Farbar Service Scanner Version: 10-12-2012 Ran by Marlena Hajman (administrator) on 13-12-2012 at 16:34:32 Running from "C:\Documents and Settings\Marlena Hajman\Pulpit" Microsoft Windows XP Dodatek Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ Srservice Service is not running. Checking service configuration: The start type of Srservice service is OK. The ImagePath of Srservice service is OK. The ServiceDll of Srservice service is OK. sr Service is not running. Checking service configuration: The start type of sr service is set to Disabled. The default start type is Boot. The ImagePath of sr: "\SystemRoot\system32\DRIVERS\sr.sys". System Restore Disabled Policy: ======================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR"=DWORD:1 Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ File Check: ======== C:\WINDOWS\system32\dhcpcsvc.dll [2004-08-04 00:43] - [2004-08-04 00:43] - 0110592 ____A (Microsoft Corporation) 94B49F2D487A7D4A79B3E96B6D5685B0 C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit C:\WINDOWS\system32\Drivers\netbt.sys [2004-08-03 23:14] - [2004-08-03 23:14] - 0162816 ____A (Microsoft Corporation) 0C80E410CD2F47134407EE7DD19CC86B C:\WINDOWS\system32\Drivers\tcpip.sys [2004-08-03 23:14] - [2004-08-03 23:14] - 0359040 ____A (Microsoft Corporation) 9F4B36614A0FC234525BA224957DE55C C:\WINDOWS\system32\Drivers\ipsec.sys [2004-08-03 23:14] - [2004-08-03 23:14] - 0074752 ____A (Microsoft Corporation) 64537AA5C003A6AFEEE1DF819062D0D1 C:\WINDOWS\system32\dnsrslvr.dll [2004-08-04 00:43] - [2004-08-04 00:43] - 0045568 ____A (Microsoft Corporation) F61C204EBCAA1D6B5FB5DFE7034741F3 C:\WINDOWS\system32\ipnathlp.dll [2004-08-04 00:44] - [2004-08-04 00:44] - 0331264 ____A (Microsoft Corporation) DDC87ADF808D192A5212CC8A1E7F8E87 C:\WINDOWS\system32\netman.dll [2004-08-04 00:44] - [2004-08-04 00:44] - 0198144 ____A (Microsoft Corporation) 3E7B6583269BC118720D0020B03CC71E C:\WINDOWS\system32\wbem\WMIsvc.dll [2012-02-29 13:51] - [2004-08-04 00:44] - 0145408 ____A (Microsoft Corporation) 482435B2A2DE8E06C83C3B1EB3237C2C C:\WINDOWS\system32\srsvc.dll [2012-02-29 13:53] - [2004-08-04 00:44] - 0171008 ____A (Microsoft Corporation) F309D9894FCA821E3C2F557A8032D47A C:\WINDOWS\system32\Drivers\sr.sys [2012-02-29 13:53] - [2004-08-04 00:39] - 0073472 ____A (Microsoft Corporation) 6145CA23BCCDA679A772EC0AF42D6EB5 C:\WINDOWS\system32\wscsvc.dll [2004-08-04 00:44] - [2004-08-04 00:44] - 0081408 ____A (Microsoft Corporation) 390D0951271908C46EECF89893876424 C:\WINDOWS\system32\wbem\WMIsvc.dll [2012-02-29 13:51] - [2004-08-04 00:44] - 0145408 ____A (Microsoft Corporation) 482435B2A2DE8E06C83C3B1EB3237C2C C:\WINDOWS\system32\wuauserv.dll [2012-02-29 13:54] - [2004-08-04 00:44] - 0006656 ____A (Microsoft Corporation) 40C600488FF127953AA2F1835E5FD433 C:\WINDOWS\system32\qmgr.dll [2012-02-29 13:53] - [2004-08-04 00:44] - 0382464 ____A (Microsoft Corporation) A6BFD910074B02C8794FC65F39CC6B28 C:\WINDOWS\system32\es.dll [2004-08-04 00:43] - [2004-08-04 00:43] - 0243200 ____A (Microsoft Corporation) DC54CC79E1FAEFA480A8117C9BF105E1 C:\WINDOWS\system32\cryptsvc.dll [2004-08-04 00:43] - [2004-08-04 00:43] - 0060416 ____A (Microsoft Corporation) 91723CD7C96C5854149F9CAE820A90DD C:\WINDOWS\system32\svchost.exe [2004-08-04 00:44] - [2004-08-04 00:44] - 0014336 ____A (Microsoft Corporation) BA98327E90022DBD6EE76490E0622E2E C:\WINDOWS\system32\rpcss.dll [2004-08-04 00:44] - [2004-08-04 00:44] - 0395776 ____A (Microsoft Corporation) 346E5B19FC986FE7185A0C2C43593722 C:\WINDOWS\system32\services.exe [2004-08-04 00:44] - [2004-08-04 00:44] - 0108544 ____A (Microsoft Corporation) 3DA8D964D2CC12EF8E8C342471A37917 Extra List: ======= Gpc(4) IPSec(6) irda(3) NetBT(7) PSched(8) Tcpip(5) 0x09000000060000000100000002000000030000000400000005000000090000000700000008000000 IpSec Tag value is correct. **** End of log ****