This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Help >.>...

13 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

First of all , i downloaded some codec like 21kb, (i know i was silly <.>) and i ran it , so i started getting warn and alarms each time i try to enter C:\ or any folder inside C:\, that i need to download some softwere , and of course i pressed No, but it's opened some webpage, i closed it fast .
i searched in google i found that i need to use FixIEDef program , i used it in normal windows mode (i have windows Vista ultimate) and i got some weird error when i ran that program , some error in line 1 , when it's stuck at scanning, so i entered safe mode and ran it, all worked fine, and it's didn't remove any thing, because he didn't find anything, so weird, i restarted, i entered my password to enter my user, it's took too much time to load and then he started sitting everything, windows explorer , windows media player etc…. and i entered to the user.. after long time of loading, it's like i into a new user , my desktop have only some icons for games.. like 4 games, and the background was black ,and my book mark is gone and my messenger chat logs are gone, i freaked out, and i couldn't open "my computer" and those, but i opened Task manager, and from there press "run" i searched into my user/documents/ , i saw that my chat logs still there.. my book marks still there.. everything, but it's like i into new user :( …
so now i on safe mode with network . talking to you guys, and i asking for help, i think that FixIEDef didn't work because of my windows, vista,
finally , here my log: (this log is copy of scan done while i in safe mode with network , if you need a scan while i in normal mode in my user, tell me ;))

Logfile of HijackThis v1.99.1
Scan saved at 9:48:53 AM, on 10/5/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)

Running processes:
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\explorer.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.farfesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 121.128.133.26 gwgt1.joymax.com
O1 - Hosts: 121.128.133.26 gwgt2.joymax.com
O1 - Hosts: 121.128.133.26 gwgt3.joymax.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Soplygui - {BCCCB3D5-17DC-43DD-9F46-A31AB28FECB2} - C:\Windows\system32\rgf.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [GSISETUP] E:\setup.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobMapUpdater] "C:\Program Files\MobMapUpdater\MobMapUpdater.exe" –silent
O4 - HKCU\..\Run: [PicoZip] C:\Program Files\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [MSFox] C:\Users\user1\AppData\Local\Temp\video41.cfg.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30011 (AppHostSvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

well, somehow i could enter to my real user, after 2 times of restart i entered to my real user all is there and fine.
but the real problem still there, many of Explorer stuff keep sucking and close, also my windows media player
and i got a picture about that warn that always keep poping up to me.
[external image: Posted Image]
and here after i press No ,
[external image: Posted Image]
(if you noticed that explorer bar is gone, it's sucked and closed.)
please… help :(
[external image: Posted Image]

Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

1. These tools MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator")


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner
Right-click ATF-Cleaner.exe and select "Run as administrator" to run the program.
Under Main choose: Select All
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.


Then:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right-click mbam-setup.exe, select "Run as administrator" and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Also "copy/paste" a new HijackThis log file into this thread.
I done exactly what you said , in safe mode with networking and here the results of Malwarebyte's Anti-Malware :
Malwarebytes' Anti-Malware 1.28
Database version: 1230
Windows 6.0.6001 Service Pack 1

10/5/2008 5:51:31 PM
mbam-log-2008-10-05 (17-51-31).txt

Scan type: Quick Scan
Objects scanned: 48752
Time elapsed: 3 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 15
Registry Values Infected: 2
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 47

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CLASSES_ROOT\monamia2 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bcccb3d5-17dc-43dd-9f46-a31ab28fecb2} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{bcccb3d5-17dc-43dd-9f46-a31ab28fecb2} (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\plodaq.bho (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59c7fc09-1c83-4648-b3e6-003d2bbc7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68af847f-6e91-45dd-9b68-d6a12c30e5d7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170b96c-28d4-4626-8358-27e6caeef907} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{d1a71fa0-ff48-48dd-9b6d-7a13a3e42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{ddb1968e-ead6-40fd-8dae-ff14757f60c7} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{f138d901-86f0-4383-99b6-9cdd406036da} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\{a7cddcdc-beeb-4685-a062-978f5e07ceee} (Adware.Shopping.Report) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWay) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\WakeNet (Trojan.Adware) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\SystemInit (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSFox (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\xdsfass (Trojan.FakeAlert) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Windows\System32\rgf.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is1163.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is11DA.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is194.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is20B2.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is2180.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is2A4.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is40D4.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is4343.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is5434.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is5D9.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is6CB3.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is6CB4.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is6E68.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is738C.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is7838.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is79C5.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_is84CE.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isA027.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isA199.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isAFBA.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isB3E4.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isC2DD.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isC3ED.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isC4C.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isD5D9.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isDA65.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isDA8.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isDADB.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isDEB7.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isE9FA.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isF091.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isF12D.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isF396.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Users\user1\AppData\Local\Temp\_isFF7F.exe (Rogue.Installer) -> Quarantined and deleted successfully.
C:\Windows\System32\m.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\System32\p.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\System32\s.ico (Malware.Trace) -> Quarantined and deleted successfully.
C:\Windows\k.txt (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\user1\Start Menu\Free MP3 Search.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\user1\Favorites\Free Porn.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\user1\Favorites\Free MP3 Search.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\user1\Start Menu\Search Online.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\user1\Desktop\????_????…doc (Trojan.Extension.Exploit) -> Quarantined and deleted successfully.
C:\Users\user1\Start Menu\Free Porn.url (Rogue.Link) -> Quarantined and deleted successfully.
C:\Users\user1\Favorites\Search Online.url (Rogue.Link) -> Quarantined and deleted successfully.


And here the Hijackthis scan results :
Logfile of HijackThis v1.99.1
Scan saved at 5:55:24 PM, on 10/5/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)

Running processes:
C:\Windows\Explorer.EXE
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.farfesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: 121.128.133.26 gwgt1.joymax.com
O1 - Hosts: 121.128.133.26 gwgt2.joymax.com
O1 - Hosts: 121.128.133.26 gwgt3.joymax.com
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [GSISETUP] E:\setup.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobMapUpdater] "C:\Program Files\MobMapUpdater\MobMapUpdater.exe" –silent
O4 - HKCU\..\Run: [PicoZip] C:\Program Files\PicoZip\PicoZipTray.exe
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30011 (AppHostSvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)


Thanks :).
- Hosts: [removed] gwgt1.joymax.com : is a IP of game, called Silkroad, i can remove those IPs from hosts file in folder system32. O4 - HKLM\..\Run: [GSISETUP] E:\setup.exe: i am not sure, in E: is a DVDRom , i have no CD/DVD in it right now. Btw, for now , the warns are gone , somehow , they might come back i am not sure, but my windows kinda damaged , windows media player still suck and close (i can keep reopen it but it's suck again and close) and also side bar … many stuff crashes but my explorer still crashing too, like when i open start main and there is some little bar for search (in vista) there when i put any letter, it's sucks… for long long time, it's like explorer is moving very slowly.
1. This tool MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator")


Download ComboFix from Here or Here to your Desktop.

In the event you already have Combofix, this is a new version that I need you to download.
It must be saved directly to your desktop.


Make sure you are disconnected from the net

1. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

  • Temporarily disable your anti-virus, script blocking and any anti-malware real-time protection before performing a scan.
  • Click on this link to see a list of programs that should be disabled. The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
  • Remember to re enable the protection again afterwards before connecting to the net

2. Close any open browsers and make sure you are disconnected from the net. Unplug the cable if need be before running combofix.
  • IF you have not already done so Combofix will disconnect your machine from the Internet when it starts.
  • If there is no internet connection when Combofix has completely finished then restart your computer to restore back the connections.

3. Now double click on combofix.exe & follow the prompts.
When finished, it will produce a report for you.
Please post the "C:\ComboFix.txt" along with a new HijackThis log for further review

Note: Do not mouseclick combofix's window while it's running. That may cause it to stall or freeze.
Give it atleast 20-30 minutes to finish if needed.
here the log of Combofix :
ComboFix 08-10-04.07 - user1 2008-10-05 18:34:13.1 - NTFSx86
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb
C:\Windows\system32\BReWErS.dll
C:\Windows\system32\tcpip.sys

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_MCHINJDRV
——-\Service_iprip


((((((((((((((((((((((((( Files Created from 2008-09-05 to 2008-10-05 )))))))))))))))))))))))))))))))
.

2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\Users\user1\AppData\Roaming\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\Users\All Users\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\ProgramData\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:47 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 17:46 . 2008-09-10 00:04 38,528 –a—— C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-05 17:46 . 2008-09-10 00:03 17,200 –a—— C:\Windows\System32\drivers\mbam.sys
2008-10-05 10:29 . 2008-10-05 11:44 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\BSplayer PRO
2008-10-05 10:20 . 2008-10-05 10:20 d——– C:\!FixIEDef
2008-10-05 09:51 . 2008-10-05 09:51 d——– C:\Program Files\ERUNT
2008-10-05 08:48 . 2008-10-05 17:55 d——– C:\Program Files\HJT
2008-10-05 08:10 . 2008-10-05 08:10 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Subversion
2008-10-05 08:06 . 2008-10-05 08:06 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Nero
2008-10-05 07:16 . 2008-10-05 07:17 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\WNR
2008-10-05 07:16 . 2008-10-05 07:16 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Skype
2008-10-04 16:41 . 2008-10-04 19:32 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-10-04 16:41 . 2008-10-04 19:32 d——– C:\ProgramData\Spybot - Search & Destroy
2008-10-04 16:41 . 2008-10-04 16:53 d——– C:\Program Files\Spybot - Search & Destroy
2008-10-04 15:15 . 2008-10-04 15:25 96,976 –a—— C:\Windows\System32\drivers\klin.dat
2008-10-04 15:15 . 2008-10-04 15:15 87,855 –a—— C:\Windows\System32\drivers\klick.dat
2008-10-04 15:14 . 2008-10-05 18:08 d——– C:\Users\All Users\Kaspersky Lab
2008-10-04 15:14 . 2008-10-05 18:08 d——– C:\ProgramData\Kaspersky Lab
2008-10-04 15:14 . 2008-10-04 15:14 d——– C:\Program Files\Kaspersky Lab
2008-10-04 15:14 . 2008-10-05 18:39 8,641,056 –ahs—- C:\Windows\System32\drivers\fidbox.dat
2008-10-04 15:14 . 2008-10-05 18:41 581,664 –ahs—- C:\Windows\System32\drivers\fidbox2.dat
2008-10-04 15:14 . 2008-10-05 18:39 69,636 –ahs—- C:\Windows\System32\drivers\fidbox.idx
2008-10-04 15:14 . 2008-10-05 18:41 4,116 –ahs—- C:\Windows\System32\drivers\fidbox2.idx
2008-10-03 14:06 . 2008-10-03 14:06 d——– C:\Users\All Users\CCP
2008-10-03 14:06 . 2008-10-03 14:06 d——– C:\ProgramData\CCP
2008-09-29 16:32 . 2008-10-03 13:56 d——– C:\CCP
2008-09-28 07:36 . 2008-09-28 07:36 d——– C:\Users\user1\AppData\Roaming\EVEMon
2008-09-28 07:36 . 2008-09-28 07:36 d——– C:\Program Files\EVEMon
2008-09-19 06:15 . 2008-09-19 06:16 d–h-c— C:\Users\All Users\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2008-09-19 06:15 . 2008-09-19 06:16 d–h-c— C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Videos
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Searches
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Saved Games
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Pictures
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Links
2008-09-14 07:04 . 2008-10-05 08:49 dr——- C:\Windows\System32\config\systemprofile\Downloads
2008-09-14 07:04 . 2008-10-05 08:17 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-09-14 07:04 . 2008-09-14 07:04 d——– C:\Users\All Users\Electronic Arts
2008-09-14 07:04 . 2008-09-14 07:04 d——– C:\ProgramData\Electronic Arts
2008-09-14 07:04 . 2008-09-14 07:04 9,576 –a—— C:\Windows\System32\ealregsnapshot1.reg
2008-09-14 06:28 . 2008-06-11 13:48 188,960 –a—— C:\Windows\System32\nvapps.xml
2008-09-13 17:13 . 2008-09-13 17:13 d——– C:\Users\user1\AppData\Roaming\SystemRequirementsLab
2008-09-10 19:01 . 2008-09-19 02:39 54,156 –ah—– C:\Windows\QTFont.qfn
2008-09-10 19:01 . 2008-09-10 19:01 1,409 –a—— C:\Windows\QTFont.for
2008-09-07 17:32 . 2008-09-27 03:25 d——– C:\Users\user1\speed racer
2008-09-07 08:08 . 2008-09-07 08:08 d——– C:\Users\Public\Public Documents

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-05 16:43 ——— d—–w C:\Users\user1\AppData\Roaming\skypePM
2008-10-05 16:43 ——— d—–w C:\Users\user1\AppData\Roaming\Skype
2008-10-05 16:43 ——— d—–w C:\Program Files\Steam
2008-10-05 16:39 ——— d—–w C:\Users\user1\AppData\Roaming\Free Download Manager
2008-10-05 06:25 ——— d—–w C:\Program Files\RegVac Registry Cleaner
2008-10-04 15:06 ——— d—–w C:\Program Files\SilkroadAddiction ecSRO
2008-10-04 12:59 ——— d—–w C:\ProgramData\Kaspersky Lab Setup Files
2008-10-04 12:05 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-04 10:48 ——— d—–w C:\Program Files\GameSpy Arcade
2008-10-04 10:41 ——— d—–w C:\Program Files\Disney Interactive Studios
2008-09-26 14:39 ——— d—–w C:\Users\user1\AppData\Roaming\uTorrent
2008-09-25 03:18 ——— d—–w C:\ProgramData\FLEXnet
2008-09-24 01:03 ——— d—–w C:\Program Files\Mass Effect
2008-09-24 01:03 ——— d—–w C:\Program Files\Common Files\BioWare
2008-09-24 01:02 ——— d—–w C:\ProgramData\Media Center Programs
2008-09-19 03:51 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-15 01:33 ——— d—–w C:\Users\user1\AppData\Roaming\FileZilla
2008-09-14 10:23 ——— d—–w C:\ProgramData\NVIDIA
2008-09-14 05:10 ——— d—–w C:\Program Files\EA Games
2008-09-14 05:07 ——— d—–w C:\Program Files\Electronic Arts
2008-09-13 15:13 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-09-09 11:37 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-09-07 10:34 ——— d—–w C:\Program Files\Messenger Plus! Live
2008-09-06 15:01 ——— d—–w C:\Users\user1\AppData\Roaming\DNA
2008-09-05 02:00 ——— d—–w C:\Program Files\Atari
2008-09-05 00:15 ——— d—–w C:\Program Files\Gravity
2008-09-03 16:44 ——— d—–w C:\Users\user1\AppData\Roaming\Printer Info Cache
2008-09-03 16:44 ——— d—–w C:\Users\user1\AppData\Roaming\Image Zone Express
2008-08-31 00:24 ——— d—–w C:\Program Files\DNA
2008-08-27 17:09 136,888 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-08-27 17:08 111,928 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-08-15 21:48 ——— d—–w C:\Users\user1\AppData\Roaming\BSplayer Pro
2008-08-13 21:09 ——— d—–w C:\Program Files\Logitech
2008-08-13 20:03 ——— d—–w C:\Program Files\Java
2008-08-13 19:21 81,920 ——w C:\Windows\bwUnin-6.1.4.36-8876480L.exe
2008-08-07 01:34 ——— d—–w C:\Users\user1\AppData\Roaming\Red Alert 3 Beta
2008-08-07 01:00 107,888 —-a-w C:\Windows\System32\CmdLineExt.dll
2008-08-07 00:45 ——— d—–w C:\Users\user1\AppData\Roaming\IGN_DLM
2008-07-29 17:21 218,376 —-a-w C:\Windows\System32\klogon.dll
2008-07-28 22:07 669,184 —-a-w C:\Windows\System32\pbsvc.exe
2008-07-28 22:07 22,328 —-a-w C:\Users\user1\AppData\Roaming\PnkBstrK.sys
2008-07-03 12:35 813,056 —-a-w C:\Users\user1\pbsetup.exe
2008-06-19 08:43 174 –sha-w C:\Program Files\desktop.ini
2008-05-16 02:16 674,600 —-a-w C:\Users\user1\pbsvc.exe
2008-04-25 00:16 32 —-a-w C:\Users\All Users\ezsid.dat
2008-04-25 00:16 32 —-a-w C:\ProgramData\ezsid.dat
2008-02-04 05:32 88 –sh–r C:\Users\All Users\39094D39B5.sys
2008-02-04 05:32 88 –sh–r C:\ProgramData\39094D39B5.sys
2008-02-04 05:32 2,828 –sha-w C:\Users\All Users\KGyGaAvL.sys
2008-02-04 05:32 2,828 –sha-w C:\ProgramData\KGyGaAvL.sys
2007-02-01 16:02 313,344 —-a-w C:\Users\user1\hjsplit.exe
2003-03-26 15:54 311,385 —-a-w C:\Program Files\dpvs.dll
2007-12-25 23:05 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-25 23:05 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-25 23:05 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"MobMapUpdater"="C:\Program Files\MobMapUpdater\MobMapUpdater.exe" [2008-03-23 1706624]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 1103480]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 22058792]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-06-08 1271032]
"PSwitch"="C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe" [2008-07-27 4426752]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2008-07-22 2772992]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
"SpybotSD TeaTimer"="C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe" [2008-09-16 1833296]
"WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-04-26 380928]
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 331776]
"HP Software Update"="C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" [2006-12-10 49152]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-11-02 286720]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 92704]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

C:\Users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-08-04 3581680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
"VIDC.XFR1"= xfcodec.dll
"msacm.divxa32"= divxa32.acm

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^user1^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
backup=C:\Windows\pss\hamachi.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSwitch

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-03-09 20:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
–a—— 2007-09-19 18:20 36864 C:\Program Files\GameSpy\Comrade\Comrade.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2007-08-16 13:24 167368 C:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2007-03-05 23:57 1103480 C:\Program Files\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a—— 2007-08-07 02:05 200704 C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-11-02 14:17 286720 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2008-04-23 16:45 22058792 C:\Program Files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\FlashFXP\\flashfxp.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FFA5B6F2-C26F-4853-BBF3-79BB4EC80E4C}"= UDP:C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"{D9F880FF-4780-46E6-8BBF-EDCED455A554}"= TCP:C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"{06AB7147-4CA6-4019-99EE-D4D9E4D8510F}"= UDP:C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{7601132C-C2CD-4755-9722-74739F1D93CC}"= TCP:C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{5BE0940B-3B79-4443-9099-7A230722CB51}"= UDP:C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{F22C1180-F102-445B-B0F9-86F8EA912D13}"= TCP:C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{B09769AF-0FE5-4B06-BFDF-CE1E6AD83CBB}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{E3D43656-14B4-44E3-8BB7-52EC739AFBE3}C:\\program files\\ubisoft\\ghost recon advanced warfighter\\graw.exe"= UDP:C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe:GRAW
"UDP Query User{A8C10895-591F-4CA3-B1BF-E609D49C953B}C:\\program files\\ubisoft\\ghost recon advanced warfighter\\graw.exe"= TCP:C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe:GRAW
"{9AD54A38-960C-4710-8831-72E54E94145F}"= UDP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{7F0A8BC8-E340-4B2D-8ADD-54BBEC67BB48}"= TCP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{A6DC8C34-F921-4E6D-B07B-1974339F455F}"= UDP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2.exe:Ghost Recon Advanced Warfighter® 2
"{9543219F-F30E-4E35-9AF6-E287680F191F}"= TCP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2.exe:Ghost Recon Advanced Warfighter® 2
"{59A005A9-425D-4F5F-8321-E605E6994CBD}"= UDP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:Ghost Recon Advanced Warfighter® 2 Dedicated Server
"{259842A2-8F7B-47D4-A4A5-670F2962887C}"= TCP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:Ghost Recon Advanced Warfighter® 2 Dedicated Server
"{EDB9306A-F556-4768-9FA6-DCD4AC9297D6}"= UDP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{7DE5E461-C472-4C67-9990-B95BC0A2AFAD}"= TCP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{679864E0-5153-40BF-A316-0550D46993B8}"= UDP:C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{BFECEDA5-1DD2-49A6-8A09-BDA60CDE5E58}"= TCP:C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"TCP Query User{A99C1663-62BC-4498-B782-1B79289A6F77}C:\\program files\\flashget\\flashget.exe"= UDP:C:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{AC616576-63DF-4A3B-9A03-61E12C77D22D}C:\\program files\\flashget\\flashget.exe"= TCP:C:\program files\flashget\flashget.exe:FlashGet
"TCP Query User{2FAE900A-D5C9-444C-B982-FC62DDE695A0}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{826E3727-A162-418C-BEA3-118F17185258}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{65A473AF-12AF-46A7-B651-459E771377B0}"= UDP:C:\Program Files\utorrent\utorrent.exe:µTorrent
"{D7C7BA9B-8AD1-401D-BB84-39B0E5050B2E}"= TCP:C:\Program Files\utorrent\utorrent.exe:µTorrent
"{22B42D2C-6A98-456E-9065-271E1E46C855}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{382EDE20-1D03-4D64-9B25-EE22F402D55B}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"TCP Query User{D4DAC1F8-310E-4913-9B83-76CF283E1924}C:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= UDP:C:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"UDP Query User{DAC07923-5E3B-4E35-A800-C5BC1A8D0379}C:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= TCP:C:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"TCP Query User{4670C380-5F6C-4D59-A2C6-53E2B6813561}C:\\windows\\system32\\dplaysvr.exe"= UDP:C:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"UDP Query User{23E2912F-6D93-4726-B252-B8424368317C}C:\\windows\\system32\\dplaysvr.exe"= TCP:C:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"TCP Query User{CA014B7F-C2A4-4423-9D7F-1B0210F53C9B}C:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= UDP:C:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"UDP Query User{1D14B836-C292-4820-B4B5-2006EB278EEA}C:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= TCP:C:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"{B0F8AD4C-AC6A-4F54-B9DB-1587C4445851}"= UDP:46615:utorrent 1
"{1CE0EC4B-197C-4E8B-BFCA-9AF0EB723AB2}"= TCP:46615:utorrent 2
"{09939247-17EE-4E69-A701-36AED499573B}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo Lite Server\etqwded.exe:Enemy Territory - QUAKE Wars™ Demo Lite Server
"{CCFCE3BB-1E04-4D44-8BDC-BFEA355EE97D}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo Lite Server\etqwded.exe:Enemy Territory - QUAKE Wars™ Demo Lite Server
"{37A13F4C-F566-47F2-80AC-C4A595B9D9C1}"= UDP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{3B2DC43E-0777-40B5-A774-FCA7299C0BBD}"= TCP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{D1A6800B-F887-4DF4-B65C-3EB18FC26D9E}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{77B5ADD9-6A77-4C65-A3B0-CA88CE8CAD69}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{38DF7FC0-61A5-491D-9BB6-CE1435E0B340}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{94C3DB7C-3B2B-4AF3-9A4F-FD1D5EB3765C}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{B6ACBA54-3DF1-4BDB-A5AB-C1EE54B2C40A}C:\\users\\user1\\desktop\\lostplanettrialdx10setup\\lostplanetdx10\\lostplanettrialdx10patch\\lost_planet_trial_dx10\\lostplanetdx10.exe"= UDP:C:\users\user1\desktop\lostplanettrialdx10setup\lostplanetdx10\lostplanettrialdx10patch\lost_planet_trial_dx10\lostplanetdx10.exe:lostplanetdx10.exe
"UDP Query User{D327D39E-EDC3-4FFC-BAA3-75ED6F9593B7}C:\\users\\user1\\desktop\\lostplanettrialdx10setup\\lostplanetdx10\\lostplanettrialdx10patch\\lost_planet_trial_dx10\\lostplanetdx10.exe"= TCP:C:\users\user1\desktop\lostplanettrialdx10setup\lostplanetdx10\lostplanettrialdx10patch\lost_planet_trial_dx10\lostplanetdx10.exe:lostplanetdx10.exe
"TCP Query User{8F3065E9-60CE-4ED4-87F3-1D3B1A8E5978}C:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= UDP:C:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"UDP Query User{B3EBDE0E-0339-4FA9-BA04-874A84FD7927}C:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= TCP:C:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"{40795003-8891-4F75-956E-F8BC84CE4C43}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{1F57DDBA-DEB4-43C1-9E91-C29FEABA07D8}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{C802490C-AC2D-447A-845D-C1E342895F8E}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{BE191FDE-3E52-47A2-B4E0-FDB0B8F13F52}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{C62ACFB7-D1A3-4CB4-93B2-B7D970E249F7}"= UDP:80:BF2142
"{44DE58B8-B353-4004-A1C9-0DA7379464AF}"= UDP:443:BF21421
"{8ADA471B-4919-427E-95F9-DE968E6D9581}"= UDP:4711:BF214211
"{696911B3-7A7A-4B0C-8F22-118C4F46D743}"= TCP:9964:BF2142
"{BCCD1151-7EB3-410A-85DF-5D3788923A21}"= TCP:16567:BF21421
"{3EE7E840-6DFC-40D1-A889-1E75950B26F1}"= UDP:1024:BF2142111
"{0B5A32F9-A79A-453C-9349-EAE2F7163FEF}"= UDP:C:\Program Files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"{A7601029-86AA-493C-996C-386E4B75E0C8}"= TCP:C:\Program Files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"TCP Query User{CCA8E869-B024-4B92-853E-C798E6B1B734}C:\\program files\\global star software\\airport tycoon 3\\at3.exe"= UDP:C:\program files\global star software\airport tycoon 3\at3.exe:at3
"UDP Query User{1A26D153-5B1C-49C8-96FA-38AB12A562F0}C:\\program files\\global star software\\airport tycoon 3\\at3.exe"= TCP:C:\program files\global star software\airport tycoon 3\at3.exe:at3
"{705BB267-8690-446D-A924-1C6931BB15BC}"= UDP:C:\Program Files\Sierra Entertainment\Empire Earth III Public Demo\EE3.exe:Empire Earth III Public Demo
"{0C380DC6-E75E-4142-BD01-3021C1F86EAC}"= TCP:C:\Program Files\Sierra Entertainment\Empire Earth III Public Demo\EE3.exe:Empire Earth III Public Demo
"TCP Query User{F4C3F32F-311C-4760-B505-E7EDA5C86B27}C:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= UDP:C:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"UDP Query User{776E14B8-BC85-4AF2-A0E5-4E71ECEEE152}C:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= TCP:C:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"TCP Query User{C3919812-6CB1-4E16-846C-E92D37D0706A}C:\\users\\user1\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\adjs75pn\\wowclient-downloader[1].exe"= UDP:C:\users\user1\appdata\local\microsoft\windows\temporary internet files\content.ie5\adjs75pn\wowclient-downloader[1].exe:wowclient-downloader[1].exe
"UDP Query User{B7D533B0-FCF1-429D-A14C-0FA8A4BDAA54}C:\\users\\user1\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\adjs75pn\\wowclient-downloader[1].exe"= TCP:C:\users\user1\appdata\local\microsoft\windows\temporary internet files\content.ie5\adjs75pn\wowclient-downloader[1].exe:wowclient-downloader[1].exe
"{A02B2BB9-451E-4FDA-8C52-DF9109D9D282}"= UDP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{5E8079D9-3119-4701-88C1-8B9A3293895C}"= TCP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{4A885F9F-8B87-4E2F-A92E-2889BBD37755}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{5EB48079-04B0-40C5-953B-E9D2ADCFD4DA}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{AE430C25-AB82-48ED-8ECF-5190A49347B8}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{6EE353FD-B795-4276-9C8D-2A8D95518653}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{CA23690C-D23B-48C8-B35B-127224CC3A73}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{1DA1C0E7-5ABB-403D-BB98-66D48A6A1614}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"TCP Query User{6D9E2E26-4216-4B37-BD83-A55E6660C2D4}C:\\program files\\gamespy\\comrade\\comrade.exe"= UDP:C:\program files\gamespy\comrade\comrade.exe:Comrade
"UDP Query User{2E59D275-6576-44CF-8DAD-52D49BC1A048}C:\\program files\\gamespy\\comrade\\comrade.exe"= TCP:C:\program files\gamespy\comrade\comrade.exe:Comrade
"TCP Query User{0A1BAE3A-AC45-41EC-A7B3-271394993EF2}C:\\program files\\sega\\universe at war earth assault (demo)\\uawea.exe"= UDP:C:\program files\sega\universe at war earth assault (demo)\uawea.exe:Universe at War: Earth Assault Application
"UDP Query User{D918B873-762D-4D51-8C0B-A7594DDB4A30}C:\\program files\\sega\\universe at war earth assault (demo)\\uawea.exe"= TCP:C:\program files\sega\universe at war earth assault (demo)\uawea.exe:Universe at War: Earth Assault Application
"TCP Query User{8AA720DA-A61B-4F6C-B721-6B86583225F9}C:\\program files\\sony\\station\\launchpad\\launchpad.exe"= UDP:C:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"UDP Query User{EC54C34F-6CA0-41FE-AC8A-35397714F7DD}C:\\program files\\sony\\station\\launchpad\\launchpad.exe"= TCP:C:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"{207A59AA-0736-467A-A7C8-96F6842058CB}"= UDP:5000:Potbs TCP
"{BB916884-DB04-4600-A20A-7CDF34136BC1}"= TCP:5000:Potbs UDP
"{6D87F103-2F1B-42DD-BB5B-99B67DE16A86}"= UDP:5100:Potbs TCP 2
"{D781F788-1E21-40E7-8093-C0EA613A7CC3}"= TCP:5100:Potbs UDP 2
"TCP Query User{A9B3F224-7C18-4467-93BD-ABB3F79A886D}C:\\program files\\the all-seeing eye\\eye.exe"= UDP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"UDP Query User{1E3201FF-4648-4D61-B393-A6FEAD52C495}C:\\program files\\the all-seeing eye\\eye.exe"= TCP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"TCP Query User{A63C9F19-A2EB-496E-B72A-2F6D2D35EA0A}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= UDP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{189E2AF2-6D9E-4D0B-B3A8-E3B7B1DD0587}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= TCP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{C4F5C479-5653-42E9-8F29-A0AA7D17EDD9}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:utorrent
"UDP Query User{2F88B71E-EC09-4EE8-8E13-F20969EC311C}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:utorrent
"TCP Query User{683A7516-0D70-4C40-ADF6-C2EBC4CF5085}C:\\program files\\sega\\medieval ii total war\\kingdoms.exe"= UDP:C:\program files\sega\medieval ii total war\kingdoms.exe:Medieval 2 Total War: Kingdoms
"UDP Query User{9D874333-EDE4-4C59-A7AC-55229E88C8B5}C:\\program files\\sega\\medieval ii total war\\kingdoms.exe"= TCP:C:\program files\sega\medieval ii total war\kingdoms.exe:Medieval 2 Total War: Kingdoms
"TCP Query User{17E6AB82-2FB9-4DDB-A029-E72825E00CBE}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{68509E5B-3379-432D-9B19-33F9F0563661}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{733955A7-309E-4852-A3E1-261A021F5ACF}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{A3455715-4A1C-45AC-A55A-0267256CE891}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{BA91CB80-423C-4CEA-9529-51F4BF8B4895}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{37C46250-CEF7-472E-8AD2-C1DDE56786A6}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{027944E8-EE4E-4867-A587-44983533AD94}D:\\theorangebox-jape\\team fortress 2\\hl2.exe"= UDP:D:\theorangebox-jape\team fortress 2\hl2.exe:hl2
"UDP Query User{92194552-A3BD-4FD0-9172-1020EF97DA12}D:\\theorangebox-jape\\team fortress 2\\hl2.exe"= TCP:D:\theorangebox-jape\team fortress 2\hl2.exe:hl2
"{4CAFD5BD-EBF3-44A3-92AF-926AC16D432F}"= UDP:27960:ET-one
"{DF3992B8-A4A7-44A5-8FCB-D608BC3FDDA2}"= TCP:27960:ET-two
"{430E254E-37B8-473B-B4D4-01798A7747D9}"= TCP:27950:ET 3
"{2832F24D-1F82-41FD-9315-697CE3581B42}"= TCP:27965:et4
"{1251027C-6AA6-4325-8403-983BA769D21F}"= TCP:27952:et5
"TCP Query User{7F9011F2-1FEB-4C9C-A83D-FC4D2C32A8BA}C:\\program files\\sierra entertainment\\world in conflict\\wic.exe"= UDP:C:\program files\sierra entertainment\world in conflict\wic.exe:World in Conflict
"UDP Query User{3EF21071-ADEC-4D26-BCB4-90B8D750CCB2}C:\\program files\\sierra entertainment\\world in conflict\\wic.exe"= TCP:C:\program files\sierra entertainment\world in conflict\wic.exe:World in Conflict
"{51BC4F92-723B-49F3-9358-90EEAC5FCAC8}"= TCP:27969:et..
"TCP Query User{8AD5694C-03C4-421C-8290-4A5084738EF6}D:\\ccp\\eve\\bin\\exefile.exe"= UDP:D:\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{9BC54F63-1E16-40A4-9E20-F32EC261CC57}D:\\ccp\\eve\\bin\\exefile.exe"= TCP:D:\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{188E9EA6-53D2-46A7-AACB-B63DCF0F1FE7}C:\\program files\\wolfenstein - enemy territory\\et.exe"= UDP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"UDP Query User{C1D84DF2-1F8E-4776-999E-28CDD739F339}C:\\program files\\wolfenstein - enemy territory\\et.exe"= TCP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"TCP Query User{373C17D8-6386-453F-8FD7-51AE8C64529C}C:\\program files\\sega\\medieval ii total war\\medieval2.exe"= UDP:C:\program files\sega\medieval ii total war\medieval2.exe:Medieval 2: Total War
"UDP Query User{E129DDAF-7415-4112-A633-2ABA1AC6E230}C:\\program files\\sega\\medieval ii total war\\medieval2.exe"= TCP:C:\program files\sega\medieval ii total war\medieval2.exe:Medieval 2: Total War
"{3CAB2482-CD19-48E9-871F-CF18C1A86D1B}"= TCP:20800:cod4
"{1DFFF86A-5565-41C7-8FAF-81C8B907427A}"= TCP:20810:cod4 .
"{3432590E-8B76-4461-BFC7-19A69F1F8817}"= TCP:28960:cod4 ..
"TCP Query User{0A5286D9-008B-4CC9-93C9-C17CA3E70424}C:\\program files\\silkroad\\silkerrsender.exe"= UDP:C:\program files\silkroad\silkerrsender.exe:FTPSender MFC ?? ????
"UDP Query User{AF244689-8D48-45D8-86C9-446E8D392D57}C:\\program files\\silkroad\\silkerrsender.exe"= TCP:C:\program files\silkroad\silkerrsender.exe:FTPSender MFC ?? ????
"{932A994F-9E62-4C93-8275-71959A3DC761}"= C:\Program Files\Windows Live\Messenger\wlcsdk.exe:Windows Live Messenger (Phone)
"{6D8BF470-23E4-4E76-8B14-407AB540100C}"= UDP:46615:torrent
"{AC266C30-6C7F-4EBB-A359-5EA278E2EB7E}"= TCP:46615:torrent
"{A27707C9-9800-496B-9BE7-957E876897B7}"= UDP:57613:Pando P2P TCP Listening Port
"{1457E6D0-1A26-4779-998F-2DEE8BF6D8B3}"= TCP:57613:Pando P2P UDP Listening Port
"TCP Query User{18814D7A-C477-456D-8D8C-9BF1756FF4C0}C:\\program files\\pando networks\\pando\\pando.exe"= UDP:C:\program files\pando networks\pando\pando.exe:pando
"UDP Query User{50926602-4485-4C40-9651-FDA7FA211BA4}C:\\program files\\pando networks\\pando\\pando.exe"= TCP:C:\program files\pando networks\pando\pando.exe:pando
"TCP Query User{B5FD2BAF-B1E3-4323-BD77-2C3AF23728A1}C:\\program files\\america's army\\system\\armyops.exe"= UDP:C:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{772128A2-C5D0-4F7F-B5CA-D2256885F141}C:\\program files\\america's army\\system\\armyops.exe"= TCP:C:\program files\america's army\system\armyops.exe:ArmyOps
"TCP Query User{498ED17F-0B55-4437-9E9E-35B78468D69B}C:\\program files\\scc-tds\\kane and lynch dead men\\kaneandlynch.exe"= UDP:C:\program files\scc-tds\kane and lynch dead men\kaneandlynch.exe:Kane & Lynch - Dead Men
"UDP Query User{E9CC7C54-9DAE-4162-9774-F985554D1869}C:\\program files\\scc-tds\\kane and lynch dead men\\kaneandlynch.exe"= TCP:C:\program files\scc-tds\kane and lynch dead men\kaneandlynch.exe:Kane & Lynch - Dead Men
"TCP Query User{E55B4ACC-F5F7-4CD7-9E69-C4CB352E6A80}C:\\program files\\silkroad\\nuconnector.exe"= UDP:C:\program files\silkroad\nuconnector.exe:nuConnector
"UDP Query User{6B32BE9F-F81B-4237-8314-7A4385FB9948}C:\\program files\\silkroad\\nuconnector.exe"= TCP:C:\program files\silkroad\nuconnector.exe:nuConnector
"{B5FAFEF8-B5F4-4FC1-91EB-6F55A6B32736}"= UDP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{B44BA0C0-E181-439C-B7D9-B993BE1CA600}"= TCP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"TCP Query User{37CD82C1-1DB3-4A34-BEC3-0BBA87C960FB}C:\\users\\user1\\desktop\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{E0F94EC4-9ED4-4CE6-86AC-7C8D867FB5EF}C:\\users\\user1\\desktop\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{3601AD05-76FA-4905-93F3-0C265F128CD4}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{92F443CE-D5E0-41D5-9C3A-246462C9A136}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{56233D0C-5EE9-4634-86E2-F371BFCAF68C}C:\\users\\user1\\desktop\\testport\\testport.exe"= UDP:C:\users\user1\desktop\testport\testport.exe:testport.exe
"UDP Query User{61C46BF7-F259-4F30-AE9C-F7D90AF06643}C:\\users\\user1\\desktop\\testport\\testport.exe"= TCP:C:\users\user1\desktop\testport\testport.exe:testport.exe
"{DF4BCDB6-2BA6-426C-89C3-5BC10E1EE55F}"= UDP:3640:Poison Ivy RAT
"{FD61E811-EA09-4930-8A1B-E4035CED7028}"= TCP:3640:Poison Ivy RAT
"TCP Query User{C45E8EDC-78F4-4970-AE67-904E3D03338A}C:\\users\\user1\\desktop\\nuclear-conversation-v1.0\\nuclear-conversation-v1.0\\nuclear-v1.0-server\\nuclear-conversation-server.exe"= UDP:C:\users\user1\desktop\nuclear-conversation-v1.0\nuclear-conversation-v1.0\nuclear-v1.0-server\nuclear-conversation-server.exe:nuclear-conversation-server.exe
"UDP Query User{1E786DBB-E8BD-4C5F-A7BB-C6EF0B01CC22}C:\\users\\user1\\desktop\\nuclear-conversation-v1.0\\nuclear-conversation-v1.0\\nuclear-v1.0-server\\nuclear-conversation-server.exe"= TCP:C:\users\user1\desktop\nuclear-conversation-v1.0\nuclear-conversation-v1.0\nuclear-v1.0-server\nuclear-conversation-server.exe:nuclear-conversation-server.exe
"TCP Query User{40C1CBF4-1EC4-41CF-ABD1-3B4728BB602A}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"UDP Query User{9E34939C-26AB-4740-BDA8-85FE39672E2E}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"TCP Query User{5C368A4D-9A43-4A2F-9C8A-A76D5C0DA152}C:\\users\\user1\\desktop\\package1.4v8.2\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.4v8.2\nuconnector.exe:nuconnector.exe
"UDP Query User{CCBEEF86-C518-4198-A37C-73F9CE530925}C:\\users\\user1\\desktop\\package1.4v8.2\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.4v8.2\nuconnector.exe:nuconnector.exe
"TCP Query User{136AC9B7-A32A-46F5-B844-AA02F1528C36}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{9D1F7C65-1D9D-490C-A25D-3B76DC34CBFB}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{5987B2BA-D4AF-40A8-9F2C-38B3D1867477}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{DDB2A27E-96EC-4142-8BE1-585B6EED87BC}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{62614F7B-680E-49DA-8B5A-BB9A808C9248}C:\\program files\\the all-seeing eye\\eye.exe"= UDP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"UDP Query User{6437B988-3588-4244-948E-72B74CB4BFFB}C:\\program files\\the all-seeing eye\\eye.exe"= TCP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"TCP Query User{69C9BAB0-ACB7-4F1F-B9AE-D820445BFC3C}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{EB5250C7-8684-43C8-8171-3FFDF6253FF8}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{70942965-3D97-4916-A4DF-9A97803AF9EB}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"UDP Query User{17C2519D-F574-4413-B459-448238E21604}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"{163249C5-3F4F-4AA7-AE3C-0F6D07B1E4C8}"= UDP:C:\Program Files\Midway Games\Hour of Victory\Binaries\LTCG-HOVGame.exe:Hour of Victory
"{2507907D-D035-4AB6-B286-90EEA48ED183}"= TCP:C:\Program Files\Midway Games\Hour of Victory\Binaries\LTCG-HOVGame.exe:Hour of Victory
"{A54679DD-2DB5-491A-8EEA-EE0C87EF7917}"= UDP:6889:utorrent
"{EAD5EDEA-972D-45AC-AE51-2660E2366887}"= TCP:6889:utorrent9
"TCP Query User{34EAB8C3-26E6-472D-9D47-C6D2260E8159}C:\\program files\\wow250\\wow.exe"= UDP:C:\program files\wow250\wow.exe:WOW
"UDP Query User{CFC6D76F-2E25-4D50-A1C1-A8D599979003}C:\\program files\\wow250\\wow.exe"= TCP:C:\program files\wow250\wow.exe:WOW
"{E46321F7-1C7A-4873-8AAA-4F67AB87CD5A}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{698F19AB-BEC7-4851-B6B3-020C75331A76}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{FC2ABEEF-6EC9-4E2E-A164-190A99EFF3A3}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{1E383CDB-BDA2-4329-8123-6ABC4EE1516E}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{20BD2485-288D-492D-9369-55D80A21C383}"= UDP:45682:torrent 45682
"{D3E2E255-1ACE-4123-9174-F854CD16D2CE}"= TCP:45682:torrent 45682 .
"{8C626AFF-FFCF-40C2-BEBF-73A7122C2D05}"= UDP:C:\Program Files\utorrent\utorrent.exe:µTorrent (TCP-In)
"{01A78D86-5532-4194-B944-8A47283FD69F}"= TCP:C:\Program Files\utorrent\utorrent.exe:µTorrent (UDP-In)
"{DB79AD20-AF51-4310-AEE8-0513AB4CE09F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{ED4368B8-FE52-4E7D-8B4B-FC01288D0A4D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2FCC5F07-5830-45F2-AF6F-C17142E2464F}"= UDP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\base\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire
"{F889D572-3F3B-46EE-93FC-7CC6B83FBC91}"= TCP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\base\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire
"{E587A31D-67CF-409B-BD81-353A6762EE34}"= UDP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\extra1\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire - The Eastern Realm
"{B9231AF3-26F8-44C6-A24D-272F61331B19}"= TCP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\extra1\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire - The Eastern Realm
"{B1ED6858-8CFD-4858-AF70-BAC4B8BFB563}"= UDP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:Tom Clancy's Rainbow Six Vegas 2
"{D62A6538-23C2-4776-830D-20B954545676}"= TCP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:Tom Clancy's Rainbow Six Vegas 2
"{7504C1FE-7898-4136-A44E-4757808CFC02}"= UDP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:Tom Clancy's Rainbow Six Vegas 2 Update
"{1F64A97B-843A-44B2-B9BF-54AB9BD44CD4}"= TCP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:Tom Clancy's Rainbow Six Vegas 2 Update
"{8D910C6A-0B6C-4D1A-9D25-67FA481FCB89}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{55012448-A8FC-44FC-B4DA-9C78E37B379E}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{616CC9F4-E298-4BD2-809C-56B3C7EE66F6}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{83139EC0-D1A8-4745-9967-0645227A87ED}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{B6BB7046-FA8F-4CF0-BE25-23101B62AC10}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{794C6230-7564-4C00-BADA-053BF917D758}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{077ED121-9770-47DA-AB02-5990452D1781}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{14186FB5-0EF3-4576-804D-DBDA3E037CBF}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{3D9BD3D6-5A22-4396-BB6E-6BC26A183BC4}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{359F727B-4083-4182-A072-5D61FC6BA4EB}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{1459E4E1-54F6-4A68-BF93-A4A53BE80CC7}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{7EAB4983-D3DA-4959-91E7-A8E0DD44E22E}"= UDP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{7CAA4EB5-0677-408A-9353-4827AA15610C}"= TCP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{F415D308-9377-4CFB-B693-646EC7A90F5E}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{4FC86898-73B8-45E6-B36C-27899F1BF7ED}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{4B901F93-995C-4074-8B11-C01008DCA565}"= UDP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{E4D6058C-F34A-4DCD-9AE2-B8AF34A769B6}"= TCP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{5D04B4BD-1623-4744-AC44-D3EBDDD3230A}"= UDP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{F049FDFD-FB96-489E-BC86-8A821D5AC217}"= TCP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{B8262603-475C-4178-9606-1665DBB54D5E}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{85BB0092-0CCD-4A37-B580-C54A76810B32}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{10B5666B-4478-48BA-8C7D-62DCA92B8F2A}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{84DEACFC-1B27-41B8-8534-119FD7442754}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"TCP Query User{77A5B938-EA00-4FA9-ADAA-380CD7AF09D3}C:\\program files\\ea games\\red alert 3 beta\\retailexe\\1.4\\ra3game.dat"= UDP:C:\program files\ea games\red alert 3 beta\retailexe\1.4\ra3game.dat:Command & Conquer™ Red Alert 3™
"UDP Query User{BB41E3C1-E2C8-41E3-A96D-65B92344C49B}C:\\program files\\ea games\\red alert 3 beta\\retailexe\\1.4\\ra3game.dat"= TCP:C:\program files\ea games\red alert 3 beta\retailexe\1.4\ra3game.dat:Command & Conquer™ Red Alert 3™
"{611A216E-5F64-46E9-ABAC-94B9C5EA0F98}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{4B558E0B-08A4-449C-B60A-A44AB1535BDC}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{C21440F8-7055-4ED7-804C-5839538D9160}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{BF3DF3A6-F1E5-45A2-9012-84D034354EAB}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"TCP Query User{4FCC326C-D2E6-47F9-AADD-5221F85A28DC}C:\\program files\\electronic arts\\eadm\\core.exe"= UDP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{35088126-B4BC-4185-848F-EB7EA808BF6F}C:\\program files\\electronic arts\\eadm\\core.exe"= TCP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{6008148F-FF3D-4169-B8FE-ED07C01285D7}C:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= UDP:C:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java™ Platform SE binary
"UDP Query User{3B3A6109-F594-4990-8876-53FE603BE79D}C:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= TCP:C:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java™ Platform SE binary
"TCP Query User{F19D6490-E33C-49A6-8239-A551EF96FE31}C:\\windows\\system32\\java.exe"= UDP:C:\windows\system32\java.exe:Java™ Platform SE binary
"UDP Query User{51EDFA4E-3B71-4C5B-B9A0-0535337DC2D7}C:\\windows\\system32\\java.exe"= TCP:C:\windows\system32\java.exe:Java™ Platform SE binary
"{462DDBC3-A304-4A57-8D41-F96A76B9D1BF}"= UDP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{93F030F2-3303-4C7D-BACC-83EE24BAB235}"= TCP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{91737325-4AF7-4C7E-82E6-2C385C54B1B3}"= UDP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{F4C16C5D-8BB5-4390-AA69-B72BE62EA2B3}"= TCP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"TCP Query User{44AD45DB-B100-4541-BE7A-310E1E24EA20}C:\\program files\\electronic arts\\eadm\\core.exe"= UDP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E8250F44-0481-4EB7-8135-84C07D707353}C:\\program files\\electronic arts\\eadm\\core.exe"= TCP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Configurable\System]
"Rip-Listener-1"= TCP:520|%SystemRoot%\System32\svchost.exe|Svc=iprip:@iprip.dll,-200|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"SNMP-1"= TCP:%SystemRoot%\system32\snmp.exe|Svc=SNMP:@%SystemRoot%\system32\snmp.exe,-5|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\FlashFXP\\flashfxp.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent

R0 klbg;Kaspersky Lab Boot Guard Driver;C:\Windows\system32\drivers\klbg.sys [2008-01-29 32784]
R1 atkdisplf;ATK Kernel Mode Enhanced Driver;C:\Windows\system32\Drivers\atkdisplowfilter.sys [2007-04-27 19968]
R1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;C:\Windows\system32\DRIVERS\klim6.sys [2008-07-09 20496]
R2 PSI_SVC_2;Protexis Licensing V2;c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe [2007-07-24 185632]
R2 SBSDWSCService;SBSD Security Center Service;C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe [2008-07-07 809296]
R2 TeamViewer;TeamViewer 3;C:\Program Files\TeamViewer3\TeamViewer_Host.exe [2008-01-28 94208]
R2 TimerStop;TimerStop;C:\Windows\system32\TimerStop.sys [2006-12-22 4096]
R3 asusgsb;ASUS Virtual Video Capture Device Driver;C:\Windows\system32\drivers\asusgsb.sys [2007-02-02 13184]
R3 PPPoEWin;PPPoEWin Miniport;C:\Windows\system32\DRIVERS\PPPoEWin.SYS [2002-12-26 98892]
R3 PsxDrv;PsxDrv;C:\Windows\system32\drivers\psxdrv.sys [2008-01-19 9216]
S3 msloop;Microsoft Loopback Adapter Driver;C:\Windows\system32\DRIVERS\loop.sys [2008-01-19 6656]
S3 Steam Client Service;Steam Client Service;C:\Program Files\Common Files\Steam\SteamService.exe [2008-06-08 87288]
S3 teamviewervpn;TeamViewer VPN Adapter;C:\Windows\system32\DRIVERS\teamviewervpn.sys [2008-01-25 25088]
S4 NetMsmqActivator;Net.Msmq Listener Adapter;C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-01-05 122880]
S4 NetPipeActivator;Net.Pipe Listener Adapter;C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-01-05 122880]
S4 NetTcpActivator;Net.Tcp Listener Adapter;C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2008-01-05 122880]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
rsmsvcs REG_MULTI_SZ ntmssvc
ipripsvc REG_MULTI_SZ iprip

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\start.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1dab5-5d85-11dc-8d60-001a92b14bf4}]
\shell\AutoRun\command - G:\AutoRunCD.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1db44-5d85-11dc-8d60-001a92b14bf4}]
\shell\AutoRun\command - I:\SR2020-Install.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-PicoZip - C:\Program Files\PicoZip\PicoZipTray.exe
HKLM-Run-GSISETUP - E:\setup.exe
HKLM-Run-RegistryMechanic - (no file)
MSConfigStartUp-BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} - C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
MSConfigStartUp-NeroFilterCheck - C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe


.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\1ruw3qzv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://alpha.astroempires.com/
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Download Manager\npfpdlm.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.1.0.30401.0.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-05 18:41:50
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\Windows\explorer.exe
-> C:\Program Files\TortoiseSVN\iconv\_tbl_simple.so
-> C:\Program Files\TortoiseSVN\iconv\windows-1252.so
-> C:\Program Files\TortoiseSVN\iconv\utf-8.so
.
———————— Other Running Processes ————————
.
C:\Windows\System32\psxss.exe
C:\Windows\System32\nvvsvc.exe
C:\Windows\System32\audiodg.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\System32\CISVC.EXE
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Common Files\microsoft shared\VS7DEBUG\mdm.exe
C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
C:\Windows\System32\IoctlSvc.exe
C:\Windows\System32\PnkBstrA.exe
C:\Windows\System32\TCPSVCS.EXE
C:\Windows\System32\snmp.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
C:\Windows\System32\conime.exe
C:\Windows\System32\rundll32.exe
C:\Windows\System32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\dllhost.exe
.
**************************************************************************
.
Completion time: 2008-10-05 19:03:23 - machine was rebooted [user1]
ComboFix-quarantined-files.txt 2008-10-05 17:02:28

Pre-Run: 3,226,894,336 bytes free
Post-Run: 3,127,476,224 bytes free

560 — E O F — 2008-08-06 00:01:21




and here the HijackThis log:
Logfile of HijackThis v1.99.1
Scan saved at 7:08:52 PM, on 10/5/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\conime.exe
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.farfesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D; IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobMapUpdater] "C:\Program Files\MobMapUpdater\MobMapUpdater.exe" –silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30011 (AppHostSvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
wmpnetwk.exe is part of Windows Media Player. It provides the "network services" of the player. WMP should contain a control to disable networking. If you can find it, use it to turn it off.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

Folder::
C:\Program Files\Bonjour

Registry::
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1dab5-5d85-11dc-8d60-001a92b14bf4}]
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1db44-5d85-11dc-8d60-001a92b14bf4}]

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
Somehow it's still the same :S! , thats so weird how explorer keep sucking , i can't move file from place to other without sucking … weird >.>
and here the HijackThis log file :

Logfile of HijackThis v1.99.1
Scan saved at 7:47:57 PM, on 10/5/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\system32\conime.exe
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\rundll32.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\explorer.exe
C:\Windows\system32\notepad.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Program Files\Java\jre1.6.0_07\launch4j-tmp\JDownloader.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\cmd.execf
C:\32788R22FWJFW\sed.cfexe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.farfesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobMapUpdater] "C:\Program Files\MobMapUpdater\MobMapUpdater.exe" –silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30011 (AppHostSvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]



    You need To disable TeaTimer, it can stop our fix.

    The best way is to do both, Right click the system tray icon and shut down. This will reset TT's registry snapshot. Then, open spybot in advanced mode and turn it off. When cleaning is done, open Spybot in advanced mode to turn back on. Once fix is completed in the all clear post!!


    Run hijackthis. Hit None of the above, Click Do a System Scan Only. Put a checkmark/tick in the box on the left side on these:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

    Close ALL windows and browsers except HijackThis and click "Fix checked"


    Reboot and "copy/paste" a new HijackThis log file into this thread.

    Also please describe how your computer behaves at the moment.
Here the log from Combofix :
ComboFix 08-10-04.07 - user1 2008-10-06 3:02:04.2 - NTFSx86
Running from: C:\Users\[removed]\Desktop\ComboFix.exe
.

((((((((((((((((((((((((( Files Created from 2008-09-06 to 2008-10-06 )))))))))))))))))))))))))))))))
.

2008-10-05 19:45 . 2008-10-06 03:01 d——– C:\32788R22FWJFW
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\Users\user1\AppData\Roaming\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\Users\All Users\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:46 d——– C:\ProgramData\Malwarebytes
2008-10-05 17:46 . 2008-10-05 17:47 d——– C:\Program Files\Malwarebytes' Anti-Malware
2008-10-05 17:46 . 2008-09-10 00:04 38,528 –a—— C:\Windows\System32\drivers\mbamswissarmy.sys
2008-10-05 17:46 . 2008-09-10 00:03 17,200 –a—— C:\Windows\System32\drivers\mbam.sys
2008-10-05 10:29 . 2008-10-05 11:44 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\BSplayer PRO
2008-10-05 10:20 . 2008-10-05 10:20 d——– C:\!FixIEDef
2008-10-05 09:51 . 2008-10-05 09:51 d——– C:\Program Files\ERUNT
2008-10-05 08:48 . 2008-10-06 03:01 d——– C:\Program Files\HJT
2008-10-05 08:10 . 2008-10-05 08:10 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Subversion
2008-10-05 08:06 . 2008-10-05 08:06 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Nero
2008-10-05 07:16 . 2008-10-05 07:17 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\WNR
2008-10-05 07:16 . 2008-10-05 07:16 d——– C:\Windows\System32\config\systemprofile\AppData\Roaming\Skype
2008-10-04 16:41 . 2008-10-04 19:32 d——– C:\Users\All Users\Spybot - Search & Destroy
2008-10-04 16:41 . 2008-10-04 19:32 d——– C:\ProgramData\Spybot - Search & Destroy
2008-10-04 16:41 . 2008-10-04 16:53 d——– C:\Program Files\Spybot - Search & Destroy
2008-10-04 15:15 . 2008-10-04 15:25 96,976 –a—— C:\Windows\System32\drivers\klin.dat
2008-10-04 15:15 . 2008-10-04 15:15 87,855 –a—— C:\Windows\System32\drivers\klick.dat
2008-10-04 15:14 . 2008-10-06 02:53 d——– C:\Users\All Users\Kaspersky Lab
2008-10-04 15:14 . 2008-10-06 02:53 d——– C:\ProgramData\Kaspersky Lab
2008-10-04 15:14 . 2008-10-04 15:14 d——– C:\Program Files\Kaspersky Lab
2008-10-04 15:14 . 2008-10-05 18:39 8,641,056 –ahs—- C:\Windows\System32\drivers\fidbox.dat
2008-10-04 15:14 . 2008-10-05 19:45 630,816 –ahs—- C:\Windows\System32\drivers\fidbox2.dat
2008-10-04 15:14 . 2008-10-05 18:39 69,636 –ahs—- C:\Windows\System32\drivers\fidbox.idx
2008-10-04 15:14 . 2008-10-05 19:45 4,284 –ahs—- C:\Windows\System32\drivers\fidbox2.idx
2008-10-03 14:06 . 2008-10-03 14:06 d——– C:\Users\All Users\CCP
2008-10-03 14:06 . 2008-10-03 14:06 d——– C:\ProgramData\CCP
2008-09-29 16:32 . 2008-10-03 13:56 d——– C:\CCP
2008-09-28 07:36 . 2008-09-28 07:36 d——– C:\Users\user1\AppData\Roaming\EVEMon
2008-09-28 07:36 . 2008-09-28 07:36 d——– C:\Program Files\EVEMon
2008-09-19 06:15 . 2008-09-19 06:16 d–h-c— C:\Users\All Users\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2008-09-19 06:15 . 2008-09-19 06:16 d–h-c— C:\ProgramData\{0691F710-1ECA-4B5A-9727-25554F1BFDC6}
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Videos
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Searches
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Saved Games
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Pictures
2008-09-14 07:04 . 2008-09-14 07:04 dr——- C:\Windows\System32\config\systemprofile\Links
2008-09-14 07:04 . 2008-10-05 08:49 dr——- C:\Windows\System32\config\systemprofile\Downloads
2008-09-14 07:04 . 2008-10-05 08:17 dr——- C:\Windows\System32\config\systemprofile\Documents
2008-09-14 07:04 . 2008-09-14 07:04 d——– C:\Users\All Users\Electronic Arts
2008-09-14 07:04 . 2008-09-14 07:04 d——– C:\ProgramData\Electronic Arts
2008-09-14 07:04 . 2008-09-14 07:04 9,576 –a—— C:\Windows\System32\ealregsnapshot1.reg
2008-09-14 06:28 . 2008-06-11 13:48 188,960 –a—— C:\Windows\System32\nvapps.xml
2008-09-13 17:13 . 2008-09-13 17:13 d——– C:\Users\user1\AppData\Roaming\SystemRequirementsLab
2008-09-10 19:01 . 2008-09-19 02:39 54,156 –ah—– C:\Windows\QTFont.qfn
2008-09-10 19:01 . 2008-09-10 19:01 1,409 –a—— C:\Windows\QTFont.for
2008-09-07 17:32 . 2008-09-27 03:25 d——– C:\Users\user1\speed racer
2008-09-07 08:08 . 2008-09-07 08:08 d——– C:\Users\Public\Public Documents

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-06 00:54 ——— d—–w C:\Users\user1\AppData\Roaming\Skype
2008-10-06 00:54 ——— d—–w C:\Program Files\Steam
2008-10-05 16:43 ——— d—–w C:\Users\user1\AppData\Roaming\skypePM
2008-10-05 16:39 ——— d—–w C:\Users\user1\AppData\Roaming\Free Download Manager
2008-10-05 06:25 ——— d—–w C:\Program Files\RegVac Registry Cleaner
2008-10-04 15:06 ——— d—–w C:\Program Files\SilkroadAddiction ecSRO
2008-10-04 12:59 ——— d—–w C:\ProgramData\Kaspersky Lab Setup Files
2008-10-04 12:05 ——— d—–w C:\Program Files\Microsoft Silverlight
2008-10-04 10:48 ——— d—–w C:\Program Files\GameSpy Arcade
2008-10-04 10:41 ——— d—–w C:\Program Files\Disney Interactive Studios
2008-09-26 14:39 ——— d—–w C:\Users\user1\AppData\Roaming\uTorrent
2008-09-25 03:18 ——— d—–w C:\ProgramData\FLEXnet
2008-09-24 01:03 ——— d—–w C:\Program Files\Mass Effect
2008-09-24 01:03 ——— d—–w C:\Program Files\Common Files\BioWare
2008-09-24 01:02 ——— d—–w C:\ProgramData\Media Center Programs
2008-09-19 03:51 ——— d–h–w C:\Program Files\InstallShield Installation Information
2008-09-15 01:33 ——— d—–w C:\Users\user1\AppData\Roaming\FileZilla
2008-09-14 10:23 ——— d—–w C:\ProgramData\NVIDIA
2008-09-14 05:10 ——— d—–w C:\Program Files\EA Games
2008-09-14 05:07 ——— d—–w C:\Program Files\Electronic Arts
2008-09-13 15:13 ——— d—–w C:\Program Files\SystemRequirementsLab
2008-09-09 11:37 ——— d—–w C:\Program Files\Common Files\Blizzard Entertainment
2008-09-07 10:34 ——— d—–w C:\Program Files\Messenger Plus! Live
2008-09-06 15:01 ——— d—–w C:\Users\user1\AppData\Roaming\DNA
2008-09-05 02:00 ——— d—–w C:\Program Files\Atari
2008-09-05 00:15 ——— d—–w C:\Program Files\Gravity
2008-09-03 16:44 ——— d—–w C:\Users\user1\AppData\Roaming\Printer Info Cache
2008-09-03 16:44 ——— d—–w C:\Users\user1\AppData\Roaming\Image Zone Express
2008-08-31 00:24 ——— d—–w C:\Program Files\DNA
2008-08-27 17:09 136,888 —-a-w C:\Windows\system32\drivers\PnkBstrK.sys
2008-08-27 17:08 111,928 —-a-w C:\Windows\System32\PnkBstrB.exe
2008-08-15 21:48 ——— d—–w C:\Users\user1\AppData\Roaming\BSplayer Pro
2008-08-13 21:09 ——— d—–w C:\Program Files\Logitech
2008-08-13 20:03 ——— d—–w C:\Program Files\Java
2008-08-13 19:21 81,920 ——w C:\Windows\bwUnin-6.1.4.36-8876480L.exe
2008-08-07 01:34 ——— d—–w C:\Users\user1\AppData\Roaming\Red Alert 3 Beta
2008-08-07 01:00 107,888 —-a-w C:\Windows\System32\CmdLineExt.dll
2008-08-07 00:45 ——— d—–w C:\Users\user1\AppData\Roaming\IGN_DLM
2008-07-29 17:21 218,376 —-a-w C:\Windows\System32\klogon.dll
2008-07-28 22:07 669,184 —-a-w C:\Windows\System32\pbsvc.exe
2008-07-28 22:07 22,328 —-a-w C:\Users\user1\AppData\Roaming\PnkBstrK.sys
2008-07-03 12:35 813,056 —-a-w C:\Users\user1\pbsetup.exe
2008-06-19 08:43 174 –sha-w C:\Program Files\desktop.ini
2008-05-16 02:16 674,600 —-a-w C:\Users\user1\pbsvc.exe
2008-04-25 00:16 32 —-a-w C:\Users\All Users\ezsid.dat
2008-04-25 00:16 32 —-a-w C:\ProgramData\ezsid.dat
2008-02-04 05:32 88 –sh–r C:\Users\All Users\39094D39B5.sys
2008-02-04 05:32 88 –sh–r C:\ProgramData\39094D39B5.sys
2008-02-04 05:32 2,828 –sha-w C:\Users\All Users\KGyGaAvL.sys
2008-02-04 05:32 2,828 –sha-w C:\ProgramData\KGyGaAvL.sys
2007-02-01 16:02 313,344 —-a-w C:\Users\user1\hjsplit.exe
2003-03-26 15:54 311,385 —-a-w C:\Program Files\dpvs.dll
2007-12-25 23:05 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2007-12-25 23:05 32,768 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2007-12-25 23:05 16,384 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.

((((((((((((((((((((((((((((( snapshot@2008-10-05_19.00.15.91 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-10-05 16:40:58 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-10-06 00:53:15 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2008-10-06 00:53:15 2,048 –sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2008-10-05 16:41:14 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-10-06 01:02:08 262,144 –sha-w C:\Windows\ServiceProfiles\LocalService\NTUSER.DAT
+ 2008-10-06 01:02:08 262,144 —ha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat.LOG1
- 2008-10-05 16:41:14 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-10-06 00:54:38 262,144 –sha-w C:\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
+ 2008-10-06 00:54:38 262,144 —ha-w C:\Windows\ServiceProfiles\NetworkService\ntuser.dat.LOG1
- 2008-10-05 16:06:36 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-10-06 00:51:22 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-10-05 17:07:07 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.dat
+ 2008-10-05 17:07:07 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.dat
- 2008-10-05 16:06:36 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-10-06 00:51:22 32,768 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-10-05 17:07:07 16,384 –sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\Low\index.dat
- 2008-10-05 13:19:55 124,864 —-a-w C:\Windows\System32\perfc009.dat
+ 2008-10-05 16:48:32 125,242 —-a-w C:\Windows\System32\perfc009.dat
- 2008-10-05 13:19:55 661,372 —-a-w C:\Windows\System32\perfh009.dat
+ 2008-10-05 16:48:32 662,120 —-a-w C:\Windows\System32\perfh009.dat
- 2008-10-05 16:09:04 11,322 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1157615157-3725563054-3644101930-1000_UserData.bin
+ 2008-10-06 00:55:08 11,632 —-a-w C:\Windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1157615157-3725563054-3644101930-1000_UserData.bin
- 2008-10-05 16:09:04 81,560 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
+ 2008-10-06 00:55:07 81,794 —-a-w C:\Windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\1TortoiseSVN]
@="{30351346-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351346-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\2TortoiseSVN]
@="{30351347-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351347-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\3TortoiseSVN]
@="{30351348-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{30351348-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\4TortoiseSVN]
@="{3035134B-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134B-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\5TortoiseSVN]
@="{3035134C-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134C-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\6TortoiseSVN]
@="{3035134D-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134D-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\7TortoiseSVN]
@="{3035134E-7B7D-4FCC-81B4-1E394CA267EB}"
[HKEY_CLASSES_ROOT\CLSID\{3035134E-7B7D-4FCC-81B4-1E394CA267EB}]
2008-02-16 11:35 536576 –a—— C:\Program Files\TortoiseSVN\bin\tortoisesvn.dll

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-19 1233920]
"MsnMsgr"="C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184]
"ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2008-01-19 125952]
"MobMapUpdater"="C:\Program Files\MobMapUpdater\MobMapUpdater.exe" [2008-03-23 1706624]
"Yahoo! Pager"="C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" [2007-08-30 4670704]
"igndlm.exe"="C:\Program Files\Download Manager\DLM.exe" [2007-03-05 1103480]
"Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-04-23 22058792]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-06-08 1271032]
"PSwitch"="C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe" [2008-07-27 4426752]
"EA Core"="C:\Program Files\Electronic Arts\EADM\Core.exe" [2008-07-22 2772992]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-08-16 167368]
"PicoZip"="C:\Program Files\PicoZip\PicoZipTray.exe" [BU]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ASUSGamerOSD"="C:\Program Files\ASUS\GamerOSD\GamerOSD.exe" [2007-04-26 380928]
"AGEIA PhysX SysTray"="C:\Program Files\AGEIA Technologies\TrayIcon.exe" [2006-03-20 331776]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 39792]
"SoundMAXPnP"="C:\Program Files\Analog Devices\Core\smax4pnp.exe" [2006-12-18 868352]
"NBKeyScan"="C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2008-06-08 2221352]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-05-16 13535776]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-05-16 92704]
"AVP"="C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" [2008-07-29 206088]
"GSISETUP"="E:\setup.exe" [BU]
"RegistryMechanic"="" [BU]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

C:\Users\user1\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Stardock ObjectDock.lnk - C:\Program Files\Stardock\ObjectDock\ObjectDock.exe [2008-08-04 3581680]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system]
"LogonHoursAction"= 2 (0x2)
"DontDisplayLogonHoursWarnings"= 1 (0x1)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.avis"= ff_acm.acm
"VIDC.XFR1"= xfcodec.dll
"msacm.divxa32"= divxa32.acm

[HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk]
path=C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
backup=C:\Windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup
backupExtension=.CommonStartup

[HKLM\~\startupfolder\C:^Users^user1^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^hamachi.lnk]
backup=C:\Windows\pss\hamachi.lnk.Startup
backupExtension=.Startup
HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PSwitch

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader]
–a—— 2007-03-09 20:09 63712 C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher]
–a—— 2008-01-11 22:16 39792 C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Comrade.exe]
–a—— 2007-09-19 18:20 36864 C:\Program Files\GameSpy\Comrade\Comrade.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\DAEMON Tools]
–a—— 2007-08-16 13:24 167368 C:\Program Files\DAEMON Tools\daemon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
–a—— 2007-03-05 23:57 1103480 C:\Program Files\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\PWRISOVM.EXE]
–a—— 2007-08-07 02:05 200704 C:\Program Files\PowerISO\PWRISOVM.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
–a—— 2007-11-02 14:17 286720 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype]
-ra—— 2008-04-23 16:45 22058792 C:\Program Files\Skype\Phone\Skype.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile\AuthorizedApplications\List]
"C:\\Program Files\\FlashFXP\\flashfxp.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{FFA5B6F2-C26F-4853-BBF3-79BB4EC80E4C}"= UDP:C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"{D9F880FF-4780-46E6-8BBF-EDCED455A554}"= TCP:C:\Program Files\Grisoft\AVG7\avginet.exe:avginet.exe
"{06AB7147-4CA6-4019-99EE-D4D9E4D8510F}"= UDP:C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{7601132C-C2CD-4755-9722-74739F1D93CC}"= TCP:C:\Program Files\Grisoft\AVG7\avgamsvr.exe:avgamsvr.exe
"{5BE0940B-3B79-4443-9099-7A230722CB51}"= UDP:C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{F22C1180-F102-445B-B0F9-86F8EA912D13}"= TCP:C:\Program Files\Grisoft\AVG7\avgcc.exe:avgcc.exe
"{B09769AF-0FE5-4B06-BFDF-CE1E6AD83CBB}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"TCP Query User{E3D43656-14B4-44E3-8BB7-52EC739AFBE3}C:\\program files\\ubisoft\\ghost recon advanced warfighter\\graw.exe"= UDP:C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe:GRAW
"UDP Query User{A8C10895-591F-4CA3-B1BF-E609D49C953B}C:\\program files\\ubisoft\\ghost recon advanced warfighter\\graw.exe"= TCP:C:\program files\ubisoft\ghost recon advanced warfighter\graw.exe:GRAW
"{9AD54A38-960C-4710-8831-72E54E94145F}"= UDP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{7F0A8BC8-E340-4B2D-8ADD-54BBEC67BB48}"= TCP:C:\Program Files\GameSpy Arcade\Aphex.exe:GameSpy Arcade
"{A6DC8C34-F921-4E6D-B07B-1974339F455F}"= UDP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2.exe:Ghost Recon Advanced Warfighter® 2
"{9543219F-F30E-4E35-9AF6-E287680F191F}"= TCP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2.exe:Ghost Recon Advanced Warfighter® 2
"{59A005A9-425D-4F5F-8321-E605E6994CBD}"= UDP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:Ghost Recon Advanced Warfighter® 2 Dedicated Server
"{259842A2-8F7B-47D4-A4A5-670F2962887C}"= TCP:C:\Program Files\Ubisoft\Ghost Recon Advanced Warfighter 2\graw2_dedicated.exe:Ghost Recon Advanced Warfighter® 2 Dedicated Server
"{EDB9306A-F556-4768-9FA6-DCD4AC9297D6}"= UDP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{7DE5E461-C472-4C67-9990-B95BC0A2AFAD}"= TCP:C:\Program Files\THQ\Gas Powered Games\GPGNet\GPG.Multiplayer.Client.exe:GPGNet - Supreme Commander
"{679864E0-5153-40BF-A316-0550D46993B8}"= UDP:C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"{BFECEDA5-1DD2-49A6-8A09-BDA60CDE5E58}"= TCP:C:\Program Files\Electronic Arts\Medal of Honor Airborne\UnrealEngine3\Binaries\MOHA.exe:Medal of Honor Airborne
"TCP Query User{A99C1663-62BC-4498-B782-1B79289A6F77}C:\\program files\\flashget\\flashget.exe"= UDP:C:\program files\flashget\flashget.exe:FlashGet
"UDP Query User{AC616576-63DF-4A3B-9A03-61E12C77D22D}C:\\program files\\flashget\\flashget.exe"= TCP:C:\program files\flashget\flashget.exe:FlashGet
"TCP Query User{2FAE900A-D5C9-444C-B982-FC62DDE695A0}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{826E3727-A162-418C-BEA3-118F17185258}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{65A473AF-12AF-46A7-B651-459E771377B0}"= UDP:C:\Program Files\utorrent\utorrent.exe:µTorrent
"{D7C7BA9B-8AD1-401D-BB84-39B0E5050B2E}"= TCP:C:\Program Files\utorrent\utorrent.exe:µTorrent
"{22B42D2C-6A98-456E-9065-271E1E46C855}"= UDP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"{382EDE20-1D03-4D64-9B25-EE22F402D55B}"= TCP:C:\Program Files\EA GAMES\Battlefield 2\BF2.exe:Battlefield 2
"TCP Query User{D4DAC1F8-310E-4913-9B83-76CF283E1924}C:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= UDP:C:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"UDP Query User{DAC07923-5E3B-4E35-A800-C5BC1A8D0379}C:\\program files\\ea games\\battlefield 2\\bf2_w32ded.exe"= TCP:C:\program files\ea games\battlefield 2\bf2_w32ded.exe:Bf2_w32ded
"TCP Query User{4670C380-5F6C-4D59-A2C6-53E2B6813561}C:\\windows\\system32\\dplaysvr.exe"= UDP:C:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"UDP Query User{23E2912F-6D93-4726-B252-B8424368317C}C:\\windows\\system32\\dplaysvr.exe"= TCP:C:\windows\system32\dplaysvr.exe:Microsoft DirectPlay Helper
"TCP Query User{CA014B7F-C2A4-4423-9D7F-1B0210F53C9B}C:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= UDP:C:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"UDP Query User{1D14B836-C292-4820-B4B5-2006EB278EEA}C:\\program files\\g2 games\\enemy engaged 2\\cohokum\\ee2.exe"= TCP:C:\program files\g2 games\enemy engaged 2\cohokum\ee2.exe:ee2
"{B0F8AD4C-AC6A-4F54-B9DB-1587C4445851}"= UDP:46615:utorrent 1
"{1CE0EC4B-197C-4E8B-BFCA-9AF0EB723AB2}"= TCP:46615:utorrent 2
"{09939247-17EE-4E69-A701-36AED499573B}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo Lite Server\etqwded.exe:Enemy Territory - QUAKE Wars™ Demo Lite Server
"{CCFCE3BB-1E04-4D44-8BDC-BFEA355EE97D}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars Demo Lite Server\etqwded.exe:Enemy Territory - QUAKE Wars™ Demo Lite Server
"{37A13F4C-F566-47F2-80AC-C4A595B9D9C1}"= UDP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{3B2DC43E-0777-40B5-A774-FCA7299C0BBD}"= TCP:C:\Program Files\Midway Games\Rise and Fall\RiseAndFall.exe:Rise and Fall: Civilizations at War
"{D1A6800B-F887-4DF4-B65C-3EB18FC26D9E}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{77B5ADD9-6A77-4C65-A3B0-CA88CE8CAD69}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{38DF7FC0-61A5-491D-9BB6-CE1435E0B340}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{94C3DB7C-3B2B-4AF3-9A4F-FD1D5EB3765C}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{B6ACBA54-3DF1-4BDB-A5AB-C1EE54B2C40A}C:\\users\\user1\\desktop\\lostplanettrialdx10setup\\lostplanetdx10\\lostplanettrialdx10patch\\lost_planet_trial_dx10\\lostplanetdx10.exe"= UDP:C:\users\user1\desktop\lostplanettrialdx10setup\lostplanetdx10\lostplanettrialdx10patch\lost_planet_trial_dx10\lostplanetdx10.exe:lostplanetdx10.exe
"UDP Query User{D327D39E-EDC3-4FFC-BAA3-75ED6F9593B7}C:\\users\\user1\\desktop\\lostplanettrialdx10setup\\lostplanetdx10\\lostplanettrialdx10patch\\lost_planet_trial_dx10\\lostplanetdx10.exe"= TCP:C:\users\user1\desktop\lostplanettrialdx10setup\lostplanetdx10\lostplanettrialdx10patch\lost_planet_trial_dx10\lostplanetdx10.exe:lostplanetdx10.exe
"TCP Query User{8F3065E9-60CE-4ED4-87F3-1D3B1A8E5978}C:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= UDP:C:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"UDP Query User{B3EBDE0E-0339-4FA9-BA04-874A84FD7927}C:\\program files\\capcom\\lost_planet_trial_dx10\\lostplanetdx10.exe"= TCP:C:\program files\capcom\lost_planet_trial_dx10\lostplanetdx10.exe:LostPlanetDX10
"{40795003-8891-4F75-956E-F8BC84CE4C43}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{1F57DDBA-DEB4-43C1-9E91-C29FEABA07D8}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqwded.exe:etqwded.exe
"{C802490C-AC2D-447A-845D-C1E342895F8E}"= UDP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{BE191FDE-3E52-47A2-B4E0-FDB0B8F13F52}"= TCP:C:\Program Files\id Software\Enemy Territory - QUAKE Wars\etqw.exe:Enemy Territory - QUAKE Wars™
"{C62ACFB7-D1A3-4CB4-93B2-B7D970E249F7}"= UDP:80:BF2142
"{44DE58B8-B353-4004-A1C9-0DA7379464AF}"= UDP:443:BF21421
"{8ADA471B-4919-427E-95F9-DE968E6D9581}"= UDP:4711:BF214211
"{696911B3-7A7A-4B0C-8F22-118C4F46D743}"= TCP:9964:BF2142
"{BCCD1151-7EB3-410A-85DF-5D3788923A21}"= TCP:16567:BF21421
"{3EE7E840-6DFC-40D1-A889-1E75950B26F1}"= UDP:1024:BF2142111
"{0B5A32F9-A79A-453C-9349-EAE2F7163FEF}"= UDP:C:\Program Files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"{A7601029-86AA-493C-996C-386E4B75E0C8}"= TCP:C:\Program Files\THQ\Company of Heroes\RelicCOH.exe:Company of Heroes - Opposing Fronts
"TCP Query User{CCA8E869-B024-4B92-853E-C798E6B1B734}C:\\program files\\global star software\\airport tycoon 3\\at3.exe"= UDP:C:\program files\global star software\airport tycoon 3\at3.exe:at3
"UDP Query User{1A26D153-5B1C-49C8-96FA-38AB12A562F0}C:\\program files\\global star software\\airport tycoon 3\\at3.exe"= TCP:C:\program files\global star software\airport tycoon 3\at3.exe:at3
"{705BB267-8690-446D-A924-1C6931BB15BC}"= UDP:C:\Program Files\Sierra Entertainment\Empire Earth III Public Demo\EE3.exe:Empire Earth III Public Demo
"{0C380DC6-E75E-4142-BD01-3021C1F86EAC}"= TCP:C:\Program Files\Sierra Entertainment\Empire Earth III Public Demo\EE3.exe:Empire Earth III Public Demo
"TCP Query User{F4C3F32F-311C-4760-B505-E7EDA5C86B27}C:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= UDP:C:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"UDP Query User{776E14B8-BC85-4AF2-A0E5-4E71ECEEE152}C:\\program files\\sierra entertainment\\timeshift\\bin\\timeshift.exe"= TCP:C:\program files\sierra entertainment\timeshift\bin\timeshift.exe:TimeShift
"TCP Query User{C3919812-6CB1-4E16-846C-E92D37D0706A}C:\\users\\user1\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\adjs75pn\\wowclient-downloader[1].exe"= UDP:C:\users\user1\appdata\local\microsoft\windows\temporary internet files\content.ie5\adjs75pn\wowclient-downloader[1].exe:wowclient-downloader[1].exe
"UDP Query User{B7D533B0-FCF1-429D-A14C-0FA8A4BDAA54}C:\\users\\user1\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\adjs75pn\\wowclient-downloader[1].exe"= TCP:C:\users\user1\appdata\local\microsoft\windows\temporary internet files\content.ie5\adjs75pn\wowclient-downloader[1].exe:wowclient-downloader[1].exe
"{A02B2BB9-451E-4FDA-8C52-DF9109D9D282}"= UDP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{5E8079D9-3119-4701-88C1-8B9A3293895C}"= TCP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{4A885F9F-8B87-4E2F-A92E-2889BBD37755}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{5EB48079-04B0-40C5-953B-E9D2ADCFD4DA}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{AE430C25-AB82-48ED-8ECF-5190A49347B8}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{6EE353FD-B795-4276-9C8D-2A8D95518653}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{CA23690C-D23B-48C8-B35B-127224CC3A73}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{1DA1C0E7-5ABB-403D-BB98-66D48A6A1614}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"TCP Query User{6D9E2E26-4216-4B37-BD83-A55E6660C2D4}C:\\program files\\gamespy\\comrade\\comrade.exe"= UDP:C:\program files\gamespy\comrade\comrade.exe:Comrade
"UDP Query User{2E59D275-6576-44CF-8DAD-52D49BC1A048}C:\\program files\\gamespy\\comrade\\comrade.exe"= TCP:C:\program files\gamespy\comrade\comrade.exe:Comrade
"TCP Query User{0A1BAE3A-AC45-41EC-A7B3-271394993EF2}C:\\program files\\sega\\universe at war earth assault (demo)\\uawea.exe"= UDP:C:\program files\sega\universe at war earth assault (demo)\uawea.exe:Universe at War: Earth Assault Application
"UDP Query User{D918B873-762D-4D51-8C0B-A7594DDB4A30}C:\\program files\\sega\\universe at war earth assault (demo)\\uawea.exe"= TCP:C:\program files\sega\universe at war earth assault (demo)\uawea.exe:Universe at War: Earth Assault Application
"TCP Query User{8AA720DA-A61B-4F6C-B721-6B86583225F9}C:\\program files\\sony\\station\\launchpad\\launchpad.exe"= UDP:C:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"UDP Query User{EC54C34F-6CA0-41FE-AC8A-35397714F7DD}C:\\program files\\sony\\station\\launchpad\\launchpad.exe"= TCP:C:\program files\sony\station\launchpad\launchpad.exe:LaunchPad
"{207A59AA-0736-467A-A7C8-96F6842058CB}"= UDP:5000:Potbs TCP
"{BB916884-DB04-4600-A20A-7CDF34136BC1}"= TCP:5000:Potbs UDP
"{6D87F103-2F1B-42DD-BB5B-99B67DE16A86}"= UDP:5100:Potbs TCP 2
"{D781F788-1E21-40E7-8093-C0EA613A7CC3}"= TCP:5100:Potbs UDP 2
"TCP Query User{A9B3F224-7C18-4467-93BD-ABB3F79A886D}C:\\program files\\the all-seeing eye\\eye.exe"= UDP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"UDP Query User{1E3201FF-4648-4D61-B393-A6FEAD52C495}C:\\program files\\the all-seeing eye\\eye.exe"= TCP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"TCP Query User{A63C9F19-A2EB-496E-B72A-2F6D2D35EA0A}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= UDP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{189E2AF2-6D9E-4D0B-B3A8-E3B7B1DD0587}C:\\program files\\ccp\\eve\\bin\\exefile.exe"= TCP:C:\program files\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{C4F5C479-5653-42E9-8F29-A0AA7D17EDD9}C:\\program files\\utorrent\\utorrent.exe"= UDP:C:\program files\utorrent\utorrent.exe:utorrent
"UDP Query User{2F88B71E-EC09-4EE8-8E13-F20969EC311C}C:\\program files\\utorrent\\utorrent.exe"= TCP:C:\program files\utorrent\utorrent.exe:utorrent
"TCP Query User{683A7516-0D70-4C40-ADF6-C2EBC4CF5085}C:\\program files\\sega\\medieval ii total war\\kingdoms.exe"= UDP:C:\program files\sega\medieval ii total war\kingdoms.exe:Medieval 2 Total War: Kingdoms
"UDP Query User{9D874333-EDE4-4C59-A7AC-55229E88C8B5}C:\\program files\\sega\\medieval ii total war\\kingdoms.exe"= TCP:C:\program files\sega\medieval ii total war\kingdoms.exe:Medieval 2 Total War: Kingdoms
"TCP Query User{17E6AB82-2FB9-4DDB-A029-E72825E00CBE}C:\\program files\\internet explorer\\iexplore.exe"= UDP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{68509E5B-3379-432D-9B19-33F9F0563661}C:\\program files\\internet explorer\\iexplore.exe"= TCP:C:\program files\internet explorer\iexplore.exe:Internet Explorer
"{733955A7-309E-4852-A3E1-261A021F5ACF}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{A3455715-4A1C-45AC-A55A-0267256CE891}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{BA91CB80-423C-4CEA-9529-51F4BF8B4895}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{37C46250-CEF7-472E-8AD2-C1DDE56786A6}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{027944E8-EE4E-4867-A587-44983533AD94}D:\\theorangebox-jape\\team fortress 2\\hl2.exe"= UDP:D:\theorangebox-jape\team fortress 2\hl2.exe:hl2
"UDP Query User{92194552-A3BD-4FD0-9172-1020EF97DA12}D:\\theorangebox-jape\\team fortress 2\\hl2.exe"= TCP:D:\theorangebox-jape\team fortress 2\hl2.exe:hl2
"{4CAFD5BD-EBF3-44A3-92AF-926AC16D432F}"= UDP:27960:ET-one
"{DF3992B8-A4A7-44A5-8FCB-D608BC3FDDA2}"= TCP:27960:ET-two
"{430E254E-37B8-473B-B4D4-01798A7747D9}"= TCP:27950:ET 3
"{2832F24D-1F82-41FD-9315-697CE3581B42}"= TCP:27965:et4
"{1251027C-6AA6-4325-8403-983BA769D21F}"= TCP:27952:et5
"TCP Query User{7F9011F2-1FEB-4C9C-A83D-FC4D2C32A8BA}C:\\program files\\sierra entertainment\\world in conflict\\wic.exe"= UDP:C:\program files\sierra entertainment\world in conflict\wic.exe:World in Conflict
"UDP Query User{3EF21071-ADEC-4D26-BCB4-90B8D750CCB2}C:\\program files\\sierra entertainment\\world in conflict\\wic.exe"= TCP:C:\program files\sierra entertainment\world in conflict\wic.exe:World in Conflict
"{51BC4F92-723B-49F3-9358-90EEAC5FCAC8}"= TCP:27969:et..
"TCP Query User{8AD5694C-03C4-421C-8290-4A5084738EF6}D:\\ccp\\eve\\bin\\exefile.exe"= UDP:D:\ccp\eve\bin\exefile.exe:CCP ExeFile
"UDP Query User{9BC54F63-1E16-40A4-9E20-F32EC261CC57}D:\\ccp\\eve\\bin\\exefile.exe"= TCP:D:\ccp\eve\bin\exefile.exe:CCP ExeFile
"TCP Query User{188E9EA6-53D2-46A7-AACB-B63DCF0F1FE7}C:\\program files\\wolfenstein - enemy territory\\et.exe"= UDP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"UDP Query User{C1D84DF2-1F8E-4776-999E-28CDD739F339}C:\\program files\\wolfenstein - enemy territory\\et.exe"= TCP:C:\program files\wolfenstein - enemy territory\et.exe:ET
"TCP Query User{373C17D8-6386-453F-8FD7-51AE8C64529C}C:\\program files\\sega\\medieval ii total war\\medieval2.exe"= UDP:C:\program files\sega\medieval ii total war\medieval2.exe:Medieval 2: Total War
"UDP Query User{E129DDAF-7415-4112-A633-2ABA1AC6E230}C:\\program files\\sega\\medieval ii total war\\medieval2.exe"= TCP:C:\program files\sega\medieval ii total war\medieval2.exe:Medieval 2: Total War
"{3CAB2482-CD19-48E9-871F-CF18C1A86D1B}"= TCP:20800:cod4
"{1DFFF86A-5565-41C7-8FAF-81C8B907427A}"= TCP:20810:cod4 .
"{3432590E-8B76-4461-BFC7-19A69F1F8817}"= TCP:28960:cod4 ..
"TCP Query User{0A5286D9-008B-4CC9-93C9-C17CA3E70424}C:\\program files\\silkroad\\silkerrsender.exe"= UDP:C:\program files\silkroad\silkerrsender.exe:FTPSender MFC ?? ????
"UDP Query User{AF244689-8D48-45D8-86C9-446E8D392D57}C:\\program files\\silkroad\\silkerrsender.exe"= TCP:C:\program files\silkroad\silkerrsender.exe:FTPSender MFC ?? ????
"{932A994F-9E62-4C93-8275-71959A3DC761}"= C:\Program Files\Windows Live\Messenger\wlcsdk.exe:Windows Live Messenger (Phone)
"{6D8BF470-23E4-4E76-8B14-407AB540100C}"= UDP:46615:torrent
"{AC266C30-6C7F-4EBB-A359-5EA278E2EB7E}"= TCP:46615:torrent
"{A27707C9-9800-496B-9BE7-957E876897B7}"= UDP:57613:Pando P2P TCP Listening Port
"{1457E6D0-1A26-4779-998F-2DEE8BF6D8B3}"= TCP:57613:Pando P2P UDP Listening Port
"TCP Query User{18814D7A-C477-456D-8D8C-9BF1756FF4C0}C:\\program files\\pando networks\\pando\\pando.exe"= UDP:C:\program files\pando networks\pando\pando.exe:pando
"UDP Query User{50926602-4485-4C40-9651-FDA7FA211BA4}C:\\program files\\pando networks\\pando\\pando.exe"= TCP:C:\program files\pando networks\pando\pando.exe:pando
"TCP Query User{B5FD2BAF-B1E3-4323-BD77-2C3AF23728A1}C:\\program files\\america's army\\system\\armyops.exe"= UDP:C:\program files\america's army\system\armyops.exe:ArmyOps
"UDP Query User{772128A2-C5D0-4F7F-B5CA-D2256885F141}C:\\program files\\america's army\\system\\armyops.exe"= TCP:C:\program files\america's army\system\armyops.exe:ArmyOps
"TCP Query User{498ED17F-0B55-4437-9E9E-35B78468D69B}C:\\program files\\scc-tds\\kane and lynch dead men\\kaneandlynch.exe"= UDP:C:\program files\scc-tds\kane and lynch dead men\kaneandlynch.exe:Kane & Lynch - Dead Men
"UDP Query User{E9CC7C54-9DAE-4162-9774-F985554D1869}C:\\program files\\scc-tds\\kane and lynch dead men\\kaneandlynch.exe"= TCP:C:\program files\scc-tds\kane and lynch dead men\kaneandlynch.exe:Kane & Lynch - Dead Men
"TCP Query User{E55B4ACC-F5F7-4CD7-9E69-C4CB352E6A80}C:\\program files\\silkroad\\nuconnector.exe"= UDP:C:\program files\silkroad\nuconnector.exe:nuConnector
"UDP Query User{6B32BE9F-F81B-4237-8314-7A4385FB9948}C:\\program files\\silkroad\\nuconnector.exe"= TCP:C:\program files\silkroad\nuconnector.exe:nuConnector
"{B5FAFEF8-B5F4-4FC1-91EB-6F55A6B32736}"= UDP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"{B44BA0C0-E181-439C-B7D9-B993BE1CA600}"= TCP:C:\Program Files\Stardock Games\Sins of a Solar Empire\Sins of a Solar Empire.exe:Sins of a Solar Empire
"TCP Query User{37CD82C1-1DB3-4A34-BEC3-0BBA87C960FB}C:\\users\\user1\\desktop\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{E0F94EC4-9ED4-4CE6-86AC-7C8D867FB5EF}C:\\users\\user1\\desktop\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{3601AD05-76FA-4905-93F3-0C265F128CD4}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{92F443CE-D5E0-41D5-9C3A-246462C9A136}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{56233D0C-5EE9-4634-86E2-F371BFCAF68C}C:\\users\\user1\\desktop\\testport\\testport.exe"= UDP:C:\users\user1\desktop\testport\testport.exe:testport.exe
"UDP Query User{61C46BF7-F259-4F30-AE9C-F7D90AF06643}C:\\users\\user1\\desktop\\testport\\testport.exe"= TCP:C:\users\user1\desktop\testport\testport.exe:testport.exe
"{DF4BCDB6-2BA6-426C-89C3-5BC10E1EE55F}"= UDP:3640:Poison Ivy RAT
"{FD61E811-EA09-4930-8A1B-E4035CED7028}"= TCP:3640:Poison Ivy RAT
"TCP Query User{C45E8EDC-78F4-4970-AE67-904E3D03338A}C:\\users\\user1\\desktop\\nuclear-conversation-v1.0\\nuclear-conversation-v1.0\\nuclear-v1.0-server\\nuclear-conversation-server.exe"= UDP:C:\users\user1\desktop\nuclear-conversation-v1.0\nuclear-conversation-v1.0\nuclear-v1.0-server\nuclear-conversation-server.exe:nuclear-conversation-server.exe
"UDP Query User{1E786DBB-E8BD-4C5F-A7BB-C6EF0B01CC22}C:\\users\\user1\\desktop\\nuclear-conversation-v1.0\\nuclear-conversation-v1.0\\nuclear-v1.0-server\\nuclear-conversation-server.exe"= TCP:C:\users\user1\desktop\nuclear-conversation-v1.0\nuclear-conversation-v1.0\nuclear-v1.0-server\nuclear-conversation-server.exe:nuclear-conversation-server.exe
"TCP Query User{40C1CBF4-1EC4-41CF-ABD1-3B4728BB602A}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"UDP Query User{9E34939C-26AB-4740-BDA8-85FE39672E2E}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"TCP Query User{5C368A4D-9A43-4A2F-9C8A-A76D5C0DA152}C:\\users\\user1\\desktop\\package1.4v8.2\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.4v8.2\nuconnector.exe:nuconnector.exe
"UDP Query User{CCBEEF86-C518-4198-A37C-73F9CE530925}C:\\users\\user1\\desktop\\package1.4v8.2\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.4v8.2\nuconnector.exe:nuconnector.exe
"TCP Query User{136AC9B7-A32A-46F5-B844-AA02F1528C36}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{9D1F7C65-1D9D-490C-A25D-3B76DC34CBFB}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{5987B2BA-D4AF-40A8-9F2C-38B3D1867477}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= UDP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"UDP Query User{DDB2A27E-96EC-4142-8BE1-585B6EED87BC}C:\\users\\user1\\desktop\\kamal'n'petru stuff\\pi2.3.2\\poison ivy 2.3.2.exe"= TCP:C:\users\user1\desktop\kamal'n'petru stuff\pi2.3.2\poison ivy 2.3.2.exe:poison ivy 2.3.2.exe
"TCP Query User{62614F7B-680E-49DA-8B5A-BB9A808C9248}C:\\program files\\the all-seeing eye\\eye.exe"= UDP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"UDP Query User{6437B988-3588-4244-948E-72B74CB4BFFB}C:\\program files\\the all-seeing eye\\eye.exe"= TCP:C:\program files\the all-seeing eye\eye.exe:Yahoo! All-Seeing Eye
"TCP Query User{69C9BAB0-ACB7-4F1F-B9AE-D820445BFC3C}C:\\program files\\mirc\\mirc.exe"= UDP:C:\program files\mirc\mirc.exe:mIRC
"UDP Query User{EB5250C7-8684-43C8-8171-3FFDF6253FF8}C:\\program files\\mirc\\mirc.exe"= TCP:C:\program files\mirc\mirc.exe:mIRC
"TCP Query User{70942965-3D97-4916-A4DF-9A97803AF9EB}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= UDP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"UDP Query User{17C2519D-F574-4413-B459-448238E21604}C:\\users\\user1\\desktop\\package1.5.stable\\nuconnector.exe"= TCP:C:\users\user1\desktop\package1.5.stable\nuconnector.exe:nuconnector.exe
"{163249C5-3F4F-4AA7-AE3C-0F6D07B1E4C8}"= UDP:C:\Program Files\Midway Games\Hour of Victory\Binaries\LTCG-HOVGame.exe:Hour of Victory
"{2507907D-D035-4AB6-B286-90EEA48ED183}"= TCP:C:\Program Files\Midway Games\Hour of Victory\Binaries\LTCG-HOVGame.exe:Hour of Victory
"{A54679DD-2DB5-491A-8EEA-EE0C87EF7917}"= UDP:6889:utorrent
"{EAD5EDEA-972D-45AC-AE51-2660E2366887}"= TCP:6889:utorrent9
"TCP Query User{34EAB8C3-26E6-472D-9D47-C6D2260E8159}C:\\program files\\wow250\\wow.exe"= UDP:C:\program files\wow250\wow.exe:WOW
"UDP Query User{CFC6D76F-2E25-4D50-A1C1-A8D599979003}C:\\program files\\wow250\\wow.exe"= TCP:C:\program files\wow250\wow.exe:WOW
"{E46321F7-1C7A-4873-8AAA-4F67AB87CD5A}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{698F19AB-BEC7-4851-B6B3-020C75331A76}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{FC2ABEEF-6EC9-4E2E-A164-190A99EFF3A3}"= UDP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{1E383CDB-BDA2-4329-8123-6ABC4EE1516E}"= TCP:C:\Program Files\BitTorrent\bittorrent.exe:BitTorrent
"{20BD2485-288D-492D-9369-55D80A21C383}"= UDP:45682:torrent 45682
"{D3E2E255-1ACE-4123-9174-F854CD16D2CE}"= TCP:45682:torrent 45682 .
"{8C626AFF-FFCF-40C2-BEBF-73A7122C2D05}"= UDP:C:\Program Files\utorrent\utorrent.exe:µTorrent (TCP-In)
"{01A78D86-5532-4194-B944-8A47283FD69F}"= TCP:C:\Program Files\utorrent\utorrent.exe:µTorrent (UDP-In)
"{DB79AD20-AF51-4310-AEE8-0513AB4CE09F}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{ED4368B8-FE52-4E7D-8B4B-FC01288D0A4D}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{2FCC5F07-5830-45F2-AF6F-C17142E2464F}"= UDP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\base\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire
"{F889D572-3F3B-46EE-93FC-7CC6B83FBC91}"= TCP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\base\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire
"{E587A31D-67CF-409B-BD81-353A6762EE34}"= UDP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\extra1\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire - The Eastern Realm
"{B9231AF3-26F8-44C6-A24D-272F61331B19}"= TCP:C:\Program Files\Ubisoft\THE SETTLERS - Rise of an Empire\extra1\bin\Settlers6.exe:THE SETTLERS - Rise of an Empire - The Eastern Realm
"{B1ED6858-8CFD-4858-AF70-BAC4B8BFB563}"= UDP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:Tom Clancy's Rainbow Six Vegas 2
"{D62A6538-23C2-4776-830D-20B954545676}"= TCP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Game.exe:Tom Clancy's Rainbow Six Vegas 2
"{7504C1FE-7898-4136-A44E-4757808CFC02}"= UDP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:Tom Clancy's Rainbow Six Vegas 2 Update
"{1F64A97B-843A-44B2-B9BF-54AB9BD44CD4}"= TCP:C:\Program Files\Ubisoft\Tom Clancy's Rainbow Six Vegas 2\Binaries\R6Vegas2_Launcher.exe:Tom Clancy's Rainbow Six Vegas 2 Update
"{8D910C6A-0B6C-4D1A-9D25-67FA481FCB89}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{55012448-A8FC-44FC-B4DA-9C78E37B379E}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx9.exe:Assassin's Creed Dx9
"{616CC9F4-E298-4BD2-809C-56B3C7EE66F6}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{83139EC0-D1A8-4745-9967-0645227A87ED}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Dx10.exe:Assassin's Creed Dx10
"{B6BB7046-FA8F-4CF0-BE25-23101B62AC10}"= UDP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{794C6230-7564-4C00-BADA-053BF917D758}"= TCP:C:\Program Files\Ubisoft\Assassin's Creed\AssassinsCreed_Launcher.exe:Assassin's Creed Update
"{077ED121-9770-47DA-AB02-5990452D1781}"= UDP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{14186FB5-0EF3-4576-804D-DBDA3E037CBF}"= TCP:C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe:Yahoo! Messenger
"{3D9BD3D6-5A22-4396-BB6E-6BC26A183BC4}"= UDP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{359F727B-4083-4182-A072-5D61FC6BA4EB}"= TCP:C:\Program Files\Yahoo!\Messenger\YServer.exe:Yahoo! FT Server
"{1459E4E1-54F6-4A68-BF93-A4A53BE80CC7}"= C:\Program Files\Skype\Phone\Skype.exe:Skype
"{7EAB4983-D3DA-4959-91E7-A8E0DD44E22E}"= UDP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{7CAA4EB5-0677-408A-9353-4827AA15610C}"= TCP:C:\Program Files\Electronic Arts\Battlefield 2142\BF2142.exe:Battlefield 2
"{F415D308-9377-4CFB-B693-646EC7A90F5E}"= UDP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{4FC86898-73B8-45E6-B36C-27899F1BF7ED}"= TCP:C:\Program Files\Activision\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty® 4 - Modern Warfare™
"{4B901F93-995C-4074-8B11-C01008DCA565}"= UDP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{E4D6058C-F34A-4DCD-9AE2-B8AF34A769B6}"= TCP:C:\Program Files\Mass Effect\Binaries\MassEffect.exe:Mass Effect Game
"{5D04B4BD-1623-4744-AC44-D3EBDDD3230A}"= UDP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{F049FDFD-FB96-489E-BC86-8A821D5AC217}"= TCP:C:\Program Files\Mass Effect\MassEffectLauncher.exe:Mass Effect Launcher
"{B8262603-475C-4178-9606-1665DBB54D5E}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{85BB0092-0CCD-4A37-B580-C54A76810B32}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\Crysis.exe:Crysis_32
"{10B5666B-4478-48BA-8C7D-62DCA92B8F2A}"= UDP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"{84DEACFC-1B27-41B8-8534-119FD7442754}"= TCP:C:\Program Files\Electronic Arts\Crytek\Crysis\Bin32\CrysisDedicatedServer.exe:CrysisDedicatedServer_32
"TCP Query User{77A5B938-EA00-4FA9-ADAA-380CD7AF09D3}C:\\program files\\ea games\\red alert 3 beta\\retailexe\\1.4\\ra3game.dat"= UDP:C:\program files\ea games\red alert 3 beta\retailexe\1.4\ra3game.dat:Command & Conquer™ Red Alert 3™
"UDP Query User{BB41E3C1-E2C8-41E3-A96D-65B92344C49B}C:\\program files\\ea games\\red alert 3 beta\\retailexe\\1.4\\ra3game.dat"= TCP:C:\program files\ea games\red alert 3 beta\retailexe\1.4\ra3game.dat:Command & Conquer™ Red Alert 3™
"{611A216E-5F64-46E9-ABAC-94B9C5EA0F98}"= UDP:C:\Program Files\DNA\btdna.exe:DNA
"{4B558E0B-08A4-449C-B60A-A44AB1535BDC}"= TCP:C:\Program Files\DNA\btdna.exe:DNA
"{C21440F8-7055-4ED7-804C-5839538D9160}"= UDP:C:\Program Files\DNA\btdna.exe:DNA (TCP-In)
"{BF3DF3A6-F1E5-45A2-9012-84D034354EAB}"= TCP:C:\Program Files\DNA\btdna.exe:DNA (UDP-In)
"TCP Query User{4FCC326C-D2E6-47F9-AADD-5221F85A28DC}C:\\program files\\electronic arts\\eadm\\core.exe"= UDP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{35088126-B4BC-4185-848F-EB7EA808BF6F}C:\\program files\\electronic arts\\eadm\\core.exe"= TCP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"TCP Query User{6008148F-FF3D-4169-B8FE-ED07C01285D7}C:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= UDP:C:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java™ Platform SE binary
"UDP Query User{3B3A6109-F594-4990-8876-53FE603BE79D}C:\\program files\\java\\jre1.6.0_07\\launch4j-tmp\\jdownloader.exe"= TCP:C:\program files\java\jre1.6.0_07\launch4j-tmp\jdownloader.exe:Java™ Platform SE binary
"TCP Query User{F19D6490-E33C-49A6-8239-A551EF96FE31}C:\\windows\\system32\\java.exe"= UDP:C:\windows\system32\java.exe:Java™ Platform SE binary
"UDP Query User{51EDFA4E-3B71-4C5B-B9A0-0535337DC2D7}C:\\windows\\system32\\java.exe"= TCP:C:\windows\system32\java.exe:Java™ Platform SE binary
"{91737325-4AF7-4C7E-82E6-2C385C54B1B3}"= UDP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{F4C16C5D-8BB5-4390-AA69-B72BE62EA2B3}"= TCP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"TCP Query User{44AD45DB-B100-4541-BE7A-310E1E24EA20}C:\\program files\\electronic arts\\eadm\\core.exe"= UDP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"UDP Query User{E8250F44-0481-4EB7-8135-84C07D707353}C:\\program files\\electronic arts\\eadm\\core.exe"= TCP:C:\program files\electronic arts\eadm\core.exe:EA Download Manager
"{462DDBC3-A304-4A57-8D41-F96A76B9D1BF}"= UDP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher
"{93F030F2-3303-4C7D-BACC-83EE24BAB235}"= TCP:C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe:Proxy Switcher

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Configurable\System]
"Rip-Listener-1"= TCP:520|%SystemRoot%\System32\svchost.exe|Svc=iprip:@iprip.dll,-200|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"SNMP-1"= TCP:%SystemRoot%\system32\snmp.exe|Svc=SNMP:@%SystemRoot%\system32\snmp.exe,-5|

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile]
"DoNotAllowExceptions"= 0 (0x0)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"C:\\Program Files\\FlashFXP\\flashfxp.exe"= C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3
"C:\\Program Files\\BitTorrent\\bittorrent.exe"= C:\Program Files\BitTorrent\bittorrent.exe:*:Enabled:BitTorrent


[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12
hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc
rsmsvcs REG_MULTI_SZ ntmssvc
ipripsvc REG_MULTI_SZ iprip

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\F]
\shell\AutoRun\command - F:\start.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1dab5-5d85-11dc-8d60-001a92b14bf4}]
\shell\AutoRun\command - G:\AutoRunCD.exe

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{82e1db44-5d85-11dc-8d60-001a92b14bf4}]
\shell\AutoRun\command - I:\SR2020-Install.exe

[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{7070D8E0-650A-46b3-B03C-9497582E6A74}]
%SystemRoot%\system32\soundschemes.exe /AddRegistration
.
.
——- Supplementary Scan ——-
.
FireFox -: Profile - C:\Users\user1\AppData\Roaming\Mozilla\Firefox\Profiles\1ruw3qzv.default\
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://alpha.astroempires.com/
FF -: plugin - C:\Program Files\DNA\plugins\npbtdna.dll
FF -: plugin - C:\Program Files\Download Manager\npfpdlm.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.1.0.30401.0.dll
FF -: plugin - C:\Program Files\Microsoft Silverlight\2.0.30523.8\npctrl.dll
FF -: plugin - C:\Program Files\Real\RhapsodyPlayerEngine\nprhapengine.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nppl3260.dll
FF -: plugin - C:\Program Files\VistaCodecPack\rm\browser\plugins\nprpjplug.dll
FF -: plugin - C:\Program Files\Yahoo!\Shared\npYState.dll
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-06 03:04:15
Windows 6.0.6001 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

PROCESS: C:\Windows\Explorer.exe
-> C:\Program Files\TortoiseSVN\iconv\_tbl_simple.so
-> C:\Program Files\TortoiseSVN\iconv\windows-1252.so
-> C:\Program Files\TortoiseSVN\iconv\utf-8.so
.
Completion time: 2008-10-06 3:06:51
ComboFix-quarantined-files.txt 2008-10-06 01:05:48
ComboFix2.txt 2008-10-05 17:03:24

Pre-Run: 2,493,739,008 bytes free
Post-Run: 2,447,007,744 bytes free

527 — E O F — 2008-08-06 00:01:21


And here the log from HijackThis :
Logfile of HijackThis v1.99.1
Scan saved at 3:17:50 AM, on 10/6/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v8.00 (8.00.6001.17184)

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
C:\Program Files\AGEIA Technologies\TrayIcon.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe
C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
C:\Program Files\Electronic Arts\EADM\Core.exe
C:\Program Files\TortoiseSVN\bin\TSVNCache.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\NOTEPAD.EXE
C:\Windows\system32\SearchFilterHost.exe
C:\Program Files\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.farfesh.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: &Yahoo;! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: MegaIEMn - {bf00e119-21a3-4fd1-b178-3b8537e75c92} - C:\Program Files\Megaupload\Mega Manager\MegaIEMn.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ASUSGamerOSD] C:\Program Files\ASUS\GamerOSD\GamerOSD.exe
O4 - HKLM\..\Run: [AGEIA PhysX SysTray] C:\Program Files\AGEIA Technologies\TrayIcon.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [GSISETUP] E:\setup.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [MobMapUpdater] "C:\Program Files\MobMapUpdater\MobMapUpdater.exe" –silent
O4 - HKCU\..\Run: [Yahoo! Pager] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [igndlm.exe] C:\Program Files\Download Manager\DLM.exe /windowsstart /startifwork
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [PSwitch] C:\Program Files\Proxy Switcher Standard\ProxySwitcher.exe
O4 - HKCU\..\Run: [EA Core] C:\Program Files\Electronic Arts\EADM\Core.exe -silent
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [PicoZip] C:\Program Files\PicoZip\PicoZipTray.exe
O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - %windir%\bdoscandel.exe (file missing)
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll
O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\nvappfilter.dll
O11 - Options group: [INTERNATIONAL] International*
O13 - Gopher Prefix:
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O18 - Protocol: wlmailhtml - {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files\Windows Live\Mail\mailcomm.dll
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O20 - Winlogon Notify: klogon - C:\Windows\system32\klogon.dll
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30011 (AppHostSvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Kaspersky Anti-Virus (AVP) - Unknown owner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe" -r (file missing)
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program Files\FileZilla Server\FileZilla Server.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt.exe
O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: TeamViewer 3 (TeamViewer) - Unknown owner - C:\Program Files\TeamViewer3\TeamViewer_Host.exe" -service (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30003 (W3SVC) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%windir%\system32\inetsrv\iisres.dll,-30001 (WAS) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)



It's still sucking for long time , it's impossilbe to do any file transfer/changing name , etc, with out sucking for long time … i guess it's still the same, but the good thing, that until now i didn't see any of these warns!
If you do this right it uninstalls Combofix and all the bad ones it found.

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the X and the U, it needs to be there.

    • [external image: Posted Image]
I will do it again , but Run is gone from start menu so i used the Run , by Task manager>File> New task (Run…)
i did Combofix , again , but this time i unplugged the internet cable from the router, and finished, and in that time i opened FixIEDef properties > Compatibility > Run this program in compatibility mode for : windows XP (SP 2) > Apply and i ran it, worked fine in normal mode, and it's finished too , so i restarted and the internet cable still unplugged, when i entered to my windows, everything loaded very fast all start up programs… etc, even the messenger and windows media player didn't suck , so i wanted to put internet cable back , first i putted the internet then the problems came , side bar+messenger + windows media player got closed , and Explorer bar sucked … weird… annoying ha?
and here one of the warns (error reports) who showed up before the program closes.
[external image: Posted Image]

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI