[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiSpyware]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules]
"{28130F52-3192-4018-8632-71B8A84086BB}"= UDP:c:\program files\Common Files\McAfee\MNA\McNASvc.exe:McAfee Network Agent
"{F23D7922-BC62-499A-9DB6-3C87C8BF517E}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{ABBC0027-5D31-4A5A-9F7C-7693744AAF11}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote
"{8FF0287A-10D9-4A8B-BFFB-5C17484BF75D}"= UDP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{CBE8D9C2-70EC-4D76-9224-650FE27170CA}"= TCP:c:\program files\Common Files\AOL\Loader\aolload.exe:AOL Loader
"{BC175D89-50EA-4ECD-B777-F8B2BB4F63E4}"= TCP:6004|c:\program files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook
"{2C7FCD33-B00A-4EA2-A7D3-46FA9AFAC85A}"= UDP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0375E23F-084E-4A6C-8E26-89CA8D8158A7}"= TCP:c:\program files\Microsoft Office\Office12\GROOVE.EXE:Microsoft Office Groove
"{0A780A99-0D9E-492C-8DAB-F7C6A265EEAB}"= UDP:c:\program files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{287AB078-3896-4616-90E6-84FD1CBB8160}"= TCP:c:\program files\Pinnacle\Studio 11\programs\RM.exe:Render Manager
"{B9A9F7D1-2E8F-47DA-AA19-AFC95A00AADC}"= UDP:c:\program files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{DC33EA1F-92AD-422A-82D6-DBB78F0F240B}"= TCP:c:\program files\Pinnacle\Studio 11\programs\Studio.exe:Studio
"{F398248E-8B20-4F3B-B9A8-8A0788A110B7}"= UDP:c:\program files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe
MSRegisterFile
"{A563E240-9C52-41B7-BC6C-71AD06E380E8}"= TCP:c:\program files\Pinnacle\Studio 11\programs\PMSRegisterFile.exe
MSRegisterFile
"{AED2EA8D-3CCD-483D-B8D0-A76C246FF719}"= UDP:c:\program files\Pinnacle\Studio 11\programs\umi.exe:umi
"{1182779B-8CDF-4766-B918-1CEB0DEBD155}"= TCP:c:\program files\Pinnacle\Studio 11\programs\umi.exe:umi
"{706CBF08-083A-4F2B-90C4-F83668D20164}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{C34FF2CE-F450-46DA-91D1-71DF66D22DE9}"= UDP:c:\program files\iTunes\iTunes.exe:iTunes
"{501942C3-F957-47F8-BB8C-E39B153A5B27}"= TCP:c:\program files\iTunes\iTunes.exe:iTunes
"{8F7622AA-1AD3-467A-A022-82A2F78A97B4}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone)
"{60D08683-3264-47CE-9664-9F93CB0DFF48}"= UDP:c:\program files\Skype\Phone\Skype.exe:Skype
"{96332A51-89F1-4AC2-85C8-36A1E39CBD56}"= TCP:c:\program files\Skype\Phone\Skype.exe:Skype
"{4656517F-02B4-4970-8F7D-0AA3D7CAFD21}"= c:\program files\AVG\AVG8\avgupd.exe:avgupd.exe
"TCP Query User{E8EEDF1B-E05F-44E6-9F04-6E1CCF2CA0E0}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{A1A39CCF-50FE-4863-8B2E-5C443021A3C2}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"TCP Query User{E7D5F52C-B30E-487B-9540-13773F433B81}c:\\program files\\internet explorer\\iexplore.exe"= UDP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"UDP Query User{3ECB5C01-C680-49EC-A481-EAD98687A05E}c:\\program files\\internet explorer\\iexplore.exe"= TCP:c:\program files\internet explorer\iexplore.exe:Internet Explorer
"TCP Query User{9B205CE7-E22C-47E8-9D8D-F1979D91B235}c:\\program files\\opera\\opera.exe"= UDP:c:\program files\opera\opera.exe:Opera Internet Browser
"UDP Query User{A4550CFA-9D9E-4FD1-8202-F995FF4564F4}c:\\program files\\opera\\opera.exe"= TCP:c:\program files\opera\opera.exe:Opera Internet Browser
"TCP Query User{A002665D-BFFC-4889-AA70-7D8B33AD6C6F}c:\\program files\\skype\\phone\\skype.exe"= UDP:c:\program files\skype\phone\skype.exe:Skype
"UDP Query User{38CDFE07-0549-442C-A388-11294BBE7337}c:\\program files\\skype\\phone\\skype.exe"= TCP:c:\program files\skype\phone\skype.exe:Skype
"TCP Query User{76DD1E39-10A5-4641-A1F3-F6FB39E24BC2}c:\\program files\\itunes\\itunes.exe"= UDP:c:\program files\itunes\itunes.exe:iTunes
"UDP Query User{E8B66173-0FCB-46DA-B035-67C29FEC9FEC}c:\\program files\\itunes\\itunes.exe"= TCP:c:\program files\itunes\itunes.exe:iTunes
"TCP Query User{D1B77E38-78AF-4478-A225-D22A81054B15}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent
"UDP Query User{E0BA7546-600A-4DFD-84F7-84F0DF0483AC}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent
"{AA5CD046-AFFF-42CD-93BA-7C5F35A30EF3}"= UDP:c:\program files\uTorrent\uTorrent.exe:µTorrent (TCP-In)
"{92FE3D2E-59F8-476A-ADE2-9BB49D9136D0}"= TCP:c:\program files\uTorrent\uTorrent.exe:µTorrent (UDP-In)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\Static\System]
"DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic|
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile\AuthorizedApplications\List]
"c:\\TOSHIBA\\ivp\\NetInt\\Netint.exe"= c:\toshiba\ivp\NetInt\Netint.exe:*:Enabled:NIE - Toshiba Software Upgrades Engine
"c:\\TOSHIBA\\Ivp\\ISM\\pinger.exe"= c:\toshiba\Ivp\ISM\pinger.exe:*:Enabled:Toshiba Software Upgrades Pinger
R1 AvgLdx86;AVG AVI Loader Driver x86;c:\windows\System32\drivers\avgldx86.sys [6/16/2008 12:34 PM 325896]
R1 sp_rsdrv2;Spyware Terminator Driver 2;c:\windows\System32\drivers\sp_rsdrv2.sys [8/4/2008 2:17 PM 141312]
R2 avg8wd;AVG8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2/11/2009 9:30 PM 298776]
R2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [11/2/2007 1:55 PM 24652]
R3 FwLnk;FwLnk Driver;c:\windows\System32\drivers\FwLnk.sys [2/28/2007 4:00 PM 7168]
S3 GoogleDesktopManager-091507-085419;Google Desktop Manager 5.1.709.15267;c:\program files\Google\Google Desktop Search\GoogleDesktop.exe [2/28/2007 4:10 PM 1840128]
.
- - - - ORPHANS REMOVED - - - -
SafeBoot-procexp90.Sys
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.toshibadirect.com/dpdstart
uInternet Settings,ProxyServer = 94.23.10.204:8118
uInternet Settings,ProxyOverride = <local>
IE: Crawler Search - tbr:iemenu
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~4\Office12\EXCEL.EXE/3000
Trusted Zone: ameritrade.com
Trusted Zone: ameritrade.com\investment1s
Trusted Zone: ameritrade.com\wwws
Trusted Zone: tdameritrade.com
Handler: tbr - {4D25FB7A-8902-4291-960E-9ADA051CFBBF} - c:\progra~1\Crawler\Toolbar\ctbr.dll
FF - ProfilePath - c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\l1ulxqku.default\
FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xcomm.dll
FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xshared.dll
FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xsupport.dll
FF - component: c:\progra~1\Crawler\Toolbar\firefox\components\xwsg.dll
FF - component: c:\program files\AVG\AVG8\Firefox\components\avgssff.dll
FF - component: c:\program files\AVG\AVG8\ToolbarFF\components\vmAVGConnector.dll
FF - component: c:\program files\SiteAdvisor\6261\FF\components\FFHook.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava11.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava12.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava13.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava14.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjava32.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npjpi160.dll
FF - plugin: c:\program files\Java\jre1.6.0\bin\npoji610.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - plugin: c:\users\Nicole\AppData\Roaming\Mozilla\Firefox\Profiles\l1ulxqku.default\extensions\moveplayer@movenetworks.com\platform\WINNT_x86-msvc\plugins\npmnqmp071101000055.dll
.