*Edit* Nevermind..it's still there. I restarted and when I tried to google winigon the redirects started happening again. Going to post the logs j.i.c.
Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 6.0.6001 Service Pack 1
11/18/2008 10:52:15 PM
mbam-log-2008-11-18 (22-52-15).txt
Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|)
Objects scanned: 202462
Time elapsed: 44 minute(s), 12 second(s)
Memory Processes Infected: 1
Memory Modules Infected: 2
Registry Keys Infected: 24
Registry Values Infected: 14
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 24
Memory Processes Infected:
C:\Users\Seer\AppData\Local\Temp\csrssc.exe (Trojan.Downloader) -> Unloaded process successfully.
Memory Modules Infected:
C:\Windows\System32\fccccCTM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Windows\System32\jsne87fidgf.dll (Trojan.BHO) -> Delete on reboot.
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a05cc918-2556-436a-b830-a90a3be9d6a1} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{a05cc918-2556-436a-b830-a90a3be9d6a1} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b200799f-9538-403d-9a6e-36f5942ec540} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a84e835e-1b9c-4fc0-980f-4b2da3c6a2a7} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bf0a1ff4-bbaf-487f-bc85-a24ef8f443a8} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1962c5bc-e475-465b-823b-133e711bceb9} (Adware.Starware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kvvwdxji (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fci (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ICF (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rs32net (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rs32net (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSSMSGS (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xsjfn83jkemfofght (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xsjfn83jkemfofght (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft startup manager (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Jnskdfmf9eldfd (Trojan.Downloader) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fccccctm -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fccccctm -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\Windows\System32\fccccCTM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Windows\System32\MTCccccf.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\MTCccccf.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\rs32net.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\Windows\System32\jsne87fidgf.dll (Trojan.BHO) -> Delete on reboot.
C:\Windows\System32\fklame32.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN11FB.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN1841.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN5B97.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN8D71.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BNAA91.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BNF5A5.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\tweAA9B.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\kvvwdxji.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\kvvwdxji32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\winpcl32.rom (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\winyom32.rom (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\opnlMgeb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\winlogin.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\sysservice.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\csrssc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\fci.exe.exe (Worm.Zhelatin) -> Quarantined and deleted successfully.
C:\Windows\System32\icf.exe.exe (Worm.Zhelatin) -> Quarantined and deleted successfully.
C:\Windows\System32\drivers\restore.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
ComboFix 08-08-03.05 - Seer 2009-11-24 23:16:41.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.1.1033.18.1256 [GMT -8:00]
Running from: C:\Users\Seer\Desktop\CF.exe
* Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Windows\Downloaded Program Files\setup.inf
.
((((((((((((((((((((((((( Files Created from 2009-10-25 to 2009-11-25 )))))))))))))))))))))))))))))))
.
No new files created in this timespan
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 06:58 41,952 ----a-w C:\Users\All Users\nvModes.dat
2008-11-19 06:58 41,952 ----a-w C:\ProgramData\nvModes.dat
2008-10-26 01:34 22,328 ----a-w C:\Users\Seer\AppData\Roaming\PnkBstrK.sys
2008-09-15 05:16 56 ---ha-w C:\Users\All Users\ezsidmv.dat
2008-09-15 05:16 56 ---ha-w C:\ProgramData\ezsidmv.dat
2008-06-26 18:33 41,192 ----a-w C:\Users\Seer\AppData\Roaming\nvModes.dat
2008-06-24 15:27 174 --sha-w C:\Program Files\desktop.ini
2008-11-19 06:57 262,144 --sha-w C:\Windows\ServiceProfiles\LocalService\ntuser.dat
2008-11-19 06:54 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-11-19 06:54 2,048 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
2008-06-15 04:33 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-06-15 04:33 32,768 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-06-15 04:33 16,384 --sha-w C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2007-08-01 16:05 56 --sha-r C:\Windows\System32\C1CACC7099.sys
2008-04-30 03:24 1,890 --sha-w C:\Windows\System32\KGyGaAvL.sys
2008-11-19 07:11 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-11-19 07:11 49,152 --sha-w C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-11-19 07:11 16,384 --sha-w C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
[code]<pre>
----a-w 325,204 2006-12-22 04:56:28 C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
</pre>[/code]
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-10-22 16:16 1410296]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-20 14:23 1773568]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 14:29 165784]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"12CFG94-z641-2SF-N31P-5M1ER6H6L1"="C:\RECYCLER\S-1-5-21-2422537357-9063600547-490267057-6977\winigon.exe" [2008-11-18 13:41 72704]
"CyberDefender Early Detection Center"="C:\Users\Seer\AppData\Local\CyberDefender Internet Security\AntiSpyware\cdas3ffc.exe" [N/A]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-18 23:36 2153472 C:\Windows\System32\oobefldr.dll]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 18:31 1033512]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 10:38 159744]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-02-27 04:48 13515296]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-02-27 04:48 92704]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 15:12 317128]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [N/A]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-05-19 03:08 77824]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 12:43 729088]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2008-02-27 04:48 166432]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 06:37 174872]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 12:18 472776]
"HP Health Check Scheduler"="[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [N/A]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [N/A]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"CyberDefender Early Detection Center"="C:\Users\Seer\AppData\Local\CyberDefender Internet Security\AntiSpyware\ISSIntro.exe" [N/A]
"Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [N/A]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 09:50 4390912 C:\Windows\RtHDVCpl.exe]
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 00:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 23:01:50 734872]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 12:05:56 65588]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages REG_MULTI_SZ msv1_0 C:\Windows\system32\fccccCTM
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DoNotAllowExceptions"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{666EC466-6176-4E0D-9459-CF2238C4E3A3}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{59A2A803-911B-4BBE-B092-62D7A09BB047}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{71414D90-91F3-4F9B-96A1-BF4E7DFD4CDB}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A2035C52-162E-4966-91DF-ABF2C908A042}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6714543A-9B10-4E9D-A17A-2D09A661542F}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{85760691-6AD0-4A62-9EFA-4A801235FD2C}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{44EC9A8C-EA96-46D9-848E-7AD73D5AB056}"= UDP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{2815E3B4-F48A-42A6-B541-334BFA7B8585}"= TCP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{2F64F22B-D565-43CF-ACB3-FD3368E1822A}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{FC51745E-F666-4DA7-990E-8C9D4A06EDD9}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6D922F78-668C-4792-967F-E784927A2450}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{2F2C9694-2CD9-48D0-98A6-AA766ED1091A}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{011A2FED-E25F-493D-85CA-C84ED81C89DC}"= UDP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"{ADFAFE51-9B62-40DD-A003-2C9D0B90EDD5}"= TCP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"{55B7A1BD-071E-4E34-B247-F390999E6A71}"= UDP:C:\Program Files\Steam\Steam.exe:Steam Client
"{91AD8762-011C-498D-8610-CC2B738A3E54}"= TCP:C:\Program Files\Steam\Steam.exe:Steam Client
"{4479AE0B-8C0F-4BEB-9534-43BD5BBAC61E}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{C92043AD-05D0-413A-B0BB-7B98AC3D7859}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E30B3CF9-49FA-4C23-81B1-E26A498612F8}"= UDP:C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe:Hellgate: London
"{7C9A1E51-0664-449C-8179-85F60920DE0D}"= TCP:C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe:Hellgate: London
"TCP Query User{B9637447-C374-4EC3-9822-5788342684A3}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= UDP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"UDP Query User{88051DB4-3D12-45A8-8065-3004FBF39BC7}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= TCP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"TCP Query User{E7BC6A92-748D-441A-8BC9-3C41D1961AED}C:\\program files\\steam\\steamapps\\akzell98\\condition zero\\hl.exe"= UDP:C:\program files\steam\steamapps\akzell98\condition zero\hl.exe:Half-Life Launcher
"UDP Query User{A1ED8856-20E2-45DA-BD18-AD1E046EDD96}C:\\program files\\steam\\steamapps\\akzell98\\condition zero\\hl.exe"= TCP:C:\program files\steam\steamapps\akzell98\condition zero\hl.exe:Half-Life Launcher
"TCP Query User{4EBBE62A-395B-4EB7-B738-8D81BD3C3651}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{C00B0A5F-8BA5-4249-8C76-1E081EE97368}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{CCA0DE84-BCDE-4A43-944C-24FFC292B567}C:\\program files\\itunes\\itunes.exe"= UDP:C:\program files\itunes\itunes.exe:iTunes
"UDP Query User{EA924170-3BA8-4383-9860-E87CD09252BE}C:\\program files\\itunes\\itunes.exe"= TCP:C:\program files\itunes\itunes.exe:iTunes
"TCP Query User{99750CE3-356A-43FD-A7C6-5C58D5BD03F0}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\condition zero\\hl.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\condition zero\hl.exe:Half-Life Launcher
"UDP Query User{67900CFF-83D6-4002-8D76-EAEA94F434EF}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\condition zero\\hl.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\condition zero\hl.exe:Half-Life Launcher
"TCP Query User{03D3B47C-F5EC-46E5-A9F5-C24B98B33D4A}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exe:DC++
"UDP Query User{DBA6B628-3335-4342-9642-230D13D9D072}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exe:DC++
"TCP Query User{77C6DCB4-EE4D-42BC-8F24-C682D993ABB5}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= UDP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"UDP Query User{744E2147-A538-408A-A183-6AE255A438EE}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= TCP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"TCP Query User{9D043A7B-D6FA-4A35-A2DD-32610CD4915D}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exe:DC++
"UDP Query User{0F0C2C68-31B5-42C9-B198-D56683F65DC4}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exe:DC++
"TCP Query User{1BD033AC-4541-4B3D-8E87-6A96FDD36399}C:\\program files\\steam\\steamapps\\common\\stalker shadow of chernobyl\\bin\\xr_3da.exe"= UDP:C:\program files\steam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe:XR_3DA
"UDP Query User{413E730D-C565-4037-B2A8-9C6526D7CE3F}C:\\program files\\steam\\steamapps\\common\\stalker shadow of chernobyl\\bin\\xr_3da.exe"= TCP:C:\program files\steam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe:XR_3DA
"TCP Query User{CE420079-D521-4C41-A2CB-A43E4A949765}C:\\program files\\aim6\\aim6.exe"= UDP:C:\program files\aim6\aim6.exe:AIM
"UDP Query User{B5D49D4F-3331-4DAB-92AD-B5102BDC0541}C:\\program files\\aim6\\aim6.exe"= TCP:C:\program files\aim6\aim6.exe:AIM
"{10E576DB-79E0-48B4-BE02-5852526C3247}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{910188CD-EA53-4F89-A9E9-E4775E4EC0ED}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{719513CD-B9A9-4963-90F2-CD0C228BE7AF}C:\\users\\seer\\appdata\\locallow\\garagegames\\iaplayer\\products\\5000\\install\\screwjumperpc.exe"= UDP:C:\users\seer\appdata\locallow\garagegames\iaplayer\products\5000\install\screwjumperpc.exe:screwjumperpc.exe
"UDP Query User{C674DA00-BA6B-4C4B-A96E-B1041CE7F2A7}C:\\users\\seer\\appdata\\locallow\\garagegames\\iaplayer\\products\\5000\\install\\screwjumperpc.exe"= TCP:C:\users\seer\appdata\locallow\garagegames\iaplayer\products\5000\install\screwjumperpc.exe:screwjumperpc.exe
"{D44C60E9-738E-4652-87E8-D04C945A7407}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{43CA2784-DC14-4ED5-AB47-2135486809D9}C:\\program files\\msn messenger\\msnmsgr.exe"= UDP:C:\program files\msn messenger\msnmsgr.exe:msnmsgr.exe
"UDP Query User{1817570F-F338-4F04-828A-529B56112D56}C:\\program files\\msn messenger\\msnmsgr.exe"= TCP:C:\program files\msn messenger\msnmsgr.exe:msnmsgr.exe
"TCP Query User{F100CD52-20DA-441B-A91E-5EEA4431FD3F}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\source sdk base\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\source sdk base\hl2.exe:hl2
"UDP Query User{D5F8EF45-E82D-49B3-8724-8B3AD36D8F52}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\source sdk base\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\source sdk base\hl2.exe:hl2
"TCP Query User{6F1B3979-08AF-4824-AD27-F6A5C1D13CD7}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"UDP Query User{E0F8E8DE-3CC9-4B3C-8BE6-A0D4A23280B3}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"TCP Query User{2DAEAFCE-AB2B-4FF3-8306-DBCF8FA7A9EE}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life 2 deathmatch\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life 2 deathmatch\hl2.exe:hl2
"UDP Query User{BDB5EB23-27EA-4E68-B137-D443B1AE7FE6}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life 2 deathmatch\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life 2 deathmatch\hl2.exe:hl2
"{13E70000-9591-419D-97A1-D174B0C60C75}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{D3F7AE90-0C65-49A9-86BC-F70B23766FF1}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{0F45737C-348B-4D85-8132-83939BD64EBD}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{03CDA35C-470B-42DF-9C23-D7635FFA0E27}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{E29525ED-C573-4D8E-AEFA-128D6843256D}C:\\program files\\steam\\steamapps\\akzell98\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\akzell98\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{EF76A7A8-9B81-4AE6-B42A-648C5B320E2C}C:\\program files\\steam\\steamapps\\akzell98\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\akzell98\counter-strike\hl.exe:Half-Life Launcher
"TCP Query User{365FD3FB-D0C4-4865-B58F-6F98E4D0BD4F}C:\\neverwinternights\\nwn\\nwmain.exe"= UDP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"UDP Query User{A8F12001-0502-4B59-B872-F23CAA658A9A}C:\\neverwinternights\\nwn\\nwmain.exe"= TCP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"TCP Query User{C69640D8-2566-4E70-8646-A1035214AEFB}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\day of defeat\\hl.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\day of defeat\hl.exe:Half-Life Launcher
"UDP Query User{AEE24181-8214-40B9-9313-D6E55EBEC1CD}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\day of defeat\\hl.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\day of defeat\hl.exe:Half-Life Launcher
"TCP Query User{8553BEFB-D708-4B05-8F8A-4E61925FC8B0}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life\hl.exe:Half-Life Launcher
"UDP Query User{B13B01C8-AEB9-4F30-ADE1-41547CBE57E5}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life\hl.exe:Half-Life Launcher
"{273604EC-8D9D-4395-9301-F646FD263AD5}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{F787724F-2E64-4705-94AF-3F2EB2FCEEA1}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{D23E272B-0A51-47F7-82FE-99CD1F7AD626}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{3B29AB32-3E07-4D9A-A2DA-F9FD0B2A65D4}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{FA657527-1897-48CB-88B6-DB42F00A8C66}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{41D16D1B-3310-4CB3-B638-EF288D3B7518}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{A37EF105-D9B4-45BA-AAAA-87FE83EB3F19}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{FB8FFD1D-F611-4778-83D4-95242453C5E6}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"TCP Query User{9FC57BCC-1616-4F63-925B-79F42B8514C4}C:\\neverwinternights\\nwn\\nwmain.exe"= UDP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"UDP Query User{C1939D45-89A4-4610-A0D8-DBF7777CBCA5}C:\\neverwinternights\\nwn\\nwmain.exe"= TCP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"TCP Query User{627BF9E3-AAC5-44C5-9BDF-7ED509854E2E}C:\\program files\\warcraft iii\\war3.exe"= UDP:C:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{881BD61D-C8C3-406F-8644-2953E1119C08}C:\\program files\\warcraft iii\\war3.exe"= TCP:C:\program files\warcraft iii\war3.exe:Warcraft III
"{D7CF7694-A0D5-43AD-90FA-4B6370CEAE0A}"= UDP:C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe:Blizzard Downloader
"{57A62713-FF5E-43C5-81E7-9FC1EF1E11CC}"= TCP:C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe:Blizzard Downloader
"{240944E3-5C84-4709-BA54-0BB8394866AD}"= UDP:3724:Blizzard Downloader: 3724
"{377F6026-00BE-48DE-98EB-E6F289B50725}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{F0C3491E-4BE8-4F9D-939F-DFDFCCB5B4EC}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{A9DB4507-7015-4495-98BC-3B6DFC66E4B0}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B859303B-A273-4A5A-9A51-FBEC71736F0B}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{3B65535E-B400-47AC-98D8-2B10B348B4E6}C:\\users\\seer\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\bw877uhr\\wow-burningcrusade-enus[1].exe"= UDP:C:\users\seer\appdata\local\microsoft\windows\temporary internet files\content.ie5\bw877uhr\wow-burningcrusade-enus[1].exe:wow-burningcrusade-enus[1].exe
"UDP Query User{723A96A8-95BA-4A7A-AB5F-C871A5ACE402}C:\\users\\seer\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\bw877uhr\\wow-burningcrusade-enus[1].exe"= TCP:C:\users\seer\appdata\local\microsoft\windows\temporary internet files\content.ie5\bw877uhr\wow-burningcrusade-enus[1].exe:wow-burningcrusade-enus[1].exe
"{D77CE48E-9549-432C-BADF-C443CA780B86}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3F4C1C06-A99F-40E6-83B1-09DB2F04FC51}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{31F0CDBE-06DC-4827-8C3D-0311B6426A30}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\age of chivalry\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\age of chivalry\hl2.exe:hl2
"UDP Query User{41E53C19-DB58-48FA-8822-4AF3241CD41E}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\age of chivalry\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\age of chivalry\hl2.exe:hl2
"TCP Query User{56E3FE84-9F62-4105-9D99-6316C68404CC}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"UDP Query User{0B32D10C-DADA-43BA-B779-F22443505E99}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"{B29A3CC0-2E75-4AD7-A082-47812EC63F34}"= UDP:C:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{8B155B15-762F-4964-8D3C-A8A0C706BE89}"= TCP:C:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{9D3ADB1E-796D-4391-ADC0-B23E1592DF52}"= UDP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{9A9362F0-EEB0-4906-9ABD-9AF80392E068}"= TCP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{435E8AF3-DBEE-42D1-B5C4-40428A7E5210}"= UDP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editor
"{AAE1B7BC-233C-4BBD-A940-C5F4F93CF7B4}"= TCP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editor
|