here the log of Combofix :
ComboFix 08-10-04.07 - user1 2008-10-05 18:34:13.1 - NTFSx86
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
C:\Windows\system32\BReWErS.dll
C:\Windows\system32\tcpip.sys
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
——-\Legacy_MCHINJDRV
——-\Service_iprip
((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 )))))))))))))))))))))))))))))))
.
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\Users\user1\AppData\Roaming\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\Users\All Users\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\ProgramData\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:47 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 17:46 . 2008-09-10 00:04 38,528 –a—— C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-05 17:46 . 2008-09-10 00:03 17,200 –a—— C:\Windows\System32\drivers\mbam.sys
2008-10-05 10:29 . 2008-10-05 11:44 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\BSplayer PRO
2008-10-05 10:20 . 2008-10-05 10:20 d——– C:\!FixIEDef
2008-10-05 09:51 . 2008-10-05 09:51 d——– C:\Program Files\ERUNT
2008-10-05 08:48 . 2008-10-05 17:55 d——– C:\Program Files\HJT
2008-10-05 08:10 . 2008-10-05 08:10 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Subversion
2008-10-05 08:06 . 2008-10-05 08:06 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Nero
2008-10-05 07:16 . 2008-10-05 07:17 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\WNR
2008-10-05 07:16 . 2008-10-05 07:16 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Skype
2008-10-04 16:41 . 2008-10-04 19:32 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-10-04 16:41 . 2008-10-04 19:32 d——– C:\ProgramData\Spybot - Search & Destroy
2008-10-04 16:41 . 2008-10-04 16:53 d——– C:\Program Files\Spybot - Search & Destroy
2008-10-04 15:15 . 2008-10-04 15:25 96,976 –a—— C:\Windows\System32\drivers\klin.dat
2008-10-04 15:15 . 2008-10-04 15:15 87,855 –a—— C:\Windows\System32\drivers\klick.dat
2008-10-04 15:14 . 2008-10-05 18:08 d——– C:\Users\All Users\Kaspersky Lab
2008-10-04 15:14 . 2008-10-05 18:08 d——– C:\ProgramData\Kaspersky Lab
2008-10-04 15:14 . 2008-10-04 15:14 d——– C:\Program Files\Kaspersky Lab
2008-10-04 15:14 . 2008-10-05 18:39 8,641,056 –ahs—- C:\Windows\System32\drivers\fidbox.dat
2008-10-04 15:14 . 2008-10-05 18:41 581,664 –ahs—- C:\Windows\System32\drivers\fidbox2.dat
2008-10-04 15:14 . 2008-10-05 18:39 69,636 –ahs—- C:\Windows\System32\drivers\fidbox.idx
2008-10-04 15:14 . 2008-10-05 18:41 4,116 –ahs—- C:\Windows\System32\drivers\fidbox2.idx
2008-10-03 14:06 . 2008-10-03 14:06 d——– C:\Users\All Users\CCP
2008-10-03 14:06 . 2008-10-03 14:06 d——– C:\ProgramData\CCP
2008-09-29 16:32 . 2008-10-03 13:56 d——– C:\CCP
2008-09-28 07:36 . 2008-09-28 07:36 d——– C:\Users\user1\AppData\Roaming\EVEMon
2008-09-28 07:36 . 2008-09-28 07:36 d——– C:\Program Files\EVEMon
2008-09-19 06:15 . 2008-09-19 06:16 d–h-c— C:\Users\All Users\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2008-09-19 06:15 . 2008-09-19 06:16 d–h-c— C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Videos
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Searches
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Saved Games
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Pictures
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Links
2008-09-14 07:04 . 2008-10-05 08:49 dr——- C:\Windows\System32\config\systemprofile\Downloads
2008-09-14 07:04 . 2008-10-05 08:17 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-09-14 07:04 . 2008-09-14 07:04 d——– C:\Users\All Users\Electronic Arts
2008-09-14 07:04 . 2008-09-14 07:04 d——– C:\ProgramData\Electronic Arts
2008-09-14 07:04 . 2008-09-14 07:04 9,576 –a—— C:\Windows\System32\ealregsnapshot1.reg
2008-09-14 06:28 . 2008-06-11 13:48 188,960 –a—— C:\Windows\System32\nvapps.xml
2008-09-13 17:13 . 2008-09-13 17:13 d——– C:\Users\user1\AppData\Roaming\SystemRequirementsLab
2008-09-10 19:01 . 2008-09-19 02:39 54,156 –ah—– C:\Windows\QTFont.qfn
2008-09-10 19:01 . 2008-09-10 19:01 1,409 –a—— C:\Windows\QTFont.for
2008-09-07 17:32 . 2008-09-27 03:25 d——– C:\Users\user1\speed racer
2008-09-07 08:08 . 2008-09-07 08:08 d——– C:\Users\Public\Public Documents
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-05 16:43 ——— d—–w C:\Users\user1\AppData\Roaming\skypePM
2008-10-05 16:43 ——— d—–w C:\Users\user1\AppData\Roaming\Skype
2008-10-05 16:43 ——— d—–w C:\Program Files\Steam
2008-10-05 16:39 ——— d—–w C:\Users\user1\AppData\Roaming\Free Download Manager
2008-10-05 06:25 ——— d—–w C:\Program Files\RegVac Registry Cleaner
2008-10-04 15:06 ——— d—–w C:\Program Files\SilkroadAddiction ecSRO
2008-10-04 12:59 ——— d—–w C:\ProgramData\Kaspersky Lab Setup Files
2008-10-04 12:05 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-04 10:48 ——— d—–w C:\Program Files\GameSpy Arcade
2008-10-04 10:41 ——— d—–w C:\Program Files\Disney Interactive Studios
2008-09-26 14:39 ——— d—–w C:\Users\user1\AppData\Roaming\uTorrent
2008-09-25 03:18 ——— d—–w C:\ProgramData\FLEXnet
2008-09-24 01:03 ——— d—–w C:\Program Files\Mass Effect
2008-09-24 01:03 ——— d—–w C:\Program Files\Common Files\BioWare
2008-09-24 01:02 ——— d—–w C:\ProgramData\Media Center Programs
2008-09-19 03:51 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-15 01:33 ——— d—–w C:\Users\user1\AppData\Roaming\FileZilla
2008-09-14 10:23 ——— d—–w C:\ProgramData\NVIDIA
2008-09-14 05:10 ——— d—–w C:\Program Files\EA Games
2008-09-14 05:07 ——— d—–w C:\Program Files\Electronic Arts
2008-09-13 15:13 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-09-09 11:37 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-09-07 10:34 ——— d—–w C:\Program Files\Messenger Plus! Live
2008-09-06 15:01 ——— d—–w C:\Users\user1\AppData\Roaming\DNA
2008-09-05 02:00 ——— d—–w C:\Program Files\Atari
2008-09-05 00:15 ——— d—–w C:\Program Files\Gravity
2008-09-03 16:44 ——— d—–w C:\Users\user1\AppData\Roaming\Printer Info Cache
2008-09-03 16:44 ——— d—–w C:\Users\user1\AppData\Roaming\Image Zone Express
2008-08-31 00:24 ——— d—–w C:\Program Files\DNA
2008-08-27 17:09 136,888 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-08-27 17:08 111,928 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-08-15 21:48 ——— d—–w C:\Users\user1\AppData\Roaming\BSplayer Pro
2008-08-13 21:09 ——— d—–w C:\Program Files\Logitech
2008-08-13 20:03 ——— d—–w C:\Program Files\Java
2008-08-13 19:21 81,920 ——w C:\Windows\bwUnin-6.1.4.36-8876480L.exe
2008-08-07 01:34 ——— d—–w C:\Users\user1\AppData\Roaming\Red Alert 3 Beta
2008-08-07 01:00 107,888 —-a-w C:\Windows\System32\CmdLineExt.dll
2008-08-07 00:45 ——— d—–w C:\Users\user1\AppData\Roaming\IGN_DLM
2008-07-29 17:21 218,376 —-a-w C:\Windows\System32\klogon.dll
2008-07-28 22:07 669,184 —-a-w C:\Windows\System32\pbsvc.exe
2008-07-28 22:07 22,328 —-a-w C:\Users\user1\AppData\Roaming\PnkBstrK.sys
2008-07-03 12:35 813,056 —-a-w C:\Users\user1\pbsetup.exe
2008-06-19 08:43 174 –sha-w C:\Program Files\desktop.ini
2008-05-16 02:16 674,600 —-a-w C:\Users\user1\pbsvc.exe
2008-04-25 00:16 32 —-a-w C:\Users\All Users\ezsid.dat
2008-04-25 00:16 32 —-a-w C:\ProgramData\ezsid.dat
2008-02-04 05:32 88 –sh–r C:\Users\All Users\39094D39B5.sys
2008-02-04 05:32 88 –sh–r C:\ProgramData\39094D39B5.sys
2008-02-04 05:32 2,828 –sha-w C:\Users\All Users\KGyGaAvL.sys
2008-02-04 05:32 2,828 –sha-w C:\ProgramData\KGyGaAvL.sys
2007-02-01 16:02 313,344 —-a-w C:\Users\user1\hjsplit.exe
2003-03-26 15:54 311,385 —-a-w C:\Program Files\dpvs.dll
2007-12-25 23:05 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-25 23:05 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-25 23:05 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"MobMapUpdater"="C:\Program Files\MobMapUpdater\MobMapUpdater.exe" [2008-03-23 1706624]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 1103480]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 22058792]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-06-08 1271032]
"PSwitch"="C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe" [2008-07-27 4426752]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2008-07-22 2772992]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-04-26 380928]
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 331776]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-02 286720]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 92704]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]
C:\Users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-08-04 3581680]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
"VIDC.XFR1"= xfcodec.dll
"msacm.divxa32"= divxa32.acm
[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup
[HKLM\~\startupfolder\C:^Users^user1^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
backup=C:\Windows\pss\hamachi.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSwitch
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-03-09 20:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
–a—— 2007-09-19 18:20 36864 C:\Program Files\GameSpy\Comrade\Comrade.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2007-08-16 13:24 167368 C:\Program Files\DAEMON Tools\daemon.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2007-03-05 23:57 1103480 C:\Program Files\Download Manager\DLM.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a—— 2007-08-07 02:05 200704 C:\Program Files\PowerISO\PWRISOVM.EXE
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-11-02 14:17 286720 C:\Program Files\QuickTime\qttask.exe
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2008-04-23 16:45 22058792 C:\Program Files\Skype\Phone\Skype.exe
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\FlashFXP\\flashfxp.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FFA5B6F2-C26F-4853-BBF3-79BB4EC80E4C}"= UDP:C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"{D9F880FF-4780-46E6-8BBF-EDCED455A554}"= TCP:C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"{06AB7147-4CA6-4019-99EE-D4D9E4D8510F}"= UDP:C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{7601132C-C2CD-4755-9722-74739F1D93CC}"= TCP:C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{5BE0940B-3B79-4443-9099-7A230722CB51}"= UDP:C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{F22C1180-F102-445B-B0F9-86F8EA912D13}"= TCP:C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{B09769AF-0FE5-4B06-BFDF-CE1E6AD83CBB}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{E3D43656-14B4-44E3-8BB7-52EC739AFBE3}C:\\program files\\ubisoft\\ghost recon advanced warfighter\\graw.exe"= UDP:C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe:GRAW
"UDP Query User{A8C10895-591F-4CA3-B1BF-E609D49C953B}C:\\program files\\ubisoft\\ghost recon advanced warfighter\\graw.exe"= TCP:C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe:GRAW
"{9AD54A38-960C-4710-8831-72E54E94145F}"= UDP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{7F0A8BC8-E340-4B2D-8ADD-54BBEC67BB48}"= TCP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{A6DC8C34-F921-4E6D-B07B-1974339F455F}"= UDP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2.exe:Ghost Recon Advanced Warfighter® 2
"{9543219F-F30E-4E35-9AF6-E287680F191F}"= TCP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2.exe:Ghost Recon Advanced Warfighter® 2
"{59A005A9-425D-4F5F-8321-E605E6994CBD}"= UDP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:Ghost Recon Advanced Warfighter® 2 Dedicated Server
"{259842A2-8F7B-47D4-A4A5-670F2962887C}"= TCP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:Ghost Recon Advanced Warfighter® 2 Dedicated Server
"{EDB9306A-F556-4768-9FA6-DCD4AC9297D6}"= UDP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{7DE5E461-C472-4C67-9990-B95BC0A2AFAD}"= TCP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{679864E0-5153-40BF-A316-0550D46993B8}"= UDP:C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{BFECEDA5-1DD2-49A6-8A09-BDA60CDE5E58}"= TCP:C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"TCP Query User{A99C1663-62BC-4498-B782-1B79289A6F77}C:\\program files\\flashget\\flashget.exe"= UDP:C:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{AC616576-63DF-4A3B-9A03-61E12C77D22D}C:\\program files\\flashget\\flashget.exe"= TCP:C:\program files\flashget\flashget.exe:FlashGet
"TCP Query User{2FAE900A-D5C9-444C-B982-FC62DDE695A0}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{826E3727-A162-418C-BEA3-118F17185258}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{65A473AF-12AF-46A7-B651-459E771377B0}"= UDP:C:\Program Files\utorrent\utorrent.exe:µTorrent
"{D7C7BA9B-8AD1-401D-BB84-39B0E5050B2E}"= TCP:C:\Program Files\utorrent\utorrent.exe:µTorrent
"{22B42D2C-6A98-456E-9065-271E1E46C855}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{382EDE20-1D03-4D64-9B25-EE22F402D55B}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"TCP Query User{D4DAC1F8-310E-4913-9B83-76CF283E1924}C:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= UDP:C:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"UDP Query User{DAC07923-5E3B-4E35-A800-C5BC1A8D0379}C:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= TCP:C:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"TCP Query User{4670C380-5F6C-4D59-A2C6-53E2B6813561}C:\\windows\\system32\\dplaysvr.exe"= UDP:C:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"UDP Query User{23E2912F-6D93-4726-B252-B8424368317C}C:\\windows\\system32\\dplaysvr.exe"= TCP:C:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"TCP Query User{CA014B7F-C2A4-4423-9D7F-1B0210F53C9B}C:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= UDP:C:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"UDP Query User{1D14B836-C292-4820-B4B5-2006EB278EEA}C:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= TCP:C:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"{B0F8AD4C-AC6A-4F54-B9DB-1587C4445851}"= UDP:46615:utorrent 1
"{1CE0EC4B-197C-4E8B-BFCA-9AF0EB723AB2}"= TCP:46615:utorrent 2
"{09939247-17EE-4E69-A701-36AED499573B}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo Lite Server\etqwded.exe:Enemy Territory - QUAKE Wars™ Demo Lite Server
"{CCFCE3BB-1E04-4D44-8BDC-BFEA355EE97D}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo Lite Server\etqwded.exe:Enemy Territory - QUAKE Wars™ Demo Lite Server
"{37A13F4C-F566-47F2-80AC-C4A595B9D9C1}"= UDP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{3B2DC43E-0777-40B5-A774-FCA7299C0BBD}"= TCP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{D1A6800B-F887-4DF4-B65C-3EB18FC26D9E}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{77B5ADD9-6A77-4C65-A3B0-CA88CE8CAD69}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{38DF7FC0-61A5-491D-9BB6-CE1435E0B340}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{94C3DB7C-3B2B-4AF3-9A4F-FD1D5EB3765C}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{B6ACBA54-3DF1-4BDB-A5AB-C1EE54B2C40A}C:\\users\\user1\\desktop\\lostplanettrialdx10setup\\lostplanetdx10\\lostplanettrialdx10patch\\lost_planet_trial_dx10\\lostplanetdx10.exe"= UDP:C:\users\user1\desktop\lostplanettrialdx10setup\lostplanetdx10\lostplanettrialdx10patch\lost_planet_trial_dx10\lostplanetdx10.exe:lostplanetdx10.exe
"UDP Query User{D327D39E-EDC3-4FFC-BAA3-75ED6F9593B7}C:\\users\\user1\\desktop\\lostplanettrialdx10setup\\lostplanetdx10\\lostplanettrialdx10patch\\lost_planet_trial_dx10\\lostplanetdx10.exe"= TCP:C:\users\user1\desktop\lostplanettrialdx10setup\lostplanetdx10\lostplanettrialdx10patch\lost_planet_trial_dx10\lostplanetdx10.exe:lostplanetdx10.exe
"TCP Query User{8F3065E9-60CE-4ED4-87F3-1D3B1A8E5978}C:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= UDP:C:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"UDP Query User{B3EBDE0E-0339-4FA9-BA04-874A84FD7927}C:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= TCP:C:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"{40795003-8891-4F75-956E-F8BC84CE4C43}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{1F57DDBA-DEB4-43C1-9E91-C29FEABA07D8}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{C802490C-AC2D-447A-845D-C1E342895F8E}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{BE191FDE-3E52-47A2-B4E0-FDB0B8F13F52}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{C62ACFB7-D1A3-4CB4-93B2-B7D970E249F7}"= UDP:80:BF2142
"{44DE58B8-B353-4004-A1C9-0DA7379464AF}"= UDP:443:BF21421
"{8ADA471B-4919-427E-95F9-DE968E6D9581}"= UDP:4711:BF214211
"{696911B3-7A7A-4B0C-8F22-118C4F46D743}"= TCP:9964:BF2142
"{BCCD1151-7EB3-410A-85DF-5D3788923A21}"= TCP:16567:BF21421
"{3EE7E840-6DFC-40D1-A889-1E75950B26F1}"= UDP:1024:BF2142111
"{0B5A32F9-A79A-453C-9349-EAE2F7163FEF}"= UDP:C:\Program Files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"{A7601029-86AA-493C-996C-386E4B75E0C8}"= TCP:C:\Program Files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"TCP Query User{CCA8E869-B024-4B92-853E-C798E6B1B734}C:\\program files\\global star software\\airport tycoon 3\\at3.exe"= UDP:C:\program files\global star software\airport tycoon 3\at3.exe:at3
"UDP Query User{1A26D153-5B1C-49C8-96FA-38AB12A562F0}C:\\program files\\global star software\\airport tycoon 3\\at3.exe"= TCP:C:\program files\global star software\airport tycoon 3\at3.exe:at3
"{705BB267-8690-446D-A924-1C6931BB15BC}"= UDP:C:\Program Files\Sierra Entertainment\Empire Earth III Public Demo\EE3.exe:Empire Earth III Public Demo
"{0C380DC6-E75E-4142-BD01-3021C1F86EAC}"= TCP:C:\Program Files\Sierra Entertainment\Empire Earth III Public Demo\EE3.exe:Empire Earth III Public Demo
"TCP Query User{F4C3F32F-311C-4760-B505-E7EDA5C86B27}C:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= UDP:C:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"UDP Query User{776E14B8-BC85-4AF2-A0E5-4E71ECEEE152}C:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= TCP:C:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"TCP Query User{C3919812-6CB1-4E16-846C-E92D37D0706A}C:\\users\\user1\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\adjs75pn\\wowclient-downloader[1].exe"= UDP:C:\users\user1\appdata\local\microsoft\windows\temporary internet files\content.ie5\adjs75pn\wowclient-downloader[1].exe:wowclient-downloader[1].exe
"UDP Query User{B7D533B0-FCF1-429D-A14C-0FA8A4BDAA54}C:\\users\\user1\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\adjs75pn\\wowclient-downloader[1].exe"= TCP:C:\users\user1\appdata\local\microsoft\windows\temporary internet files\content.ie5\adjs75pn\wowclient-downloader[1].exe:wowclient-downloader[1].exe
"{A02B2BB9-451E-4FDA-8C52-DF9109D9D282}"= UDP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{5E8079D9-3119-4701-88C1-8B9A3293895C}"= TCP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{4A885F9F-8B87-4E2F-A92E-2889BBD37755}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{5EB48079-04B0-40C5-953B-E9D2ADCFD4DA}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{AE430C25-AB82-48ED-8ECF-5190A49347B8}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{6EE353FD-B795-4276-9C8D-2A8D95518653}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{CA23690C-D23B-48C8-B35B-127224CC3A73}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{1DA1C0E7-5ABB-403D-BB98-66D48A6A1614}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"TCP Query User{6D9E2E26-4216-4B37-BD83-A55E6660C2D4}C:\\program files\\gamespy\\comrade\\comrade.exe"= UDP:C:\program files\gamespy\comrade\comrade.exe:Comrade
"UDP Query User{2E59D275-6576-44CF-8DAD-52D49BC1A048}C:\\program files\\gamespy\\comrade\\comrade.exe"= TCP:C:\program files\gamespy\comrade\comrade.exe:Comrade
"TCP Query User{0A1BAE3A-AC45-41EC-A7B3-271394993EF2}C:\\program files\\sega\\universe at war earth assault (demo)\\uawea.exe"= UDP:C:\program files\sega\universe at war earth assault (demo)\uawea.exe:Universe at War: Earth Assault Application
"UDP Query User{D918B873-762D-4D51-8C0B-A7594DDB4A30}C:\\program files\\sega\\universe at war earth assault (demo)\\uawea.exe"= TCP:C:\program files\sega\universe at war earth assault (demo)\uawea.exe:Universe at War: Earth Assault Application
"TCP Query User{8AA720DA-A61B-4F6C-B721-6B86583225F9}C:\\program files\\sony\\station\\launchpad\\launchpad.exe"= UDP:C:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"UDP Query User{EC54C34F-6CA0-41FE-AC8A-35397714F7DD}C:\\program files\\sony\\station\\launchpad\\launchpad.exe"= TCP:C:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"{207A59AA-0736-467A-A7C8-96F6842058CB}"= UDP:5000:Potbs TCP
"{BB916884-DB04-4600-A20A-7CDF34136BC1}"= TCP:5000:Potbs UDP
"{6D87F103-2F1B-42DD-BB5B-99B67DE16A86}"= UDP:5100:Potbs TCP 2
"{D781F788-1E21-40E7-8093-C0EA613A7CC3}"= TCP:5100:Potbs UDP 2
"TCP Query User{A9B3F224-7C18-4467-93BD-ABB3F79A886D}C:\\program files\\the all-seeing eye\\eye.exe"= UDP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"UDP Query User{1E3201FF-4648-4D61-B393-A6FEAD52C495}C:\\program files\\the all-seeing eye\\eye.exe"= TCP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"TCP Query User{A63C9F19-A2EB-496E-B72A-2F6D2D35EA0A}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= UDP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{189E2AF2-6D9E-4D0B-B3A8-E3B7B1DD0587}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= TCP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{C4F5C479-5653-42E9-8F29-A0AA7D17EDD9}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:utorrent
"UDP Query User{2F88B71E-EC09-4EE8-8E13-F20969EC311C}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:utorrent
"TCP Query User{683A7516-0D70-4C40-ADF6-C2EBC4CF5085}C:\\program files\\sega\\medieval ii total war\\kingdoms.exe"= UDP:C:\program files\sega\medieval ii total war\kingdoms.exe:Medieval 2 Total War: Kingdoms
"UDP Query User{9D874333-EDE4-4C59-A7AC-55229E88C8B5}C:\\program files\\sega\\medieval ii total war\\kingdoms.exe"= TCP:C:\program files\sega\medieval ii total war\kingdoms.exe:Medieval 2 Total War: Kingdoms
"TCP Query User{17E6AB82-2FB9-4DDB-A029-E72825E00CBE}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{68509E5B-3379-432D-9B19-33F9F0563661}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{733955A7-309E-4852-A3E1-261A021F5ACF}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{A3455715-4A1C-45AC-A55A-0267256CE891}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{BA91CB80-423C-4CEA-9529-51F4BF8B4895}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{37C46250-CEF7-472E-8AD2-C1DDE56786A6}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{027944E8-EE4E-4867-A587-44983533AD94}D:\\theorangebox-jape\\team fortress 2\\hl2.exe"= UDP:D:\theorangebox-jape\team fortress 2\hl2.exe:hl2
"UDP Query User{92194552-A3BD-4FD0-9172-1020EF97DA12}D:\\theorangebox-jape\\team fortress 2\\hl2.exe"= TCP:D:\theorangebox-jape\team fortress 2\hl2.exe:hl2
"{4CAFD5BD-EBF3-44A3-92AF-926AC16D432F}"= UDP:27960:ET-one
"{DF3992B8-A4A7-44A5-8FCB-D608BC3FDDA2}"= TCP:27960:ET-two
"{430E254E-37B8-473B-B4D4-01798A7747D9}"= TCP:27950:ET 3
"{2832F24D-1F82-41FD-9315-697CE3581B42}"= TCP:27965:et4
"{1251027C-6AA6-4325-8403-983BA769D21F}"= TCP:27952:et5
"TCP Query User{7F9011F2-1FEB-4C9C-A83D-FC4D2C32A8BA}C:\\program files\\sierra entertainment\\world in conflict\\wic.exe"= UDP:C:\program files\sierra entertainment\world in conflict\wic.exe:World in Conflict
"UDP Query User{3EF21071-ADEC-4D26-BCB4-90B8D750CCB2}C:\\program files\\sierra entertainment\\world in conflict\\wic.exe"= TCP:C:\program files\sierra entertainment\world in conflict\wic.exe:World in Conflict
"{51BC4F92-723B-49F3-9358-90EEAC5FCAC8}"= TCP:27969:et..
"TCP Query User{8AD5694C-03C4-421C-8290-4A5084738EF6}D:\\ccp\\eve\\bin\\exefile.exe"= UDP:D:\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{9BC54F63-1E16-40A4-9E20-F32EC261CC57}D:\\ccp\\eve\\bin\\exefile.exe"= TCP:D:\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{188E9EA6-53D2-46A7-AACB-B63DCF0F1FE7}C:\\program files\\wolfenstein - enemy territory\\et.exe"= UDP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"UDP Query User{C1D84DF2-1F8E-4776-999E-28CDD739F339}C:\\program files\\wolfenstein - enemy territory\\et.exe"= TCP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"TCP Query User{373C17D8-6386-453F-8FD7-51AE8C64529C}C:\\program files\\sega\\medieval ii total war\\medieval2.exe"= UDP:C:\program files\sega\medieval ii total war\medieval2.exe:Medieval 2: Total War
"UDP Query User{E129DDAF-7415-4112-A633-2ABA1AC6E230}C:\\program files\\sega\\medieval ii total war\\medieval2.exe"= TCP:C:\program files\sega\medieval ii total war\medieval2.exe:Medieval 2: Total War
"{3CAB2482-CD19-48E9-871F-CF18C1A86D1B}"= TCP:20800:cod4
"{1DFFF86A-5565-41C7-8FAF-81C8B907427A}"= TCP:20810:cod4 .
"{3432590E-8B76-4461-BFC7-19A69F1F8817}"= TCP:28960:cod4 ..
"TCP Query User{0A5286D9-008B-4CC9-93C9-C17CA3E70424}C:\\program files\\silkroad\\silkerrsender.exe"= UDP:C:\program files\silkroad\silkerrsender.exe:FTPSender MFC ?? ????
"UDP Query User{AF244689-8D48-45D8-86C9-446E8D392D57}C:\\program files\\silkroad\\silkerrsender.exe"= TCP:C:\program files\silkroad\silkerrsender.exe:FTPSender MFC ?? ????
"{932A994F-9E62-4C93-8275-71959A3DC761}"= C:\Program Files\Windows Live\Messenger\wlcsdk.exe:Windows Live Messenger (Phone)
"{6D8BF470-23E4-4E76-8B14-407AB540100C}"= UDP:46615:torrent
"{AC266C30-6C7F-4EBB-A359-5EA278E2EB7E}"= TCP:46615:torrent
"{A27707C9-9800-496B-9BE7-957E876897B7}"= UDP:57613:Pando P2P TCP Listening Port
"{1457E6D0-1A26-4779-998F-2DEE8BF6D8B3}"= TCP:57613:Pando P2P UDP Listening Port
"TCP Query User{18814D7A-C477-456D-8D8C-9BF1756FF4C0}C:\\program files\\pando networks\\pando\\pando.exe"= UDP:C:\program files\pando networks\pando\pando.exe:pando
"UDP Query User{50926602-4485-4C40-9651-FDA7FA211BA4}C:\\program files\\pando networks\\pando\\pando.exe"= TCP:C:\program files\pando networks\pando\pando.exe:pando
"TCP Query User{B5FD2BAF-B1E3-4323-BD77-2C3AF23728A1}C:\\program files\\america's army\\system\\armyops.exe"= UDP:C:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{772128A2-C5D0-4F7F-B5CA-D2256885F141}C:\\program files\\america's army\\system\\armyops.exe"= TCP:C:\program files\america's army\system\armyops.exe:ArmyOps
"TCP Query User{498ED17F-0B55-4437-9E9E-35B78468D69B}C:\\program files\\scc-tds\\kane and lynch dead men\\kaneandlynch.exe"= UDP:C:\program files\scc-tds\kane and lynch dead men\kaneandlynch.exe:Kane & Lynch - Dead Men
"UDP Query User{E9CC7C54-9DAE-4162-9774-F985554D1869}C:\\program files\\scc-tds\\kane and lynch dead men\\kaneandlynch.exe"= TCP:C:\program files\scc-tds\kane and lynch dead men\kaneandlynch.exe:Kane & Lynch - Dead Men
"TCP Query User{E55B4ACC-F5F7-4CD7-9E69-C4CB352E6A80}C:\\program files\\silkroad\\nuconnector.exe"= UDP:C:\program files\silkroad\nuconnector.exe:nuConnector
"UDP Query User{6B32BE9F-F81B-4237-8314-7A4385FB9948}C:\\program files\\silkroad\\nuconnector.exe"= TCP:C:\program files\silkroad\nuconnector.exe:nuConnector
"{B5FAFEF8-B5F4-4FC1-91EB-6F55A6B32736}"= UDP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{B44BA0C0-E181-439C-B7D9-B993BE1CA600}"= TCP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"TCP Query User{37CD82C1-1DB3-4A34-BEC3-0BBA87C960FB}C:\\users\\user1\\desktop\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{E0F94EC4-9ED4-4CE6-86AC-7C8D867FB5EF}C:\\users\\user1\\desktop\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{3601AD05-76FA-4905-93F3-0C265F128CD4}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{92F443CE-D5E0-41D5-9C3A-246462C9A136}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{56233D0C-5EE9-4634-86E2-F371BFCAF68C}C:\\users\\user1\\desktop\\testport\\testport.exe"= UDP:C:\users\user1\desktop\testport\testport.exe:testport.exe
"UDP Query User{61C46BF7-F259-4F30-AE9C-F7D90AF06643}C:\\users\\user1\\desktop\\testport\\testport.exe"= TCP:C:\users\user1\desktop\testport\testport.exe:testport.exe
"{DF4BCDB6-2BA6-426C-89C3-5BC10E1EE55F}"= UDP:3640:Poison Ivy RAT
"{FD61E811-EA09-4930-8A1B-E4035CED7028}"= TCP:3640:Poison Ivy RAT
"TCP Query User{C45E8EDC-78F4-4970-AE67-904E3D03338A}C:\\users\\user1\\desktop\\nuclear-conversation-v1.0\\nuclear-conversation-v1.0\\nuclear-v1.0-server\\nuclear-conversation-server.exe"= UDP:C:\users\user1\desktop\nuclear-conversation-v1.0\nuclear-conversation-v1.0\nuclear-v1.0-server\nuclear-conversation-server.exe:nuclear-conversation-server.exe
"UDP Query User{1E786DBB-E8BD-4C5F-A7BB-C6EF0B01CC22}C:\\users\\user1\\desktop\\nuclear-conversation-v1.0\\nuclear-conversation-v1.0\\nuclear-v1.0-server\\nuclear-conversation-server.exe"= TCP:C:\users\user1\desktop\nuclear-conversation-v1.0\nuclear-conversation-v1.0\nuclear-v1.0-server\nuclear-conversation-server.exe:nuclear-conversation-server.exe
"TCP Query User{40C1CBF4-1EC4-41CF-ABD1-3B4728BB602A}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"UDP Query User{9E34939C-26AB-4740-BDA8-85FE39672E2E}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"TCP Query User{5C368A4D-9A43-4A2F-9C8A-A76D5C0DA152}C:\\users\\user1\\desktop\\package1.4v8.2\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.4v8.2\nuconnector.exe:nuconnector.exe
"UDP Query User{CCBEEF86-C518-4198-A37C-73F9CE530925}C:\\users\\user1\\desktop\\package1.4v8.2\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.4v8.2\nuconnector.exe:nuconnector.exe
"TCP Query User{136AC9B7-A32A-46F5-B844-AA02F1528C36}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{9D1F7C65-1D9D-490C-A25D-3B76DC34CBFB}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{5987B2BA-D4AF-40A8-9F2C-38B3D1867477}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{DDB2A27E-96EC-4142-8BE1-585B6EED87BC}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{62614F7B-680E-49DA-8B5A-BB9A808C9248}C:\\program files\\the all-seeing eye\\eye.exe"= UDP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"UDP Query User{6437B988-3588-4244-948E-72B74CB4BFFB}C:\\program files\\the all-seeing eye\\eye.exe"= TCP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"TCP Query User{69C9BAB0-ACB7-4F1F-B9AE-D820445BFC3C}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{EB5250C7-8684-43C8-8171-3FFDF6253FF8}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{70942965-3D97-4916-A4DF-9A97803AF9EB}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"UDP Query User{17C2519D-F574-4413-B459-448238E21604}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"{163249C5-3F4F-4AA7-AE3C-0F6D07B1E4C8}"= UDP:C:\Program Files\Midway Games\Hour of Victory\Binaries\LTCG-HOVGame.exe:Hour of Victory
"{2507907D-D035-4AB6-B286-90EEA48ED183}"= TCP:C:\Program Files\Midway Games\Hour of Victory\Binaries\LTCG-HOVGame.exe:Hour of Victory
"{A54679DD-2DB5-491A-8EEA-EE0C87EF7917}"= UDP:6889:utorrent
"{EAD5EDEA-972D-45AC-AE51-2660E2366887}"= TCP:6889:utorrent9
"TCP Query User{34EAB8C3-26E6-472D-9D47-C6D2260E8159}C:\\program files\\wow250\\wow.exe"= UDP:C:\program files\wow250\wow.exe:WOW
"UDP Query User{CFC6D76F-2E25-4D50-A1C1-A8D599979003}C:\\program files\\wow250\\wow.exe"= TCP:C:\program files\wow250\wow.exe:WOW
"{E46321F7-1C7A-4873-8AAA-4F67AB87CD5A}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{698F19AB-BEC7-4851-B6B3-020C75331A76}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{FC2ABEEF-6EC9-4E2E-A164-190A99EFF3A3}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{1E383CDB-BDA2-4329-8123-6ABC4EE1516E}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{20BD2485-288D-492D-9369-55D80A21C383}"= UDP:45682:torrent 45682
"{D3E2E255-1ACE-4123-9174-F854CD16D2CE}"= TCP:45682:torrent 45682 .
"{8C626AFF-FFCF-40C2-BEBF-73A7122C2D05}"= UDP:C:\Program Files\utorrent\utorrent.exe:µTorrent (TCP-In)
"{01A78D86-5532-4194-B944-8A47283FD69F}"= TCP:C:\Program Files\utorrent\utorrent.exe:µTorrent (UDP-In)
"{DB79AD20-AF51-4310-AEE8-0513AB4CE09F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{ED4368B8-FE52-4E7D-8B4B-FC01288D0A4D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2FCC5F07-5830-45F2-AF6F-C17142E2464F}"= UDP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\base\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire
"{F889D572-3F3B-46EE-93FC-7CC6B83FBC91}"= TCP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\base\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire
"{E587A31D-67CF-409B-BD81-353A6762EE34}"= UDP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\extra1\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire - The Eastern Realm
"{B9231AF3-26F8-44C6-A24D-272F61331B19}"= TCP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\extra1\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire - The Eastern Realm
"{B1ED6858-8CFD-4858-AF70-BAC4B8BFB563}"= UDP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:Tom Clancy's Rainbow Six Vegas 2
"{D62A6538-23C2-4776-830D-20B954545676}"= TCP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:Tom Clancy's Rainbow Six Vegas 2
"{7504C1FE-7898-4136-A44E-4757808CFC02}"= UDP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:Tom Clancy's Rainbow Six Vegas 2 Update
"{1F64A97B-843A-44B2-B9BF-54AB9BD44CD4}"= TCP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:Tom Clancy's Rainbow Six Vegas 2 Update
"{8D910C6A-0B6C-4D1A-9D25-67FA481FCB89}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{55012448-A8FC-44FC-B4DA-9C78E37B379E}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{616CC9F4-E298-4BD2-809C-56B3C7EE66F6}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{83139EC0-D1A8-4745-9967-0645227A87ED}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{B6BB7046-FA8F-4CF0-BE25-23101B62AC10}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{794C6230-7564-4C00-BADA-053BF917D758}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{077ED121-9770-47DA-AB02-5990452D1781}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{14186FB5-0EF3-4576-804D-DBDA3E037CBF}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{3D9BD3D6-5A22-4396-BB6E-6BC26A183BC4}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{359F727B-4083-4182-A072-5D61FC6BA4EB}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{1459E4E1-54F6-4A68-BF93-A4A53BE80CC7}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{7EAB4983-D3DA-4959-91E7-A8E0DD44E22E}"= UDP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{7CAA4EB5-0677-408A-9353-4827AA15610C}"= TCP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{F415D308-9377-4CFB-B693-646EC7A90F5E}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{4FC86898-73B8-45E6-B36C-27899F1BF7ED}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{4B901F93-995C-4074-8B11-C01008DCA565}"= UDP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{E4D6058C-F34A-4DCD-9AE2-B8AF34A769B6}"= TCP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{5D04B4BD-1623-4744-AC44-D3EBDDD3230A}"= UDP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{F049FDFD-FB96-489E-BC86-8A821D5AC217}"= TCP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{B8262603-475C-4178-9606-1665DBB54D5E}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{85BB0092-0CCD-4A37-B580-C54A76810B32}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{10B5666B-4478-48BA-8C7D-62DCA92B8F2A}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{84DEACFC-1B27-41B8-8534-119FD7442754}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"TCP Query User{77A5B938-EA00-4FA9-ADAA-380CD7AF09D3}C:\\program files\\ea games\\red alert 3 beta\\retailexe\\1.4\\ra3game.dat"= UDP:C:\program files\ea games\red alert 3 beta\retailexe\1.4\ra3game.dat:Command & Conquer™ Red Alert 3™
"UDP Query User{BB41E3C1-E2C8-41E3-A96D-65B92344C49B}C:\\program files\\ea games\\red alert 3 beta\\retailexe\\1.4\\ra3game.dat"= TCP:C:\program files\ea games\red alert 3 beta\retailexe\1.4\ra3game.dat:Command & Conquer™ Red Alert 3™
"{611A216E-5F64-46E9-ABAC-94B9C5EA0F98}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{4B558E0B-08A4-449C-B60A-A44AB1535BDC}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{C21440F8-7055-4ED7-804C-5839538D9160}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{BF3DF3A6-F1E5-45A2-9012-84D034354EAB}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"TCP Query User{4FCC326C-D2E6-47F9-AADD-5221F85A28DC}C:\\program files\\electronic arts\\eadm\\core.exe"= UDP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{35088126-B4BC-4185-848F-EB7EA808BF6F}C:\\program files\\electronic arts\\eadm\\core.exe"= TCP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{6008148F-FF3D-4169-B8FE-ED07C01285D7}C:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= UDP:C:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java™ Platform SE binary
"UDP Query User{3B3A6109-F594-4990-8876-53FE603BE79D}C:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= TCP:C:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java™ Platform SE binary
"TCP Query User{F19D6490-E33C-49A6-8239-A551EF96FE31}C:\\windows\\system32\\java.exe"= UDP:C:\windows\system32\java.exe:Java™ Platform SE binary
"UDP Query User{51EDFA4E-3B71-4C5B-B9A0-0535337DC2D7}C:\\windows\\system32\\java.exe"= TCP:C:\windows\system32\java.exe:Java™ Platform SE binary
"{462DDBC3-A304-4A57-8D41-F96A76B9D1BF}"= UDP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{93F030F2-3303-4C7D-BACC-83EE24BAB235}"= TCP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{91737325-4AF7-4C7E-82E6-2C385C54B1B3}"= UDP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{F4C16C5D-8BB5-4390-AA69-B72BE62EA2B3}"= TCP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"TCP Query User{44AD45DB-B100-4541-BE7A-310E1E24EA20}C:\\program files\\electronic arts\\eadm\\core.exe"= UDP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E8250F44-0481-4EB7-8135-84C07D707353}C:\\program files\\electronic arts\\eadm\\core.exe"= TCP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Configurable\System]
"Rip-Listener-1"= TCP:520|%SystemRoot%\System32\svchost.exe|Svc=iprip:@iprip.dll,-200|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"SNMP-1"= TCP:%SystemRoot%\system32\snmp.exe|Svc=SNMP:@%SystemRoot%\system32\snmp.exe,-5|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\FlashFXP\\flashfxp.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent
R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 atkdisplf;ATK Kernel Mode Enhanced Driver;C:\Windows\system32\Drivers\atkdisplowfilter.sys [2007-04-27 19968]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-07-09 20496]
R2 PSI_SVC_2;Protexis Licensing V2;c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
R2 TeamViewer;TeamViewer 3;C:\Program Files\TeamViewer3\TeamViewer_Host.exe [2008-01-28 94208]
R2 TimerStop;TimerStop;C:\Windows\system32\TimerStop.sys [2006-12-22 4096]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\Windows\system32\drivers\asusgsb.sys [2007-02-02 13184]
R3 PPPoEWin;PPPoEWin Miniport;C:\Windows\system32\DRIVERS\PPPoEWin.SYS [2002-12-26 98892]
R3 PsxDrv;PsxDrv;C:\Windows\system32\drivers\psxdrv.sys [2008-01-19 9216]
S3 msloop;Microsoft Loopback Adapter Driver;C:\Windows\system32\DRIVERS\loop.sys [2008-01-19 6656]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-06-08 87288]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S4 NetMsmqActivator;Net.Msmq Listener Adapter;C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-01-05 122880]
S4 NetPipeActivator;Net.Pipe Listener Adapter;C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-01-05 122880]
S4 NetTcpActivator;Net.Tcp Listener Adapter;C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-01-05 122880]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
rsmsvcs REG_MULTI_SZ ntmssvc
ipripsvc REG_MULTI_SZ iprip
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\start.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1dab5-5d85-11dc-8d60-001a92b14bf4}]
\shell\AutoRun\command - G:\AutoRunCD.exe
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1db44-5d85-11dc-8d60-001a92b14bf4}]
\shell\AutoRun\command - I:\SR2020-Install.exe
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
- - - - ORPHANS REMOVED - - - -
HKCU-Run-PicoZip - C:\Program Files\PicoZip\PicoZipTray.exe
HKLM-Run-GSISETUP - E:\setup.exe
HKLM-Run-RegistryMechanic - (no file)
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-NeroFilterCheck - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\1ruw3qzv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://alpha.astroempires.com/
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Download Manager\npfpdlm.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.1.0.30401.0.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2008-10-05 18:41:50
Windows 6.0.6001 Service Pack 1 NTFS
scanning hidden processes …
scanning hidden autostart entries …
scanning hidden files …
scan completed successfully
hidden files: 0
**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————
PROCESS: C:\Windows\explorer.exe
-> C:\Program Files\TortoiseSVN\iconv\_tbl_simple.so
-> C:\Program Files\TortoiseSVN\iconv\windows-1252.so
-> C:\Program Files\TortoiseSVN\iconv\utf-8.so
.
———————— Other Running Processes ————————
.
C:\Windows\System32\psxss.exe
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\CISVC.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\System32\IoctlSvc.exe
C:\Windows\System32\PnkBstrA.exe
C:\Windows\System32\TCPSVCS.EXE
C:\Windows\System32\snmp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Windows\System32\conime.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-10-05 19:03:23 - machine was rebooted [user1]
ComboFix-quarantined-files.txt 2008-10-05 17:02:28
Pre-Run: 3,226,894,336 bytes free
Post-Run: 3,127,476,224 bytes free
560 — E O F — 2008-08-06 00:01:21
and here the HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 7:08:52 PM, on 10/5/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\HJT\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.farfesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobMapUpdater] "C:\Program Files\MobMapUpdater\MobMapUpdater.exe" –silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30011 (AppHostSvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)