|
Log-Analyse und Auswertung: GVU Trojaner eingefangen-.-Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.09.2012, 19:13 | #1 |
| GVU Trojaner eingefangen-.- Hallo, ich habe mir den GVU Trojaner eingefangen. Und zwar die Version mit Webcam (Version 2.07??). Der Trojaner ist auf dem Konto "Gast" und dieses Konto ist jetzt sozusagen gesperrt. Mein Admin-Konto funktioniert jedoch noch. Ich habe per Eingabeaufforderung durch cmd.exe herrausgefunden das der Virus wahrscheinlich "de.3m5.wendel.flcd.FLCDB.4E7DF207D694E815646D9C9DD7DC91A41EB7FD23.1" heißt (falls es euch weiterhilft). Würde ich ihn einfach mit dem Befehl "del de.3m5.wendel.flcd.FLCDB.4E7DF207D694E815646D9C9DD7DC91A41EB7FD23.1" löschen wäre er ja noch auf der Regystry oder? mein Extras.txt war für ein Anhang zu groß. Ich sende ihn in 2 oder 3 Teilen(siehe nächste posts) Die 2 Anhänge sind einmal der OTL.txt und einmal von Malwarebytes Anti-Malware der Logfile Danke im Vorraus! |
02.09.2012, 19:18 | #2 |
| GVU Trojaner eingefangen-.- Hier mein Extras.txt:
__________________Teil1: OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 02.09.2012 19:20:41 - Run 1 OTL by OldTimer - Version 3.2.59.1 Folder = C:\Users\Thomas\Downloads 64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 5,97 Gb Total Physical Memory | 3,78 Gb Available Physical Memory | 63,32% Memory free 11,93 Gb Paging File | 9,05 Gb Available in Paging File | 75,86% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 149,04 Gb Total Space | 4,43 Gb Free Space | 2,97% Space Free | Partition Type: NTFS Drive D: | 148,65 Gb Total Space | 141,90 Gb Free Space | 95,45% Space Free | Partition Type: NTFS Computer Name: MEINPC | User Name: Thomas | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Extra Registry (SafeList) ========== ========== File Associations ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation) .html [@ = Reg Error: Value error.] -- Reg Error: Key error. File not found [HKEY_USERS\S-1-5-21-1065754088-3869420085-4235070589-1001\SOFTWARE\Classes\<extension>] .html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation) InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation) exefile [open] -- "%1" %* helpfile [open] -- Reg Error: Key error. htmlfile [edit] -- Reg Error: Key error. htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1" http [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) https [open] -- "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation) inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation) piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation) Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [explore] -- Reg Error: Value error. Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "cval" = 1 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] "VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data] "AntiVirusOverride" = 0 "AntiSpywareOverride" = 0 "FirewallOverride" = 0 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc] ========== Firewall Settings ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "DisableNotifications" = 1 "EnableFirewall" = 1 "DefaultOutboundAction" = 0 "DefaultInboundAction" = 1 "DisableUnicastResponsesToMulticastBroadcast" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile] "DisableNotifications" = 0 "EnableFirewall" = 1 ========== Authorized Applications List ========== ========== Vista Active Open Ports Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{056120AE-A7FC-4315-9DB9-ABB9322FE150}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 | "{0AAE4866-7ED3-46B4-B4E4-2BB063994F7A}" = rport=138 | protocol=17 | dir=out | app=system | "{0CE93336-987E-42DF-B817-902AADCB8249}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{18F21AA0-9794-4C09-89E8-42EEDF77D4B5}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery | "{19E3258A-F082-4779-B4A4-AC7DE184AD18}" = rport=10243 | protocol=6 | dir=out | app=system | "{1E6854B3-6133-4B8E-BA24-97AA3F250CB3}" = rport=445 | protocol=6 | dir=out | app=system | "{2A9CE41D-120E-409A-88E2-D0367394D4BD}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2AF6154B-9DD4-4152-A81A-CAC015DF78CA}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{2E905B92-E279-4626-B115-E0E7413D1CFD}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | "{2FE8D25F-0AD1-41ED-A52F-1F8B2CEB86A1}" = rport=139 | protocol=6 | dir=out | app=system | "{38E7C3E6-BE26-4881-B2CF-D623DDF69EDB}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{3D5DFE3E-3EE1-4C2B-BC0B-82B188CA3DFD}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{4490D034-80D5-4184-AF0A-1ACC10E6A9CB}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{46EC443E-5D67-43DE-A2BE-75572BF23B8E}" = lport=2869 | protocol=6 | dir=in | app=system | "{496454C1-D293-4297-B80E-508E878BBF22}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{4C2D9C6C-1DF4-4654-8081-B0C84D51B41C}" = lport=138 | protocol=17 | dir=in | app=system | "{51C447C9-B109-4015-8F25-AB2C0F09047D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{51F3E6B2-B4D1-45BB-B001-9FB8309943F1}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{59D62537-E0FC-4C21-AED8-C8B2987BC9F2}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | "{5B29686F-C5CB-44E1-B7BB-5DA8492758AF}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{5FF0A790-E042-4B25-B342-935F0602BB4B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{67F947DA-0E4E-4B73-8663-24DC8BC266D3}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{6874A24C-1CA9-445E-8252-79CC968488FB}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{6B5919A5-4C43-41EE-863A-5D5585EAB181}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{6DDC83BD-DE55-46F9-A659-394DA42F9759}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{705B2264-4857-4DFE-945E-6F3A7A2C958C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{73C39E55-F14D-48E2-97F6-E0A294546633}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | "{7F2AC573-B64B-41F1-962B-C821BBCD4C98}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{7FC7D479-593E-4D81-90BB-9C1EE2DAA064}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | "{80DF72AD-ED22-45B9-A8D0-815729CB0C5E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{83B1E8E5-ADBD-4DB5-8C95-2A76796E6261}" = rport=137 | protocol=17 | dir=out | app=system | "{89882C56-38F4-4346-BF39-97136F3DB8D6}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{8CE4EEF5-7300-45D6-9A07-CC527CF92F16}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{8DC981D4-5182-43A0-8BF7-F6AF10C7D771}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery | "{92D4404F-93AA-4C77-A2BA-9DBC1C5E085D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{9F1054F0-08E3-4079-8C28-E1E5D03B8C29}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | "{A2C2FE38-C959-4C67-B9CD-17D4A0DB219C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | "{A8538735-92DA-4C69-B6AE-81AB0542CD3E}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{AC4AB12C-137F-4FB8-A18A-195E4A0A23F6}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{AC902279-4354-4C4C-837D-00E1C289E177}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | "{B08CA4B1-44B5-40AB-B032-B60E779A4B3D}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{B381FB77-3782-42F3-9A1B-3DA8FE3F7D9B}" = lport=445 | protocol=6 | dir=in | app=system | "{B7796D1D-B7BE-4F16-BD42-65DBFAA7F2C9}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{BDFDB8FF-D69D-4631-BA13-F5FAD43B7326}" = lport=139 | protocol=6 | dir=in | app=system | "{CDA299BB-DF90-49CC-8A4C-5213F55BE1B7}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{D20A8EEA-6EC8-4EA2-8F59-8B13404A7AE7}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{D59E4B1D-9443-44D8-AC06-E6E2F30E871C}" = lport=4000 | protocol=6 | dir=out | app=c:\program files (x86)\dll-files.com fixer\dllfixer.exe | "{ED565F9A-875C-4242-993B-0C8AD5712106}" = lport=137 | protocol=17 | dir=in | app=system | "{F3FD6218-2170-47B4-A304-D1041A8F96C3}" = lport=10243 | protocol=6 | dir=in | app=system | "{FFA0CB31-E250-461F-A755-AE46A1BDE57C}" = lport=2869 | protocol=6 | dir=in | app=system | ========== Vista Active Application Exception List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules] "{03260243-6474-42C2-9E78-088C72F899FB}" = protocol=6 | dir=in | app=c:\program files (x86)\gamigo\heroes in the sky\his.exe | "{07D10362-9544-4765-A313-E413919F9391}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{083D3AA9-EAA0-46E3-A7EF-F417034F41CB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{0ECC651E-76F2-4839-B2D8-9AB45951289F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{1018304F-BE4A-4854-8C54-EB6D80469305}" = protocol=17 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex52.659\world of revenge.exe | "{1044B84E-26BB-4835-A9D0-5938C95DC9F3}" = protocol=17 | dir=in | app=c:\program files (x86)\gamigo\heroes in the sky\his.exe | "{11E37D41-2220-4DDC-985A-B199809AA096}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{11F43477-081B-447A-B6F4-3DA7E5667732}" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex17.534\metin2client.bin | "{17F9BD88-CCE7-4986-AD7F-F37C9CEBDAF5}" = protocol=6 | dir=in | app=c:\users\thomas\desktop\client\metin2client.bin | "{1C5ED55C-61E7-4BFB-926E-E46ADBB7914F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{252F2737-BEDE-4F4F-A611-E2FC0172BF9D}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | "{25FA91B7-3316-4AF7-9CE0-5214428F6BFA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{2E1743FD-4237-4213-8D6D-5049139771E0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{338AFC49-2BA8-4E6B-B0BF-86298CE08E84}" = protocol=17 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex17.657\client\metin2client.bin | "{36D1846C-0AE7-4965-982B-F1006787A5BB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{39CC37A0-DF09-4E37-A8E4-ADAEBBADD962}" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | "{3E023D55-E1B4-48C3-AAC8-C410C13B1552}" = protocol=6 | dir=in | app=c:\users\thomas\xampp\apache\bin\httpd.exe | "{3E094A1A-D10B-4426-B1ED-45B13B5B5C23}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackops.exe | "{3E23DACD-743B-47CA-9273-8FE1EADBE6F6}" = protocol=17 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex17.534\metin2client.bin | "{3EFF0034-9D74-4082-A1EF-95EB2A70A4F8}" = protocol=17 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{42D1E7D2-4F96-40E8-987D-A39927457977}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{445C042B-DA67-484C-A15C-EF82C2DFD17D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{457AF7C9-2797-44E6-8B1B-7ECA2BD5F098}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{4A8AE06D-047A-4644-840A-73930E13C6F1}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{4D99F149-EAD9-499F-B950-A84236B1DAC5}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{4F963B9A-AC62-4B81-88D3-B08104C7A8F4}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | "{505970F6-13CB-4922-A2CF-D7F400FD38E1}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas\binaries\r6vegas_launcher.exe | "{5512E0D5-276D-4200-AA59-385DE990AC46}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{55AA7193-9686-480D-892E-30C78F053661}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe | "{564F1C92-C418-4DB0-9BD6-582CBE520CB4}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{57448B57-B793-4610-8826-C963F4D1552C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{5913AE29-18D5-4F06-850E-2F2202B1C959}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_launcher.exe | "{5CD13B85-D835-4E5C-944A-50540B45A96E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | "{652AC1A1-E45F-4249-BAAF-696A1E8A8ADA}" = protocol=17 | dir=in | app=c:\users\thomas\desktop\onlinespiele\client\metin2client.bin | "{669ACBA3-AF77-4362-B4FC-99C6C7CADD8E}" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\akamai\netsession_win.exe | "{67D4DD85-3659-4399-9266-585F1C772E74}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{698C4B38-BAE0-489F-89E7-347DE92E153C}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{6D0F0E1B-44C9-4E80-8B40-E1C40EBF2865}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{6DC19D8C-4F48-4C6B-860B-660BAF6165FC}" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | "{6DE6A1AE-2500-417C-8988-E2F91A848F39}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas\binaries\r6vegas_game.exe | "{6F111602-71AF-4091-827D-48210B940729}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe | "{70886708-DE23-463A-A03A-4178E3EC99D6}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_game.exe | "{71C233FD-9CF7-4340-B57C-4D6EADBB8861}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas 2\binaries\r6vegas2_launcher.exe | "{78831BE5-6652-4299-AF1C-993F470E0745}" = protocol=17 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex06.767\client\metin2client.bin | "{7B77C89A-EC3E-4882-9C1B-5A93B0BC5296}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{7D0CF167-CE21-46FD-8180-7DDE5C5A00EB}" = protocol=6 | dir=out | app=system | "{7E71DEC5-4EFE-42BA-87A2-E55056ACF819}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | "{7F35CDE8-379E-4CAE-84F1-1EA17E0988BF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty black ops\blackopsmp.exe | "{8834CF90-58C6-4A2D-8D64-442592DBFB15}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{8AFB4347-9222-4DF9-A1A1-A716DEEF7440}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{8C2BFB37-8FE1-4977-BF88-0EB18E44FD2A}" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex06.767\client\metin2client.bin | "{8C4676D9-BFF8-42B4-94A5-C762DCA027B9}" = protocol=17 | dir=in | app=c:\users\thomas\desktop\client\metin2client.bin | "{8C4F0104-B7C4-4D77-A8E3-0D9165782E6B}" = protocol=6 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas\binaries\r6vegas_game.exe | "{8FC142E4-277D-44C2-A9B5-68F28F547573}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | "{918D9996-2B09-475A-822C-4CD443CEDE4E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | "{96048E43-2D1A-4B3A-9C3A-78DDD16F7224}" = protocol=6 | dir=in | app=c:\users\thomas\desktop\onlinespiele\client\metin2client.bin | "{96922536-4D39-4F77-A67F-EFF7348EE35B}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | "{9A283793-76DE-4BB4-864E-5FFF0325D533}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{9BDEA6A9-007A-443B-BFDE-AF4461B4C354}" = protocol=17 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | "{9E6BD9D5-1374-4EBF-9ECA-3A267A4A8A1A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{9EC3AD51-15EF-41B4-879B-D2E220EF3161}" = protocol=17 | dir=in | app=c:\users\thomas\appdata\local\akamai\netsession_win.exe | "{A0CB6ACC-4F47-4C01-80F9-8DF210FDAC9E}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{A2818F45-BC38-4AF4-8F0D-4AA822453BE2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{A368783D-77C2-4469-9B50-16DAA57550CB}" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex52.659\world of revenge.exe | "{A3BA07B8-418C-4609-A2EF-DECCFA25E065}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{A6030673-FD67-40AD-8910-E3AD072E2260}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{A61E1CDF-1162-417D-9298-2F40028C882A}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe | "{A8FDE5E5-1A5E-4C39-8312-142C00C06FD5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4sp.exe | "{AF3FD0DC-08F5-41B8-A373-16F0A9EB772E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | "{B100F5F5-A5C3-4FEC-94FC-DB75E992F2BD}" = protocol=17 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex73.842\client\metin2client.bin | "{B1CB212C-1BF0-40FF-92C0-25D78A1B7B3F}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{B4F5F8A3-6D57-4A37-B52E-43E657E8CD12}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{B743DF67-62D7-4D1A-8A45-976DDACBCB11}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | "{BACB6AED-1AA6-457D-8500-10A1982FF55F}" = protocol=6 | dir=in | app=c:\program files (x86)\ea games\battlefield 2\bf2.exe | "{BDC16EA1-EB23-4AF6-96CB-1BA055EC7CB5}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | "{BFEFE4F4-3637-4322-9287-6DA680E3FFDB}" = protocol=17 | dir=in | app=c:\users\thomas\xampp\apache\bin\httpd.exe | "{C20CA15E-AB07-4106-8D47-3A3D907C4427}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty modern warfare 2\iw4mp.exe | "{C32332B4-040D-477F-8D17-EC092BC84671}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | "{C79C4EEB-E887-4C3B-8EAB-520D6F02A96B}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | "{C7AC115D-CE74-4CA6-B432-EEFC33A37A5B}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{C8FA57D0-E164-43A6-BE4B-34024E91EB86}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{D82A5EDF-1788-4B1D-B59A-37066375DC39}" = protocol=6 | dir=in | app=c:\program files (x86)\battlelog web plugins\sonar\0.70.4\sonarhost.exe | "{D9CB81C8-A45F-46F7-8FA3-AC18198602E9}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | "{DD633671-F6BF-4CF5-99E7-613F443E1519}" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex73.842\client\metin2client.bin | "{DDE31C91-1012-4B77-8F41-87BC0E6508AC}" = protocol=17 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.311\client\metin2client.bin | "{E1D0A39D-C3DA-4A55-910E-E26DEF81F67E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | "{E6A6740D-44DA-46DD-8163-8072515ACE11}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe | "{EC846EE4-EEA7-4450-A72F-984FF2893F28}" = protocol=17 | dir=in | app=c:\program files (x86)\ubisoft\tom clancy's rainbow six vegas\binaries\r6vegas_launcher.exe | "{F0147C23-1AB3-4592-BC30-1E28391EFA09}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | "{F27394FD-516B-4D63-BE36-1440C9756C57}" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.311\client\metin2client.bin | "{F4CC6AEA-6D84-4791-AF6A-8DED1490899E}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | "{FAF666CF-9BE0-4940-9223-45BB92E11772}" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex17.657\client\metin2client.bin | "TCP Query User{000ED246-723B-408A-A683-8A6C5E490DAA}C:\users\thomas\appdata\local\temp\rar$ex00.375\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.375\metin2.bin | "TCP Query User{0026196A-172D-483A-A19A-7BBB849A44A8}C:\users\thomas\appdata\local\temp\rar$ex40.097\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex40.097\world of revenge client\worldofrevenge.exe | "TCP Query User{0032B716-D5D4-40DD-9517-0C24F3CC01FF}C:\users\thomas\appdata\local\temp\rar$ex00.209\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.209\world of revenge client\worldofrevenge.exe | "TCP Query User{00D1BC88-2C7C-407A-AE43-5160113AB222}C:\users\thomas\appdata\local\temp\rar$ex31.508\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex31.508\world of revenge client\worldofrevenge.exe | "TCP Query User{0108C285-1541-476A-B51C-FB013F91F791}C:\users\thomas\appdata\local\temp\rar$ex00.224\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.224\metin2.bin | "TCP Query User{01A1CF60-FE78-4A20-96AA-8BFC3D28DC28}C:\users\thomas\appdata\local\temp\rar$ex00.182\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.182\world of revenge client\worldofrevenge.exe | "TCP Query User{01EEF2E6-68AA-4640-A9A3-D8D028093987}C:\users\thomas\appdata\local\temp\rar$ex00.180\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.180\world of revenge client\worldofrevenge.exe | "TCP Query User{026997E0-67F0-45DD-A782-CEC8D22A67DA}C:\users\thomas\appdata\local\temp\rar$ex01.177\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.177\world of revenge client\worldofrevenge.exe | "TCP Query User{02A79A19-6BD5-4974-83A4-E30415D4DA08}C:\users\thomas\appdata\local\temp\rar$ex38.352\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex38.352\world of revenge client\worldofrevenge.exe | "TCP Query User{02D9E1D1-3C4E-478B-B487-3BA54FAA43B0}C:\users\thomas\appdata\local\temp\rar$ex00.187\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.187\world of revenge client\worldofrevenge.exe | "TCP Query User{030B669F-F757-4BE7-B5BB-05C30AEE05CB}C:\users\thomas\appdata\local\temp\rar$ex85.771\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex85.771\world of revenge client\worldofrevenge.exe | "TCP Query User{0311F275-D62B-491A-A55F-92E079790B95}C:\users\thomas\appdata\local\temp\rar$ex00.362\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.362\world of revenge client\worldofrevenge.exe | "TCP Query User{034BC6EA-9075-4C33-90EE-235D2F684142}C:\users\thomas\appdata\local\temp\rar$ex00.001\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.001\world of revenge client\worldofrevenge.exe | "TCP Query User{0354D62C-34C1-464A-ADEF-8FFC5225B3EA}C:\users\thomas\appdata\local\temp\rar$ex16.943\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex16.943\world of revenge client\worldofrevenge.exe | "TCP Query User{042895E5-35AD-4D9D-AA1D-8368586B571D}C:\users\thomas\appdata\local\temp\rar$ex16.252\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex16.252\world of revenge client\worldofrevenge.exe | "TCP Query User{05C00E22-A2F9-43CB-AD39-0ECDC2820686}C:\users\thomas\appdata\local\temp\rar$ex27.229\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex27.229\world of revenge client\worldofrevenge.exe | "TCP Query User{05E3C030-6FCB-4759-B5B5-E593F4B92A4E}C:\users\thomas\appdata\local\temp\rar$ex00.100\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.100\metin2.bin | "TCP Query User{05F40775-7121-48FD-8081-215C179F9C6C}C:\users\thomas\appdata\local\temp\rar$ex01.985\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.985\world of revenge client\worldofrevenge.exe | "TCP Query User{066E0736-BF61-471D-A060-33E8D8CEAA99}C:\users\thomas\appdata\local\temp\rar$ex00.154\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.154\metin2.bin | "TCP Query User{068EB127-18B0-470C-BF62-F56F30F4CC81}C:\users\thomas\appdata\local\temp\rar$ex01.655\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.655\world of revenge client\worldofrevenge.exe | "TCP Query User{06EA7AC0-4FF2-4319-99BC-A5BA4E05F4B6}C:\users\thomas\appdata\local\temp\rar$ex00.887\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.887\world of revenge client\worldofrevenge.exe | "TCP Query User{073DB63C-2C42-4652-BC35-94560A5ACC1A}C:\users\thomas\appdata\local\temp\rar$ex00.260\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.260\metin2.bin | "TCP Query User{077C3A7C-A3ED-43DA-AAD9-2F7E33BEFA90}C:\users\thomas\appdata\local\temp\rar$ex00.035\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.035\world of revenge client\worldofrevenge.exe | "TCP Query User{0A0BF0A3-84CA-4125-A8AE-FF3BB41CFD5C}C:\users\thomas\appdata\local\temp\rar$ex92.905\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex92.905\metin2.bin | "TCP Query User{0A761D93-26E8-42DE-AA8F-8976165ACCC3}C:\users\thomas\appdata\local\temp\rar$ex00.873\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.873\world of revenge client\worldofrevenge.exe | "TCP Query User{0AA022B6-D6F2-4BE6-870E-84428B1CB849}C:\users\thomas\appdata\local\temp\rar$ex07.581\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex07.581\metin2.bin | "TCP Query User{0AAD7E66-BB87-45E1-AF81-7D3C01994BCE}C:\users\thomas\appdata\local\temp\rar$ex87.328\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex87.328\metin2.bin | "TCP Query User{0B1A5CD2-13C8-407B-ABD8-A4408647A6B7}C:\users\thomas\appdata\local\temp\rar$ex60.796\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex60.796\world of revenge client\worldofrevenge.exe | "TCP Query User{0C30D85D-63CB-4C4C-AAD4-99D70E21B107}C:\users\thomas\appdata\local\temp\rar$ex02.946\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex02.946\world of revenge client\worldofrevenge.exe | "TCP Query User{0C708530-D538-487F-A627-2C69AA9E8EB4}C:\program files (x86)\littlefighter2\lf2_v2.0a\lf2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\littlefighter2\lf2_v2.0a\lf2.exe | "TCP Query User{0CCB465F-F4E6-4B27-8E4B-78896C7F5DA6}C:\users\thomas\appdata\local\temp\rar$ex06.413\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex06.413\world of revenge client\worldofrevenge.exe | "TCP Query User{0D6CC5D0-814B-454C-AB44-9A3138E69932}C:\program files (x86)\java\jre7\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe | "TCP Query User{0E33ACD1-36EE-4554-AE15-81551B1D07A3}C:\users\thomas\appdata\local\temp\rar$ex00.403\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.403\world of revenge client\worldofrevenge.exe | "TCP Query User{0F085A9F-108F-402F-8599-39FAAC3042EA}C:\users\thomas\appdata\local\temp\rar$ex23.202\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex23.202\world of revenge client\worldofrevenge.exe | "TCP Query User{0F6BB826-0FE2-4807-9F09-5EA984B5AEA8}C:\users\thomas\appdata\local\temp\rar$ex20.429\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex20.429\world of revenge client\worldofrevenge.exe | "TCP Query User{0F75D764-DB35-4701-B4F3-89DFEDB85153}C:\users\thomas\appdata\local\temp\rar$ex01.752\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.752\metin2.bin | "TCP Query User{0FC26BE4-87E6-43AC-BB57-CF19019DF666}C:\users\thomas\appdata\local\temp\rar$ex00.041\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.041\world of revenge client\worldofrevenge.exe | "TCP Query User{11497606-A546-462F-8E11-12B8805672DF}C:\users\thomas\appdata\local\temp\rar$ex19.359\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex19.359\world of revenge client\worldofrevenge.exe | "TCP Query User{123E08D3-14C7-4593-A9E3-3B046EC3F3A2}C:\users\thomas\appdata\local\temp\rar$ex95.940\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex95.940\world of revenge client\worldofrevenge.exe | "TCP Query User{13F30350-0274-4992-870C-E735EDA0F321}C:\users\thomas\appdata\local\temp\rar$ex00.170\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.170\world of revenge client\worldofrevenge.exe | "TCP Query User{1484252E-FE6F-4986-929D-63652432CB1A}C:\users\thomas\appdata\local\temp\rar$ex07.518\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex07.518\metin2.bin | "TCP Query User{14EB1D9B-C1F0-496C-96EE-9BC85A86EE36}C:\users\thomas\appdata\local\temp\rar$ex49.756\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex49.756\world of revenge client\worldofrevenge.exe | "TCP Query User{15064E36-B9AD-4C1B-B1D9-22AC17D5D4FD}C:\users\thomas\appdata\local\temp\rar$ex48.015\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex48.015\world of revenge client\worldofrevenge.exe | "TCP Query User{15A1B811-F0FB-4A5B-830D-105C55A9392A}C:\users\thomas\appdata\local\temp\rar$ex00.342\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.342\world of revenge client\worldofrevenge.exe | "TCP Query User{15BAC207-6458-4B0E-92B1-1869A3B9DB1D}C:\users\thomas\appdata\local\temp\rar$ex00.427\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.427\world of revenge client\worldofrevenge.exe | "TCP Query User{1694DD0C-A356-4A25-975F-EFE7317455A9}C:\users\thomas\appdata\local\temp\rar$ex00.910\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.910\world of revenge client\worldofrevenge.exe | "TCP Query User{16AE8168-6A68-473D-B900-5188F80A4BDA}C:\users\thomas\appdata\local\temp\rar$ex00.656\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.656\metin2.bin | "TCP Query User{17241DBA-0724-4FBC-BE15-5C4CE9B3B378}C:\users\thomas\appdata\local\temp\rar$ex31.040\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex31.040\metin2.bin | "TCP Query User{17359B7A-BF51-4E4E-9C98-C92673E9D035}C:\users\thomas\appdata\local\temp\rar$ex00.131\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.131\world of revenge client\worldofrevenge.exe | "TCP Query User{173A5961-DDC6-475E-AD98-C286C48E244A}C:\users\thomas\appdata\local\temp\rar$ex00.485\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.485\world of revenge client\worldofrevenge.exe | "TCP Query User{17594BAE-C9BB-4D29-815A-87DFCB2C6A70}C:\users\thomas\appdata\local\temp\rar$ex00.892\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.892\metin2.bin | "TCP Query User{1778F4AE-198D-4A22-87E7-DE2F3F06BEF1}C:\users\thomas\appdata\local\temp\rar$ex00.383\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.383\world of revenge client\worldofrevenge.exe | "TCP Query User{185BC762-6889-408A-A89C-FB294D3E2C53}C:\users\thomas\appdata\local\temp\rar$ex08.309\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex08.309\world of revenge client\worldofrevenge.exe | "TCP Query User{18E1841D-CF38-4FA2-8D64-01F60B56AD54}C:\users\thomas\appdata\local\temp\rar$ex00.901\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.901\world of revenge client\worldofrevenge.exe | "TCP Query User{19048973-58F5-4DFD-B690-5B55F4734A8E}C:\users\thomas\desktop\wor\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\desktop\wor\worldofrevenge.exe | "TCP Query User{1C0FDB13-805E-4E57-A2AB-024D767C4699}C:\users\thomas\appdata\local\temp\rar$ex00.861\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.861\world of revenge client\worldofrevenge.exe | "TCP Query User{1CB853DA-A511-4373-B4EE-E2B3E3B17137}C:\users\thomas\appdata\local\temp\rar$ex08.427\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex08.427\world of revenge client\worldofrevenge.exe | "TCP Query User{1CC9822B-3E4A-45C8-A0BC-77D9D756B5D6}C:\users\thomas\appdata\local\temp\rar$ex25.483\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex25.483\world of revenge client\worldofrevenge.exe | "TCP Query User{1D3103BC-EB2A-4D3F-976E-1E93B066F587}C:\users\thomas\appdata\local\temp\rar$ex00.958\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.958\world of revenge client\worldofrevenge.exe | "TCP Query User{1DE17417-B68C-4ABC-B7F9-EAC049865A1F}C:\users\thomas\appdata\local\temp\rar$ex00.576\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.576\world of revenge client\worldofrevenge.exe | "TCP Query User{1DF96407-8E00-41DE-8ACF-6B03287A386A}C:\users\thomas\appdata\local\temp\rar$ex08.289\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex08.289\world of revenge client\worldofrevenge.exe | "TCP Query User{1F1FAE14-4BAA-4D9A-87C4-455505E67A68}C:\users\thomas\appdata\local\temp\rar$ex02.004\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex02.004\world of revenge client\worldofrevenge.exe | "TCP Query User{1F2ED6E2-5B82-4BD7-9111-B5D2CB894F8B}C:\users\thomas\appdata\local\temp\rar$ex00.277\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.277\world of revenge client\worldofrevenge.exe | "TCP Query User{1F91D195-E578-4F1B-997F-6463F94B7878}C:\users\thomas\appdata\local\temp\rar$ex72.547\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex72.547\world of revenge client\worldofrevenge.exe | "TCP Query User{1FD997E6-7174-47E7-BF46-DDE5D735B9B6}C:\users\thomas\appdata\local\temp\rar$ex34.557\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex34.557\world of revenge client\worldofrevenge.exe | "TCP Query User{1FF3E4FD-D78A-4CCD-A625-7E41B7EADDFC}C:\users\thomas\appdata\local\temp\rar$ex93.680\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex93.680\world of revenge client\worldofrevenge.exe | "TCP Query User{200FAFF5-FD7A-4EB9-B144-3E429C4FCBB1}C:\users\thomas\appdata\local\temp\rar$ex33.380\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex33.380\world of revenge client\worldofrevenge.exe | "TCP Query User{21212360-C33E-4C44-8C3C-797C404F93FE}C:\users\thomas\appdata\local\temp\rar$ex07.566\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex07.566\world of revenge client\worldofrevenge.exe | "TCP Query User{21FD788E-46D1-47AA-8480-803CEB6E471D}C:\users\thomas\appdata\local\temp\rar$ex00.633\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.633\world of revenge client\worldofrevenge.exe | "TCP Query User{228953FF-5A52-4DC3-B2DE-136E74103DE7}C:\users\thomas\appdata\local\temp\rar$ex57.029\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex57.029\world of revenge client\worldofrevenge.exe | "TCP Query User{238F34B6-7816-4CA9-9195-7A5BE83727BC}C:\users\thomas\appdata\local\temp\rar$ex03.635\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex03.635\world of revenge client\worldofrevenge.exe | "TCP Query User{241717D8-4443-4C13-A466-3720B5DE6689}C:\users\thomas\appdata\local\temp\rar$ex00.217\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.217\metin2.bin | "TCP Query User{242DA2A2-2B1F-4DA6-8007-12BCADFE2EF3}C:\users\thomas\appdata\local\temp\rar$ex58.636\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex58.636\world of revenge client\worldofrevenge.exe | "TCP Query User{245AC72D-07EE-45AA-9DAB-F7EA495CFFAE}C:\users\thomas\appdata\local\temp\rar$ex01.455\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.455\metin2.bin | "TCP Query User{2463037A-3CB1-4DC8-A39A-3D887B1E216F}C:\users\thomas\appdata\local\temp\rar$ex00.754\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.754\world of revenge client\worldofrevenge.exe | "TCP Query User{24A3D280-8DC3-4A0F-84D6-5D1CD48126B2}C:\users\thomas\appdata\local\temp\rar$ex93.743\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex93.743\world of revenge client\worldofrevenge.exe | "TCP Query User{260D74D4-B507-439B-8DA2-992CA69FB08F}C:\users\thomas\appdata\local\temp\rar$ex00.050\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.050\world of revenge client\worldofrevenge.exe | "TCP Query User{274722E5-7AA4-49E9-8D0C-9611234D1496}C:\users\thomas\appdata\local\temp\rar$ex61.065\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex61.065\world of revenge client\worldofrevenge.exe | "TCP Query User{274C3C9C-8C71-4526-B0D7-F54E36902931}C:\users\thomas\appdata\local\temp\rar$ex26.024\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex26.024\world of revenge client\worldofrevenge.exe | "TCP Query User{2898058C-FE81-442D-B45A-76B342B310E2}C:\users\thomas\appdata\local\temp\rar$ex04.510\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex04.510\world of revenge client\worldofrevenge.exe | "TCP Query User{29710E4A-0BD0-49F7-BB24-F3AE55F95296}C:\users\thomas\appdata\local\temp\rar$ex02.730\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex02.730\world of revenge client\worldofrevenge.exe | "TCP Query User{29BCD054-E5EC-47D9-92BA-59141324CDE0}C:\users\thomas\appdata\local\temp\rar$ex18.770\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex18.770\world of revenge client\worldofrevenge.exe | "TCP Query User{2AEDE4B6-0C9E-4860-89EE-918DD26BE28E}C:\users\thomas\appdata\local\temp\rar$ex11.164\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex11.164\world of revenge client\worldofrevenge.exe | "TCP Query User{2B5B723B-B0E0-4B5F-A9F9-0378FF4F2E38}C:\users\thomas\appdata\local\temp\rar$ex61.921\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex61.921\world of revenge client\worldofrevenge.exe | "TCP Query User{2B8A94AD-DA03-41BA-801B-5569A463F1A8}C:\users\thomas\appdata\local\temp\rar$ex99.164\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex99.164\world of revenge client\worldofrevenge.exe | "TCP Query User{2BACBFC3-ABA8-450B-B59A-25407B1A072B}C:\users\thomas\appdata\local\temp\rar$ex07.969\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex07.969\metin2.bin | "TCP Query User{2C1055F9-78C0-425B-8C59-47122818B6EE}C:\users\thomas\appdata\local\temp\rar$ex56.384\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex56.384\metin2.bin | "TCP Query User{2DCF0149-C6A8-4D22-964C-C5579AB73DD7}C:\users\thomas\appdata\local\temp\rar$ex00.928\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.928\world of revenge client\worldofrevenge.exe | "TCP Query User{2E413A2F-8B6A-48B9-9B13-6200258FF4DD}C:\users\thomas\appdata\local\temp\rar$ex00.506\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.506\world of revenge client\worldofrevenge.exe | "TCP Query User{2E87B0FF-9730-4420-B5C8-BC0F141738AE}C:\users\thomas\appdata\local\temp\rar$ex36.303\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex36.303\metin2.bin | "TCP Query User{318756AA-05C0-4777-9A93-EB7BFAF74AD5}C:\users\thomas\appdata\local\temp\rar$ex66.961\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex66.961\world of revenge client\worldofrevenge.exe | "TCP Query User{3190A7A4-9953-4425-874D-7BC3728B209A}C:\users\thomas\appdata\local\temp\rar$ex03.390\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex03.390\world of revenge client\worldofrevenge.exe | "TCP Query User{3191DF8F-B214-410E-B54D-BBFA36062491}C:\users\thomas\appdata\local\temp\rar$ex21.629\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex21.629\metin2.bin | "TCP Query User{3208CF69-922F-480B-82AF-A709D9AD2938}C:\users\thomas\appdata\local\temp\rar$ex64.236\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex64.236\world of revenge client\worldofrevenge.exe | "TCP Query User{321ABE87-0EC8-4A16-B02C-4AF0E00A6584}C:\users\thomas\appdata\local\temp\rar$ex24.620\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex24.620\world of revenge client\worldofrevenge.exe | "TCP Query User{322ACA74-0AFC-4108-8DA5-436AAB7F8F8B}C:\users\thomas\appdata\local\temp\rar$ex06.173\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex06.173\metin2.bin | "TCP Query User{323164B9-C1B8-4045-8A3F-78756A376125}C:\users\thomas\appdata\local\temp\rar$ex69.324\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex69.324\metin2.bin | "TCP Query User{3271B7D2-DCE0-451A-95E6-4CCC8615BAD1}C:\users\thomas\appdata\local\temp\rar$ex00.006\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.006\world of revenge client\worldofrevenge.exe | "TCP Query User{32BC598C-7C4F-4541-9D93-EB18555549B3}C:\users\thomas\appdata\local\temp\rar$ex00.386\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.386\world of revenge client\worldofrevenge.exe | "TCP Query User{344FFC0D-0895-4BA6-8823-4FB5BEAEE602}C:\users\thomas\appdata\local\temp\rar$ex00.999\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.999\world of revenge client\worldofrevenge.exe | "TCP Query User{34749B9F-70BA-4926-8DDF-8487D67CD507}C:\users\thomas\appdata\local\temp\rar$ex03.236\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex03.236\world of revenge client\worldofrevenge.exe | "TCP Query User{34793705-F6D3-46AA-BD1D-152080304578}C:\users\thomas\appdata\local\temp\rar$ex01.153\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.153\world of revenge client\worldofrevenge.exe | "TCP Query User{35888B71-842B-4A48-BDAB-8FEAAF5A1498}C:\users\thomas\appdata\local\temp\rar$ex11.736\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex11.736\world of revenge client\worldofrevenge.exe | "TCP Query User{35EB76DA-9FC3-4714-B33B-6AA7983F2800}C:\users\thomas\appdata\local\temp\rar$ex00.396\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.396\world of revenge client\worldofrevenge.exe | "TCP Query User{35EC7EE9-88CF-4521-A68A-B31C32B2DCC4}C:\users\thomas\appdata\local\temp\rar$ex00.857\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.857\world of revenge client\worldofrevenge.exe | "TCP Query User{3603219B-113D-4C2F-B610-EBF2961C4A9A}C:\users\thomas\appdata\local\temp\rar$ex72.034\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex72.034\world of revenge client\worldofrevenge.exe | "TCP Query User{3743B5C8-CF62-4B7F-9DE6-9B22324ADB0A}C:\users\thomas\appdata\local\temp\rar$ex00.787\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.787\world of revenge client\worldofrevenge.exe | "TCP Query User{374F7F7F-5580-451C-A551-46AD8E7152F4}C:\users\thomas\appdata\local\temp\rar$ex31.543\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex31.543\metin2.bin | "TCP Query User{3780EDF2-C682-4B36-B7F8-2B7B4E0C9374}C:\users\thomas\appdata\local\temp\rar$ex77.571\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex77.571\world of revenge client\worldofrevenge.exe | "TCP Query User{37E4FA82-F7E3-47D1-BDD6-0484C03E3E0C}C:\users\thomas\appdata\local\temp\rar$ex02.920\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex02.920\metin2.bin | "TCP Query User{37ED7014-E39F-4981-A403-D30B5784A1BC}C:\users\thomas\appdata\local\temp\rar$ex00.092\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.092\world of revenge client\worldofrevenge.exe | "TCP Query User{38575CFA-1414-4F20-BECD-1FA454A449B4}C:\users\thomas\appdata\local\temp\rar$ex05.850\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex05.850\metin2.bin | "TCP Query User{38BD017A-D3BF-416F-8A57-D52C9602B5B2}C:\users\thomas\appdata\local\temp\rar$ex00.908\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.908\metin2.bin | "TCP Query User{38D5579C-C1E5-49B5-8468-981CC543A565}C:\users\thomas\appdata\local\temp\rar$ex00.462\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.462\world of revenge client\worldofrevenge.exe | "TCP Query User{3935330E-6E6B-41CF-9FF4-C024D366CEB1}C:\users\thomas\appdata\local\temp\rar$ex29.715\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex29.715\world of revenge client\worldofrevenge.exe | "TCP Query User{3AA85B9F-9DBE-4466-9A12-035762BC8FE3}C:\users\thomas\appdata\local\temp\rar$ex00.664\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.664\metin2.bin | "TCP Query User{3B28F6E0-CC20-4C23-A38C-FEE0FBC4A30C}C:\program files (x86)\metin2\metin2client.bin" = protocol=6 | dir=in | app=c:\program files (x86)\metin2\metin2client.bin | "TCP Query User{3BD254F8-05A2-4A09-ADB3-836CF99DC218}C:\users\thomas\appdata\local\temp\rar$ex58.493\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex58.493\world of revenge client\worldofrevenge.exe | "TCP Query User{3C85E3ED-245B-4E3A-8AA9-DC11BFDC036D}C:\users\thomas\appdata\local\temp\rar$ex01.307\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.307\world of revenge client\worldofrevenge.exe | "TCP Query User{3CEACD17-B821-4987-B8AD-C28CA9ED3883}C:\users\thomas\appdata\local\temp\rar$ex00.782\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.782\world of revenge client\worldofrevenge.exe | "TCP Query User{3D93B492-BD1D-44CA-9DBF-56ABDF20E3C3}C:\users\thomas\appdata\local\temp\rar$ex00.501\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.501\world of revenge client\worldofrevenge.exe | "TCP Query User{3E266C56-5141-4ADE-86CA-9325E0F193C7}C:\users\thomas\appdata\local\temp\rar$ex00.855\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.855\metin2.bin | "TCP Query User{3EF1C755-1C74-43FF-9CB4-97C15D90B791}C:\users\thomas\appdata\local\temp\rar$ex00.474\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.474\world of revenge client\worldofrevenge.exe | "TCP Query User{3F0E2A7F-4028-4FE3-9571-1E5E277CEDBB}C:\users\thomas\appdata\local\temp\rar$ex79.504\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex79.504\world of revenge client\worldofrevenge.exe | "TCP Query User{4023EB87-A64B-463A-8AA0-8A0A64D24807}C:\users\thomas\appdata\local\temp\rar$ex88.650\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex88.650\world of revenge client\worldofrevenge.exe | "TCP Query User{40339013-3272-4811-808B-CE8FAC247920}C:\users\thomas\appdata\local\temp\rar$ex84.081\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex84.081\world of revenge client\worldofrevenge.exe | "TCP Query User{41579988-A791-4E43-8BDC-7AC7C7C92EC1}C:\users\thomas\appdata\local\temp\rar$ex00.171\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.171\metin2.bin | "TCP Query User{417C610A-9EAF-46EF-B424-1C78010AB3C9}C:\users\thomas\appdata\local\temp\rar$ex00.034\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.034\metin2.bin | "TCP Query User{428BC1FA-AA8F-42C8-A389-B4E2203CC426}C:\users\thomas\appdata\local\temp\rar$ex11.674\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex11.674\world of revenge client\worldofrevenge.exe | "TCP Query User{430FD2EC-AD12-4CBD-B249-D69D5F758EB5}C:\users\thomas\appdata\local\temp\rar$ex09.918\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex09.918\world of revenge client\worldofrevenge.exe | "TCP Query User{434FE49C-E92B-44B6-A251-2EF8D045C042}C:\users\thomas\appdata\local\temp\rar$ex00.613\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.613\metin2.bin | "TCP Query User{43621CFE-C8F0-49E2-886D-B2A8D3E649A9}C:\users\thomas\appdata\local\temp\rar$ex82.149\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex82.149\metin2.bin | "TCP Query User{437F771D-001C-4087-99D9-CC4C8299EE34}C:\users\thomas\appdata\local\temp\rar$ex36.674\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex36.674\world of revenge client\worldofrevenge.exe | "TCP Query User{43AE1883-7BD1-4443-B467-1347B149F81B}C:\users\thomas\appdata\local\temp\rar$ex00.406\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.406\world of revenge client\worldofrevenge.exe | "TCP Query User{43C8E085-4D30-4F22-BBFE-F9597DAB1D1C}C:\users\thomas\appdata\local\temp\rar$ex01.357\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.357\world of revenge client\worldofrevenge.exe | "TCP Query User{443D6E5A-89F9-41FC-934D-743A439194C4}C:\users\thomas\appdata\local\temp\rar$ex59.417\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex59.417\metin2.bin | "TCP Query User{444F4351-42CC-4023-A91E-1E87AC228EEA}C:\users\thomas\appdata\local\temp\rar$ex03.793\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex03.793\metin2.bin | "TCP Query User{4548D69F-1E7C-4531-A9E9-D60FB0EB21F4}C:\users\thomas\appdata\local\temp\rar$ex40.277\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex40.277\metin2.bin | "TCP Query User{459F8BF1-7043-42A9-B075-6BBF5520E322}C:\users\thomas\appdata\local\temp\rar$ex55.929\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex55.929\metin2.bin | "TCP Query User{45D3F434-2EA8-4108-9379-5170A4CBDF20}C:\users\thomas\appdata\local\temp\rar$ex83.197\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex83.197\metin2.bin | "TCP Query User{4663DECA-FD13-49F4-8AAC-AB17BC7A51A3}C:\program files (x86)\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\javaw.exe | "TCP Query User{46D1B435-93EE-4398-81ED-68A9182D040B}C:\users\thomas\appdata\local\temp\rar$ex00.683\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.683\world of revenge client\worldofrevenge.exe | "TCP Query User{46EB475E-DFBF-4D76-9734-939B3EBE4B85}C:\users\thomas\appdata\local\temp\rar$ex01.641\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.641\world of revenge client\worldofrevenge.exe | "TCP Query User{475F4884-5751-4DAB-B743-DA284400EEE0}C:\users\thomas\appdata\local\temp\rar$ex00.981\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.981\world of revenge client\worldofrevenge.exe | "TCP Query User{479C248A-6F4F-48DF-935C-3E82E17DB2FD}C:\users\thomas\appdata\local\temp\rar$ex00.479\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.479\metin2.bin | "TCP Query User{47ED2461-5C28-4865-BB1A-B8F245E9E692}C:\users\thomas\appdata\local\temp\rar$ex00.746\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.746\metin2.bin | "TCP Query User{48555365-3F9C-4EF2-9752-61A7D52F8101}C:\users\thomas\appdata\local\temp\rar$ex00.733\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.733\metin2.bin | "TCP Query User{4887BF75-8933-4584-B01D-8F9DAD8D22E2}C:\users\thomas\appdata\local\temp\rar$ex01.963\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.963\metin2.bin | "TCP Query User{48999CA3-9485-4E29-B1FF-C53E24CFA3AB}C:\users\thomas\appdata\local\temp\rar$ex15.964\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex15.964\world of revenge client\worldofrevenge.exe | "TCP Query User{48BC1FD2-7C5C-4722-90E7-05A883F9B03B}C:\users\thomas\appdata\local\temp\rar$ex75.463\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex75.463\world of revenge client\worldofrevenge.exe | "TCP Query User{48C98D26-ADF7-4567-AB5B-7E6ED15200D1}C:\users\thomas\appdata\local\temp\rar$ex00.140\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.140\metin2.bin | "TCP Query User{49977725-B8C6-4BF2-BB43-5A3B46E1A250}C:\users\thomas\appdata\local\temp\rar$ex00.738\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.738\metin2.bin | "TCP Query User{49BDC108-0E90-4B46-A603-177CD81672B7}C:\users\thomas\appdata\local\temp\rar$ex20.767\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex20.767\world of revenge client\worldofrevenge.exe | "TCP Query User{49C86D8B-7DD9-4089-A758-4AB805BA2951}C:\users\thomas\appdata\local\temp\rar$ex00.937\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.937\world of revenge client\worldofrevenge.exe | "TCP Query User{49E08065-A6A1-4C0F-A93D-9E255CFE3A45}C:\users\thomas\appdata\local\temp\rar$ex00.925\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.925\world of revenge client\worldofrevenge.exe | "TCP Query User{4A0A3743-BBD3-4A59-9D6B-E8B73C97AD34}C:\users\thomas\appdata\local\temp\rar$ex68.468\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex68.468\world of revenge client\worldofrevenge.exe | "TCP Query User{4B2AF77F-4AA4-4824-986D-B3A5E97808F5}C:\program files (x86)\metin2\metin2.bin" = protocol=6 | dir=in | app=c:\program files (x86)\metin2\metin2.bin | "TCP Query User{4B68B62E-A0DB-4F10-9B6E-571B130450A0}C:\users\thomas\appdata\local\temp\rar$ex07.532\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex07.532\world of revenge client\worldofrevenge.exe | "TCP Query User{4CEBA0AD-9B69-4BFE-97FA-882582F75564}C:\users\thomas\appdata\local\temp\rar$ex76.678\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex76.678\world of revenge client\worldofrevenge.exe | "TCP Query User{4CF86319-A0C4-4863-B922-0E6131FE1961}C:\users\thomas\appdata\local\temp\rar$ex00.518\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.518\world of revenge client\worldofrevenge.exe | "TCP Query User{4E65D8BE-83D9-4DA7-B9BE-E9CD87ACA3FD}C:\users\thomas\appdata\local\temp\rar$ex00.920\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.920\metin2.bin | "TCP Query User{4EF228B7-118C-4A93-AE5D-512958680228}C:\users\thomas\appdata\local\temp\rar$ex81.156\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex81.156\metin2.bin | "TCP Query User{4F0B8071-2653-40C3-95E7-DE94EA0264D5}C:\users\thomas\appdata\local\temp\rar$ex00.907\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.907\metin2.bin | "TCP Query User{5027F562-BA03-47AF-8493-B87B2AB959C4}C:\users\thomas\appdata\local\temp\rar$ex59.637\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex59.637\world of revenge client\worldofrevenge.exe | "TCP Query User{50736EEE-82DD-42A9-AC66-D02ABBB808D3}C:\users\thomas\appdata\local\temp\rar$ex00.971\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.971\world of revenge client\worldofrevenge.exe | "TCP Query User{52123DAC-3BF8-44E4-85EB-7B21F317ABA7}C:\users\thomas\appdata\local\temp\rar$ex00.820\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.820\world of revenge client\worldofrevenge.exe | "TCP Query User{52C1F4DF-8B17-426D-8BF3-19B3E8BCE18A}C:\users\thomas\appdata\local\temp\rar$ex00.311\client\metin2client.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.311\client\metin2client.bin | "TCP Query User{52E137E3-ECAF-4204-B326-C477A5E9A108}C:\users\thomas\appdata\local\temp\rar$ex52.175\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex52.175\metin2.bin | "TCP Query User{534649F3-43B0-4C7F-84E0-C41D1836346A}C:\users\thomas\appdata\local\temp\rar$ex73.694\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex73.694\metin2.bin | "TCP Query User{53B03A98-DE95-4E7A-B0A5-EBAFD9282AA3}C:\users\thomas\appdata\local\temp\rar$ex00.427\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.427\metin2.bin | "TCP Query User{53D74B51-EE44-4501-B8AB-5E99E7BE409A}C:\users\thomas\appdata\local\temp\rar$ex00.601\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.601\metin2.bin | "TCP Query User{540DC21C-DE89-4F7E-B022-18CBB1610AC4}C:\users\thomas\appdata\local\temp\rar$ex00.468\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.468\metin2.bin | "TCP Query User{54E862C1-C9B5-4955-8A2A-E64A53B00179}C:\users\thomas\appdata\local\temp\rar$ex11.551\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex11.551\world of revenge client\worldofrevenge.exe | "TCP Query User{54F14AC5-1D22-4E74-8DB1-632222E35ECA}C:\users\thomas\appdata\local\temp\rar$ex00.950\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.950\world of revenge client\worldofrevenge.exe | "TCP Query User{5501EE6E-E815-4EC9-9C9E-1CD87C47C409}C:\users\thomas\appdata\local\temp\rar$ex00.977\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.977\world of revenge client\worldofrevenge.exe | "TCP Query User{550C3C07-82EC-4638-B796-F2E229109154}C:\users\thomas\appdata\local\temp\rar$ex00.418\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.418\world of revenge client\worldofrevenge.exe | "TCP Query User{5597F3AF-AD6D-4B8E-B6DC-A1BCDE11EF93}C:\users\thomas\appdata\local\temp\rar$ex00.841\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.841\world of revenge client\worldofrevenge.exe | "TCP Query User{560F4BDE-AB06-40F5-9D7E-9D9D48FDFC2B}C:\users\thomas\appdata\local\temp\rar$ex00.995\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.995\world of revenge client\worldofrevenge.exe | "TCP Query User{564E51B6-9722-4CA9-9E07-CE653CA54653}C:\users\thomas\appdata\local\temp\rar$ex00.799\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.799\world of revenge client\worldofrevenge.exe | "TCP Query User{5716F8DC-DB58-40DD-ACB3-FD40842230CD}C:\users\thomas\appdata\local\temp\rar$ex16.047\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex16.047\metin2.bin | "TCP Query User{57667ECE-69FA-4FE5-9DA8-24D4D1F2E16E}C:\users\thomas\appdata\local\temp\rar$ex01.121\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.121\world of revenge client\worldofrevenge.exe | "TCP Query User{580D684B-E835-407D-AF3D-7B56003C808B}C:\users\thomas\appdata\local\temp\rar$ex55.269\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex55.269\world of revenge client\worldofrevenge.exe | "TCP Query User{58362764-D1B2-4EF4-ACEB-585776CEA0CC}C:\users\thomas\appdata\local\temp\rar$ex27.841\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex27.841\world of revenge client\worldofrevenge.exe | "TCP Query User{59C3E5F0-D2BC-4B19-A9D0-D44BA783B12C}C:\users\thomas\appdata\local\temp\rar$ex01.971\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.971\world of revenge client\worldofrevenge.exe | "TCP Query User{5A549214-7AE7-4B11-99EB-F19216B78346}C:\users\thomas\appdata\local\temp\rar$ex00.401\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.401\world of revenge client\worldofrevenge.exe | "TCP Query User{5A69E94B-2E1F-4355-A55D-07FD962557D8}C:\users\thomas\appdata\local\temp\rar$ex00.803\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.803\world of revenge client\worldofrevenge.exe | "TCP Query User{5A7F2A70-B59C-4723-968A-BD90D1BC8784}C:\users\thomas\appdata\local\temp\rar$ex00.679\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.679\metin2.bin | "TCP Query User{5A9AB318-051B-4A1F-AFE3-ECE442D38B04}C:\users\thomas\appdata\local\temp\rar$ex01.946\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.946\world of revenge client\worldofrevenge.exe | "TCP Query User{5ADE4514-1363-4B72-99DD-640C3B558D5B}C:\users\thomas\appdata\local\temp\rar$ex00.067\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.067\world of revenge client\worldofrevenge.exe | "TCP Query User{5C8B2972-4553-4AF8-8848-7C0D97876D54}C:\users\thomas\appdata\local\temp\rar$ex24.118\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex24.118\world of revenge client\worldofrevenge.exe | "TCP Query User{5D75BE51-19D7-4AF4-AC52-61BAA5F4CC94}C:\users\thomas\appdata\local\temp\rar$ex08.482\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex08.482\world of revenge client\worldofrevenge.exe | "TCP Query User{5DD0D90E-67FA-49E1-9485-827C4641B418}C:\users\thomas\appdata\local\temp\rar$ex00.785\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.785\world of revenge client\worldofrevenge.exe | "TCP Query User{5DF431FF-43D5-4EA8-89E9-AB55E40B1003}C:\users\thomas\appdata\local\temp\rar$ex00.891\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.891\world of revenge client\worldofrevenge.exe | "TCP Query User{5E6E8093-871B-4B5A-B0C4-DB640610510D}C:\users\thomas\appdata\local\temp\rar$ex00.696\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.696\world of revenge client\worldofrevenge.exe | "TCP Query User{5E9D0D9D-0CD5-48C0-BA25-25E7AA999813}C:\users\thomas\appdata\local\temp\rar$ex05.729\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex05.729\metin2.bin | "TCP Query User{5EDC5AB0-B917-4ADF-97EA-33D07E611C7B}C:\users\thomas\appdata\local\temp\rar$ex00.665\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.665\metin2.bin | "TCP Query User{5F871E86-1E34-42FD-B210-75728CBFC664}C:\users\thomas\appdata\local\temp\rar$ex27.423\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex27.423\world of revenge client\worldofrevenge.exe | "TCP Query User{5FB9A6BB-1227-4421-B428-F5739BC3D43C}C:\users\thomas\appdata\local\temp\rar$ex00.916\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.916\world of revenge client\worldofrevenge.exe | "TCP Query User{5FBE131F-4A6D-4416-A9D4-BF39080C8CF3}C:\users\thomas\appdata\local\temp\rar$ex59.555\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex59.555\world of revenge client\worldofrevenge.exe | "TCP Query User{5FDEBF7A-3E41-44CC-9352-F16340557B48}C:\users\thomas\appdata\local\temp\rar$ex00.288\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.288\world of revenge client\worldofrevenge.exe | "TCP Query User{60D34416-17FD-440C-B7AF-987971E37386}C:\users\thomas\appdata\local\temp\rar$ex73.842\client\metin2client.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex73.842\client\metin2client.bin | "TCP Query User{6170D6F5-A2EA-440C-B4B7-AA881D2E0F6A}C:\users\thomas\appdata\local\temp\rar$ex38.347\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex38.347\world of revenge client\worldofrevenge.exe | "TCP Query User{61770DF1-BA1B-43AD-A78B-4DA65FA40A74}C:\users\thomas\appdata\local\temp\rar$ex00.804\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.804\world of revenge client\worldofrevenge.exe | "TCP Query User{61A41A97-FD04-4817-A314-92D802E62B68}C:\users\thomas\appdata\local\temp\rar$ex59.093\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex59.093\world of revenge client\worldofrevenge.exe | "TCP Query User{633A4435-59E3-4C01-8A31-4DD625061038}C:\users\thomas\appdata\local\temp\rar$ex17.657\client\metin2client.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex17.657\client\metin2client.bin | "TCP Query User{64360439-018D-46A5-8F73-6A5A04274B1F}C:\users\thomas\appdata\local\temp\rar$ex00.798\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.798\world of revenge client\worldofrevenge.exe | "TCP Query User{65048079-4246-47F1-9FC4-3C4FFC8F7C35}C:\users\thomas\appdata\local\temp\rar$ex10.813\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex10.813\world of revenge client\worldofrevenge.exe | "TCP Query User{6546AA2C-475F-4B73-866B-ED8CE92AC1B3}C:\users\thomas\appdata\local\temp\rar$ex06.395\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex06.395\world of revenge client\worldofrevenge.exe | "TCP Query User{66C229F0-FDA3-41C1-8DBE-EB52340216FE}C:\users\thomas\appdata\local\temp\rar$ex09.604\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex09.604\metin2.bin | "TCP Query User{66E0E740-3378-4447-9AF3-6603B8DDEB49}C:\users\thomas\appdata\local\temp\rar$ex65.002\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex65.002\world of revenge client\worldofrevenge.exe | "TCP Query User{670B5669-261D-48EC-A33C-8E5AC399AE63}C:\users\thomas\appdata\local\temp\rar$ex76.601\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex76.601\metin2.bin | "TCP Query User{691B3FE7-EF22-48E7-9953-3565FCB60542}C:\users\thomas\appdata\local\temp\rar$ex00.859\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.859\world of revenge client\worldofrevenge.exe | "TCP Query User{6A8558C2-73F6-4FD7-9456-F9DEF697E849}C:\users\thomas\appdata\local\temp\rar$ex00.354\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex00.354\world of revenge client\worldofrevenge.exe | "TCP Query User{6AC7D234-6F25-4C32-9BF3-4E3BAD79355C}C:\users\thomas\appdata\local\temp\rar$ex52.659\world of revenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex52.659\world of revenge.exe | "TCP Query User{6B5C7CD2-0704-4223-B9DA-FF8D61807E50}C:\users\thomas\appdata\local\temp\rar$ex33.752\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex33.752\metin2.bin | "TCP Query User{6B74F5B7-139B-4B1B-9708-3086CF9F89A9}C:\users\thomas\appdata\local\temp\rar$ex01.339\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex01.339\metin2.bin | "TCP Query User{6B8CC710-826F-441E-B57B-BC288AD34227}C:\users\thomas\appdata\local\temp\rar$ex26.600\world of revenge client\worldofrevenge.exe" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex26.600\world of revenge client\worldofrevenge.exe | "TCP Query User{6BA5717F-77C0-4CE6-97C7-9C39380569FA}C:\users\thomas\appdata\local\temp\rar$ex10.664\metin2.bin" = protocol=6 | dir=in | app=c:\users\thomas\appdata\local\temp\rar$ex10.664\metin2.bin | < End of report > |
02.09.2012, 19:21 | #3 | |
| GVU Trojaner eingefangen-.- Und der zweite Teil:
__________________Zitat:
|
02.09.2012, 19:23 | #4 | |
| GVU Trojaner eingefangen-.- So hier ist der 3. Teil: Zitat:
|
02.09.2012, 19:25 | #5 | |
| GVU Trojaner eingefangen-.- der 4. und letzte: Zitat:
|
Themen zu GVU Trojaner eingefangen-.- |
anhang, anhänge, anti-malware, befehl, cmd.exe, einfach, eingabeaufforderung, funktionier, funktioniert, hänge, konto, löschen, malwarebytes, malwarebytes anti-malware, posts, sende, teile, teilen, troja, trojaner, version, virus, wahrscheinlich, webcam, würde |