--- Search result list ---
--- Spybot-S&D version: 1.2 ---
2004-02-26 Includes\Cookies.sbi
2004-02-29 Includes\Dialer.sbi
2004-02-29 Includes\Hijackers.sbi
2004-02-26 Includes\Keyloggers.sbi
2004-02-29 Includes\Malware.sbi
2003-03-16 Includes\plugin-ignore.ini
2004-03-09 Includes\Revision.sbi
2004-02-26 Includes\Security.sbi
2004-02-29 Includes\Spybots.sbi
2003-03-16 Includes\Temporary.sbi
2004-02-26 Includes\Tracks.uti
2004-02-29 Includes\Trojans.sbi
--- System information ---
Windows XP (Build: 2600) Service Pack 1
/ DataAccess: Security Update for Microsoft Data Access Components
/ Windows Media Player / SP0: Windows Media Player Hotfix [See wm828026 for more information]
/ Windows Media Player: Windows Media Update 817787
/ Windows Media Player: Windows Media Update 828026
/ Windows XP / SP1: Windows XP Service Pack 1a
/ Windows XP / SP2: Windows XP Hotfix - KB810217
/ Windows XP / SP2: Windows XP Hotfix (SP2) [See KB810243 for more information]
/ Windows XP / SP2: Advanced Networking Pack for Windows XP
/ Windows XP / SP2: Windows XP Hotfix - KB820291
/ Windows XP / SP2: Windows XP Hotfix - KB821253
/ Windows XP / SP2: Windows XP Hotfix - KB822603
/ Windows XP / SP2: Windows XP Hotfix - KB823182
/ Windows XP / SP2: Windows XP Hotfix - KB824105
/ Windows XP / SP2: Windows XP Hotfix - KB824141
/ Windows XP / SP2: Windows XP Hotfix - KB824146
/ Windows XP / SP2: Windows XP Hotfix - KB825119
/ Windows XP / SP2: Windows XP Hotfix - KB826939
/ Windows XP / SP2: Windows XP Hotfix - KB826942
/ Windows XP / SP2: Windows XP Hotfix - KB828028
/ Windows XP / SP2: Windows XP Hotfix - KB828035
/ Windows XP / SP2: Windows XP Hotfix - KB829558
/ Windows XP / SP2: Windows XP Hotfix (SP2) Q322011
/ Windows XP / SP2: Windows XP Hotfix (SP2) Q327979
/ Windows XP / SP2: Windows XP Hotfix (SP2) Q814995
/ Windows XP / SP2: Windows XP Hotfix (SP2) Q819696
--- Startup entries list ---
Spybot-S&D Startup list report, 14/03/2004 4:07:20 PM
Located: HK_CU:Run, MsnMsgr
file: "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background
Located: HK_CU:Run, STYLEXP
file: C:\Program Files\TGTSoft\StyleXP\StyleXP.exe -Hide
Located: HK_CU:Run, Yahoo! Pager
file: C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe -quiet
Located: HK_CU:Run, WINT
file: C:\WINDOWS\System32\wcpsu.exe
MD5: 12694B3F3462619DEC289041733BE2D9
Located: HK_LM:Run, IgfxTray
file: C:\WINDOWS\System32\igfxtray.exe
MD5: 26F4DF6C5A39420CF1A6AD2C3FD7B3F8
Located: HK_LM:Run, HotKeysCmds
file: C:\WINDOWS\System32\hkcmd.exe
MD5: DAA3B4C4A574ADEEBC99A7029DEDACDD
Located: HK_LM:Run, TrackPointSrv
file: tp4serv.exe
Located: HK_LM:Run, TP4EX
file: tp4ex.exe
Located: HK_LM:Run, TPHOTKEY
file: C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
MD5: 7A0AB3CEED7BDA5EC61EDF62D7102965
Located: HK_LM:Run, AGRSMMSG
file: AGRSMMSG.exe
Located: HK_LM:Run, QuickTime Task
file: "C:\Program Files\QuickTime\qttask.exe" -atboottime
Located: HK_LM:Run, Mirabilis ICQ
file: C:\PROGRA~1\ICQ\ICQNet.exe
MD5: 4E34897AC56FE596D9D445A82E392D57
Located: HK_LM:Run, NAV Agent
file: C:\PROGRA~1\NORTON~1\navapw32.exe
MD5: 89EDB06C1EA1A7F4A513FF1DBECBF73B
Located: HK_LM:Run, LTSMMSG
file: LTSMMSG.exe
Located: HK_LM:Run, TkBellExe (DISABLED)
file: "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
Located: Startup (common), Adobe Gamma Loader.lnk
file: C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
MD5: C2FF17734176CD15221C10044EF0BA1A
Located: Startup (common), BlackICE Utility.lnk
file: C:\Program Files\ISS\BlackICE\blackice.exe
MD5: 9166615A9EA43018CDCB822AE9BD2D1D
Located: Startup (common), Microsoft Office.lnk
file: C:\Program Files\Microsoft Office\Office\OSA9.EXE
MD5: 1A92B01BA716EB8C863BD4BE6A71CB32
--- Browser helper object list ---
Spybot-S&D Browser helper object report, 14/03/2004 4:07:20 PM
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
Class file: AcroIEHelper.ocx
Attributes:
Date: 02/03/2001 12:02:04 PM
MD5: 8394ABFC1BE196A62C9F532511936DF7
Path: C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\
Short name: ACROIE~1.OCX
Size: 37808 bytes
Version: 0.1.0.0
Class name: AcroIEHlprObj Class
CLSID database: legitimate software
Description: Adobe Acrobat reader
Filename: ACROIEHELPER.OCX
{53707962-6F74-2D53-2644-206D7942484F}
Class file: SDHelper.dll
Attributes: archive
Date: 16/03/2003 1:02:00 AM
MD5: 423CBD3CFAEEB62C5C97A9449567B474
Path: C:\PROGRA~1\SPYBOT~1\
Short name:
Size: 711168 bytes
Version: 255.255.255.255
CLSID database: legitimate software
Description: Spybot-S&D IE Browser plugin
Filename: SDHelper.dll
{BDF3E430-B101-42AD-A544-FADC6B084872}
Class file: NavShExt.dll
Attributes: archive
Date: 27/02/2002 11:07:30 AM
MD5: 3AB9B9A20D4D8B6A1632910AB6C56FD9
Path: C:\Program Files\Norton AntiVirus\
Short name:
Size: 102400 bytes
Version: 0.8.0.0
Class name: CNavExtBho Class
CLSID database: legitimate software
Description: Norton Antivirus
Filename: NavShExt.dll
Name: NAV Helper
--- ActiveX list ---
Spybot-S&D ActiveX report, 14/03/2004 4:07:20 PM
Microsoft XML Parser for Java
Download location: file://C:\WINDOWS\Java\classes\xmldso.cab
Name: Microsoft XML Parser for Java
Version: 1,0,9,2
Yahoo! Chat
Download location:
http://us.chat1.yimg.com/us.yimg.com.../c381/chat.cab
Last modified: Sat, 29 Sep 2001 00:18:53 GMT
Name: Yahoo! Chat
Version: 1,0,0,381
{00B71CFB-6864-4346-A978-C0A14556272C}
Class file: msgrchkr.dll
Attributes: archive
Date: 29/05/2003 3:00:18 PM
MD5: 42D567DF86B9B7AC4A89664C9651B68B
Path: C:\WINDOWS\Downloaded Program Files\
Short name:
Size: 77408 bytes
Version: 0.7.0.1
Class name: Checkers Class
Contains file: msgrchkr.dll
Attributes: archive
Date: 29/05/2003 3:00:18 PM
MD5: 42D567DF86B9B7AC4A89664C9651B68B
Path: C:\WINDOWS\Downloaded Program Files\
Short name:
Size: 77408 bytes
Version: 0.7.0.1
Download location:
http://messenger.zone.msn.com/binary/msgrchkr.cab
Last modified: Tue, 23 Sep 2003 20:14:14 GMT
Version: 7,1,9502,1
{02BF25D5-8C17-4B23-BC80-D3488ABDDC6B}
Class file: QTPlugin.ocx
Attributes: archive
Date: 21/01/2004 4:04:36 PM
MD5: CE3D865CCF4267C85934D9B7CA8521F2
Path: C:\Program Files\QuickTime\
Short name:
Size: 327736 bytes
Version: 0.6.0.4
Class name: QuickTime Object
CLSID database: legitimate software
Description: Apple Quicktime
Filename: QTPLUGIN.OCX
Download location:
http://www.apple.com/qtactivex/qtplugin.cab
Last modified: Thu, 09 Oct 2003 18:24:41 GMT
Version: 6,4,0,29
{166B1BCA-3F9C-11CF-8075-444553540000}
Class file: SwDir.dll
Attributes: archive
Date: 11/02/2003 6:02:58 AM
MD5: 92FA0AE21D3A08B65D291724AA7D0E43
Path: C:\WINDOWS\system32\Macromed\Director\
Short name:
Size: 32768 bytes
Version: 0.8.0.5
Class name: Shockwave ActiveX Control
CLSID database: unknown class
Description: Macromedia ShockWave Flash Player 7
Filename: SWDIR.DLL
Download location:
http://download.macromedia.com/pub/s...irector/sw.cab
Last modified: Tue, 08 Oct 2002 18:22:24 GMT
Version: 8,5,1,102
{56336BCB-3D8A-11D6-A00B-0050DA18DE71}
Class file: RdxIE.dll
Attributes: archive
Date: 28/01/2004 12:13:52 PM
MD5: C350FD4B920362062BD39EA31007ACFB
Path: C:\WINDOWS\Downloaded Program Files\
Short name:
Size: 520349 bytes
Version: 0.6.0.0
Class name: RdxIE Class
CLSID database: confirmed malware
Description: Netster
Contains file: RdxIE.dll
Attributes: archive
Date: 28/01/2004 12:13:52 PM
MD5: C350FD4B920362062BD39EA31007ACFB
Path: C:\WINDOWS\Downloaded Program Files\
Short name:
Size: 520349 bytes
Version: 0.6.0.0
Download location:
http://software-dl.real.com/183bba77...p/RdxIE601.cab
Last modified: Wed, 28 Jan 2004 20:13:56 GMT
Version: 6,0,0,10
{59131903-4A33-40D5-80C2-5242DD365AB3}
Class file: MS3DVI~1.OCX
Attributes: archive
Date: 18/04/2003 6:17:30 AM
MD5: 17609769953405A1225B13B470DB8F1D
Path: C:\PROGRA~1\MILKSH~1\
Short name: MS3DVI~1.OCX
Size: 987136 bytes
Version: 0.1.0.0
Class name: MS3DViewerOCX Control
Download location:
http://www.swissquake.ch/chumbalum-s...DViewerOCX.cab
Last modified: Sat, 19 Apr 2003 11:43:17 GMT
Version: 1,0,0,6
{62475759-9E84-458E-A1AB-5D2C442ADFDE}
Download location:
http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
Last modified: Sun, 14 Dec 2003 18:03:23 GMT
Version: 0,0,0,1
{74D05D43-3236-11D4-BDCD-00C04F9A3B61}
Class file: xscan53.ocx
Attributes: archive
Date: 27/11/2003 4:40:00 PM
MD5: 509CDDE8175702B1FF4E2B43F0332436
Path: C:\WINDOWS\DOWNLO~1\
Short name:
Size: 435712 bytes
Version: 0.5.0.70
Class name: HouseCall Control
CLSID database: legitimate software
Description: Trend Micro Antivirus online scanner
Filename: XSCAN53.OCX
Contains file: aucfg.ini
Attributes: archive
Date: 01/11/2002 4:17:50 PM
MD5: AF03B6DA00B295F2B2DFD949B7290F53
Path: C:\WINDOWS\
Short name:
Size: 256 bytes
Version: 255.255.255.255
Contains file: loadhttp.dll
Attributes: archive
Date: 15/10/2002 2:29:40 PM
MD5: A91762435EDBE0B0C9E6B19512934319
Path: C:\WINDOWS\
Short name:
Size: 77824 bytes
Version: 0.1.0.32
Contains file: mfc42.dll
Attributes: archive
Date: 18/08/2001 5:00:00 AM
MD5: 2E9656044FE42AC91E6EE49DC47A5472
Path: C:\WINDOWS\System32\
Short name:
Size: 995383 bytes
Version: 0.6.0.0
Contains file: msvcrt.dll
Attributes:
Date: 29/08/2002 2:41:08 AM
MD5: 886A6C3C185AAEDECD00477F72279B07
Path: C:\WINDOWS\System32\
Short name:
Size: 323072 bytes
Version: 0.7.0.0
Contains file: patchw32.dll
Attributes: archive
Date: 14/12/2001 1:34:46 PM
MD5: 6C6CAC2D5F122CF24B92EE12CB87D8A6
Path: C:\WINDOWS\
Short name:
Size: 164864 bytes
Version: 0.5.0.1
Contains file: runtsckl.exe
Attributes: archive
Date: 27/11/2003 4:40:04 PM
MD5: FBD7758A9AD865A4FAC3A56C0DF0FAC9
Path: C:\WINDOWS\
Short name:
Size: 99328 bytes
Version: 0.1.0.0
Contains file: tmupdate.ini
Attributes: archive
Date: 04/07/2002 3:05:34 PM
MD5: 787089A662510400220211AD5A431F06
Path: C:\WINDOWS\
Short name:
Size: 269 bytes
Version: 255.255.255.255
Contains file: xscan53.ocx
Attributes: archive
Date: 27/11/2003 4:40:00 PM
MD5: 509CDDE8175702B1FF4E2B43F0332436
Path: C:\WINDOWS\Downloaded Program Files\
Short name:
Size: 435712 bytes
Version: 0.5.0.70
Download location:
http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
Last modified: Fri, 05 Dec 2003 03:12:29 GMT
Version: 5,70,0,1079
{8E0D4DE5-3180-4024-A327-4DFAD1796A8D}
Class file: messengerstatsclient.dll
Attributes: archive
Date: 29/05/2003 3:00:20 PM
MD5: B069B555A00AA026F657AA4FD13AE154
Path: C:\WINDOWS\Downloaded Program Files\
Short name: MESSEN~1.DLL
Size: 160864 bytes
Version: 0.7.0.1
Class name: MessengerStatsClient Class
Contains file: messengerstatsclient.dll
Attributes: archive
Date: 29/05/2003 3:00:20 PM
MD5: B069B555A00AA026F657AA4FD13AE154
Path: C:\WINDOWS\Downloaded Program Files\
Short name: MESSEN~1.DLL
Size: 160864 bytes
Version: 0.7.0.1
Download location:
http://messenger.zone.msn.com/binary...tatsClient.cab
Last modified: Tue, 23 Sep 2003 20:14:14 GMT
Version: 7,1,9502,1
{9F1C11AA-197B-4942-BA54-47A8489BB47F}
Class file: iuctl.dll
Attributes: archive
Date: 31/01/2004 12:39:50 AM
MD5: 5BC0EE4544F65976945F5B1010172032
Path: C:\WINDOWS\System32\
Short name:
Size: 115512 bytes
Version: 0.5.0.4
Class name: Update Class
CLSID database: legitimate software
Description: Windows Update
Filename: %WINDIR%\System32\iuctl.dll,iuengine.dll
Contains file: iuctl.dll
Attributes: archive
Date: 31/01/2004 12:39:50 AM
MD5: 5BC0EE4544F65976945F5B1010172032
Path: C:\WINDOWS\System32\
Short name:
Size: 115512 bytes
Version: 0.5.0.4
Contains file: iuengine.dll
Attributes: archive
Date: 09/02/2004 9:09:36 PM
MD5: 920DDB6C300D8F54E3D64D7B733C9D17
Path: C:\WINDOWS\System32\
Short name:
Size: 183064 bytes
Version: 0.5.0.4
Download location:
http://v4.windowsupdate.microsoft.co...8004.123900463
Last modified: Tue, 26 Aug 2003 01:19:52 GMT
Version: 5,4,3790,14
{C5E28B9D-0A68-4B50-94E9-E8F6B4697514}
Class file: NSVPLA~1.DLL
Attributes: archive
Date: 10/12/2003 2:36:06 PM
MD5: 7DE2078460CCE8F2E7E20362434B836B
Path: C:\PROGRA~1\COMMON~1\NSV\
Short name: NSVPLA~1.DLL
Size: 112128 bytes
Version: 0.1.0.0
Class name: NsvPlayX Control
Download location:
http://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
Last modified: Mon, 15 Dec 2003 19:07:26 GMT
Version: 1,0,0,997
{D27CDB6E-AE6D-11CF-96B8-444553540000}
Class file: Flash.ocx
Attributes: archive
Date: 08/12/2003 2:01:58 PM
MD5: F7E435D02F7A48120B746E33254A70BC
Path: C:\WINDOWS\System32\macromed\flash\
Short name:
Size: 933888 bytes
Version: 0.7.0.0
Class name: Shockwave Flash Object
CLSID database: legitimate software
Description: Macromedia Shockwave Flash Player
Download location:
http://download.macromedia.com/pub/s...sh/swflash.cab
Last modified: Thu, 11 Dec 2003 15:54:18 GMT
Version: 7,0,19,0
--- Process list ---
Spybot-S&D process list report, 14/03/2004 4:07:20 PM
PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 280 ( 460) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
PID: 444 ( 460) C:\Program Files\Internet Explorer\iexplore.exe
PID: 460 ( 216) C:\WINDOWS\Explorer.EXE
PID: 616 ( 4) \SystemRoot\System32\smss.exe
PID: 644 ( 460) C:\WINDOWS\System32\hkcmd.exe
PID: 648 ( 460) C:\WINDOWS\LTSMMSG.exe
PID: 668 ( 460) C:\WINDOWS\System32\tp4serv.exe
PID: 680 ( 616) csrss.exe
PID: 704 ( 616) \??\C:\WINDOWS\system32\winlogon.exe
PID: 748 ( 704) C:\WINDOWS\system32\services.exe
PID: 760 ( 704) C:\WINDOWS\system32\lsass.exe
PID: 764 ( 460) C:\WINDOWS\AGRSMMSG.exe
PID: 900 ( 748) C:\WINDOWS\System32\ibmpmsvc.exe
PID: 932 ( 748) C:\WINDOWS\system32\svchost.exe
PID: 956 ( 748) C:\WINDOWS\System32\svchost.exe
PID: 980 ( 748) C:\Program Files\TGTSoft\StyleXP\StyleXPService.exe
PID: 1060 ( 460) C:\Program Files\Common Files\Real\Update_OB\realsched.exe
PID: 1116 ( 460) C:\PROGRA~1\NORTON~1\navapw32.exe
PID: 1140 ( 460) C:\Program Files\MSN Messenger\MsnMsgr.Exe
PID: 1156 ( 460) C:\PROGRA~1\Yahoo!\MESSEN~1\ypager.exe
PID: 1176 ( 460) C:\WINDOWS\System32\wcpsu.exe
PID: 1180 ( 748) svchost.exe
PID: 1216 ( 748) svchost.exe
PID: 1232 (1980) C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe
PID: 1320 ( 460) C:\Program Files\ISS\BlackICE\blackice.exe
PID: 1444 ( 748) C:\WINDOWS\system32\spoolsv.exe
PID: 1552 ( 748) C:\WINDOWS\system32\crypserv.exe
PID: 1588 ( 748) C:\Program Files\Norton AntiVirus\navapsvc.exe
PID: 1620 ( 748) C:\WINDOWS\System32\QCONSVC.EXE
PID: 1664 ( 748) C:\Program Files\ISS\BlackICE\rapapp.exe
PID: 1752 ( 748) C:\WINDOWS\System32\svchost.exe
PID: 1980 ( 460) C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe
PID: 2032 (1076) C:\PROGRA~1\ICQ\ICQ.exe
PID: 2864 ( 460) C:\WINDOWS\system32\mmc.exe
--- Browser start & search pages list ---
Spybot-S&D browser pages report, 14/03/2004 4:07:20 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
C:\WINDOWS\System32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir...ie&ar=iesearch
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
about
:blank
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir...ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir...r=6&ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir...ie&ar=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
--- Winsock Layered Service Provider list ---
Spybot-S&D winsock LSP report, 14/03/2004 4:07:20 PM
NS Provider ( 1) Tcpip ({22059D40-7E9E-11CF-AE5A-00AA00A7112B})
NS Provider ( 2) NTDS ({3B2637EE-E580-11CF-A555-00C04FD8D4AC})
NS Provider ( 3) Network Location Awareness (NLA) Namespace ({6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83})
Protocol ( 1) MSAFD Irda [IrDA] ({3972523D-2AF1-11D1-B655-00805F3642CC})
Protocol ( 2) MSAFD Tcpip [TCP/IP] ({E70F1AA0-AB8B-11CF-8CA3-00805F48A192})
Protocol ( 3) MSAFD Tcpip [UDP/IP] ({E70F1AA0-AB8B-11CF-8CA3-00805F48A192})
Protocol ( 4) MSAFD Tcpip [RAW/IP] ({E70F1AA0-AB8B-11CF-8CA3-00805F48A192})
Protocol ( 5) RSVP UDP Service Provider ({9D60A9E0-337A-11D0-BD88-0000C082E69A})
Protocol ( 6) RSVP TCP Service Provider ({9D60A9E0-337A-11D0-BD88-0000C082E69A})
Protocol ( 7) MSAFD NetBIOS [\Device\NetBT_Tcpip_{23D04F0F-F793-4D76-932E-B3FBE1178335}] SEQPACKET 4 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol ( 8) MSAFD NetBIOS [\Device\NetBT_Tcpip_{23D04F0F-F793-4D76-932E-B3FBE1178335}] DATAGRAM 4 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol ( 9) MSAFD NetBIOS [\Device\NetBT_Tcpip_{18AF4567-703D-45D0-B813-56EBC194EF7E}] SEQPACKET 3 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol (10) MSAFD NetBIOS [\Device\NetBT_Tcpip_{18AF4567-703D-45D0-B813-56EBC194EF7E}] DATAGRAM 3 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol (11) MSAFD NetBIOS [\Device\NetBT_Tcpip_{1FDEDE8E-97A5-41D1-843C-B64141323D51}] SEQPACKET 0 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol (12) MSAFD NetBIOS [\Device\NetBT_Tcpip_{1FDEDE8E-97A5-41D1-843C-B64141323D51}] DATAGRAM 0 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol (13) MSAFD NetBIOS [\Device\NetBT_Tcpip_{94CBE47D-DDB6-4319-9B84-41B825FE08E2}] SEQPACKET 1 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol (14) MSAFD NetBIOS [\Device\NetBT_Tcpip_{94CBE47D-DDB6-4319-9B84-41B825FE08E2}] DATAGRAM 1 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol (15) MSAFD NetBIOS [\Device\NetBT_Tcpip_{9384846F-014D-4CAE-A201-8CA220839B78}] SEQPACKET 2 ({8D5F1830-C273-11CF-95C8-00805F48A192})
Protocol (16) MSAFD NetBIOS [\Device\NetBT_Tcpip_{9384846F-014D-4CAE-A201-8CA220839B78}] DATAGRAM 2 ({8D5F1830-C273-11CF-95C8-00805F48A192})