| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 58792 | 2005-06-12 05:41:00 | adsl sending receiving | Arnie (6624) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 363323 | 2005-06-12 05:41:00 | Hi All I have adsl thru a USRobotics router and it is continually sending and receiving. Below is Hijackthis report. Any one see anything unusal AMD 2.8 Windows XP SP2. Logfile of HijackThis v1.99.1 Scan saved at 4:21:55 p.m., on 12/06/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\F-Secure\Common\FSM32.EXE C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe C:\WINDOWS\System32\GEARSec.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\F-Secure\Common\FSMB32.EXE C:\Program Files\F-Secure\Common\FCH32.EXE C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pcworld.co.nz/ R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPKbho.dll O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll O2 - BHO: (no name) - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - (no file) O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'c:\program files\newdotnet\newdotnet6_38.dll' missing O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: ppctlcab - www.pestscan.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - go.microsoft.com O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - ak.imgfarm.com O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - www.streamaudio.com O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - www.pestscan.com O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - download.mcafee.com O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - messenger.msn.com O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - download.mcafee.com O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe Thanks Arnie |
Arnie (6624) | ||
| 363324 | 2005-06-12 05:51:00 | Yes, your computer is definitely infected with malware. Go to the forum's Spyware FAQ (pressf1.pcworld.co.nz 16) and follow the instructions to scan with updated anti-virus, Ad-aware, Spybot, etc etc. Go to Add/Remove Programs in Control Panel and remove newdotnet if present. If it is not there download this removal tool: www.newdotnet.com and run it, following the directions on that page. Download the LSP fix from here: www.cexx.org and run it - launch the LSP application, and click the "I know what I'm doing" checkbox then click Finish. When you have done all of the above come back with a new HijackThis log. |
FoxyMX (5) | ||
| 363325 | 2005-06-12 05:54:00 | Thanks Foxy Will do. I am running up to date Adaware etc. |
Arnie (6624) | ||
| 363326 | 2005-06-12 07:16:00 | Hi Foxy How does this look? Logfile of HijackThis v1.99.1 Scan saved at 6:09:00 p.m., on 12/06/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE C:\WINDOWS\System32\drivers\CDAC11BA.EXE C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe C:\Program Files\F-Secure\Anti-Virus\FSGK32.EXE C:\Program Files\F-Secure\Anti-Virus\fssm32.exe C:\WINDOWS\System32\GEARSec.exe C:\Program Files\F-Secure\BackWeb\7681197\Program\BackWeb-7681197.exe C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\F-Secure\Common\FSMA32.EXE C:\Program Files\F-Secure\Common\FSMB32.EXE C:\Program Files\F-Secure\Common\FCH32.EXE C:\Program Files\F-Secure\Common\FAMEH32.EXE C:\Program Files\F-Secure\Common\FNRB32.EXE C:\Program Files\F-Secure\Common\FIH32.EXE C:\Program Files\F-Secure\Anti-Virus\fsav32.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe C:\Program Files\F-Secure\Common\FSM32.EXE C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.pcworld.co.nz/ R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL O2 - BHO: IE Privacy Keeper - Last IE Window Detector - {1201333E-BAD9-481C-BCF5-6904498CF85B} - C:\Program Files\UnH Solutions\IE Privacy Keeper\IEPKbho.dll O2 - BHO: (no name) - {206E52E0-D52E-11D4-AD54-0000E86C26F6} - C:\PROGRA~1\FRESHD~1\FRESHD~1\fdcatch.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: IeCaptureBho Object - {7c1ce531-09e9-4fc5-9803-1c2956615786} - C:\Program Files\Google\Google Desktop Search\GoogleDesktopIE.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Program Files\Common Files\Microsoft Shared\Works Shared\WkUFind.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure\Common\FSM32.EXE" /splash O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Easy-WebPrint Add To Print List - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Easy-WebPrint High Speed Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Preview - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Print - res://C:\Program Files\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll O16 - DPF: ppctlcab - www.pestscan.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - go.microsoft.com O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - ak.imgfarm.com O16 - DPF: {2253F320-AB68-4A07-917D-4F12D8884A06} (ChainCast VMR Client Proxy) - www.streamaudio.com O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - www.pestscan.com O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - download.mcafee.com O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - update.microsoft.com O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - update.microsoft.com O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - messenger.msn.com O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - download.mcafee.com O23 - Service: F-Secure BackWeb (BackWeb Client - 7681197) - Unknown owner - C:\PROGRA~1\F-Secure\BackWeb\7681197\Program\SERVIC~1.EXE O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA.EXE O23 - Service: F-Secure BackWeb LAN Access - Unknown owner - C:\Program Files\F-Secure\BackWeb\7681197\Program\fsbwlan.exe O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Program Files\F-Secure\Anti-Virus\fsgk32st.exe O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - C:\Program Files\F-Secure\Common\FNRB32.EXE O23 - Service: F-Secure Authentication Agent (FSAA) - F-Secure Corporation. All Rights Reserved. - C:\Program Files\F-Secure\Common\FSAA.EXE O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure\Common\FSMA32.EXE O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Symantec\Norton Ghost\Agent\PQV2iSvc.exe O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe |
Arnie (6624) | ||
| 363327 | 2005-06-12 07:47:00 | R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\3.bin\MWSSRCAS.DLL Close all windows except HJT. Then tick this and click on fix. And once u reboot, boot into safe mode and uninstall the entry from add/remove and its folder. O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll This isnt nasty. BUT isnt needed in startup O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe This isnt nasty. BUT isnt needed in startup. O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - ak.imgfarm.com |
Speedy Gonzales (78) | ||
| 363328 | 2005-06-12 10:46:00 | In addition to what Speedy has specified above I am not too sure about this one: O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - C:\WINDOWS\System32\drivers\CDAC11BA . EXE C-Dilla has been reported in the past to be something best not on a computer so you might want to have a look at this page (http://www . answersthatwork . com/) and make a decision as to whether to have it fixed or not . Scroll down to the "Cdac11ba . exe (C-Dilla, bought by MacroVision)" section . How is your computer behaving now after doing the fixes? |
FoxyMX (5) | ||
| 363329 | 2005-06-12 11:01:00 | O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll If you have used Spybots 'immunize feature' it is supposed to be rumming, don't delete this or the immumization feature will be disabled |
bartsdadhomer (80) | ||
| 363330 | 2005-06-13 02:24:00 | Hi All Sorry I did not get back last night, however none of the fixes had any effect. What I have found is actually happening is that it is only sending/receiving to itself if you understand that?? Millions of bits over a few hours. Disconnected from the ADSL AND the network connection to my sons laptop and the other end of the house. rebooted and still it continues non stop. Could there be a hidden virus doing this? Perhaps I could Ghost "C" to "E" which is the other partition of a 80gb disk and then do a complete format and reinstall of "C" or has anyone any ideas of what I understand is a very unusual situation. I know the basics of computers but not too much else. A bit long in the tooth to be too technical. Thanks for you clear instructions so far very clear and easy to follow. Regards |
Arnie (6624) | ||
| 363331 | 2005-06-13 07:14:00 | There is no point "ghosting" an image to a separate drive and then reinstalling that back as you will be back to where you were before. You would need to do a complete fresh reformat and reinstall if that is what you wanted to do. What firewall do you have? How are you determining all this data usage? |
Jen (38) | ||
| 363332 | 2005-06-13 12:32:00 | Hi Jen The ghosting was just in case there was a fix and save going thru all the reinstall of all the programs etc again . The data figures are what is showing on the local area connection status and is still going on with nothing connected to the router but my computer . Continues even with the line to the phone jack removed . One can see them clicking over continuously . Router Firewall plus windows . Below is the netstat -an with all connected . Microsoft Windows XP [Version 5 . 1 . 2600] (C) Copyright 1985-2001 Microsoft Corp . C:\Documents and Settings\Arnold>netstat -an Active Connections Proto Local Address Foreign Address State TCP 0 . 0 . 0 . 0:135 0 . 0 . 0 . 0:0 LISTENING TCP 0 . 0 . 0 . 0:445 0 . 0 . 0 . 0:0 LISTENING TCP 0 . 0 . 0 . 0:1025 0 . 0 . 0 . 0:0 LISTENING TCP 0 . 0 . 0 . 0:2869 0 . 0 . 0 . 0:0 LISTENING TCP 127 . 0 . 0 . 1:1029 0 . 0 . 0 . 0:0 LISTENING TCP 127 . 0 . 0 . 1:1276 127 . 0 . 0 . 1:1277 ESTABLISHED TCP 127 . 0 . 0 . 1:1277 127 . 0 . 0 . 1:1276 ESTABLISHED TCP 192 . 168 . 1 . 2:139 0 . 0 . 0 . 0:0 LISTENING UDP 0 . 0 . 0 . 0:371 *:* UDP 0 . 0 . 0 . 0:445 *:* UDP 0 . 0 . 0 . 0:500 *:* UDP 0 . 0 . 0 . 0:1026 *:* UDP 0 . 0 . 0 . 0:1041 *:* UDP 0 . 0 . 0 . 0:4500 *:* UDP 127 . 0 . 0 . 1:123 *:* UDP 127 . 0 . 0 . 1:1229 *:* UDP 127 . 0 . 0 . 1:1900 *:* UDP 192 . 168 . 1 . 2:123 *:* UDP 192 . 168 . 1 . 2:137 *:* UDP 192 . 168 . 1 . 2:138 *:* UDP 192 . 168 . 1 . 2:1900 *:* Now disconnected from the phone line and other computer . Microsoft Windows XP [Version 5 . 1 . 2600] (C) Copyright 1985-2001 Microsoft Corp . C:\Documents and Settings\Arnold>netstat -an Active Connections Proto Local Address Foreign Address State TCP 0 . 0 . 0 . 0:135 0 . 0 . 0 . 0:0 LISTENING TCP 0 . 0 . 0 . 0:445 0 . 0 . 0 . 0:0 LISTENING TCP 0 . 0 . 0 . 0:1025 0 . 0 . 0 . 0:0 LISTENING TCP 0 . 0 . 0 . 0:2869 0 . 0 . 0 . 0:0 LISTENING TCP 127 . 0 . 0 . 1:1029 0 . 0 . 0 . 0:0 LISTENING TCP 127 . 0 . 0 . 1:1276 127 . 0 . 0 . 1:1277 ESTABLISHED TCP 127 . 0 . 0 . 1:1277 127 . 0 . 0 . 1:1276 ESTABLISHED TCP 192 . 168 . 1 . 2:139 0 . 0 . 0 . 0:0 LISTENING TCP 192 . 168 . 1 . 2:2098 192 . 168 . 1 . 1:5431 CLOSE_WAIT UDP 0 . 0 . 0 . 0:371 *:* UDP 0 . 0 . 0 . 0:445 *:* UDP 0 . 0 . 0 . 0:500 *:* UDP 0 . 0 . 0 . 0:1026 *:* UDP 0 . 0 . 0 . 0:1041 *:* UDP 0 . 0 . 0 . 0:4500 *:* UDP 127 . 0 . 0 . 1:123 *:* UDP 127 . 0 . 0 . 1:1229 *:* UDP 127 . 0 . 0 . 1:1900 *:* UDP 192 . 168 . 1 . 2:123 *:* UDP 192 . 168 . 1 . 2:137 *:* UDP 192 . 168 . 1 . 2:138 *:* UDP 192 . 168 . 1 . 2:1900 *:* |
Arnie (6624) | ||
| 1 2 | |||||