Bullguard Antivirus Forum Download A Free Copy Of Bullguard Antivirus Software
Free Antivirus Forum - Learn about antivirus, firewalls and personal security Free Antivirus Forum - Learn about antivirus, firewalls and personal security
 HomeLog InRegisterCommunity CalendarSearch the ForumView The Member ListHelp
Internet Redircet Virus on Vista
   
BullGuard Antivirus Forum > Virus Removal > Removal Help > Internet Redircet Virus on Vista  
Forum Quick Jump
 
New Topic Post reply to : Internet Redircet Virus on Vista Printable version of : Internet Redircet Virus on Vista
[ << Previous Thread | Next Thread >> ]

Seer
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11-19-2008 12:57 (GMT +1)    Quote: Internet Redircet Virus on VistaAlert an admin about: Internet Redircet Virus on Vista
Hey all, been looking around and have seen that this one's around there, just can't seem to figure out how to get rid of it hehe. When I do a google search the links get redirected to shopping sites or 'anti-spyware' sites that are just more redirecting viruses.  Any help would be much appreciated.
 
Here's my hjt log:
 
Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 3:55:32 PM, on 11/18/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
Boot mode: Safe mode with network support
Running processes:
C:\Windows\Explorer.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Users\Seer\AppData\Local\Temp\csrssc.exe
C:\Program Files\DAEMON Tools\daemon.exe
G:\bootcd\wintools\autorun.exe
C:\Users\Seer\AppData\Local\Temp\HIJACK.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://safesearch.cyberdefender.com/smallsearch.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.hotmail.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=73&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: C:\Windows\system32\jsne87fidgf.dll - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\Windows\system32\jsne87fidgf.dll
O2 - BHO: (no name) - {F0D48690-A07D-4B74-825C-DB90E57ED8DB} - C:\Windows\system32\fccccCTM.dll
O3 - Toolbar: MyIdentityDefender - {A26503FE-B3B8-4910-A9DC-9CBD25C6B8D6} - C:\Users\Seer\AppData\LocalLow\CyberDefender\cdmyidd.dll (file missing)
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [WAWifiMessage] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [Symantec PIF AlertEng] "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" /a /m "C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [ccApp] "c:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\rqRkiFwv.dll,#1
O4 - HKLM\..\Run: [xsjfn83jkemfofght] C:\Users\Seer\AppData\Local\Temp\winlogin.exe
O4 - HKLM\..\Run: [rs32net] C:\Windows\System32\rs32net.exe
O4 - HKLM\..\Run: [Microsoft Startup Manager] C:\Windows\system32\sysservice.exe
O4 - HKLM\..\Run: [CyberDefender Early Detection Center] "C:\Users\Seer\AppData\Local\CyberDefender Internet Security\AntiSpyware\ISSIntro.exe"
O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [HPAdvisor] C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe autoRun
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [xsjfn83jkemfofght] C:\Users\Seer\AppData\Local\Temp\winlogin.exe
O4 - HKCU\..\Run: [Jnskdfmf9eldfd] C:\Users\Seer\AppData\Local\Temp\csrssc.exe
O4 - HKCU\..\Run: [12CFG94-z641-2SF-N31P-5M1ER6H6L1] C:\RECYCLER\S-1-5-21-2422537357-9063600547-490267057-6977\winigon.exe
O4 - HKCU\..\Run: [rs32net] C:\Windows\System32\rs32net.exe
O4 - HKCU\..\Run: [MSSMSGS] rundll32.exe winpcl32.rom,busRun
O4 - HKCU\..\Run: [CyberDefender Early Detection Center] "C:\Users\Seer\AppData\Local\CyberDefender Internet Security\AntiSpyware\cdas3ffc.exe" /minimize
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Adobe Media Player.lnk = C:\Program Files\Adobe Media Player\Adobe Media Player.exe
O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O13 - Gopher Prefix:
O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262E} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.0/srl_bin/sysreqlab3.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/VistaMSNPUplden-us.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab
O16 - DPF: {6F15128C-E66A-490C-B848-5000B5ABEEAC} (HP Download Manager) - https://h20436.www2.hp.com/ediags/dex/secure/HPDEXAXO.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} (GMNRev Class) - http://h20270.www2.hp.com/ediags/gmn2/install/HPProductDetection.cab
O16 - DPF: {8FA2192F-B95D-40E3-898F-8D7ABB8E00D0} (SpinTop Games Launcher) - http://aolsvc.aol.com/onlinegames/free-trial-mystery-pi-the-lottery-ticket/SpinTopGamesLauncher.cab
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://cf405wc.cs.wwu.edu/activex/AxisCamControl.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {DA758BB1-5F89-4465-975F-8D7179A4BCF3} (WheelofFortune Object) - http://messenger.zone.msn.com/binary/WoF.cab57176.cab
O16 - DPF: {DB7BF79A-FC51-4B5A-92BC-A65731174380} (InstantAction Game Launcher) - http://www.instantaction.com/download/iaplayer.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {F8C5C0F1-D884-43EB-A5A0-9E1C4A102FA8} (GoPetsWeb Control) - https://secure.gopetslive.com/dev/GoPetsWeb.cab
O16 - DPF: {FFBB3F3B-0A5A-4106-BE53-DFE1E2340CB1} (DownloadManager Control) - http://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.2.1.cab
O20 - Winlogon Notify: kvvwdxji - C:\Windows\SYSTEM32\kvvwdxji32.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O22 - SharedTaskScheduler: mcb7uehuj3n8weuhejsw - {C5BF49A2-94F3-42BD-F434-3604812C897D} - C:\Windows\system32\jsne87fidgf.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLCapSvc.exe
O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\CLSched.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: FCI - Unknown owner - C:\Windows\system32\fci.exe.exe:ext.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: ICF - Unknown owner - C:\Windows\system32\icf.exe.exe:ext.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
--
End of file - 11275 bytes
Back to Top
 

Touch
Forum Moderator




Date Joined Jun 2004
Total Posts : 14350
 
   Posted 11-19-2008 1:02 (GMT +1)    Quote: Internet Redircet Virus on VistaAlert an admin about: Internet Redircet Virus on Vista
Hello smile
 
and save it on the desktop. Then double click on it (Fix_download.exe).
You may have to allow the program to download files from the web! 

The program download the necessary cleaning programs. Once the program 
is downloaded, there will be a folder on your desktop named 
Fix.   – if the instructions not automatically opens, so 
double-click "FIX_manual.htm" in Fix folder. 

Please follow the instructions and copy the logs here,
in this Topic.
 
Note : Fix_download.exe is detected by some antivirus programs  as a "RiskTool" /infection; it is not a virus. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.


 

 If necessary,
temporarily disable your anti-virus, real-time protection before downloading
 


Do NOT post your problem in someone elses thread.
A non-profit, volunteer network.

Back to Top
 

Seer
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11-19-2008 6:47 (GMT +1)    Quote: Internet Redircet Virus on VistaAlert an admin about: Internet Redircet Virus on Vista
Hmm Malware wasn't in the folder, so tried going to a link you posted in another thread but the website won't let me through. Wondering if my comp is blocking it?
 
Would it be possible to e-mail it or post as an attatchment please? 
 
Also, thanks for the quick reply. I was geared up to wait 3 days :P
 
*2nd Edit*
Nevermind on it blocking me out. It does, but I had a copy dl'ed already that didn't run. Looked on the web for another DL thinking it broken and someone had suggested renaming the install. Tried it, and it worked. Will continue steps.

Post Edited (Seer) : 19-11-2008 06:01:32 GMT

Back to Top
 

Seer
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11-19-2008 8:31 (GMT +1)    Quote: Internet Redircet Virus on VistaAlert an admin about: Internet Redircet Virus on Vista
Awesome.  Almost everything seems to work perfectly. Only other issue is on some sites the pitures don't show up *shrug*
ComboFix is the one that did it for me. Also, for those that have this problem and are blocked from the DL sites, http://www.allyoulike.com/?p=6161  that site is for a ComboFix DL I found, and while I didn't have a site for Malwarebytes, just look for an address that doesn't have words in it like malware, spyware, removal/er, etc. 
 
Thanks, Touch for all your help! It's very much appreciated!  Also if you'd like me to post my logs let me know.
Back to Top
 

Seer
New Member


Date Joined Nov 2008
Total Posts : 12
 
   Posted 11-19-2008 8:48 (GMT +1)    Quote: Internet Redircet Virus on VistaAlert an admin about: Internet Redircet Virus on Vista
*Edit* Nevermind..it's still there. I restarted and when I tried to google winigon the redirects started happening again. Going to post the logs j.i.c.
Malwarebytes' Anti-Malware 1.30
Database version: 1306
Windows 6.0.6001 Service Pack 1
 
11/18/2008 10:52:15 PM
mbam-log-2008-11-18 (22-52-15).txt
 
Scan type: Full Scan (C:\|D:\|E:\|F:\|G:\|H:\|)
Objects scanned: 202462
Time elapsed: 44 minute(s), 12 second(s)
 
Memory Processes Infected: 1
Memory Modules Infected: 2
Registry Keys Infected: 24
Registry Values Infected: 14
Registry Data Items Infected: 3
Folders Infected: 0
Files Infected: 24
 
Memory Processes Infected:
C:\Users\Seer\AppData\Local\Temp\csrssc.exe (Trojan.Downloader) -> Unloaded process successfully.
 
Memory Modules Infected:
C:\Windows\System32\fccccCTM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Windows\System32\jsne87fidgf.dll (Trojan.BHO) -> Delete on reboot.
 
Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{a05cc918-2556-436a-b830-a90a3be9d6a1} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\CLSID\{a05cc918-2556-436a-b830-a90a3be9d6a1} (Trojan.Vundo.H) -> Delete on reboot.
HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\cdmyidd.securitytoolbar.1 (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{b200799f-9538-403d-9a6e-36f5942ec540} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{a84e835e-1b9c-4fc0-980f-4b2da3c6a2a7} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\CLSID\{bf0a1ff4-bbaf-487f-bc85-a24ef8f443a8} (Adware.Comet) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1962c5bc-e475-465b-823b-133e711bceb9} (Adware.Starware) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\kvvwdxji (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\MRSoft (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\fci (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\ICF (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\restore (Rootkit.Agent) -> Quarantined and deleted successfully.
 
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rs32net (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\rs32net (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{a26503fe-b3b8-4910-a9dc-9cbd25c6b8d6} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\{c5bf49a2-94f3-42bd-f434-3604812c897d} (Trojan.BHO) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSServer (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MSSMSGS (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xsjfn83jkemfofght (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\xsjfn83jkemfofght (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\microsoft startup manager (Backdoor.Bot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Jnskdfmf9eldfd (Trojan.Downloader) -> Quarantined and deleted successfully.
 
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Notification Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fccccctm -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo.H) -> Data: c:\windows\system32\fccccctm -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFolderOptions (Hijack.FolderOptions) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
 
Folders Infected:
(No malicious items detected)
 
Files Infected:
C:\Windows\System32\fccccCTM.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\Windows\System32\MTCccccf.ini (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\MTCccccf.ini2 (Trojan.Vundo.H) -> Quarantined and deleted successfully.
C:\Windows\System32\rs32net.exe (Trojan.FakeAlert.H) -> Quarantined and deleted successfully.
C:\Windows\System32\jsne87fidgf.dll (Trojan.BHO) -> Delete on reboot.
C:\Windows\System32\fklame32.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN11FB.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN1841.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN5B97.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BN8D71.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BNAA91.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\BNF5A5.tmp (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\tweAA9B.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\kvvwdxji.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\kvvwdxji32.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\winpcl32.rom (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\winyom32.rom (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Windows\System32\opnlMgeb.dll (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\winlogin.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\Windows\System32\sysservice.exe (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Users\Seer\AppData\Local\Temp\csrssc.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Windows\System32\fci.exe.exe (Worm.Zhelatin) -> Quarantined and deleted successfully.
C:\Windows\System32\icf.exe.exe (Worm.Zhelatin) -> Quarantined and deleted successfully.
C:\Windows\System32\drivers\restore.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
 
 
 
ComboFix 08-08-03.05 - Seer 2009-11-24 23:16:41.1 - NTFSx86
Microsoft® Windows Vista™ Home Premium   6.0.6001.1.1252.1.1033.18.1256 [GMT -8:00]
Running from: C:\Users\Seer\Desktop\CF.exe
 * Created a new restore point
.
- REDUCED FUNCTIONALITY MODE -
.
 
(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))
.
 
C:\Windows\Downloaded Program Files\setup.inf
 
.
(((((((((((((((((((((((((   Files Created from 2009-10-25 to 2009-11-25  )))))))))))))))))))))))))))))))
.
 
No new files created in this timespan
 
.
((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-11-19 06:58 41,952      ----a-w      C:\Users\All Users\nvModes.dat
2008-11-19 06:58 41,952      ----a-w      C:\ProgramData\nvModes.dat
2008-10-26 01:34 22,328      ----a-w      C:\Users\Seer\AppData\Roaming\PnkBstrK.sys
2008-09-15 05:16 56      ---ha-w      C:\Users\All Users\ezsidmv.dat
2008-09-15 05:16 56      ---ha-w      C:\ProgramData\ezsidmv.dat
2008-06-26 18:33 41,192      ----a-w      C:\Users\Seer\AppData\Roaming\nvModes.dat
2008-06-24 15:27 174      --sha-w      C:\Program Files\desktop.ini
2008-11-19 06:57      262,144     --sha-w      C:\Windows\ServiceProfiles\LocalService\ntuser.dat
2008-11-19 06:54 2,048      --sha-w      C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
2008-11-19 06:54 2,048      --sha-w      C:\Windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
2008-06-15 04:33 16,384      --sha-w      C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-06-15 04:33 32,768      --sha-w      C:\Windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-06-15 04:33 16,384      --sha-w      C:\Windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
2007-08-01 16:05 56      --sha-r      C:\Windows\System32\C1CACC7099.sys
2008-04-30 03:24 1,890      --sha-w      C:\Windows\System32\KGyGaAvL.sys
2008-11-19 07:11 16,384      --sha-w      C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
2008-11-19 07:11 49,152      --sha-w      C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
2008-11-19 07:11 16,384      --sha-w      C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
.
[code]<pre>
----a-w           325,204 2006-12-22 04:56:28  C:\SwSetup\SP34746\WCAMC\FW_210_Silence Install .exe
</pre>[/code]
 
 
(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Steam"="C:\Program Files\Steam\Steam.exe" [2008-10-22 16:16 1410296]
"HPAdvisor"="C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe" [2007-03-20 14:23 1773568]
"DAEMON Tools"="C:\Program Files\DAEMON Tools\daemon.exe" [2007-04-03 14:29 165784]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 11:34 5724184]
"12CFG94-z641-2SF-N31P-5M1ER6H6L1"="C:\RECYCLER\S-1-5-21-2422537357-9063600547-490267057-6977\winigon.exe" [2008-11-18 13:41 72704]
"CyberDefender Early Detection Center"="C:\Users\Seer\AppData\Local\CyberDefender Internet Security\AntiSpyware\cdas3ffc.exe" [N/A]
"WindowsWelcomeCenter"="oobefldr.dll" [2008-01-18 23:36 2153472 C:\Windows\System32\oobefldr.dll]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2008-01-18 18:31 1033512]
"QlbCtrl"="C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-02-13 10:38 159744]
"NvCplDaemon"="C:\Windows\system32\NvCpl.dll" [2008-02-27 04:48 13515296]
"NvMediaCenter"="C:\Windows\system32\NvMcTray.dll" [2008-02-27 04:48 92704]
"WAWifiMessage"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe" [2007-01-10 15:12 317128]
"Symantec PIF AlertEng"="C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe" [N/A]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0\bin\jusched.exe" [2007-05-19 03:08 77824]
"SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-10-09 12:43 729088]
"NvSvc"="C:\Windows\system32\nvsvc.dll" [2008-02-27 04:48 166432]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-02-12 06:37 174872]
"hpWirelessAssistant"="C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-03-01 12:18 472776]
"HP Health Check Scheduler"="[ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe" [N/A]
"ccApp"="c:\Program Files\Common Files\Symantec Shared\ccApp.exe" [N/A]
"HP Software Update"="C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe" [2005-02-16 22:11 49152]
"CyberDefender Early Detection Center"="C:\Users\Seer\AppData\Local\CyberDefender Internet Security\AntiSpyware\ISSIntro.exe" [N/A]
"Malwarebytes Anti-Malware (reboot)"="C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" [N/A]
"RtHDVCpl"="RtHDVCpl.exe" [2007-03-09 09:50 4390912 C:\Windows\RtHDVCpl.exe]
 
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Reader Speed Launch.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe [2006-10-23 00:48:20 40048]
Adobe Reader Synchronizer.lnk - C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe [2006-10-22 23:01:50 734872]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office\OSA9.EXE [1999-02-17 12:05:56 65588]
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
 
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"msacm.ac3filter"= ac3filter.acm
 
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Authentication Packages      REG_MULTI_SZ         msv1_0 C:\Windows\system32\fccccCTM
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"UacDisableNotify"=dword:00000001
"InternetSettingsDisableNotify"=dword:00000001
"AutoUpdateDisableNotify"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
 
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Svc]
"AntiVirusOverride"=dword:00000001
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile]
"DoNotAllowExceptions"= 0 (0x0)
 
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{666EC466-6176-4E0D-9459-CF2238C4E3A3}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{59A2A803-911B-4BBE-B092-62D7A09BB047}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{71414D90-91F3-4F9B-96A1-BF4E7DFD4CDB}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{A2035C52-162E-4966-91DF-ABF2C908A042}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{6714543A-9B10-4E9D-A17A-2D09A661542F}"= UDP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{85760691-6AD0-4A62-9EFA-4A801235FD2C}"= TCP:C:\Program Files\earthlink totalaccess\TaskPanl.exe:taskpanl
"{44EC9A8C-EA96-46D9-848E-7AD73D5AB056}"= UDP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{2815E3B4-F48A-42A6-B541-334BFA7B8585}"= TCP:C:\Program Files\uTorrent\utorrent.exe:µTorrent
"{2F64F22B-D565-43CF-ACB3-FD3368E1822A}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{FC51745E-F666-4DA7-990E-8C9D4A06EDD9}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{6D922F78-668C-4792-967F-E784927A2450}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{2F2C9694-2CD9-48D0-98A6-AA766ED1091A}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent
"{011A2FED-E25F-493D-85CA-C84ED81C89DC}"= UDP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"{ADFAFE51-9B62-40DD-A003-2C9D0B90EDD5}"= TCP:C:\Program Files\Sierra\FEAR\FEAR.exe:FEAR
"{55B7A1BD-071E-4E34-B247-F390999E6A71}"= UDP:C:\Program Files\Steam\Steam.exe:Steam Client
"{91AD8762-011C-498D-8610-CC2B738A3E54}"= TCP:C:\Program Files\Steam\Steam.exe:Steam Client
"{4479AE0B-8C0F-4BEB-9534-43BD5BBAC61E}"= UDP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{C92043AD-05D0-413A-B0BB-7B98AC3D7859}"= TCP:C:\Program Files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{E30B3CF9-49FA-4C23-81B1-E26A498612F8}"= UDP:C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe:Hellgate: London
"{7C9A1E51-0664-449C-8179-85F60920DE0D}"= TCP:C:\Program Files\Flagship Studios\Hellgate London\Launcher.exe:Hellgate: London
"TCP Query User{B9637447-C374-4EC3-9822-5788342684A3}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= UDP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"UDP Query User{88051DB4-3D12-45A8-8065-3004FBF39BC7}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= TCP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"TCP Query User{E7BC6A92-748D-441A-8BC9-3C41D1961AED}C:\\program files\\steam\\steamapps\\akzell98\\condition zero\\hl.exe"= UDP:C:\program files\steam\steamapps\akzell98\condition zero\hl.exe:Half-Life Launcher
"UDP Query User{A1ED8856-20E2-45DA-BD18-AD1E046EDD96}C:\\program files\\steam\\steamapps\\akzell98\\condition zero\\hl.exe"= TCP:C:\program files\steam\steamapps\akzell98\condition zero\hl.exe:Half-Life Launcher
"TCP Query User{4EBBE62A-395B-4EB7-B738-8D81BD3C3651}C:\\nexon\\maplestory\\maplestory.exe"= UDP:C:\nexon\maplestory\maplestory.exe:MapleStory
"UDP Query User{C00B0A5F-8BA5-4249-8C76-1E081EE97368}C:\\nexon\\maplestory\\maplestory.exe"= TCP:C:\nexon\maplestory\maplestory.exe:MapleStory
"TCP Query User{CCA0DE84-BCDE-4A43-944C-24FFC292B567}C:\\program files\\itunes\\itunes.exe"= UDP:C:\program files\itunes\itunes.exe:iTunes
"UDP Query User{EA924170-3BA8-4383-9860-E87CD09252BE}C:\\program files\\itunes\\itunes.exe"= TCP:C:\program files\itunes\itunes.exe:iTunes
"TCP Query User{99750CE3-356A-43FD-A7C6-5C58D5BD03F0}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\condition zero\\hl.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\condition zero\hl.exe:Half-Life Launcher
"UDP Query User{67900CFF-83D6-4002-8D76-EAEA94F434EF}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\condition zero\\hl.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\condition zero\hl.exe:Half-Life Launcher
"TCP Query User{03D3B47C-F5EC-46E5-A9F5-C24B98B33D4A}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exe:DC++
"UDP Query User{DBA6B628-3335-4342-9642-230D13D9D072}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exe:DC++
"TCP Query User{77C6DCB4-EE4D-42BC-8F24-C682D993ABB5}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= UDP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"UDP Query User{744E2147-A538-408A-A183-6AE255A438EE}C:\\program files\\ea games\\ultima online the eighth age\\client.exe"= TCP:C:\program files\ea games\ultima online the eighth age\client.exe:Ultima Online Client
"TCP Query User{9D043A7B-D6FA-4A35-A2DD-32610CD4915D}C:\\program files\\dc++\\dcplusplus.exe"= UDP:C:\program files\dc++\dcplusplus.exe:DC++
"UDP Query User{0F0C2C68-31B5-42C9-B198-D56683F65DC4}C:\\program files\\dc++\\dcplusplus.exe"= TCP:C:\program files\dc++\dcplusplus.exe:DC++
"TCP Query User{1BD033AC-4541-4B3D-8E87-6A96FDD36399}C:\\program files\\steam\\steamapps\\common\\stalker shadow of chernobyl\\bin\\xr_3da.exe"= UDP:C:\program files\steam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe:XR_3DA
"UDP Query User{413E730D-C565-4037-B2A8-9C6526D7CE3F}C:\\program files\\steam\\steamapps\\common\\stalker shadow of chernobyl\\bin\\xr_3da.exe"= TCP:C:\program files\steam\steamapps\common\stalker shadow of chernobyl\bin\xr_3da.exe:XR_3DA
"TCP Query User{CE420079-D521-4C41-A2CB-A43E4A949765}C:\\program files\\aim6\\aim6.exe"= UDP:C:\program files\aim6\aim6.exe:AIM
"UDP Query User{B5D49D4F-3331-4DAB-92AD-B5102BDC0541}C:\\program files\\aim6\\aim6.exe"= TCP:C:\program files\aim6\aim6.exe:AIM
"{10E576DB-79E0-48B4-BE02-5852526C3247}"= UDP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{910188CD-EA53-4F89-A9E9-E4775E4EC0ED}"= TCP:C:\Program Files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"TCP Query User{719513CD-B9A9-4963-90F2-CD0C228BE7AF}C:\\users\\seer\\appdata\\locallow\\garagegames\\iaplayer\\products\\5000\\install\\screwjumperpc.exe"= UDP:C:\users\seer\appdata\locallow\garagegames\iaplayer\products\5000\install\screwjumperpc.exe:screwjumperpc.exe
"UDP Query User{C674DA00-BA6B-4C4B-A96E-B1041CE7F2A7}C:\\users\\seer\\appdata\\locallow\\garagegames\\iaplayer\\products\\5000\\install\\screwjumperpc.exe"= TCP:C:\users\seer\appdata\locallow\garagegames\iaplayer\products\5000\install\screwjumperpc.exe:screwjumperpc.exe
"{D44C60E9-738E-4652-87E8-D04C945A7407}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"TCP Query User{43CA2784-DC14-4ED5-AB47-2135486809D9}C:\\program files\\msn messenger\\msnmsgr.exe"= UDP:C:\program files\msn messenger\msnmsgr.exe:msnmsgr.exe
"UDP Query User{1817570F-F338-4F04-828A-529B56112D56}C:\\program files\\msn messenger\\msnmsgr.exe"= TCP:C:\program files\msn messenger\msnmsgr.exe:msnmsgr.exe
"TCP Query User{F100CD52-20DA-441B-A91E-5EEA4431FD3F}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\source sdk base\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\source sdk base\hl2.exe:hl2
"UDP Query User{D5F8EF45-E82D-49B3-8724-8B3AD36D8F52}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\source sdk base\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\source sdk base\hl2.exe:hl2
"TCP Query User{6F1B3979-08AF-4824-AD27-F6A5C1D13CD7}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"UDP Query User{E0F8E8DE-3CC9-4B3C-8BE6-A0D4A23280B3}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"TCP Query User{2DAEAFCE-AB2B-4FF3-8306-DBCF8FA7A9EE}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life 2 deathmatch\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life 2 deathmatch\hl2.exe:hl2
"UDP Query User{BDB5EB23-27EA-4E68-B137-D443B1AE7FE6}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life 2 deathmatch\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life 2 deathmatch\hl2.exe:hl2
"{13E70000-9591-419D-97A1-D174B0C60C75}"= UDP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{D3F7AE90-0C65-49A9-86BC-F70B23766FF1}"= TCP:C:\Windows\System32\PnkBstrA.exe:PnkBstrA
"{0F45737C-348B-4D85-8132-83939BD64EBD}"= UDP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"{03CDA35C-470B-42DF-9C23-D7635FFA0E27}"= TCP:C:\Windows\System32\PnkBstrB.exe:PnkBstrB
"TCP Query User{E29525ED-C573-4D8E-AEFA-128D6843256D}C:\\program files\\steam\\steamapps\\akzell98\\counter-strike\\hl.exe"= UDP:C:\program files\steam\steamapps\akzell98\counter-strike\hl.exe:Half-Life Launcher
"UDP Query User{EF76A7A8-9B81-4AE6-B42A-648C5B320E2C}C:\\program files\\steam\\steamapps\\akzell98\\counter-strike\\hl.exe"= TCP:C:\program files\steam\steamapps\akzell98\counter-strike\hl.exe:Half-Life Launcher
"TCP Query User{365FD3FB-D0C4-4865-B58F-6F98E4D0BD4F}C:\\neverwinternights\\nwn\\nwmain.exe"= UDP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"UDP Query User{A8F12001-0502-4B59-B872-F23CAA658A9A}C:\\neverwinternights\\nwn\\nwmain.exe"= TCP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"TCP Query User{C69640D8-2566-4E70-8646-A1035214AEFB}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\day of defeat\\hl.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\day of defeat\hl.exe:Half-Life Launcher
"UDP Query User{AEE24181-8214-40B9-9313-D6E55EBEC1CD}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\day of defeat\\hl.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\day of defeat\hl.exe:Half-Life Launcher
"TCP Query User{8553BEFB-D708-4B05-8F8A-4E61925FC8B0}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life\\hl.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life\hl.exe:Half-Life Launcher
"UDP Query User{B13B01C8-AEB9-4F30-ADE1-41547CBE57E5}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\half-life\\hl.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\half-life\hl.exe:Half-Life Launcher
"{273604EC-8D9D-4395-9301-F646FD263AD5}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{F787724F-2E64-4705-94AF-3F2EB2FCEEA1}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main
"{D23E272B-0A51-47F7-82FE-99CD1F7AD626}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{3B29AB32-3E07-4D9A-A2DA-F9FD0B2A65D4}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD
"{FA657527-1897-48CB-88B6-DB42F00A8C66}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{41D16D1B-3310-4CB3-B638-EF288D3B7518}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater
"{A37EF105-D9B4-45BA-AAAA-87FE83EB3F19}"= UDP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"{FB8FFD1D-F611-4778-83D4-95242453C5E6}"= TCP:C:\Program Files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server
"TCP Query User{9FC57BCC-1616-4F63-925B-79F42B8514C4}C:\\neverwinternights\\nwn\\nwmain.exe"= UDP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"UDP Query User{C1939D45-89A4-4610-A0D8-DBF7777CBCA5}C:\\neverwinternights\\nwn\\nwmain.exe"= TCP:C:\neverwinternights\nwn\nwmain.exe:Neverwinter Nights
"TCP Query User{627BF9E3-AAC5-44C5-9BDF-7ED509854E2E}C:\\program files\\warcraft iii\\war3.exe"= UDP:C:\program files\warcraft iii\war3.exe:Warcraft III
"UDP Query User{881BD61D-C8C3-406F-8644-2953E1119C08}C:\\program files\\warcraft iii\\war3.exe"= TCP:C:\program files\warcraft iii\war3.exe:Warcraft III
"{D7CF7694-A0D5-43AD-90FA-4B6370CEAE0A}"= UDP:C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe:Blizzard Downloader
"{57A62713-FF5E-43C5-81E7-9FC1EF1E11CC}"= TCP:C:\Users\Public\Documents\Blizzard Entertainment\World of Warcraft\WoW-2.3.0.7561-to-2.4.0.8089-enUS-downloader.exe:Blizzard Downloader
"{240944E3-5C84-4709-BA54-0BB8394866AD}"= UDP:3724:Blizzard Downloader: 3724
"{377F6026-00BE-48DE-98EB-E6F289B50725}"= C:\Program Files\HP\QuickPlay\QP.exe:Quick Play
"{F0C3491E-4BE8-4F9D-939F-DFDFCCB5B4EC}"= C:\Program Files\HP\QuickPlay\QPService.exe:Quick Play Resident Program
"{A9DB4507-7015-4495-98BC-3B6DFC66E4B0}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes
"{B859303B-A273-4A5A-9A51-FBEC71736F0B}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes
"TCP Query User{3B65535E-B400-47AC-98D8-2B10B348B4E6}C:\\users\\seer\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\bw877uhr\\wow-burningcrusade-enus[1].exe"= UDP:C:\users\seer\appdata\local\microsoft\windows\temporary internet files\content.ie5\bw877uhr\wow-burningcrusade-enus[1].exe:wow-burningcrusade-enus[1].exe
"UDP Query User{723A96A8-95BA-4A7A-AB5F-C871A5ACE402}C:\\users\\seer\\appdata\\local\\microsoft\\windows\\temporary internet files\\content.ie5\\bw877uhr\\wow-burningcrusade-enus[1].exe"= TCP:C:\users\seer\appdata\local\microsoft\windows\temporary internet files\content.ie5\bw877uhr\wow-burningcrusade-enus[1].exe:wow-burningcrusade-enus[1].exe
"{D77CE48E-9549-432C-BADF-C443CA780B86}"= UDP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{3F4C1C06-A99F-40E6-83B1-09DB2F04FC51}"= TCP:C:\Program Files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
"TCP Query User{31F0CDBE-06DC-4827-8C3D-0311B6426A30}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\age of chivalry\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\age of chivalry\hl2.exe:hl2
"UDP Query User{41E53C19-DB58-48FA-8822-4AF3241CD41E}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\age of chivalry\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\age of chivalry\hl2.exe:hl2
"TCP Query User{56E3FE84-9F62-4105-9D99-6316C68404CC}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= UDP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"UDP Query User{0B32D10C-DADA-43BA-B779-F22443505E99}C:\\program files\\steam\\steamapps\\onetimeuse513@hotmail.com\\counter-strike source\\hl2.exe"= TCP:C:\program files\steam\steamapps\onetimeuse513@hotmail.com\counter-strike source\hl2.exe:hl2
"{B29A3CC0-2E75-4AD7-A082-47812EC63F34}"= UDP:C:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{8B155B15-762F-4964-8D3C-A8A0C706BE89}"= TCP:C:\Program Files\Ubisoft\Far Cry 2\bin\FarCry2.exe:Far Cry 2
"{9D3ADB1E-796D-4391-ADC0-B23E1592DF52}"= UDP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{9A9362F0-EEB0-4906-9ABD-9AF80392E068}"= TCP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Launcher.exe:Far Cry 2 Updater
"{435E8AF3-DBEE-42D1-B5C4-40428A7E5210}"= UDP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editor
"{AAE1B7BC-233C-4BBD-A940-C5F4F93CF7B4}"= TCP:C:\Program Files\Ubisoft\Far Cry 2\bin\FC2Editor.exe:Editor