Farbar Service Scanner Version: 14-04-2013 Ran by Gšsiorek (administrator) on 01-05-2013 at 15:00:44 Running from "D:\Documents and Settings\Gšsiorek.G-D81B3B7B737E4\Pulpit\Anty viry" Microsoft Windows XP Dodatek Service Pack 3 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Attempt to access Google IP returned error. Google IP is offline Attempt to access Google.com returned error: Google.com is offline Attempt to access Yahoo IP returned error. Yahoo IP is offline Attempt to access Yahoo.com returned error: Yahoo.com is offline Windows Firewall: ============= sharedaccess Service is not running. Checking service configuration: The start type of sharedaccess service is OK. The ImagePath of sharedaccess service is OK. The ServiceDll of sharedaccess service is OK. winmgmt Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open winmgmt registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open winmgmt registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open winmgmt registry key. The service key does not exist. Firewall Disabled Policy: ================== System Restore: ============ Srservice Service is not running. Checking service configuration: The start type of Srservice service is OK. The ImagePath of Srservice service is OK. The ServiceDll of Srservice service is OK. sr Service is not running. Checking service configuration: The start type of sr service is set to Disabled. The default start type is Boot. The ImagePath of sr: "\SystemRoot\system32\DRIVERS\sr.sys". System Restore Disabled Policy: ======================== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore] "DisableSR"=DWORD:1 Security Center: ============ wscsvc Service is not running. Checking service configuration: The start type of wscsvc service is OK. The ImagePath of wscsvc service is OK. The ServiceDll of wscsvc service is OK. winmgmt Service is not running. Checking service configuration: Checking Start type: ATTENTION!=====> Unable to open winmgmt registry key. The service key does not exist. Checking ImagePath: ATTENTION!=====> Unable to open winmgmt registry key. The service key does not exist. Checking ServiceDll: ATTENTION!=====> Unable to open winmgmt registry key. The service key does not exist. Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ File Check: ======== D:\WINDOWS\system32\dhcpcsvc.dll [2013-04-28 15:38] - [2008-04-15 16:00] - 0126464 ____A (Microsoft Corporation) 6B4AFE7C676CFF3EFF2DC06A4EE945F7 D:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit D:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit D:\WINDOWS\system32\Drivers\tcpip.sys [2013-04-28 15:38] - [2010-09-09 17:57] - 0361344 ____A (Microsoft Corporation) 68F06FE0021B01E670AF37B8C5964FDF D:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit D:\WINDOWS\system32\dnsrslvr.dll [2013-04-28 15:38] - [2008-04-15 16:00] - 0045568 ____A (Microsoft Corporation) 4F7E82841ED3CF026BD8D5CE7C7379DB D:\WINDOWS\system32\ipnathlp.dll [2013-04-28 15:38] - [2008-04-15 16:00] - 0330752 ____A (Microsoft Corporation) DA5C015911F68F22ED821E9EE49AB233 D:\WINDOWS\system32\netman.dll [2013-04-28 15:38] - [2008-04-15 16:00] - 0198144 ____A (Microsoft Corporation) 4FE97D0B1B182DF2A9BDD4C02155EF5E D:\WINDOWS\system32\wbem\WMIsvc.dll [2009-07-28 19:26] - [2008-04-15 16:00] - 0145408 ____A (Microsoft Corporation) 70C22297534A88B0AD0568900AB5A6D9 D:\WINDOWS\system32\srsvc.dll [2009-07-28 19:27] - [2004-08-04 01:44] - 0171008 ____A (Microsoft Corporation) F309D9894FCA821E3C2F557A8032D47A D:\WINDOWS\system32\Drivers\sr.sys [2009-07-28 19:27] - [2004-08-04 01:39] - 0073472 ___AC (Microsoft Corporation) 6145CA23BCCDA679A772EC0AF42D6EB5 D:\WINDOWS\system32\wscsvc.dll [2004-08-04 01:44] - [2004-08-04 01:44] - 0081408 ____A (Microsoft Corporation) 390D0951271908C46EECF89893876424 D:\WINDOWS\system32\wbem\WMIsvc.dll [2009-07-28 19:26] - [2008-04-15 16:00] - 0145408 ____A (Microsoft Corporation) 70C22297534A88B0AD0568900AB5A6D9 D:\WINDOWS\system32\wuauserv.dll [2009-07-28 19:28] - [2008-04-15 16:00] - 0006656 ____A (Microsoft Corporation) 04550D5EB7EE82C115DB547C01DF09FD D:\WINDOWS\system32\qmgr.dll [2009-07-28 19:28] - [2008-04-15 16:00] - 0409088 ____A (Microsoft Corporation) 78200FAA6FD9C69394134C238C87FB7F D:\WINDOWS\system32\es.dll [2013-04-28 15:38] - [2008-04-15 16:00] - 0246272 ____A (Microsoft Corporation) BE1B1412A3D488C50B8F67F792196108 D:\WINDOWS\system32\cryptsvc.dll [2013-04-28 15:38] - [2008-04-15 16:00] - 0062464 ____A (Microsoft Corporation) 6B105FE95F2E9F0B6346044BA59D41C9 D:\WINDOWS\system32\svchost.exe [2013-04-28 15:38] - [2008-04-15 16:00] - 0014336 ____A (Microsoft Corporation) 8607D35D92528E2DF386F19A960D23CE D:\WINDOWS\system32\rpcss.dll [2013-04-28 15:38] - [2008-04-15 16:00] - 0399360 ____A (Microsoft Corporation) 02396DAB9DD407B06539981F477F3FEC D:\WINDOWS\system32\services.exe [2013-04-28 15:38] - [2008-04-15 16:00] - 0109056 ____A (Microsoft Corporation) 3E3AE424E27C4CEFE4CAB368C7B570EA Extra List: ======= cmdHlp(11) Gpc(4) IPSec(6) irda(3) NetBT(7) PSched(8) Tcpip(5) 0x0B0000000600000001000000020000000300000004000000050000000B0000000A000000070000000800000009000000 IpSec Tag value is correct. **** End of log ****