection: dwPreConnections=%d CreateConnection: lookup of %S returned %S CreateConnection: no mapping for lpRemoteName=%S and connected to a network CreateConnection: no mapping for lpRemoteName=%S and not connected to a network N U L L CreateConnection: found default entry %S CreateConnection: lpRemoteName=%S is permanently disabled CreateConnection: network for entry %S is %S CreateConnection: %S is already connected! CreateConnection: lpEntryName=%S is already connected! CreateConnection: RASADP_FailedConnectionTimeout=%d CreateConnection: lpRemoteName=%S is temporarily disabled (failed connection %d ticks ago) CreateConnection: StartDialer returned %d CreateConnection: mapped %S->%S CreateConnection: SetAddressEntryName failed CreateConnection: %d (> 1) new RAS connections! (can't write registry) CreateConnection: disabling %S CreateConnection: SetAddressAttribute failed AcsRedialOnLinkFailureThread: lpszPhonebook=%s, lpszEntry=%s AcsRedialOnLinkFailureThread: no currently logged-on user! Skip redial,e=%d AcsRedialOnLinkFailure: LocalAlloc failed AcsRedialOnLinkFailure: CreateThread failed (error=0x%x) SetLoggedOnUserImpersonationToken: WTSQueryUserToken failed (dwErr=%d) SetLoggedOnUserImpersonationToken: NtSetInformationThread failed (error=%d) ClearImpersonationToken: SetThreadToken failed (error=%d) SetCurrentLoginSession %d ClearCurrentLoginSession MatchLoginSession %d InitCurrentLoginSession InitCurrentLoginSession: Setting current session %d RefreshImpersonation: SetLoggedOnUserImpersonationToken failed Failed to open HKCU for the current user InitSecurityDescriptor: LocalAlloc failed InitSecurityDescriptor: InitializeSid failed (dwErr=0x%x) InitSecurityDescriptor: InitializeAcl failed (dwErr=0x%x) InitSecurityDescriptor: AddAccessAllowedAce failed (dwErr=0x%x) InitSecurityDescriptor: InitializeSecurityDescriptor failed (dwErr=0x%x) InitSecurityDescriptor: SetSecurityDescriptorDacl failed (dwErr=0x%x) InitSecurityDescriptor: SetSecurityDescriptorOwner failed (dwErr=0x%x) InitSecurityDescriptor: SetSecurityDescriptorGroup failed (dwErr=0x%x) TraceCurrentUser: impersonating Current User %d DwGetHhcu: failed to open current user. 0x%x AcsInitialize: WSAStartup failed (dwErr=%d) AcsInitialize: SetupDiGetClassDevs failed (0x%x) AcsInitialize: Modem device is present. Initializing RasTapi AcsInitialize: TapInitialize failed (dwErr=%d) AcsInitialize: SetupDiEnumDeviceInterfaces did not return any items. Registering for device notifications AcsInitialize: RegisterDeviceNotification failed (0x%x) AcsInitialize: SetupDiEnumDeviceInterfaces failed (0x%x) R A S A U T O AcsInitialize: RouterLogRegister failed 0x%x \ D e v i c e \ R a s A c d AcsInitialize: NtCreateFile failed (status=0x%x) AcsInitialize: InitSecurityAttribute failed (dwErr=0x%x) AcsInitialize: CreateEvent (new user) failed AcsInitialize: CreateEvent (FUS) failed AcsInitialize: CreateEvent (hPnpEventG) failed AcsInitialize: CreateEvent (logoff) failed RasAutoDialSharedConnectionEvent AcsInitialize: CreateEvent failed AcsInitialize: InitializeImpersonation failed (dwErr=0x%x) AcsInitialize: InitializeAddressMap failed AcsInitialize: InitializeNetworkMap failed AcsInitialize: CreateThread failed (error=0x%x) WaitForAllThreads: waiting for all threads to terminate WaitForAllThreads: all threads terminated ª?p,.ѱ ÀOªäAddressToUnicodeString: unknown address type (%d) CopyString: LocalAlloc failed CanonicalizeAddress(%S) returns %S GetOrganization: org for %S is %S RASAUTO S y s t e m \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ N e t b i o s \ L i n k a g e GetPrimaryNetbiosDevice: RegKeyOpenEx failed (dwError=%d) L a n a M a p GetPrimaryNetbiosDevice: RegGetValue(LanaMap) failed b i n d GetPrimaryNetbiosDevice: RegGetValue(bind) failed GetPrimaryNetbiosDevice: LocalAlloc failed N w l n k N b _ N d i s W a n GetPrimaryNetbiosDevice: ignoring %S GetPrimaryNetbiosDevice: NtOpenFile(%S) failed (status=0x%x) GetPrimaryNetbiosDevice: opened %S GetPrimaryNetbiosDevice: couldn't parse %S \ D e v i c e \ % s GetPrimaryNetbiosDevice: network (%S, %S, %d) is up S Y S T E M \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ T c p i p \ P a r a m e t e r s \ T r a n s i e n t N a m e S e r v e r S Y S T E M \ C u r r e n t C o n t r o l S e t \ S e r v i c e s \ T c p i p \ P a r a m e t e r s D h c p N a m e S e r v e r DnsAddresses: pszIpAddresses=%S InitializeNetworkMap: NewTable failed NewNetworkMapEntry: LocalAlloc failed NewNetworkMapEntry: NewTable failed NewNetworkMapEntry: PutTableEntry failed AddNetworkAddress(%S,%S,%d) AddNetworkAddress: %S exists with dwTag=%d AddNetworkMap: LocalAlloc failed AddNetworkMap: PutTableEntry failed IsAddressAccessible: fType=%d, pszAddress=%S IsAddressAccessible: IPX address! IsAddressAccessible: invalid type: %d CheckNetworkMap: Entry valid CheckNetworkMap: Entry %p is invalid! up down CheckNetwork: %S is %s (NetworkMapG.dwcUpNetworks=%d AcsCheckNetworkThread UpdateNetworkMap: no change (%d connections) UpdateNetworkMap: arithmetic overflow UpdateNetworkMap: LocalAlloc failed UpdateNetworkMap: old DNS=%S, new DNS=%S UpdateNetworkMap: entry %S, network %S is connected UpdateNetworkMap: network %S is up (dwcUpNetworks=%d) UpdateNetworkMap: DNS is %s UpdateNetworkMap: CreateThread failed (error=0x%x) UpdateNetworkMap: waiting for AcsCheckNetworkThread to terminate... UpdateNetworkMap: AcsCheckNetworkThread done (NetworkMapG.dwcUpNetworks=%d GetNetworkConnected: %S is %d SetNetworkConnected: %S is %d (dwcUpNetworks=%d) GetNetworkConnectionTag: network=%S, tag=%d IsNetworkConnected: dwcUpNetworks=%d GetSystemProcessInfo: VirtualAlloc failed (status=0x%x) GetSystemProcesInfo: enlarging buffer to %d R A S A P I 3 2 LoadRasDlls: couldn't load rasapi32.dll RasDialW RasEnumConnectionsW RasEnumEntriesW RasGetConnectStatusW RasGetHport RasGetProjectionInfoW RasGetEntryPropertiesW RasGetAutodialAddressW RasSetAutodialAddressW RasEnumAutodialAddressesW RasGetAutodialEnableW RasSetAutodialEnableW RasAutodialAddressToNetwork RasAutodialEntryToNetwork RasConnectionNotificationW RasGetAutodialParamW RasSetAutodialParamW RasQuerySharedAutoDial RasQuerySharedConnection RasQueryRedialOnLinkFailure RasGetCredentialsW RasHangUpW LoadRasDlls: couldn't find entrypoints in rasapi32.dll R A S M A N LoadRasDlls: couldn't load rasman.dll RasPortRetrieveUserData RasPortEnumProtocols RasPortEnum RasInitialize RasReferenceRasman RasPortOpen RasPortClose RasGetInfo RasGetPortUserData RasRegisterRedialCallback LoadRasDlls: couldn't find entrypoints in rasman.dll LoadRasDlls: set redial-on-link-failure handler LoadRasDlls: RasConnectionNotification returned dwErr=%d ActiveConnections: LocalAlloc failed ActiveConnections: RasEnumConnections failed (dwStatus=0x%x) ActiveConnections: arithmetic overflow ActiveConnections: RasGetConnectStatus(%S) failed (dwStatus=0x%x) ActiveConnections: state for hrasconn 0x%x is %d ActiveConnections: (%S, 0x%x) m o d e m i s d n x 2 5 V P N PortAvailable: RasPortEnum failed (dwErr=%d) PortAvailable: LocalAlloc failed PortAvailable: lpszAnsiDeviceType=%s, lpszAnsiDeviceName=%s, media=%s, type=%s, name=%s, usage=%d PortAvailable: status=%d, current usage=%d Port already open for call out PortAvailable: RasGetInfo failed (dwErr=%d) Port is not available for call_out w i n s t a 0 \ d e f a u l t StartAutoDialer: RasGetEntryProperties(%S) failed (dwErr=%d) StartAutoDialer: LocalAlloc failed StartAutoDialer: no port available r a s a u t o u - d "