GMER 2.1.19357 - http://www.gmer.net Rootkit scan 2014-03-19 18:21:30 Windows 5.1.2600 Dodatek Service Pack 3 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3 ST3500320AS rev.SD15 465,76GB Running: gmer.exe; Driver: C:\DOCUME~1\MARZEN~1\USTAWI~1\Temp\pwdcifod.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwAdjustPrivilegesToken [0xB20F17E4] SSDT B877DAB4 ZwClose SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwConnectPort [0xB20F0D90] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateFile [0xB20F144A] SSDT B877DA6E ZwCreateKey SSDT B877DABE ZwCreateSection SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwCreateSymbolicLinkObject [0xB20F3F9E] SSDT B877DA64 ZwCreateThread SSDT B877DA73 ZwDeleteKey SSDT B877DA7D ZwDeleteValueKey SSDT B877DAAF ZwDuplicateObject SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwEnumerateKey [0xB20F282A] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwEnumerateValueKey [0xB20F2A80] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwLoadDriver [0xB20F3652] SSDT B877DA82 ZwLoadKey SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwMakeTemporaryObject [0xB20F1058] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenFile [0xB20F1626] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenKey [0xB20F2030] SSDT B877DA50 ZwOpenProcess SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwOpenSection [0xB20F12F2] SSDT B877DA55 ZwOpenThread SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryKey [0xB20F2C8E] SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwQueryMultipleValueKey [0xB20F30E2] SSDT B877DAD7 ZwQueryValueKey SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwRenameKey [0xB20F25B2] SSDT B877DA8C ZwReplaceKey SSDT B877DAC8 ZwRequestWaitReplyPort SSDT B877DA87 ZwRestoreKey SSDT B877DAC3 ZwSetContextThread SSDT B877DACD ZwSetSecurityObject SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwSetSystemInformation [0xB20F393E] SSDT B877DA78 ZwSetValueKey SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwShutdownSystem [0xB20F0FC2] SSDT B877DAD2 ZwSystemDebugControl SSDT B877DA5F ZwTerminateProcess SSDT \SystemRoot\System32\DRIVERS\cmdguard.sys ZwTerminateThread [0xB20F0980] ---- Kernel code sections - GMER 2.1 ---- .text C:\WINDOWS\system32\DRIVERS\nv4_mini.sys section is writeable [0xB4B403C0, 0x82971A, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text D:\programy\użytki\bezpieczeństwo_diagnostyka\gmer\gmer.exe[260] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe[348] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\ADVANC~1\wh_exec.exe[388] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe[400] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\RTHDCPL.EXE[404] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\RUNDLL32.EXE[504] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Logitech\Logitech WebCam Software\LWS.exe[564] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\COMODO\COMODO Internet Security\cfp.exe[572] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 00780630 C:\Program Files\COMODO\COMODO Internet Security\cfp.exe .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avgnt.exe[608] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] KERNEL32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] KERNEL32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.Systray.exe[620] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Messenger\msmsgs.exe[632] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\ctfmon.exe[640] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe[648] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avshadow.exe[692] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Skype\Phone\Skype.exe[696] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\csrss.exe[796] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 10001450 C:\WINDOWS\system32\cmdcsr.dll .text C:\WINDOWS\system32\csrss.exe[796] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 100017F0 C:\WINDOWS\system32\cmdcsr.dll .text C:\WINDOWS\system32\services.exe[872] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] RPCRT4.dll!RpcServerRegisterIfEx 77E8CE4B 5 Bytes JMP 1001F870 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\services.exe[872] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\lsass.exe[884] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] RPCRT4.dll!RpcServerRegisterIfEx 77E8CE4B 5 Bytes JMP 1001F870 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1056] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exe[1120] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] RPCRT4.dll!RpcServerRegisterIfEx 77E8CE4B 5 Bytes JMP 1001F870 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1136] rpcss.dll!WhichService 76A64234 8 Bytes JMP EDF01001 .text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1232] ntdll.dll!NtAllocateVirtualMemory 7C90CF6E 5 Bytes JMP 00534850 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe .text C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe[1232] ntdll.dll!NtCreateFile 7C90D0AE 5 Bytes JMP 0054ECA0 C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe .text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] RPCRT4.dll!RpcServerRegisterIfEx 77E8CE4B 5 Bytes JMP 1001F870 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1268] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1336] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1396] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1500] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\spoolsv.exe[1668] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\sched.exe[1716] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe[1728] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[1788] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Explorer.EXE[2020] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\AntiVir Desktop\avguard.exe[2492] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Java\jre7\bin\jqs.exe[2664] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LightScribe\LSSrvc.exe[2728] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe[3000] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\nvsvc32.exe[3024] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 00A2D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 00A3BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 00A3B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 00A37F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 00A2D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00A35070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00A35C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 00A33BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 00A344D0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 00A38D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 00A38AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 00A39E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe[3104] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 00A39D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\system32\svchost.exe[3200] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] KERNEL32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] KERNEL32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Avira\My Avira\Avira.OE.ServiceHost.exe[3364] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe[3408] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 0046D120 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 0047BCD0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 0047B9B0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10001FFD C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 0046D240 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 00475070 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 00475C00 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!lstrlenW + 43 7C809AEC 7 Bytes JMP 01B10455 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!MapViewOfFileEx + 6A 7C80B9A0 7 Bytes JMP 01B1049D C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] kernel32.dll!ValidateLocale + B1C8 7C8449C8 7 Bytes JMP 01725A06 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 00478D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] GDI32.dll!SetDIBitsToDevice + 20A 77F19E14 7 Bytes JMP 01B104C4 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 00478AE0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 00479E10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 00479D10 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 00473BA0 C:\WINDOWS\system32\guard32.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[3572] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 004744D0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] ntdll.dll!NtClose 7C90CFEE 5 Bytes JMP 1001D120 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] ntdll.dll!NtReplyWaitReceivePort 7C90DA8E 5 Bytes JMP 1002BCD0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] ntdll.dll!NtReplyWaitReceivePortEx 7C90DA9E 5 Bytes JMP 1002B9B0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] ntdll.dll!LdrLoadDll 7C91632D 5 Bytes JMP 10027F40 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] ntdll.dll!LdrUnloadDll 7C9171CD 5 Bytes JMP 1001D240 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] kernel32.dll!CreateProcessW 7C802336 5 Bytes JMP 10025070 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] kernel32.dll!CreateProcessA 7C80236B 5 Bytes JMP 10025C00 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] GDI32.dll!DeleteDC 77F16E5F 5 Bytes JMP 10028D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] GDI32.dll!GetPixel 77F1B74C 5 Bytes JMP 10028AE0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] GDI32.dll!CreateDCA 77F1B7D2 5 Bytes JMP 10029E10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] GDI32.dll!CreateDCW 77F1BE38 5 Bytes JMP 10029D10 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] ADVAPI32.dll!CreateProcessAsUserW 77DDA8A9 5 Bytes JMP 10023BA0 C:\WINDOWS\system32\guard32.dll .text C:\WINDOWS\System32\alg.exe[3884] ADVAPI32.dll!CreateProcessAsUserA 77E00CE8 5 Bytes JMP 100244D0 C:\WINDOWS\system32\guard32.dll ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\Tcpip \Device\Ip cmdhlp.sys AttachedDevice \Driver\Tcpip \Device\Tcp cmdhlp.sys AttachedDevice \Driver\Tcpip \Device\Udp cmdhlp.sys AttachedDevice \Driver\Tcpip \Device\RawIp cmdhlp.sys ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0xFF 0xA4 0x3A ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA6 0xA4 0xEC 0x02 ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7D 0x14 0x69 0x6C ... Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet001\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDF 0x44 0x0C 0xE8 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0xFF 0xA4 0x3A ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA6 0xA4 0xEC 0x02 ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7D 0x14 0x69 0x6C ... Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDF 0x44 0x0C 0xE8 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0xFF 0xA4 0x3A ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA6 0xA4 0xEC 0x02 ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7D 0x14 0x69 0x6C ... Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet003\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDF 0x44 0x0C 0xE8 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0xFF 0xA4 0x3A ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA6 0xA4 0xEC 0x02 ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7D 0x14 0x69 0x6C ... Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet004\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDF 0x44 0x0C 0xE8 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0xFF 0xA4 0x3A ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA6 0xA4 0xEC 0x02 ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7D 0x14 0x69 0x6C ... Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet005\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDF 0x44 0x0C 0xE8 ... Reg HKLM\SYSTEM\ControlSet006\Control\Video\{C5838AD8-FBC3-456F-BB22-DD32932C7091}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF8 0xFF 0xA4 0x3A ... Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xA6 0xA4 0xEC 0x02 ... Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x7D 0x14 0x69 0x6C ... Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet006\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xDF 0x44 0x0C 0xE8 ... Reg HKLM\SYSTEM\CurrentControlSet\Control\Video\{C5838AD8-FBC3-456F-BB22-DD32932C7091}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF5 0x5E 0x43 0x2B ... Reg HKLM\SYSTEM\CurrentControlSet\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet008\Control\Video\{C5838AD8-FBC3-456F-BB22-DD32932C7091}\0000@D3D_\x3332\x3331 2089309684 Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0xF5 0x5E 0x43 0x2B ... Reg HKLM\SYSTEM\ControlSet008\Services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files\DAEMON Tools Lite\ Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy@Num 14 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\0@UID {93E4F22D-9F0B-46EF-BA84-91C6096006DC} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\0@Filename D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\gmer\gmer.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\0@DeviceName D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\gmer\gmer.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\0\Rules\0@UID {28709DA5-D111-4EC4-B735-04CCF3B716CF} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\1@UID {D70245B7-88CD-4311-9C2A-3A182EE708A5} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\1@Filename D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\avira-free-antivirus.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\1@DeviceName D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\avira-free-antivirus.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\1\Rules\0@UID {5470A62F-FD19-4CC1-8E71-C1C844C93AD1} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10@UID {7DBDDA3D-F2F6-4C4B-B044-AB01ABBC0147} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10@Filename System Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10@DeviceName System Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10@LastID 3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules@Num 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0@UID {15C4F0ED-8847-44E5-AE02-9B85A423A19C} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0@ID 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0@Protocol 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0@Action 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0@Direction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0@Description Zezw?l na wychodz?ce po??czenia od Systemu, je?eli odbiorca znajduje si? w [Dom #2] Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0@IPProto 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0\DestinationIP@Type 20 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0\DestinationIP@Name Dom #2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0\SourceIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0\SourceIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0\SourceIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\0\SourceIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@UID {A2F2DB27-AB17-4183-B26F-D68678472197} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@Days 127 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@StartHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@StartMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@StopHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@StopMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@ID 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@Protocol 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@Action 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@Direction 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@Description Zezw?l na przychodz?ce po??czenia do Systemu, je?eli nadawca znajduje si? w [Dom #2] Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1@IPProto 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP@Name Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\DestinationIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP@Type 20 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP@Name Dom #2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\1\SourceIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@UID {81D67A95-AFC4-4472-8561-D720AC143A48} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@Days 127 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@StartHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@StartMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@StopHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@StopMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@ID 25512 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@Protocol 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@Action 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@Direction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@Description Zezw?l na wychodz?ce po??czenia od Systemu, je?eli odbiorca znajduje si? w [Dom #1] Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2@IPProto 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP@Type 20 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP@Name Dom #1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\DestinationIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP@Name Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\2\SourceIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@UID {C7CD3A69-0EBC-4AB9-9AE0-EEC011D9D283} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@Days 127 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@StartHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@StartMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@StopHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@StopMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@ID 25512 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@Protocol 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@Action 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@Direction 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@Description Zezw?l na przychodz?ce po??czenia do Systemu, je?eli nadawca znajduje si? w [Dom #1] Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3@IPProto 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP@Name Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\DestinationIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP@Type 20 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP@Name Dom #1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\10\Rules\3\SourceIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\11@UID {24DF266A-3D21-4C66-975C-61C73F8E947F} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\11@Flags 3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\11@DeviceName COMODO Internet Security Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\11@LastID 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\11@TreatAs Tylko wychodz?ce Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\11\Rules@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12@UID {8D11056A-CF60-4B09-9C3B-8EA6A55AE342} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12@DeviceName Aplikacje Windows Update Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12@TreatAs Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@UID {A549396D-00FA-45F9-957D-2D1F181D1F4C} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@Days 127 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@StartHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@StartMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@StopHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@StopMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@ID 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@Protocol 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@Action 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@Direction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@Description Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0@IPProto 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP@Name Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\DestinationIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP@Name Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\12\Rules\0\SourceIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\13@UID {FA4FBF44-C125-4662-BC51-BF2DF82BAC8A} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\13@DeviceName Systemowe aplikacje Windows Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\13\Rules\0@UID {66A7DAC7-155A-413A-827E-FB53374808FE} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\2@UID {8952BF86-A5A3-4BDC-9799-3EE11599FA98} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\2@Filename C:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\2@DeviceName C:\Program Files\Activision\Call of Duty - World at War\CoDWaW.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\2\Rules\0@UID {66370311-9D0B-4854-8230-212111BDB6B3} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\3@UID {F7330B0E-3CEE-4B80-BF22-F559B83F19CE} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\3@Filename C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\3@DeviceName C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Dane aplikacji\fst_pl_72\upfst_pl_72.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\3\Rules\0@UID {67903437-A610-448D-8298-47C4D9B86C36} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4@UID {4CF6DF96-BFFC-4DF7-BB08-0A277C54025E} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4@Filename C:\Program Files\mks\ArcaVir\asc.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4@DeviceName C:\Program Files\mks\ArcaVir\asc.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4@LastID 3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules@Num 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\0@UID {0846291D-7B66-4AE5-80C7-81890C1DEFF3} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\0@ID 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\0@Action 6 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@UID {7EFA63A2-0414-46F6-ACD0-A15146D4B2E6} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@Days 127 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@StartHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@StartMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@StopHour 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@StopMinute 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@ID 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@Protocol 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@Action 6 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@Direction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@Description Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1@IPProto 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP@Name Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\DestinationIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP@Name Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP\Address Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\4\Rules\1\SourceIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\5@UID {C8209ECC-086E-4FDF-94A8-788BC19E495D} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\5@Filename C:\Program Files\Java\jre7\lib\deploy.jar Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\5@DeviceName C:\Program Files\Java\jre7\lib\deploy.jar Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\5@LastID 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\5\Rules@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\5\Rules\0@UID {1AC2EBF1-FA56-4D17-97DC-907D6D554C68} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\5\Rules\0@ID 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6@UID {3643FCEA-11E1-4B43-BF05-EF6C6B22608F} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6@Filename C:\Games\World_of_Tanks\WOTLauncher.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6@DeviceName C:\Games\World_of_Tanks\WOTLauncher.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0@UID {5F59DD79-DB80-4EE3-AA6F-560B009F62E8} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0@Protocol 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0@Action 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0@Direction 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\DestinationPort Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\DestinationPort@Type 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\DestinationPort@SetName Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\DestinationPort@PortType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\DestinationPort@PortStart 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\DestinationPort@PortEnd 65535 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourceIP\Address@Type 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourceIP\Address\IPV4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourceIP\Address\IPV4@AddrType 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourceIP\Address\IPV4@AddrStart 192.168.1.8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourceIP\Address\IPV4@AddrEnd 255.255.255.0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourcePort Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourcePort@Type 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourcePort@SetName Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourcePort@PortType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourcePort@PortStart 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\6\Rules\0\SourcePort@PortEnd 65535 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7@UID {491FE82C-4E75-42D9-BBC2-0B90999A4C06} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7@Filename C:\Games\World_of_Warplanes\WorldOfWarplanes.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7@DeviceName C:\Games\World_of_Warplanes\WorldOfWarplanes.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0@UID {29305102-9954-4B82-BBAA-3562878D7123} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0@Protocol 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0@Direction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0@IPProto 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0\SourceIP\Address@Type 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0\SourceIP\Address\MAC Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0\SourceIP\Address\MAC@AddrType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\7\Rules\0\SourceIP\Address\MAC@MAC 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\8@UID {849F0E3A-5FB8-4CC5-BF19-92FCA61559DE} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\8@Filename D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\AVG\AVG-AntiVirus-Free-Edition(13206).exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\8@DeviceName D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\AVG\AVG-AntiVirus-Free-Edition(13206).exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\8\Rules\0@UID {44491260-C613-459B-B139-BC477E45DC27} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9@UID {B08FA852-9197-454F-AC67-5F222AC5FD8F} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9@Filename C:\Program Files\Skype\Phone\Skype.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9@DeviceName C:\Program Files\Skype\Phone\Skype.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0@UID {7165C39A-0FB4-445B-8F7B-1FCDD71AE4BF} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0@Protocol 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0@Action 6 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0@Direction 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\DestinationPort Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\DestinationPort@Type 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\DestinationPort@SetName Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\DestinationPort@PortType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\DestinationPort@PortStart 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\DestinationPort@PortEnd 65535 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourceIP\Address@Type 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourceIP\Address\IPV4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourceIP\Address\IPV4@AddrType 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourceIP\Address\IPV4@AddrStart 192.168.1.3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourceIP\Address\IPV4@AddrEnd 255.255.255.0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourcePort Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourcePort@Type 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourcePort@SetName Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourcePort@PortType 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourcePort@PortStart 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\Firewall\Policy\9\Rules\0\SourcePort@PortEnd 65535 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy@Num 13 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\0@UID {10D67976-4C20-4C50-9C8F-DC4F04FF8F2E} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\0@Filename D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\OTL\OTL.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\0@DeviceName D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\OTL\OTL.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\1@UID {8BB3196D-0AA0-47A5-8F25-E6A806297B38} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\1@Filename C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Temp\{be40d336-27e4-4c89-bd70-fd9e5c6e8306}\.be\Avira.OE.Setup.Bundle.AntiVirus.En-us.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\1@DeviceName C:\Documents and Settings\Marzena i Tomek\Ustawienia lokalne\Temp\{be40d336-27e4-4c89-bd70-fd9e5c6e8306}\.be\Avira.OE.Setup.Bundle.AntiVirus.En-us.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\10@UID {BF8F6D19-2225-471F-A56E-99B35D293ECC} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\10@Flags 9 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\10@DeviceName Aplikacje Windows Update Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\10@TreatAs Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11@UID {464EC53D-57DD-45B5-AF36-25F768D301F6} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11@DeviceName COMODO Internet Security Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections@Num 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0@Flags 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions@Num 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\0@UID {3632D0C4-EECB-473B-A319-6E3466677D4D} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\0@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\0@DeviceName Systemowe aplikacje Windows Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\1@UID {FB5E0B75-430F-41CB-BE32-779336666ADC} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\1@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\1@Filename C:\Program Files\COMODO\COMODO Internet Security\* Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\1@DeviceName C:\Program Files\COMODO\COMODO Internet Security\* Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\2@UID {25A70E1C-CB6A-4CAB-A79C-E2905E7FA721} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\2@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\2@Filename %windir%\system32\msiexec.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\2@DeviceName C:\WINDOWS\system32\msiexec.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\3@UID {1A65BD62-E56C-4490-8D16-3A0795A7EEDF} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\3@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\3@Filename %windir%\explorer.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\0\Exceptions\3@DeviceName C:\WINDOWS\explorer.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions@Num 3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\0@UID {90D63AB2-CD84-4246-BA81-728B2007EB8E} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\0@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\0@DeviceName Systemowe aplikacje Windows Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\1@UID {8EC3779D-0D8A-4877-BB03-C32F268E22DB} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\1@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\1@Filename C:\Program Files\COMODO\COMODO Internet Security\* Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\1@DeviceName C:\Program Files\COMODO\COMODO Internet Security\* Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\2@UID {5F278254-E4A2-4024-8C45-1CDD0DE2BD22} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\2@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\2@Filename %windir%\system32\msiexec.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Protections\1\Exceptions\2@DeviceName C:\WINDOWS\system32\msiexec.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules@Num 13 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\0@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\0@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\0\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\0\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\0\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\0\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\1@Flags 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\1@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\1\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\1\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\1\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\1\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\10 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\10@Flags 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\10@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\10\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\10\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\10\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\10\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\11 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\11@Flags 65536 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\11@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\11\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\11\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\11\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\11\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\12 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\12@Flags 512 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\12@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\12\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\12\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\12\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\12\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\2@Flags 1024 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\2@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\2\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\2\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\2\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\2\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\3@Flags 2048 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\3@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\3\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\3\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\3\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\3\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\4@Flags 4096 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\4@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\4\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\4\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\4\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\4\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\5 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\5@Flags 32 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\5@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\5\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\5\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\5\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\5\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\6 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\6@Flags 64 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\6@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\6\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\6\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\6\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\6\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\7 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\7@Flags 128 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\7@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\7\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\7\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\7\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\7\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\8@Flags 256 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\8@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\8\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\8\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\8\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\8\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\9 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\9@Flags 16 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\9@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\9\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\9\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\9\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\11\Rules\9\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12@UID {7EE319E2-2A20-4808-8B9B-0E2B2C0857C4} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12@DeviceName Wszystkie aplikacje Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Protections@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules@Num 6 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0@Flags 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0@DefaultAction 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0\Blocked@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0\Blocked\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0\Blocked\0@UID {8E1E55DB-6E29-45FC-8F34-AA53D85715E3} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0\Blocked\0@Condition Os==XP Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0\Blocked\0@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0\Blocked\0@Filename ?:\Recycle?\* Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\0\Blocked\0@DeviceName ?:\Recycle?\* Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\1@Flags 16 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\1@DefaultAction 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\1\Allowed@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\1\Allowed\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\1\Allowed\0@UID {99556C37-F5D6-4BB4-8FF3-436416F55CA5} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\1\Allowed\0@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\1\Allowed\0@DeviceName Pliki tymczasowe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\2@Flags 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\2@DefaultAction 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\2\Allowed@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\2\Allowed\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\2\Allowed\0@UID {FB1F18F2-7F3E-4A1D-997C-6367A057DC7B} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\2\Allowed\0@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\2\Allowed\0@DeviceName Klucze tymczasowe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3@DefaultAction 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed@Num 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\0@UID {6F3E9CF9-DC82-4E8A-80FF-977E6FB4AF5F} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\0@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\0@Filename %windir%\system32\msctf.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\0@DeviceName C:\WINDOWS\system32\msctf.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\1@UID {67BFEF20-B462-4808-A11B-DAC8CA6B17AC} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\1@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\1@Filename %windir%\system32\shell32.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\1@DeviceName C:\WINDOWS\system32\shell32.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\2@UID {EBAC2E3F-003B-422F-8331-8765101B5A7C} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\2@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\2@Filename %windir%\system32\browseui.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\2@DeviceName C:\WINDOWS\system32\browseui.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\3@UID {948D397E-4E3A-4BD3-B9CF-1206C407044A} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\3@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\3@Filename %windir%\system32\ieframe.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\3\Allowed\3@DeviceName C:\WINDOWS\system32\ieframe.dll Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4@DefaultAction 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4\Allowed@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4\Allowed\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4\Allowed\0@UID {B9D15C26-2C23-4197-8E93-7F6A61771E35} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4\Allowed\0@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4\Allowed\0@Filename %windir%\system32\ctfmon.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\4\Allowed\0@DeviceName C:\WINDOWS\system32\ctfmon.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5@Flags 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5@DefaultAction 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5\Allowed@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5\Allowed\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5\Allowed\0@UID {3F50C469-8260-4B2D-A6BA-ED87AC7D988C} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5\Allowed\0@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5\Allowed\0@Filename * Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\12\Rules\5\Allowed\0@DeviceName * Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2@UID {88B4534F-F22A-49B0-BB7B-4BF1B0E4ECD6} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2@Filename E:\START_2014.EXE Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2@DeviceName E:\START_2014.EXE Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0@Flags 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0@DefaultAction 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0\Allowed@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0\Allowed\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0\Allowed\0@UID {9DF5FD14-AC1B-43F4-B876-B4E72F84538B} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0\Allowed\0@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0\Allowed\0@Filename E:\data\Program\sm55.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\2\Rules\0\Allowed\0@DeviceName E:\data\Program\sm55.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3@UID {B6AAF094-0B87-4F11-B2EF-7FE3267A3F14} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3@Filename E:\data\Program\sm55.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3@DeviceName E:\data\Program\sm55.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules@Num 14 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\0@Flags 2097152 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\0@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\0\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\1@Flags 512 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\1@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\1\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\1\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\1\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\1\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\10 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\10@Flags 2048 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\10@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\10\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\10\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\10\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\10\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\11 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\11@Flags 1024 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\11@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\11\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\11\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\11\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\11\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\12 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\12@Flags 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\12@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\12\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\12\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\12\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\12\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\13 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\13@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\13@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\13\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\13\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\13\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\13\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\2@Flags 65536 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\2@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\2\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\2\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\2\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\2\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\3@Flags 256 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\3@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\3\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\3\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\3\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\3\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\4@Flags 128 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\4@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\4\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\4\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\4\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\4\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\5 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\5@Flags 64 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\5@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\5\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\5\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\5\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\5\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\6 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\6@Flags 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\6@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\6\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\6\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\6\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\6\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\7 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\7@Flags 16 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\7@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\7\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\7\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\7\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\7\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\8@Flags 32 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\8@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\8\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\8\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\8\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\8\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\9 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\9@Flags 4096 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\9@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\9\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\9\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\9\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\3\Rules\9\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4@UID {D8603B14-9CDA-4C20-841A-616EB9741B22} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4@Filename C:\Program Files\DriverDoc\Solvusoftdd.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4@DeviceName C:\Program Files\DriverDoc\Solvusoftdd.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules@Num 15 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules\14 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules\14@Flags 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules\14@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules\14\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules\14\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules\14\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\4\Rules\14\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5@UID {AE328DC5-F181-48D8-8219-D2C6297BED15} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5@Filename C:\Program Files\mks\ArcaVir\ArcaMainSV.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5@DeviceName C:\Program Files\mks\ArcaVir\ArcaMainSV.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0@Flags 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0@DefaultAction 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0\Allowed@Num 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0\Allowed\0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0\Allowed\0@UID {D3634189-33F8-4C8F-96F4-46417BE52D17} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0\Allowed\0@Flags 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0\Allowed\0@Filename C:\Program Files\mks\ArcaVir\asc.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\5\Rules\0\Allowed\0@DeviceName C:\Program Files\mks\ArcaVir\asc.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6@UID {515745F2-35B3-4D51-B47E-8BF88EEF62B2} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6@Filename C:\Games\World_of_Warplanes\WorldOfWarplanes.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6@DeviceName C:\Games\World_of_Warplanes\WorldOfWarplanes.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules@Num 14 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\0@Flags 2097152 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\0@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\0\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\1@Flags 512 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\1@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\1\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\1\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\1\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\1\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\10 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\10@Flags 2048 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\10@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\10\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\10\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\10\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\10\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\11 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\11@Flags 1024 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\11@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\11\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\11\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\11\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\11\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\12 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\12@Flags 4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\12@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\12\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\12\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\12\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\12\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\13 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\13@Flags 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\13@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\13\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\13\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\13\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\13\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\2@Flags 65536 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\2@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\2\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\2\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\2\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\2\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\3@Flags 256 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\3@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\3\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\3\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\3\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\3\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\4 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\4@Flags 128 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\4@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\4\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\4\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\4\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\4\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\5 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\5@Flags 64 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\5@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\5\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\5\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\5\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\5\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\6 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\6@Flags 8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\6@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\6\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\6\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\6\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\6\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\7 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\7@Flags 16 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\7@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\7\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\7\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\7\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\7\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\8 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\8@Flags 32 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\8@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\8\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\8\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\8\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\8\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\9 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\9@Flags 4096 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\9@DefaultAction 1 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\9\Allowed Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\9\Allowed@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\9\Blocked Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\6\Rules\9\Blocked@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\7@UID {600D2709-58C3-4802-87F1-B237430E6A0F} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\7@Filename D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\AVG\AVG-AntiVirus-Free-Edition(13206).exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\7@DeviceName D:\programy\u?ytki\bezpiecze?stwo_diagnostyka\AVG\AVG-AntiVirus-Free-Edition(13206).exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\8@UID {D8BB81BF-82CE-4D25-A77E-4BFC97C565DD} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\8@Flags 3 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\8@DeviceName Systemowe aplikacje Windows Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\8@TreatAs Aplikacje systemu Windows Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\8\Rules@Num 0 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\9@UID {E20272F6-EB6C-4816-84EB-FC1C971B8388} Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\9@Flags 2 Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\9@Filename %windir%\explorer.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Configurations\0\HIPS\Policy\9@DeviceName C:\WINDOWS\explorer.exe Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Data@Timestamp.{0D85521A-A20D-44D9-8380-EFB7C9BE423B} 0xF4 0x9A 0x29 0x53 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Data@Timestamp.{1861B42B-B05F-47B8-8566-BEE85A4D4FDC} 0x1E 0x98 0x29 0x53 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Data@Timestamp.{B4865C2A-9D0E-423B-8DA7-087F623C4B4F} 0xF4 0x9A 0x29 0x53 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Data@Timestamp.{40210ABD-EB84-4326-AEF8-709448FA2BAE} 0xF4 0x9A 0x29 0x53 ... Reg HKLM\SYSTEM\Software\COMODO\Firewall Pro\Data@Timestamp.{BEBAFD97-F7E0-43C2-A7DF-0D1B5EE26620} 0xBC 0x98 0x29 0x53 ... ---- EOF - GMER 2.1 ----