Farbar Service Scanner Version: 06-08-2012 Ran by kasa (administrator) on 04-09-2012 at 09:27:44 Running from "C:\Documents and Settings\kasa\Pulpit" Microsoft Windows XP Professional Dodatek Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. WAN connected Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ Srservice Service is not running. Checking service configuration: The start type of Srservice service is OK. The ImagePath of Srservice service is OK. The ServiceDll of Srservice service is OK. sr Service is not running. Checking service configuration: The start type of sr service is set to Disabled. The default start type is Boot. The ImagePath of sr: "\SystemRoot\system32\DRIVERS\sr.sys". System Restore Disabled Policy: ======================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR"=DWORD:1 Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll [2008-05-09 01:43] - [2008-04-15 14:00] - 0126464 ____A (Microsoft Corporation) 6B4AFE7C676CFF3EFF2DC06A4EE945F7 C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit C:\WINDOWS\system32\dnsrslvr.dll [2008-05-09 01:43] - [2009-04-20 19:19] - 0045568 ____A (Microsoft Corporation) 082BE13166A3354F25F78E0B2601012B C:\WINDOWS\system32\ipnathlp.dll [2008-05-09 01:43] - [2008-04-15 14:00] - 0330752 ____A (Microsoft Corporation) DA5C015911F68F22ED821E9EE49AB233 C:\WINDOWS\system32\netman.dll [2008-05-09 01:43] - [2008-04-15 14:00] - 0198144 ____A (Microsoft Corporation) 4FE97D0B1B182DF2A9BDD4C02155EF5E C:\WINDOWS\system32\wbem\WMIsvc.dll [2008-05-09 06:55] - [2008-04-15 14:00] - 0145408 ____A (Microsoft Corporation) 70C22297534A88B0AD0568900AB5A6D9 C:\WINDOWS\system32\srsvc.dll [2008-05-09 06:56] - [2008-04-15 14:00] - 0171520 ____A (Microsoft Corporation) 316D0E66074AE4CDE641C50D3A1C5148 C:\WINDOWS\system32\Drivers\sr.sys [2008-05-09 06:56] - [2008-04-15 14:00] - 0073472 ____A (Microsoft Corporation) EB032822BE406EF220D546DDFFCF0002 C:\WINDOWS\system32\wscsvc.dll [2008-05-09 01:44] - [2008-04-15 14:00] - 0080896 ____A (Microsoft Corporation) B6669F49D42E09BC0F9889FAA0F3336D C:\WINDOWS\system32\wbem\WMIsvc.dll [2008-05-09 06:55] - [2008-04-15 14:00] - 0145408 ____A (Microsoft Corporation) 70C22297534A88B0AD0568900AB5A6D9 C:\WINDOWS\system32\wuauserv.dll [2008-05-09 06:56] - [2008-04-15 14:00] - 0006656 ____A (Microsoft Corporation) 04550D5EB7EE82C115DB547C01DF09FD C:\WINDOWS\system32\qmgr.dll [2008-05-09 06:56] - [2008-04-15 14:00] - 0409088 ___AC (Microsoft Corporation) 78200FAA6FD9C69394134C238C87FB7F C:\WINDOWS\system32\es.dll [2008-05-09 01:43] - [2008-07-07 22:29] - 0253952 ____A (Microsoft Corporation) 6AFF804839C85859E0247164FBE5F5BB C:\WINDOWS\system32\cryptsvc.dll [2008-05-09 01:43] - [2008-04-15 14:00] - 0062464 ____A (Microsoft Corporation) 6B105FE95F2E9F0B6346044BA59D41C9 C:\WINDOWS\system32\svchost.exe [2010-05-05 10:01] - [2004-08-04 12:00] - 0014336 ____A (Microsoft Corporation) BA98327E90022DBD6EE76490E0622E2E C:\WINDOWS\system32\rpcss.dll [2008-05-09 01:44] - [2009-02-09 12:53] - 0401408 ____A (Microsoft Corporation) A37311D9D628C1042A2836731787F0F3 C:\WINDOWS\system32\services.exe [2008-05-09 01:44] - [2009-02-09 13:25] - 0111104 ____A (Microsoft Corporation) 02A467E27AF55F7064C5B251E587315F Extra List: ======= DNE(8) Gpc(6) IPSec(4) NetBT(5) PSched(7) Tcpip(3) 0x09000000040000000100000002000000030000000900000005000000060000000700000008000000 IpSec Tag value is correct. **** End of log ****