System Investigator by OlrikLog Created On: 2114_03-10-2009
SINO Version: 2.4.9.9
Total RAM: 2046 MB |
Free RAM: 1052 MB | Pagefile Size: 3939 MB
C: |
22365 MB out of 49999 MB Free | Local Fixed Disk
D: |
12279 MB out of 49999 MB Free | Local Fixed Disk
E: |
21738 MB out of 52626 MB Free | Local Fixed Disk
F: |
0 MB out of 389 MB Free | CD-ROM Disc
<<<< System Information >>>>Computer Name: HOME-NATHAN
Username: NaTHaN
Language Setting: ENU
Windows Directory: C:\WINDOWS
Windows Version: Windows XP Service Pack 3
<<<< Startup Items >>>>[desktop] -
<Startup> - desktop.ini
[desktop] -
<Startup> - desktop.ini
[MsnMsgr] -
<HKU\S-1-5-21-1757981266-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
[Messenger (Yahoo!)] -
<HKU\S-1-5-21-1757981266-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
[ctfmon.exe] -
<HKU\S-1-5-21-1757981266-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\ctfmon.exe
[Google Update] -
<HKU\S-1-5-21-1757981266-861567501-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Documents and Settings\NaTHaN\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" /c
[desktop] -
<Startup> - desktop.ini
[desktop] -
<Common Startup> - desktop.ini
[StartCCC] -
<HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
[RTHDCPL] -
<HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - RTHDCPL.EXE
[Alcmtr] -
<HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - ALCMTR.EXE
[AVG8_TRAY] -
<HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - C:\PROGRA~1\AVG\AVG8\avgtray.exe
[SunJavaUpdateSched] -
<HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run> - "D:\Program Files\Java\jre6\bin\jusched.exe"
<<<< MS Services >>>>Alerter (Alerter) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Application Layer Gateway Service (ALG) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\alg.exe
Application Management (AppMgmt) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
ASP.NET State Service (aspnet_state) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Ati HotKey Poller (Ati HotKey Poller) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\Ati2evxx.exe
Windows Audio (AudioSrv) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Background Intelligent Transfer Service (BITS) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Computer Browser (Browser) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Indexing Service (CiSvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\cisvc.exe
ClipBook (ClipSrv) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\clipsrv.exe
.NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
COM+ System Application (COMSysApp) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Cryptographic Services (CryptSvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
DCOM Server Process Launcher (DcomLaunch) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost -k DcomLaunch
DHCP Client (Dhcp) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Logical Disk Manager Administrative Service (dmadmin) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\dmadmin.exe /com
Logical Disk Manager (dmserver) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
DNS Client (Dnscache) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k NetworkService
Error Reporting Service (ERSvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Event Log (Eventlog) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\services.exe
COM+ Event System (EventSystem) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Fast User Switching Compatibility (FastUserSwitchingCompatibility) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
Help and Support (helpsvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Human Interface Device Access (HidServ) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
HTTP SSL (HTTPFilter) -
Running [Manual | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k HTTPFilter
Windows CardSpace (idsvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
IMAPI CD-Burning COM Service (ImapiService) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\imapi.exe
Server (lanmanserver) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Workstation (lanmanworkstation) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
TCP/IP NetBIOS Helper (LmHosts) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Messenger (Messenger) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
NetMeeting Remote Desktop Sharing (mnmsrvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\mnmsrvc.exe
Distributed Transaction Coordinator (MSDTC) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\msdtc.exe
Windows Installer (MSIServer) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\msiexec.exe /V
Network DDE (NetDDE) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\netdde.exe
Network DDE DSDM (NetDDEdsdm) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\netdde.exe
Net Logon (Netlogon) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Network Connections (Netman) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Net.Tcp Port Sharing Service (NetTcpPortSharing) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
Network Location Awareness (NLA) (Nla) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
NT LM Security Support Provider (NtLmSsp) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Removable Storage (NtmsSvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Microsoft Office Diagnostics Service (odserv) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
Office Source Engine (ose) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Plug and Play (PlugPlay) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\services.exe
IPSEC Services (PolicyAgent) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Protected Storage (ProtectedStorage) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Remote Access Auto Connection Manager (RasAuto) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Access Connection Manager (RasMan) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Desktop Help Session Manager (RDSessMgr) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\sessmgr.exe
Routing and Remote Access (RemoteAccess) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Registry (RemoteRegistry) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Remote Procedure Call (RPC) Locator (RpcLocator) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\locator.exe
Remote Procedure Call (RPC) (RpcSs) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost -k rpcss
QoS RSVP (RSVP) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\rsvp.exe
Security Accounts Manager (SamSs) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Smart Card (SCardSvr) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\SCardSvr.exe
Task Scheduler (Schedule) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Secondary Logon (seclogon) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
System Event Notification (SENS) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Shell Hardware Detection (ShellHWDetection) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Print Spooler (Spooler) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\spoolsv.exe
System Restore Service (srservice) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
SSDP Discovery Service (SSDPSRV) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Image Acquisition (WIA) (stisvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k imgsvc
MS Software Shadow Copy Provider (SwPrv) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\dllhost.exe /Processid:{5EB8EAC4-6955-4CE3-A272-07C94FE3613C}
Performance Logs and Alerts (SysmonLog) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\smlogsvc.exe
Telephony (TapiSrv) -
Running [Manual | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Terminal Services (TermService) -
Running [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost -k DComLaunch
Themes (Themes) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Telnet (TlntSvr) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\tlntsvr.exe
Distributed Link Tracking Client (TrkWks) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Universal Plug and Play Device Host (upnphost) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Uninterruptible Power Supply (UPS) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\ups.exe
Volume Shadow Copy (VSS) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\vssvc.exe
Windows Time (W32Time) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
WebClient (WebClient) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Management Instrumentation (winmgmt) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Portable Media Serial Number Service (WmdmPmSN) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Management Instrumentation Driver Extensions (Wmi) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
WMI Performance Adapter (WmiApSrv) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\wbem\wmiapsrv.exe
Security Center (wscsvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Automatic Updates (wuauserv) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Wireless Zero Configuration (WZCSVC) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Network Provisioning Service (xmlprov) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
<<<< Non-MS Services >>>>ATI Smart (ATI Smart) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\ati2sgag.exe
AVG Free8 E-mail Scanner (avg8emc) -
Running [Auto | Stoppable | Not_Pausable] - C:\PROGRA~1\AVG\AVG8\avgemc.exe
AVG Free8 WatchDog (avg8wd) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
Wired AutoConfig (Dot3svc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k dot3svc
Extensible Authentication Protocol Service (EapHost) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k eapsvcs
Health Key and Certificate Management Service (hkmsvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Java Quick Starter (JavaQuickStarterService) -
Running [Auto | Stoppable | Pausable] - "D:\Program Files\Java\jre6\bin\jqs.exe" -service -config "D:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
Network Access Protection Agent (napagent) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
ckpesto (ppfyjwfru) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
SeaPort (SeaPort) -
Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe"
Yahoo! Updater (YahooAUService) -
Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe"
<<<< Boot.ini >>>>[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
<<<< Ipconfig >>>>Windows IP Configuration
Host Name . . . . . . . . . . . . : home-nathan
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : Yes
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Local Area Connection 5:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Realtek RTL8169/8110 Family Gigabit Ethernet NIC
Physical Address. . . . . . . . . : 00-E0-4D-41-15-B3
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.1.2
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.1.1
DHCP Server . . . . . . . . . . . : 192.168.1.1
DNS Servers . . . . . . . . . . . : 192.168.1.1
Lease Obtained. . . . . . . . . . : Saturday, October 03, 2009 9:01:00 PM
Lease Expires . . . . . . . . . . : Saturday, October 03, 2009 10:01:00 PM
<<<< Pinging >>>>OpenDNS Domain TestPinging to www.opendns.com [208.69.38.150]:
Response - 312ms
Response - 312ms
Response - 312ms
Response - 296ms
Packets: Sent = 4, Received = 4, Lost = 0
Minimum = 296ms - Maximum = 312ms
OpenDNS IP TestPinging to 208.67.222.222 [208.67.222.222]:
Response - 312ms
Response - 296ms
Response - 296ms
Response - 297ms
Packets: Sent = 4, Received = 4, Lost = 0
Minimum = 296ms - Maximum = 297ms
YouTube Domain TestPinging to www.youtube.com [74.125.153.113]:
Response - 78ms
Response - 78ms
Response - 62ms
Response - 77ms
Packets: Sent = 4, Received = 4, Lost = 0
Minimum = 62ms - Maximum = 77ms
YouTube IP TestPinging to 208.117.236.69 [208.117.236.69]:
Response - 219ms
Response - 203ms
Response - 217ms
Response - 203ms
Packets: Sent = 4, Received = 4, Lost = 0
Minimum = 203ms - Maximum = 217ms
localhost TestPinging to 127.0.0.1 [127.0.0.1]:
Response - 0ms
Response - 0ms
Response - 0ms
Response - 0ms
Packets: Sent = 4, Received = 4, Lost = 0
Minimum = 0ms - Maximum = 0ms
<<<< Netstat >>>>Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1016
c:\windows\system32\WS2_32.dll
C:\WINDOWS\system32\RPCRT4.dll
c:\windows\system32\rpcss.dll
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ADVAPI32.dll
[svchost.exe]
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
[System]
TCP 0.0.0.0:2869 0.0.0.0:0 LISTENING 1180
C:\WINDOWS\system32\httpapi.dll
c:\windows\system32\upnphost.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
TCP 0.0.0.0:5101 0.0.0.0:0 LISTENING 4056
[YahooMessenger.exe]
TCP 127.0.0.1:1025 0.0.0.0:0 LISTENING 568
[alg.exe]
TCP 127.0.0.1:4000 0.0.0.0:0 LISTENING 2936
[msnmsgr.exe]
TCP 127.0.0.1:5152 0.0.0.0:0 LISTENING 1696
[jqs.exe]
TCP 127.0.0.1:10080 0.0.0.0:0 LISTENING 996
[avgnsx.exe]
TCP 127.0.0.1:10110 0.0.0.0:0 LISTENING 1964
[avgemc.exe]
TCP 127.0.0.1:13128 0.0.0.0:0 LISTENING 996
[avgnsx.exe]
TCP 127.0.0.1:18080 0.0.0.0:0 LISTENING 996
[avgnsx.exe]
TCP 192.168.1.2:139 0.0.0.0:0 LISTENING 4
[System]
TCP 127.0.0.1:1120 127.0.0.1:1121 ESTABLISHED 1328
[firefox.exe]
TCP 127.0.0.1:1121 127.0.0.1:1120 ESTABLISHED 1328
[firefox.exe]
TCP 127.0.0.1:1123 127.0.0.1:1124 ESTABLISHED 1328
[firefox.exe]
TCP 127.0.0.1:1124 127.0.0.1:1123 ESTABLISHED 1328
[firefox.exe]
TCP 127.0.0.1:3110 127.0.0.1:3111 ESTABLISHED 4056
[YahooMessenger.exe]
TCP 127.0.0.1:3111 127.0.0.1:3110 ESTABLISHED 4056
[YahooMessenger.exe]
TCP 127.0.0.1:3931 127.0.0.1:10080 ESTABLISHED 1328
[firefox.exe]
TCP 127.0.0.1:4000 127.0.0.1:4007 ESTABLISHED 2936
[msnmsgr.exe]
TCP 127.0.0.1:4007 127.0.0.1:4000 ESTABLISHED 2936
[msnmsgr.exe]
TCP 127.0.0.1:10080 127.0.0.1:3931 ESTABLISHED 996
[avgnsx.exe]
TCP 192.168.1.2:3932 67.205.44.129:80 ESTABLISHED 996
[avgnsx.exe]
TCP 192.168.1.2:3993 64.4.34.216:1863 ESTABLISHED 2936
[msnmsgr.exe]
TCP 192.168.1.2:3998 68.180.217.30:5050 ESTABLISHED 4056
[YahooMessenger.exe]
TCP 192.168.1.2:4016 68.142.233.172:443 ESTABLISHED 4056
[YahooMessenger.exe]
TCP 127.0.0.1:10080 127.0.0.1:4118 FIN_WAIT_2 996
[avgnsx.exe]
TCP 127.0.0.1:1433 127.0.0.1:10080 CLOSE_WAIT 2924
[jusched.exe]
TCP 127.0.0.1:3933 127.0.0.1:10080 CLOSE_WAIT 2680
[EXCEL.EXE]
TCP 127.0.0.1:4118 127.0.0.1:10080 CLOSE_WAIT 3612
[SINO.exe]
TCP 127.0.0.1:5152 127.0.0.1:2723 CLOSE_WAIT 1696
[jqs.exe]
TCP 192.168.1.2:4119 67.205.44.129:80 CLOSE_WAIT 996
[avgnsx.exe]
TCP 127.0.0.1:4101 127.0.0.1:10080 TIME_WAIT 0
TCP 127.0.0.1:4106 127.0.0.1:10080 TIME_WAIT 0
TCP 127.0.0.1:4111 127.0.0.1:10080 TIME_WAIT 0
TCP 127.0.0.1:4114 127.0.0.1:10080 TIME_WAIT 0
TCP 127.0.0.1:4122 127.0.0.1:10080 TIME_WAIT 0
TCP 127.0.0.1:4124 127.0.0.1:10080 TIME_WAIT 0
TCP 127.0.0.1:10080 127.0.0.1:4116 TIME_WAIT 0
TCP 127.0.0.1:10080 127.0.0.1:4109 TIME_WAIT 0
TCP 127.0.0.1:10080 127.0.0.1:4099 TIME_WAIT 0
TCP 192.168.1.2:4102 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4103 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4105 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4107 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4108 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4112 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4113 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4115 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4121 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4123 192.168.1.1:80 TIME_WAIT 0
TCP 192.168.1.2:4125 192.168.1.1:80 TIME_WAIT 0
UDP 0.0.0.0:1027 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\ipnathlp.dll
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 0.0.0.0:4500 *:* 760
[lsass.exe]
UDP 0.0.0.0:445 *:* 4
[System]
UDP 0.0.0.0:500 *:* 760
[lsass.exe]
UDP 127.0.0.1:3793 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\WINHTTP.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
UDP 127.0.0.1:2301 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\WINHTTP.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
UDP 127.0.0.1:2340 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:2627 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\WINHTTP.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
UDP 127.0.0.1:1028 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\ipnathlp.dll
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 127.0.0.1:1778 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:1658 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\WINHTTP.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
UDP 127.0.0.1:3957 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\WINHTTP.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
UDP 127.0.0.1:1815 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:1660 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:1790 *:* 1208
[wlcomm.exe]
UDP 127.0.0.1:1794 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:1666 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:3932 *:* 2680
[EXCEL.EXE]
UDP 127.0.0.1:4504 *:* 1328
[firefox.exe]
UDP 127.0.0.1:2624 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:3202 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:3113 *:* 4056
[YahooMessenger.exe]
UDP 127.0.0.1:2489 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\WINHTTP.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
UDP 127.0.0.1:2334 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:2338 *:* 2936
[msnmsgr.exe]
UDP 127.0.0.1:1900 *:* 1180
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 127.0.0.1:123 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 127.0.0.1:2280 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\WINHTTP.dll
C:\WINDOWS\system32\upnp.dll
C:\WINDOWS\system32\RPCRT4.dll
C:\WINDOWS\system32\ole32.dll
[svchost.exe]
UDP 192.168.1.2:53 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\ipnathlp.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 192.168.1.2:138 *:* 4
[System]
UDP 192.168.1.2:137 *:* 4
[System]
UDP 192.168.1.2:9 *:* 2936
[msnmsgr.exe]
UDP 192.168.1.2:123 *:* 1064
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 192.168.1.2:1900 *:* 1180
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
<<<< Routing Table >>>>===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x50002 ...00 e0 4d 41 15 b3 ...... Realtek RTL8169/8110 Family Gigabit Ethernet NIC - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.1.1 192.168.1.2 20
64.4.34.216 255.255.255.255 192.168.1.1 192.168.1.2 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.1.0 255.255.255.0 192.168.1.2 192.168.1.2 20
192.168.1.2 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.1.255 255.255.255.255 192.168.1.2 192.168.1.2 20
202.79.210.121 255.255.255.255 192.168.1.1 192.168.1.2 20
224.0.0.0 240.0.0.0 192.168.1.2 192.168.1.2 20
255.255.255.255 255.255.255.255 192.168.1.2 192.168.1.2 1
Default Gateway: 192.168.1.1
===========================================================================
Persistent Routes:
None
Route Table
<<<< Hosts File >>>>The HOSTS file is 734 Bytes in size.
END OF LOG FILE, Date of Completion: 2114_03-10-2009 ----------