Farbar Service Scanner Version: 06-08-2012 Ran by Hubert (administrator) on 14-09-2012 at 18:20:55 Running from "C:\Users\Hubert\Desktop" Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is set to Disabled. The default start type is Auto. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. Windows Update: ============ wuauserv Service is not running. Checking service configuration: The start type of wuauserv service is set to Disabled. The default start type is Auto. The ImagePath of wuauserv service is OK. The ServiceDll of wuauserv service is OK. Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== WinDefend Service is not running. Checking service configuration: The start type of WinDefend service is set to Disabled. The default start type is Auto. The ImagePath of WinDefend service is OK. The ServiceDll of WinDefend service is OK. Windows Defender Disabled Policy: ========================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender] "DisableAntiSpyware"=DWORD:1 Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0204288 ____A (Microsoft Corporation) 43A988A9C10333476CB5FB667CBD629D C:\Windows\system32\Drivers\afd.sys [2008-01-21 04:24] - [2008-01-21 04:24] - 0273920 ____A (Microsoft Corporation) 763E172A55177E478CB419F88FD0BA03 C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys [2008-01-21 04:25] - [2008-01-21 04:25] - 0891448 ____A (Microsoft Corporation) FC6E2835D667774D409C7C7021EAF9C4 C:\Windows\system32\dnsrslvr.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0086528 ____A (Microsoft Corporation) F5A0F1DA1ED8B429597E71D27D976E31 C:\Windows\system32\mpssvc.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0393216 ____A (Microsoft Corporation) D1639BA315B0D79DEC49A4B0E1FB929B C:\Windows\system32\bfe.dll [2008-01-21 04:23] - [2008-01-21 04:23] - 0328704 ____A (Microsoft Corporation) 8582E233C346AEFE759833E8A30DD697 C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe [2008-01-21 04:23] - [2008-01-21 04:23] - 1054720 ____A (Microsoft Corporation) D5FB73D19C46ADE183F968E13F186B23 C:\Windows\system32\wscsvc.dll [2008-01-21 04:23] - [2008-01-21 04:23] - 0061440 ____A (Microsoft Corporation) 683DD16B590372F2C9661D277F35E49C C:\Windows\system32\wbem\WMIsvc.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0161792 ____A (Microsoft Corporation) 00B79A7C984678F24CF052E5BEB3A2F5 C:\Windows\system32\wuaueng.dll [2008-01-21 04:25] - [2008-01-21 04:25] - 1695232 ____A (Microsoft Corporation) D79538B67FA641E986855DEF651E78FE C:\Windows\system32\qmgr.dll [2008-01-21 04:25] - [2008-01-21 04:25] - 0758272 ____A (Microsoft Corporation) 02ED7B4DBC2A3232A389106DA7515C3D C:\Windows\system32\es.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0262144 ____A (Microsoft Corporation) F4BF4FA769DB51B106D2B4B35256988B C:\Windows\system32\cryptsvc.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0128000 ____A (Microsoft Corporation) 6DE363F9F99334514C46AEC02D3E3678 C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\system32\ipnathlp.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0288256 ____A (Microsoft Corporation) E1499BD0FF76B1B2FBBF1AF339D91165 C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll [2008-01-21 04:24] - [2008-01-21 04:24] - 0547328 ____A (Microsoft Corporation) 33FB1F0193EE2051067441492D56113C **** End of log ****