Got the info.txt and the SysProt.txt since Gmer would not work. I had ran it as an administrator before too.
As far as how my computer is acting, I get constant alerts from WinPatrol asking if programs such as c:\PROGRA~2\hazafupe\hazafupe.dll,a and C:\ProgramData\wemafuni\wemafuni.dll,s and the names of these programs may occasionally change.
I also have trouble running some websites on my browsers. I have Firefox, Internet Explorer, and Safari. I can't run Youtube on any of them. I can only run Facebook on Internet Explorer. I can only google search on Safari and so forth. I have also been getting pop ups.
info.txt logfile of random's system information tool 1.06 2009-12-04 18:22:59
======Uninstall list======
-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
-->MsiExec /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
Ace DivX Player v2.1-->"C:\Program Files\GustoSoft\Ace DivX Player\unins000.exe"
Activation Assistant for the 2007 Microsoft Office suites-->"C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E1}\Microsoft Office Activation Assistant.exe" REMOVE=TRUE MODIFY=FALSE
Adobe Flash Player 10 Plugin-->C:\Windows\system32\Macromed\Flash\uninstall_plugin.exe
Adobe Flash Player 9 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete
Adobe Flash Player ActiveX-->C:\Windows\system32\Macromed\Flash\uninstall_activeX.exe
Adobe Reader 7.0.8-->MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A70800000002}
Adobe Reader Korean Fonts-->MsiExec.exe /I{AC76BA86-7AD7-5670-0000-7E8A45000001}
Adobe Shockwave Player-->C:\WINDOWS\System32\Adobe\SHOCKW~1\UNWISE.EXE C:\WINDOWS\System32\Adobe\SHOCKW~1\Install.log
AGEIA PhysX v7.11.13-->MsiExec.exe /X{95FC26FB-19FD-4A96-BBB1-B1062E8648F5}
Apple Mobile Device Support-->MsiExec.exe /I{8355F970-601D-442D-A79B-1D7DB4F24CAD}
Apple Software Update-->MsiExec.exe /I{6956856F-B6B3-4BE0-BA0B-8F495BE32033}
Audiosurf Demo-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/12910Audition-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{3D281B1C-BF39-4893-B32A-EAB3B84BDE34}\setup.exe" -l0x9 -removeonly
avast! Antivirus-->C:\Program Files\Alwil Software\Avast4\aswRunDll.exe "C:\Program Files\Alwil Software\Avast4\Setup\setiface.dll",RunSetup
Battlefield Heroes-->"C:\Program Files\EA Games\Battlefield Heroes\uninstaller.exe" "C:\Program Files\EA Games\Battlefield Heroes\Uninstall.xml"
Battleswarm: Field of Honor-->C:\Program Files\Reality Gap\Battleswarm\Uninstall.exe
Bejeweled 2 Deluxe-->"C:\Program Files\Gateway Games\Bejeweled 2 Deluxe\Uninstall.exe"
BigFix-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\00\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{34FF0741-EC67-4C05-AC2A-6D257123DF2E}\setup.exe" -l0x9 -uninst -f"C:\Program Files\BigFix\Uninst.isu" -c"C:\Program Files\BigFix\Lib\UninstallHelper.dll"
Blasterball 3-->"C:\Program Files\Gateway Games\Blasterball 3\Uninstall.exe"
Bonjour-->MsiExec.exe /I{07287123-B8AC-41CE-8346-3D777245C35B}
BrightShadow-->C:\Program Files\InstallShield Installation Information\{68A6DB8D-478D-41C9-BE5C-43B2C4E9C143}\setup.exe -runfromtemp -l0x0009 -removeonly
Browser Address Error Redirector-->regsvr32 /u /s "c:\google\BAE.dll"
BS.Player FREE-->"C:\Program Files\Webteh\BSplayer\uninstall.exe"
Chuzzle Deluxe-->"C:\Program Files\Gateway Games\Chuzzle Deluxe\Uninstall.exe"
Counter-Strike: Source-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/240Day of Defeat: Source-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/300Digital Media Reader-->C:\Program Files\Common Files\InstallShield\Driver\8\Intel 32\IDriver.exe /M{BE2CC4A5-2128-4EA2-941D-14F7A6A1AB61} /l1033
Diner Dash-->"C:\Program Files\Gateway Games\Diner Dash\Uninstall.exe"
DivX 4.12 Codec-->"C:\Program Files\DivXCodec\uninstall.exe"
DivX Codec-->C:\Program Files\DivX\DivXCodecUninstall.exe /CODEC
DivX Converter-->C:\Program Files\DivX\DivXConverterUninstall.exe /CONVERTER
DivX Player-->C:\Program Files\DivX\DivXPlayerUninstall.exe /PLAYER
DivX Plus DirectShow Filters-->C:\Program Files\DivX\DivXDSFiltersUninstall.exe /DSFILTERS
DivX Web Player-->C:\Program Files\DivX\DivXWebPlayerUninstall.exe /PLUGIN
Dynasty Warriors 6-->MsiExec.exe /X{7506D1CD-B7FE-40C7-AE1F-FE8666361700}
EA SPORTS online 2008-->C:\Program Files\EA SPORTS\EA SPORTS online\EASOUNInstaller.exe
EPSON NX410 Series Printer Uninstall-->C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FINSFCA.EXE /R /APD /P:"EPSON NX410 Series"
EPSON Scan-->C:\Program Files\epson\escndv\setup\setup.exe /r
FIFA 08-->MsiExec.exe /X{0A2A5039-B37F-489D-B1DC-A5258DF9E697}
FIFA 10-->MsiExec.exe /X{11202615-E557-4ECF-9B86-F59C81E52909}
Finale Viewer 2008-->C:\Program Files\Finale Viewer 2008\uninstallFinViewer.exe
Free M4a to MP3 Converter 6.0-->"C:\Program Files\Free M4a to MP3 Converter\unins000.exe"
Frets On Fire-->"C:\Program Files\Frets on Fire\Uninstall.exe"
GameSpy Arcade-->C:\PROGRA~1\GAMESP~1\UNWISE.EXE C:\PROGRA~1\GAMESP~1\INSTALL.LOG
GameTracker Lite-->C:\Program Files\GameTracker\gametracker-uninst.exe
Garena-->C:\Program Files\InstallShield Installation Information\{89C89156-A70F-4C6D-9CAE-2EA71F1396FE}\setup.exe -runfromtemp -l0x0009 -removeonly
Garry's Mod-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/4000Gateway Game Console-->"C:\Program Files\Gateway Games\Gateway Game Console\Uninstall.exe"
Gateway Recovery Center Installer-->MsiExec.exe /X{7F3BCF8A-8E02-4659-AF25-F9AB66BD6718}
Google Updater-->"C:\Program Files\Google\Google Updater\GoogleUpdater.exe" -uninstall
Graboid Video 1.65-->C:\Program Files\Graboid\uninst.exe
Grand Fantasia-->C:\AeriaGames\GrandFantasia\Uninst.exe
Half-Life 2: Deathmatch-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/320Half-Life 2-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/220HijackThis 2.0.2-->"C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall /qb+ REBOOTPROMPT=""
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {A7EEA2F2-BFCD-4A54-A575-7B81A786E658} /qb+ REBOOTPROMPT=""
Hunting Unlimited-->C:\Windows\IsUninst.exe -f"C:\Program Files\Hunting Unlimited\Uninst.isu"
ijji REACTOR-->"C:\Program Files\InstallShield Installation Information\{901DC58A-5C1B-4315-BA40-5AD3D3A463B9}\setup.exe" -runfromtemp -l0x0009 -removeonly
Insurgency-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/17700Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Intel(R) Management Engine Interface-->C:\Windows\system32\heciudlg.exe -uninstall
Intel(R) Matrix Storage Manager-->C:\Windows\System32\Imsmudlg.exe
Intel(R) PRO Network Connections Drivers-->Prounstl.exe
Intel(R) Viiv(TM) Software-->MsiExec.exe /X{26C610BF-761B-4209-BD6A-A0F1B73D6DDE} /qb!
iTunes-->MsiExec.exe /I{5D601655-6D54-4384-B52C-17EC5385FBBD}
Java(TM) SE Runtime Environment 6-->MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160000}
JEOPARDY-->"C:\Program Files\Gateway Games\JEOPARDY\Uninstall.exe"
kill.switch-->C:\PROGRA~1\KILL~1.SWI\UNWISE.EXE C:\PROGRA~1\KILL~1.SWI\INSTALL.LOG
Killing Floor-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/1250K-Lite Codec Pack 3.2.5 Standard-->"C:\Program Files\K-Lite Codec Pack\unins000.exe"
Left 4 Dead-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/500Lexmark X6100 Series-->C:\Program Files\Lexmark X6100 Series\Install\x86\Uninst.exe
Madden NFL 08-->C:\Program Files\EA Sports\Madden NFL 08\EAUninstall.exe
Magic ISO Maker v5.5 (build 0272)-->C:\PROGRA~1\MagicISO\UNWISE.EXE C:\PROGRA~1\MagicISO\INSTALL.LOG
MagicDisc 2.7.105-->C:\PROGRA~1\MAGICD~1\UNWISE.EXE C:\PROGRA~1\MAGICD~1\INSTALL.LOG
Microsoft .NET Framework 3.5 SP1-->C:\Windows\Microsoft.NET\Framework\v3.5\Microsoft .NET Framework 3.5 SP1\setup.exe
Microsoft .NET Framework 3.5 SP1-->MsiExec.exe /I{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}
Microsoft Digital Image Starter Edition 2006-->"C:\Program Files\Common Files\Microsoft Shared\Picture It!\RmvSuite.exe" ADDREMOVE=1 SKU=TRIAL VERSION=12
Microsoft Money 2006-->"C:\Program Files\Microsoft Money 2006\MNYCoreFiles\Setup\uninst.exe" /s:120
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0115-0409-0000-0000000FF1CE} /uninstall {DE5A002D-8122-4278-A7EE-3121E7EA254E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-0117-0409-0000-0000000FF1CE} /uninstall {2FC4457D-409E-466F-861F-FB0CB796B53E}
Microsoft Office 2007 Service Pack 2 (SP2)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Professional 2007 Trial-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall PROR /dll OSETUP.DLL
Microsoft Office Professional 2007-->MsiExec.exe /X{91120000-0014-0000-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0409-0000-0000000FF1CE} /uninstall {ABDDE972-355B-4AF1-89A8-DA50B7B5C045}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-040C-0000-0000000FF1CE} /uninstall {F580DDD5-8D37-4998-968E-EBB76BB86787}
Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)-->msiexec /package {90120000-001F-0C0A-0000-0000000FF1CE} /uninstall {187308AB-5FA7-4F14-9AB9-D290383A10D9}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Silverlight-->MsiExec.exe /I{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053-->MsiExec.exe /X{770657D0-A123-3C07-8E44-1C83EC895118}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d}
Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{A49F249F-0C91-497F-86DF-B2585E8E76B7}
Microsoft Works-->MsiExec.exe /I{6D52C408-B09A-4520-9B18-475B81D393F1}
mIRC-->C:\Program Files\mIRC\uninstall.exe _?=C:\Program Files\mIRC
Mozilla Firefox (3.0.15)-->C:\Program Files\Mozilla Firefox\uninstall\helper.exe
MP4 Player -->C:\Program Files\MP4 Player\uninst.exe
MPlugin-->"C:\Program Files\InstallShield Installation Information\{6102D63A-9387-4FC8-98E4-181121F8C0BA}\setup.exe" -runfromtemp -l0x0009 -removeonly
MSXML 4.0 SP2 (KB936181)-->MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF}
MSXML 4.0 SP2 (KB941833)-->MsiExec.exe /I{C523D256-313D-4866-B36A-F3DE528246EF}
MSXML 4.0 SP2 (KB954430)-->MsiExec.exe /I{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}
MSXML 4.0 SP2 (KB973688)-->MsiExec.exe /I{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}
Musicnotes Player V1.23.1-->"C:\Program Files\Musicnotes\Player\unins000.exe"
Neffy 1,2,0,22-->C:\Program Files\Neffy\uninst.exe
Neo Steam : The Shattered Continent-->C:\Games\Neo Steam\uninst.exe
OGA Notifier 2.0.0048.0-->MsiExec.exe /I{B2544A03-10D0-4E5E-BA69-0362FFC20D18}
OpenAL-->"C:\Program Files\OpenAL\oalinst.exe" /U
Pando Media Booster-->C:\Program Files\Pando Networks\Media Booster\uninst.exe
Penguins!-->"C:\Program Files\Gateway Games\Penguins!\Uninstall.exe"
Plain Sight-->MsiExec.exe /I{A4957F2C-A8C1-4575-A5C7-78BCDA42A83A}
PokerStars.net-->"C:\Program Files\PokerStars.NET\PokerStarsUninstall.exe" /u:PokerStars.net
Polar Bowler-->"C:\Program Files\Gateway Games\Polar Bowler\Uninstall.exe"
Polar Golfer-->"C:\Program Files\Gateway Games\Polar Golfer\Uninstall.exe"
Power2Go 5.0-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{40BF1E83-20EB-11D8-97C5-0009C5020658}\Setup.exe" -uninstall
QuickTime-->MsiExec.exe /I{C78EAC6F-7A73-452E-8134-DBB2165C5A68}
Safari-->MsiExec.exe /I{E56D39F8-2A9F-44B4-B068-A72E45A073E6}
SBC Yahoo! DSL Home Networking Installer-->C:\Program Files\2Wire\Uninstaller.exe
Scions Of Fate-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{DA3C53B8-49B0-41CF-9D5C-D96A7FCBD029}\setup.exe" -l0x9 -removeonly
SCRABBLE-->"C:\Program Files\Gateway Games\SCRABBLE\Uninstall.exe"
Security Update for 2007 Microsoft Office System (KB969559)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {69F52148-9BF6-4CDC-BF76-103DEAF3DD08}
Security Update for 2007 Microsoft Office System (KB973704)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {E626DC89-A787-4553-9BB3-DC2EC7E1593F}
Security Update for Microsoft Office Excel 2007 (KB973593)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7D6255E3-3423-4D8B-A328-F6F8D28DD5FE}
Security Update for Microsoft Office Outlook 2007 (KB972363)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {120BE9A0-9B09-4855-9E0C-7DEE45CB03C0}
Security Update for Microsoft Office PowerPoint 2007 (KB957789)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7559E742-FF9F-4FAE-B279-008ED296CB4D}
Security Update for Microsoft Office Publisher 2007 (KB969693)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {7BE67088-1EB3-4569-8E75-DDAFBF61BC4E}
Security Update for Microsoft Office system 2007 (972581)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {3D019598-7B59-447A-80AE-815B703B84FF}
Security Update for Microsoft Office system 2007 (KB969613)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {5ECEB317-CBE9-4E08-AB10-756CB6F0FB6C}
Security Update for Microsoft Office system 2007 (KB974234)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {FCD742B9-7A55-44BC-A776-F795F21FEDDC}
Security Update for Microsoft Office Visio Viewer 2007 (KB973709)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {71127777-8B2C-4F97-AF7A-6CF8CAC8224D}
SigmaTel Audio-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\10\01\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A462213D-EED4-42C2-9A60-7BDD4D4B0B17}\setup.exe" -l0x9 -remove -removeonly
Smash Online 1.0-->C:\Gamigo Games\Smash Online\uninst.exe
Soft Data Fax Modem with SmartCP-->C:\Program Files\CONEXANT\CNXT_MODEM_PCI_HSF\UIU32m.exe -U -I*.INF
Soul of the Ultimate Nation-->C:\Program Files\InstallShield Installation Information\{4B22DD86-47B1-4454-BFF7-64FCA3D0631C}\setup.exe -runfromtemp -l0x0009 -removeonly
Source SDK Base-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/215Steam-->MsiExec.exe /X{048298C9-A4D3-490B-9FF9-AB023A9238F3}
System Requirements Lab-->C:\Program Files\SystemRequirementsLab\Uninstall.exe
System Requirements Lab-->MsiExec.exe /I{1E99F5D7-4262-4C7C-9135-F066E7485811}
TalesRunner 1.58720081016-->C:\Program Files\gpotato\TalesRunner\uninst.exe
Team Fortress 2-->"C:\Program Files\Steam\steam.exe"
steam://uninstall/440The Sims 2 Family Fun Stuff-->C:\Program Files\EA GAMES\The Sims 2 Family Fun Stuff\EAUninstall.exe
The Sims 2 Glamour Life Stuff-->C:\Program Files\EA GAMES\The Sims 2 Glamour Life Stuff\EAUninstall.exe
The Sims 2 Nightlife-->C:\Program Files\EA GAMES\The Sims 2 Nightlife\EAUninstall.exe
The Sims 2 Open For Business-->C:\Program Files\EA GAMES\The Sims 2 Open For Business\EAUninstall.exe
The Sims 2 Pets-->C:\Program Files\EA GAMES\The Sims 2 Pets\EAUninstall.exe
The Sims 2 University-->C:\Program Files\EA GAMES\The Sims 2 University\EAUninstall.exe
The Sims 2-->C:\Program Files\EA GAMES\The Sims 2\EAUninstall.exe
The Sims Complete Collection-->RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{F2527115-B8BF-4FDB-B5DA-5AADFB7C13E1}\Setup.exe" -l0x9 -l0009
TmNationsForever-->"C:\Program Files\TmNationsForever\unins000.exe"
Uniblue RegistryBooster 2009-->"C:\ProgramData\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\Uniblue RegistryBooster.exe" REMOVE=TRUE MODIFY=FALSE
Uniblue RegistryBooster 2009-->C:\ProgramData\{B46E1EF5-0B37-4DB4-A4E2-9F2B41036185}\Uniblue RegistryBooster.exe
Update for 2007 Microsoft Office System (KB967642)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {C444285D-5E4F-48A4-91DD-47AAAA68E92D}
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)-->C:\Windows\system32\msiexec.exe /package {CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9} /uninstall {B2AE9C82-DC7B-3641-BFC8-87275C4F3607} /qb+ REBOOTPROMPT=""
Update for Microsoft Office 2007 Help for Common Features (KB963673)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {AB365889-0395-4FAD-B702-CA5985D53D42}
Update for Microsoft Office Access 2007 Help (KB963663)-->msiexec /package {90120000-0015-0409-0000-0000000FF1CE} /uninstall {6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}
Update for Microsoft Office Excel 2007 Help (KB963678)-->msiexec /package {90120000-0016-0409-0000-0000000FF1CE} /uninstall {199DF7B6-169C-448C-B511-1054101BE9C9}
Update for Microsoft Office Outlook 2007 Help (KB963677)-->msiexec /package {90120000-001A-0409-0000-0000000FF1CE} /uninstall {0451F231-E3E3-4943-AB9F-58EB96171784}
Update for Microsoft Office Powerpoint 2007 Help (KB963669)-->msiexec /package {90120000-0018-0409-0000-0000000FF1CE} /uninstall {397B1D4F-ED7B-4ACA-A637-43B670843876}
Update for Microsoft Office Publisher 2007 Help (KB963667)-->msiexec /package {90120000-0019-0409-0000-0000000FF1CE} /uninstall {2E40DE55-B289-4C8B-8901-5D369B16814F}
Update for Microsoft Office Script Editor Help (KB963671)-->msiexec /package {90120000-006E-0409-0000-0000000FF1CE} /uninstall {CD11C6A2-FFC6-4271-8EAB-79C3582F505C}
Update for Microsoft Office Word 2007 (KB974561)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {0CDDBAA2-2111-4A0E-A1B0-76C40C635331}
Update for Microsoft Office Word 2007 Help (KB963665)-->msiexec /package {90120000-001B-0409-0000-0000000FF1CE} /uninstall {80E762AA-C921-4839-9D7D-DB62A72C0726}
Update for Outlook 2007 Junk Email Filter (kb975960)-->msiexec /package {91120000-0014-0000-0000-0000000FF1CE} /uninstall {F1AB1BED-7477-4D5A-BD0C-04C2109459A5}
VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B}
Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F}
Veoh Web Player-->"C:\Program Files\Veoh Networks\VeohWebPlayer\uninst.exe"
VideoLAN VLC media player 0.8.6d-->C:\Program Files\VideoLAN\VLC\uninstall.exe
Windows Driver Package - ViXS Systems Inc. ViXS PureTV-U (11/17/2006 6.2.77.1)-->C:\PROGRA~1\DIFX\2B7BF24833E54BA6\dpinst.exe /u C:\Windows\System32\DriverStore\FileRepository\xcbda.inf_80d7a2b2\xcbda.inf
Windows Live installer-->MsiExec.exe /X{A7E4ECCA-4A8E-4258-8EC8-2DCCF5B11320}
Windows Live Messenger-->MsiExec.exe /X{508CE775-4BA4-4748-82DF-FE28DA9F03B0}
Windows Live OneCare safety scanner-->"C:\Program Files\Windows Live Safety Center\UnInstall.exe"
Windows Live OneCare safety scanner-->MsiExec.exe /X{FE0646A7-19D0-41B4-A2BB-2C35D644270D}
WinPatrol 2008-->C:\PROGRA~1\BILLPS~1\WINPAT~1\Setup.exe /remove /q0
WinRAR archiver-->C:\Program Files\WinRAR\uninstall.exe
WYDGLOBAL (remove only)-->"C:\GameNetworks\WYDGLOBAL\uninstall.exe"
=====HijackThis Backups=====
O4 - HKCU\..\Run: [ares vista] "C:\Program Files\Ares Vista\AresVista.exe" -h [2009-01-10]
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) [2009-01-10]
O9 - Extra 'Tools' menuitem: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU) [2009-01-10]
O9 - Extra button: Absolute Poker - {13C1DBF6-7535-495c-91F6-8C13714ED485} - C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Absolute Poker\Absolute Poker.lnk (file missing) (HKCU) [2009-01-10]
======Security center information======
AS: Windows Defender (disabled)
======System event log======
Computer Name: Phong-PC
Event Code: 3004
Message: Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid= ... tid=146262 Scan ID: {E3965903-E764-4A40-A42C-FE993AB19867}
User: PHONG-PC\Owner
Name: Trojan:Win32/Vundo.gen!BS
ID: 146262
Severity ID: 5
Category ID: 8
Path Found: file:C:\ProgramData\wemafuni\wemafuni.dll
Alert Type: Spyware or other potentially unwanted software
Detection Type: Generic
Record Number: 159507
Source Name: Microsoft-Windows-Windows Defender
Time Written: 20091204235558.000000-000
Event Type: Warning
User:
Computer Name: Phong-PC
Event Code: 3004
Message: Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid= ... tid=146262 Scan ID: {A9E52797-6E44-48DD-A49A-EDFC2525BB95}
User: PHONG-PC\Owner
Name: Trojan:Win32/Vundo.gen!BS
ID: 146262
Severity ID: 5
Category ID: 8
Path Found: file:C:\ProgramData\wemafuni\wemafuni.dll
Alert Type: Spyware or other potentially unwanted software
Detection Type: Generic
Record Number: 159508
Source Name: Microsoft-Windows-Windows Defender
Time Written: 20091204235713.000000-000
Event Type: Warning
User:
Computer Name: Phong-PC
Event Code: 3004
Message: Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid= ... tid=146262 Scan ID: {5DA5151F-7FFA-4E7F-8177-BCF486300AD6}
User: PHONG-PC\Owner
Name: Trojan:Win32/Vundo.gen!BS
ID: 146262
Severity ID: 5
Category ID: 8
Path Found: file:C:\ProgramData\wemafuni\wemafuni.dll
Alert Type: Spyware or other potentially unwanted software
Detection Type: Generic
Record Number: 159510
Source Name: Microsoft-Windows-Windows Defender
Time Written: 20091205000644.000000-000
Event Type: Warning
User:
Computer Name: Phong-PC
Event Code: 3004
Message: Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid= ... tid=146262 Scan ID: {0D4A7DF4-225E-47FB-B7DF-E75184D67F1D}
User: PHONG-PC\Owner
Name: Trojan:Win32/Vundo.gen!BS
ID: 146262
Severity ID: 5
Category ID: 8
Path Found: file:C:\ProgramData\wemafuni\wemafuni.dll
Alert Type: Spyware or other potentially unwanted software
Detection Type: Generic
Record Number: 159513
Source Name: Microsoft-Windows-Windows Defender
Time Written: 20091205000951.000000-000
Event Type: Warning
User:
Computer Name: Phong-PC
Event Code: 3004
Message: Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow.
For more information please see the following:
http://go.microsoft.com/fwlink/?linkid= ... tid=146262 Scan ID: {36B3B20A-3E30-41D3-B1AB-644F753D8B8D}
User: PHONG-PC\Owner
Name: Trojan:Win32/Vundo.gen!BS
ID: 146262
Severity ID: 5
Category ID: 8
Path Found: file:C:\ProgramData\wemafuni\wemafuni.dll
Alert Type: Spyware or other potentially unwanted software
Detection Type: Generic
Record Number: 159515
Source Name: Microsoft-Windows-Windows Defender
Time Written: 20091205002144.000000-000
Event Type: Warning
User:
=====Application event log=====
Computer Name: Phong-PC
Event Code: 1000
Message: Faulting application 6uie5oim.exe, version 1.0.15.15252, time stamp 0x4b07cc3d, faulting module 6uie5oim.exe, version 1.0.15.15252, time stamp 0x4b07cc3d, exception code 0xc0000005, fault offset 0x0000c4b1, process id 0x17f4, application start time 0x01ca74761a759b82.
Record Number: 37466
Source Name: Application Error
Time Written: 20091204001120.000000-000
Event Type: Error
User:
Computer Name: Phong-PC
Event Code: 1000
Message: Faulting application 6uie5oim.exe, version 1.0.15.15252, time stamp 0x4b07cc3d, faulting module 6uie5oim.exe, version 1.0.15.15252, time stamp 0x4b07cc3d, exception code 0xc0000005, fault offset 0x0000c4b1, process id 0x818, application start time 0x01ca747654a5584c.
Record Number: 37467
Source Name: Application Error
Time Written: 20091204001240.000000-000
Event Type: Error
User:
Computer Name: Phong-PC
Event Code: 1000
Message: Faulting application 6uie5oim.exe, version 1.0.15.15252, time stamp 0x4b07cc3d, faulting module 6uie5oim.exe, version 1.0.15.15252, time stamp 0x4b07cc3d, exception code 0xc0000005, fault offset 0x0000c4b1, process id 0x870, application start time 0x01ca747728045f53.
Record Number: 37494
Source Name: Application Error
Time Written: 20091204001835.000000-000
Event Type: Error
User:
Computer Name: Phong-PC
Event Code: 1000
Message: Faulting application firefox.exe, version 1.9.0.3576, time
SysProt AntiRootkit v1.0.1.0
by swatkat
******************************************************************************************
******************************************************************************************
No Hidden Processes found
******************************************************************************************
******************************************************************************************
Kernel Modules:
Module Name: \SystemRoot\System32\Drivers\dump_iaStor.sys
Service Name: ---
Module Base: 8BA0B000
Module End: 8BAC3000
Hidden: Yes
******************************************************************************************
******************************************************************************************
No SSDT Hooks found
******************************************************************************************
******************************************************************************************
No Kernel Hooks found
******************************************************************************************
******************************************************************************************
No IRP Hooks found
******************************************************************************************
******************************************************************************************
Ports:
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54484
Remote Address: IP-72-55-158-137.HOSTMEUP.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: CLOSE_WAIT
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54445
Remote Address: 66.179.234.169:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: CLOSE_WAIT
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54392
Remote Address: CHANNEL64-09-01-SNC1.FACEBOOK.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54349
Remote Address: PHONG-P.GATEWAY.2WIRE.NET:58080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54348
Remote Address: PHONG-P.GATEWAY.2WIRE.NET:58080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54300
Remote Address: PHONG-P.GATEWAY.2WIRE.NET:58080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54299
Remote Address: PHONG-P.GATEWAY.2WIRE.NET:58080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54272
Remote Address: 69.63.187.16:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54250
Remote Address: WWW-11-03-ASH1.FACEBOOK.COM:HTTP
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P.GATEWAY.2WIRE.NET:NETBIOS-SSN
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: PHONG-P:54483
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: ESTABLISHED
Local Address: PHONG-P:54481
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54478
Remote Address: LOCALHOST:21660
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: ESTABLISHED
Local Address: PHONG-P:54444
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: ESTABLISHED
Local Address: PHONG-P:54443
Remote Address: LOCALHOST:21660
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: ESTABLISHED
Local Address: PHONG-P:54433
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54403
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54401
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54398
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54391
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:54390
Remote Address: LOCALHOST:21668
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:54383
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54382
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54366
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54363
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54360
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54354
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54343
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54336
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54329
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54317
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54308
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54305
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54296
Remote Address: LOCALHOST:21668
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54291
Remote Address: LOCALHOST:12080
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:54271
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:54270
Remote Address: LOCALHOST:21668
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: FIN_WAIT2
Local Address: PHONG-P:54249
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:54248
Remote Address: LOCALHOST:21668
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: FIN_WAIT2
Local Address: PHONG-P:54162
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:54161
Remote Address: LOCALHOST:21668
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: FIN_WAIT2
Local Address: PHONG-P:54068
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53899
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53740
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53712
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53706
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53499
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53445
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53425
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53288
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53255
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53030
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53021
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53014
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:53008
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:52838
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:52623
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:52389
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:52369
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:52315
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51816
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51598
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51588
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51492
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51375
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51048
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51034
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51024
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:51000
Remote Address: LOCALHOST:12080
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:49209
Remote Address: LOCALHOST:49208
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:49208
Remote Address: LOCALHOST:49209
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:49205
Remote Address: LOCALHOST:49204
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:49204
Remote Address: LOCALHOST:49205
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:49169
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
State: LISTENING
Local Address: PHONG-P:49168
Remote Address: LOCALHOST:27015
Type: TCP
Process: C:\Program Files\iTunes\iTunesHelper.exe
State: ESTABLISHED
Local Address: PHONG-P:27015
Remote Address: LOCALHOST:49168
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: ESTABLISHED
Local Address: PHONG-P:27015
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
State: LISTENING
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54437
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54435
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54432
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54429
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54426
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54423
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54420
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54417
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54414
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54411
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54408
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54405
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54400
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54397
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54396
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54393
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54390
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: ESTABLISHED
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54386
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54381
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54380
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54371
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54370
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54369
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54367
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54365
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54362
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54359
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54356
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54350
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54345
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54342
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54335
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54332
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54331
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54328
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54315
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54314
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54313
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54312
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54311
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54310
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54307
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54301
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54293
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54290
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54287
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54284
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54270
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: CLOSE_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54248
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: CLOSE_WAIT
Local Address: PHONG-P:21668
Remote Address: LOCALHOST:54161
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: CLOSE_WAIT
Local Address: PHONG-P:21668
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Mozilla Firefox\firefox.exe
State: LISTENING
Local Address: PHONG-P:21660
Remote Address: LOCALHOST:54493
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21660
Remote Address: LOCALHOST:54488
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21660
Remote Address: LOCALHOST:54478
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: ESTABLISHED
Local Address: PHONG-P:21660
Remote Address: LOCALHOST:54477
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:21660
Remote Address: LOCALHOST:54443
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: ESTABLISHED
Local Address: PHONG-P:21660
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: LISTENING
Local Address: PHONG-P:12143
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: PHONG-P:12119
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: PHONG-P:12110
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54494
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54483
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54444
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54441
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54421
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54418
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54415
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54391
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54340
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54297
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54288
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54285
Type: TCP
Process: [System Idle Process]
State: TIME_WAIT
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54271
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54249
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54162
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:54068
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53899
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53740
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53712
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53706
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53499
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53445
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53425
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53288
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53255
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53030
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53021
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53014
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:53008
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:52838
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:52623
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:52389
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:52369
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:52315
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51816
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51598
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51588
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51492
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51375
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51048
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51034
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51024
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: LOCALHOST:51000
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: ESTABLISHED
Local Address: PHONG-P:12080
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
State: LISTENING
Local Address: PHONG-P:12025
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
State: LISTENING
Local Address: PHONG-P:7438
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\svchost.exe
State: LISTENING
Local Address: PHONG-P:DCCM
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\svchost.exe
State: LISTENING
Local Address: PHONG-P:5354
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: LISTENING
Local Address: PHONG-P:63843
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: LISTENING
Local Address: PHONG-P:62590
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
State: LISTENING
Local Address: PHONG-P:61660
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: LISTENING
Local Address: PHONG-P:58080
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: LISTENING
Local Address: PHONG-P:58002
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: LISTENING
Local Address: PHONG-P:58001
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: LISTENING
Local Address: PHONG-P:54772
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
State: LISTENING
Local Address: PHONG-P:49161
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\services.exe
State: LISTENING
Local Address: PHONG-P:49156
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\lsass.exe
State: LISTENING
Local Address: PHONG-P:49154
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\svchost.exe
State: LISTENING
Local Address: PHONG-P:49153
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\svchost.exe
State: LISTENING
Local Address: PHONG-P:49152
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\wininit.exe
State: LISTENING
Local Address: PHONG-P:10035
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\lxbfcoms.exe
State: LISTENING
Local Address: PHONG-P:9667
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: LISTENING
Local Address: PHONG-P:9666
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: LISTENING
Local Address: PHONG-P:5357
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: PHONG-P:FTPS
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\svchost.exe
State: LISTENING
Local Address: PHONG-P:MICROSOFT-DS
Remote Address: 0.0.0.0:0
Type: TCP
Process: System
State: LISTENING
Local Address: PHONG-P:EPMAP
Remote Address: 0.0.0.0:0
Type: TCP
Process: C:\WINDOWS\System32\svchost.exe
State: LISTENING
Local Address: PHONG-P.GATEWAY.2WIRE.NET:61234
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P.GATEWAY.2WIRE.NET:58855
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P.GATEWAY.2WIRE.NET:54573
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P.GATEWAY.2WIRE.NET:5353
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: PHONG-P.GATEWAY.2WIRE.NET:SSDP
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P.GATEWAY.2WIRE.NET:SSDP
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P.GATEWAY.2WIRE.NET:138
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: PHONG-P.GATEWAY.2WIRE.NET:NETBIOS-NS
Remote Address: NA
Type: UDP
Process: System
State: NA
Local Address: PHONG-P:62404
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P:61234
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P:58856
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P:55272
Remote Address: NA
Type: UDP
Process: C:\Program Files\Internet Explorer\iexplore.exe
State: NA
Local Address: PHONG-P:55074
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P:55073
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P:54574
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P:54572
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P:51896
Remote Address: NA
Type: UDP
Process: C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
State: NA
Local Address: PHONG-P:SSDP
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P:SSDP
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Media Server\bin\mediaserver.exe
State: NA
Local Address: PHONG-P:64592
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: PHONG-P:59024
Remote Address: NA
Type: UDP
Process: C:\Program Files\Bonjour\mDNSResponder.exe
State: NA
Local Address: PHONG-P:58224
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
State: NA
Local Address: PHONG-P:55075
Remote Address: NA
Type: UDP
Process: C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
State: NA
Local Address: PHONG-P:53299
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P:51895
Remote Address: NA
Type: UDP
Process: C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
State: NA
Local Address: PHONG-P:31439
Remote Address: NA
Type: UDP
Process: C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
State: NA
Local Address: PHONG-P:31438
Remote Address: NA
Type: UDP
Process: C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe
State: NA
Local Address: PHONG-P:IPSEC-MSFT
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P:UPNP-DISCOVERY
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P:SSDP
Remote Address: NA
Type: UDP
Process: C:\Program Files\Intel\IntelDH\Intel Media Server\Shells\Remote UI Service.exe
State: NA
Local Address: PHONG-P:500
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
Local Address: PHONG-P:123
Remote Address: NA
Type: UDP
Process: C:\WINDOWS\System32\svchost.exe
State: NA
******************************************************************************************
******************************************************************************************
Hidden files/folders:
Object: C:\System Volume Information\MountPointManagerRemoteDatabase
Status: Access denied
Object: C:\System Volume Information\SPP
Status: Access denied
Object: C:\System Volume Information\tracking.log
Status: Access denied
Object: C:\System Volume Information\{15896458-dfb5-11de-a628-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{3678dced-dbda-11de-819b-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{3eb5f9f1-d9d9-11de-a5b7-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{42e134ed-db09-11de-a939-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{471f3b07-da94-11de-be83-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{60074506-dd4f-11de-9159-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{6725b791-d6ac-11de-9c43-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{6c3edb6b-d327-11de-993e-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{9225e8f2-e066-11de-91a3-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{b3a74b35-d120-11de-8b45-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{b3a74b49-d120-11de-8b45-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{bc987379-d4b6-11de-bf98-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{bd465686-d876-11de-8bc3-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{c2a764fe-d61a-11de-a96c-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{d616de4d-db96-11de-bf15-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\System Volume Information\{e2e2db0b-ddf5-11de-a135-0019d1113830}{3808876b-c176-4e48-b7ae-04046e6cc752}
Status: Access denied
Object: C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTDiagLog.etl
Status: Access denied
Object: C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-Application.etl
Status: Access denied
Object: C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTEventlog-Security.etl
Status: Access denied
Object: C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTEventLog-System.etl
Status: Access denied
Object: C:\WINDOWS\System32\LogFiles\WMI\RtBackup\EtwRTMsMpPsSession.etl
Status: Access denied