TwiztedPair
Technical User
Ok Well i learned a leason, never mess with things you dont understand, My Question is this:
How do i restore the RPC Server and its functions back to normal?
After i cleared up my computer processes,at 100% cpu at all times, but i tweaked something that is not allowing RPC server to function, thus my WindowsInstaller\Sheild is not responding, and the NETWORKING console isnt working right either,when i used the help and support to diagnose the networking issue, nothing was correct, everything needed WMI ... I know this might take a while, so any help from anyone would be very apreciated!
I have tried restore , didnt work,undo-the spybot-and adaware spyblaster, everything i thought i removed, i put back,but i cant uninstall anything that uses the RPC server, or install the cdrom that would give me DSLfor the first time, ya dial up is my curse~
Here is my spybot breakdown:
--- Search result list ---
--- Spybot - Search && Destroy version: 1.3 ---
2004-11-29 Includes\LSP.sbi
2006-11-24 Includes\Hijackers.sbi
2006-10-27 Includes\Keyloggers.sbi
2006-12-15 Includes\Malware.sbi
2006-10-20 Includes\PUPS.sbi
2006-12-08 Includes\Security.sbi
2006-10-13 Includes\Spybots.sbi
2006-12-08 Includes\Trojans.sbi
2006-12-08 Includes\Dialer.sbi
2006-12-15 Includes\Cookies.sbi
2006-12-15 Includes\Revision.sbi
2005-02-17 Includes\Tracks.uti
2006-12-15 Includes\TrojansC.sbi
2006-12-15 Includes\SpybotsC.sbi
2006-12-15 Includes\SecurityC.sbi
2006-12-15 Includes\PUPSC.sbi
2006-12-15 Includes\MalwareC.sbi
2006-12-15 Includes\KeyloggersC.sbi
2006-12-15 Includes\HijackersC.sbi
2006-12-15 Includes\DialerC.sbi
--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution
/ MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
/ Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734)
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899589)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Update for Windows XP (KB900485)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Update for Windows XP (KB904942)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Security Update for Windows XP (KB908531)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Security Update for Windows XP (KB911280)
/ Windows XP / SP3: Security Update for Windows XP (KB911562)
/ Windows XP / SP3: Security Update for Windows XP (KB911567)
/ Windows XP / SP3: Security Update for Windows XP (KB911927)
/ Windows XP / SP3: Security Update for Windows XP (KB912812)
/ Windows XP / SP3: Security Update for Windows XP (KB912919)
/ Windows XP / SP3: Security Update for Windows XP (KB913446)
/ Windows XP / SP3: Security Update for Windows XP (KB913580)
/ Windows XP / SP3: Security Update for Windows XP (KB914388)
/ Windows XP / SP3: Security Update for Windows XP (KB914389)
/ Windows XP / SP3: Hotfix for Windows XP (KB914440)
/ Windows XP / SP3: Hotfix for Windows XP (KB915865)
/ Windows XP / SP3: Security Update for Windows XP (KB916281)
/ Windows XP / SP3: Update for Windows XP (KB916595)
/ Windows XP / SP3: Security Update for Windows XP (KB917159)
/ Windows XP / SP3: Security Update for Windows XP (KB917344)
/ Windows XP / SP3: Security Update for Windows XP (KB917422)
/ Windows XP / SP3: Security Update for Windows XP (KB917953)
/ Windows XP / SP3: Security Update for Windows XP (KB918439)
/ Windows XP / SP3: Security Update for Windows XP (KB918899)
/ Windows XP / SP3: Security Update for Windows XP (KB919007)
/ Windows XP / SP3: Security Update for Windows XP (KB920213)
/ Windows XP / SP3: Security Update for Windows XP (KB920214)
/ Windows XP / SP3: Security Update for Windows XP (KB920670)
/ Windows XP / SP3: Security Update for Windows XP (KB920683)
/ Windows XP / SP3: Security Update for Windows XP (KB920685)
/ Windows XP / SP3: Update for Windows XP (KB920872)
/ Windows XP / SP3: Security Update for Windows XP (KB921398)
/ Windows XP / SP3: Security Update for Windows XP (KB921883)
/ Windows XP / SP3: Update for Windows XP (KB922582)
/ Windows XP / SP3: Security Update for Windows XP (KB922616)
/ Windows XP / SP3: Security Update for Windows XP (KB922819)
/ Windows XP / SP3: Security Update for Windows XP (KB923191)
/ Windows XP / SP3: Security Update for Windows XP (KB923414)
/ Windows XP / SP3: Security Update for Windows XP (KB923980)
/ Windows XP / SP3: Security Update for Windows XP (KB924191)
/ Windows XP / SP3: Security Update for Windows XP (KB924270)
/ Windows XP / SP3: Security Update for Windows XP (KB924496)
--- Startup entries list ---
Located: HK_LM:Run, AOLT4
command: F:\AOLSETUP.EXE -ACS
Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 53408
MD5: 8c5d5b71e4e8a1fb8f1fa6cc57fe411e
Located: HK_LM:Run, HostManager
command: C:\Program Files\Common Files\AOL\1160364451\EE\AOLHostManager.exe
file: C:\Program Files\Common Files\AOL\1160364451\EE\AOLHostManager.exe
size: 125528
MD5: 2e6ed35c3e2374bc63c8b91b90da72e2
Located: HK_LM:Run, HP Component Manager
command: "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
file: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
size: 221184
MD5: c130eae1da69ac31208880ef5e0bec4c
Located: HK_LM:Run, HP Software Update
command: "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
file: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
size: 49152
MD5: 4575c69bc34b111c99a5dfbe8af10ebb
Located: HK_LM:Run, HPDJ Taskbar Utility
command: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
file: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
size: 188416
MD5: 1d2f88932715651eec76dde73a981a93
Located: HK_LM:Run, HPHmon05
command: C:\WINDOWS\system32\hphmon05.exe
file: C:\WINDOWS\system32\hphmon05.exe
size: 483328
MD5: ec273d5f06235f8f003316003f518ee3
Located: HK_LM:Run, HPHUPD05
command: C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
file: C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
size: 49152
MD5: 671f926abfabfb767d708bbee49df45d
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: c74c7963eec07af49dce44d64819b2bf
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
file: C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
size: 49263
MD5: ffb2d7833002457d3801aa4422ffb44f
Located: HK_LM:Run, USRpdA
command: C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
file: C:\WINDOWS\SYSTEM32\USRmlnkA.exe
size: 77891
MD5: 3455e6fbf1a7c0e97666b874642c75be
Located: HK_LM:Run, Adaptec DirectCD (DISABLED)
command: C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
Located: HK_LM:Run, CreateCD (DISABLED)
command: C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
file: C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE
size: 262144
MD5: a3f4c80f595f73c7e250a7971124a9c9
Located: HK_LM:Run, EnsoniqMixer (DISABLED)
command: starter.exe
file: C:\WINDOWS\starter.exe
size: 32768
MD5: 768978e0a8cf41212bbb87edf8d3a070
Located: HK_LM:Run, HPDJ Taskbar Utility (DISABLED)
command: C:\WINDOWS\SYSTEM\hpztsb05.exe
Located: HK_LM:Run, HPHmon04 (DISABLED)
command: C:\WINDOWS\SYSTEM\HPHMON04.EXE
Located: HK_LM:Run, HPHUPD04 (DISABLED)
command: "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
Located: HK_LM:Run, LapLink Scheduler (DISABLED)
command: "C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE"
file: C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE
size: 126976
MD5: a4865cff062014ef2b24be9d338d4795
Located: HK_LM:Run, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\system32\Rundll32.exe
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Located: HK_LM:Run, LoadQM (DISABLED)
command: loadqm.exe
file: C:\WINDOWS\loadqm.exe
size: 7536
MD5: 69d7217f9d7f49d6706baf90f52b472b
Located: HK_LM:Run, Logitech Utility (DISABLED)
command: LOGI_MWX.EXE
file: C:\WINDOWS\LOGI_MWX.EXE
size: 19968
MD5: 83c41797e4e981237704a6fce42d25d8
Located: HK_LM:Run, MMTray (DISABLED)
command: C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
Located: HK_LM:Run, NAV Agent (DISABLED)
command: C:\PROGRA~1\NORTON~2\NORTON~1\NAVAPW32.EXE
Located: HK_LM:Run, NPROTECT (DISABLED)
command: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
file: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408d8b6263f3c6fb992b6d2b4bda6
Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: c74c7963eec07af49dce44d64819b2bf
Located: HK_LM:Run, RealTray (DISABLED)
command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
Located: HK_LM:Run, Share-to-Web Namespace Daemon (DISABLED)
command: C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
Located: HK_LM:Run, SystemTray (DISABLED)
command: SysTray.Exe
file: C:\WINDOWS\system32\SysTray.Exe
size: 3072
MD5: 46e07fd3a40760fda18cf6b4fc691742
Located: HK_LM:Run, TaskMonitor (DISABLED)
command: C:\WINDOWS\taskmon.exe
Located: HK_LM:Run, WhenUSave (DISABLED)
command: C:\PROGRA~1\SAVE\Save.exe
Located: HK_LM:Run, zBrowser Launcher (DISABLED)
command: C:\Program Files\Logitech\iTouch\iTouch.exe
Located: HK_LM:RunServices, AolAcsDaemon1 (DISABLED)
command: "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
file: C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
size: 34392
MD5: 82ad514a15f8223fe67d656c088bbdcf
Located: HK_LM:RunServices, GoBack Polling Service (DISABLED)
command: C:\Program Files\Wild File\GoBack\GBPoll.exe
Located: HK_LM:RunServices, KB891711 (DISABLED)
command: C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
file: C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
size: 9088
MD5: cbd841775a04e82b2828fc301aafee70
Located: HK_LM:RunServices, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\system32\Rundll32.exe
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Located: HK_LM:RunServices, NPROTECT (DISABLED)
command: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
file: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408d8b6263f3c6fb992b6d2b4bda6
Located: HK_LM:RunServices, SchedulingAgent (DISABLED)
command: mstask.exe
Located: HK_LM:RunServices, ScriptBlocking (DISABLED)
command: "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
Located: HK_LM:RunServices, SymTray - Norton SystemWorks (DISABLED)
command: C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8
Located: HK_CU:Run, Uniblue SpeedUpMyPC
command:
Located: HK_CU:Run, Yahoo! Pager
command: "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
Located: HK_CU:Run, BeachHead2000.exe (DISABLED)
command: C:\DOCUME~1\Travis\Desktop\BEACHH~1.EXE /r
Located: HK_CU:Run, LDM (DISABLED)
command: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
file: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
size: 16384
MD5: 32f2fec86fd01e8f12590b79d751edee
Located: HK_CU:Run, MoneyAgent (DISABLED)
command: "C:\Program Files\Microsoft Money\System\Money Express.exe"
Located: HK_CU:Run, Taskbar Display Controls (DISABLED)
command: RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
Located: HK_CU:Run, Uniblue SpeedUpMyPC (DISABLED)
command:
Located: HK_CU:Run, zzgshp (DISABLED)
command: C:\WINDOWS\gshp.vbs
Located: Startup (common), America Online Tray Icon.lnk
command: C:\Program Files\America Online 8.0\aoltray.exe
file: C:\Program Files\America Online 8.0\aoltray.exe
size: 36940
MD5: 5c7a3ffd590793388856b5fafb77c9c4
Located: Startup (common), AOL Companion.lnk
command: C:\Program Files\AOL Companion\companion.exe
file: C:\Program Files\AOL Companion\companion.exe
size: 229450
MD5: 063fd98c07665762ff189aa6cbca4c08
--- Browser helper object list ---
{02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
BHO name:
CLSID name: Yahoo! Toolbar Helper
description: Yahoo Companion!
classification: Legitimate
known filename: ycomp5_0_2_7.dll
info link: info source: TonyKlein
Path: C:\Program Files\Yahoo!\Companion\Installs\cpn\
Long name: yt.dll
Short name:
Date (created): 08/04/2006 1:17:38 PM
Date (last access): 12/26/2006
Date (last write): 07/07/2006 12:52:12 PM
Filesize: 439872
Attributes: archive
MD5: EAEEA6DDC9924A49FA047D66DBBFF665
CRC32: 500EF533
Version: 7.214.0.7
{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDHelper.dll
info link: info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 05/12/2004 1:03:00 AM
Date (last access): 12/26/2006
Date (last write): 05/12/2004 1:03:00 AM
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
BHO name:
CLSID name: SSVHelper Class
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} (AOL Toolbar Launcher)
BHO name: AOL Toolbar Launcher
CLSID name: AOL Toolbar Launcher
Path: C:\Program Files\AOL\AOL Toolbar 4.0\
Long name: aoltb.dll
Short name:
Date (created): 11/13/2006 1:47:10 PM
Date (last access): 12/26/2006
Date (last write): 11/13/2006 1:47:10 PM
Filesize: 968240
Attributes: archive
MD5: 94788D5B3F1A8CEBE94A1E460D8236ED
CRC32: D11C0396
Version: 0.4.0.0
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (NAV Helper)
BHO name: NAV Helper
CLSID name: CNavExtBho Class
Path: C:\Program Files\Norton AntiVirus\
Long name: NavShExt.dll
Short name: NAVSHEXT.DLL
Date (created): 09/23/2005 5:37:48 PM
Date (last access): 12/26/2006
Date (last write): 10/17/2006 1:44:30 PM
Filesize: 140960
Attributes: archive
MD5: BE517CE3FCE02A4701DC63D0C9949C0F
CRC32: F60FBE38
Version: 0.12.0.6
{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: Googletoolbar.dll
info link: info source: TonyKlein
Path: c:\program files\google\
Long name: GoogleToolbar3.dll
Short name: GOOGLE~3.DLL
Date (created): 10/16/2006 7:11:00 PM
Date (last access): 12/26/2006
Date (last write): 10/12/2006 11:38:04 AM
Filesize: 2108480
Attributes: readonly archive
MD5: 4CB9CC5E19F70337BFE200A4DAD58025
CRC32: 07D15995
Version: 0.4.0.0
--- ActiveX list ---
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla
Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class)
DPF name:
CLSID name: McAfee.com Operating System Class
Path: C:\WINDOWS\SYSTEM32\
Long name: mcinsctl.dll
Short name:
Date (created): 10/30/2003 12:48:12 PM
Date (last access): 12/26/2006
Date (last write): 10/30/2003 12:48:12 PM
Filesize: 339968
Attributes:
MD5: 0D72FDD4645706AF21B7105EF2124854
CRC32: 83BADCC5
Version: 0.4.0.0
{644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class)
DPF name:
CLSID name: Symantec RuFSI Utility Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: rufsi.dll
Short name:
Date (created): 05/17/2006 2:32:42 PM
Date (last access): 12/26/2006
Date (last write): 05/17/2006 2:32:42 PM
Filesize: 161480
Attributes: archive
MD5: D9021B7C1D765851774FD9A753AEC435
CRC32: 6D65423F
Version: 7.214.0.2
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0
{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Flash\
Long name: Flash9.ocx
Short name: FLASH9.OCX
Date (created): 06/22/2006 1:44:22 PM
Date (last access): 12/26/2006
Date (last write): 06/22/2006 1:44:22 PM
Filesize: 2201224
Attributes: readonly archive
MD5: 99F80CA1EBE95677668F54CAC6F4AD6D
CRC32: B7385E3B
Version: 0.9.0.0
--- Process list ---
Spybot - Search && Destroy process list report, 12/26/2006 1:08:52 PM
PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 144 ( 476) ALG.EXE
PID: 208 ( 476) C:\WINDOWS\System32\svchost.exe
PID: 300 ( 4) \SystemRoot\System32\smss.exe
PID: 408 ( 300) CSRSS.EXE
PID: 432 ( 300) \??\C:\WINDOWS\system32\winlogon.exe
PID: 476 ( 432) C:\WINDOWS\system32\services.exe
PID: 480 (1480) C:\WINDOWS\SYSTEM32\USRmlnkA.exe
PID: 488 ( 432) C:\WINDOWS\system32\lsass.exe
PID: 668 ( 476) SVCHOST.EXE
PID: 724 ( 476) C:\WINDOWS\System32\svchost.exe
PID: 796 ( 476) SVCHOST.EXE
PID: 864 ( 476) SVCHOST.EXE
PID: 924 ( 476) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 968 ( 476) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 1040 ( 476) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PID: 1052 ( 476) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PID: 1076 ( 476) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PID: 1232 ( 476) C:\WINDOWS\system32\spoolsv.exe
PID: 1332 ( 476) C:\WINDOWS\system32\netdde.exe
PID: 1376 ( 476) C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
PID: 1388 ( 476) C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PID: 1404 ( 476) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
PID: 1424 (1388) AOLTPSPD.EXE
PID: 1460 ( 476) C:\WINDOWS\system32\clipsrv.exe
PID: 1480 ( 372) C:\WINDOWS\Explorer.EXE
PID: 1500 ( 476) C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
PID: 1512 ( 476) C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
PID: 1656 ( 476) C:\WINDOWS\system32\svchost.exe
PID: 1680 ( 476) C:\WINDOWS\system32\tlntsvr.exe
PID: 1748 ( 476) C:\WINDOWS\wanmpsvc.exe
PID: 2052 (1480) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 2060 (1480) C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
PID: 2088 (1480) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PID: 2096 (1480) C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
PID: 2120 (1480) C:\WINDOWS\system32\hphmon05.exe
PID: 2128 (1480) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PID: 2136 ( 480) C:\WINDOWS\SYSTEM32\USRshutA.exe
PID: 2160 (1480) C:\WINDOWS\system32\ctfmon.exe
PID: 2184 ( 480) C:\WINDOWS\SYSTEM32\USRmlnkA.exe
PID: 2304 (1480) C:\Program Files\AOL Companion\companion.exe
PID: 2312 (1480) C:\Program Files\America Online 8.0\aoltray.exe
PID: 2408 ( 476) C:\WINDOWS\system32\HPZipm12.exe
PID: 3652 (1480) C:\Program Files\Common Files\AOL\System Information\sinf.exe
PID: 3676 (1480) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 12/26/2006 1:08:52 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\First Home Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C863E098-BDE5-4837-989A-8F0B9504877D}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C863E098-BDE5-4837-989A-8F0B9504877D}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{89962E66-6C1B-440B-A791-5CC35B551662}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{89962E66-6C1B-440B-A791-5CC35B551662}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F942E102-3A22-489F-9853-E191A457A6AA}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F942E102-3A22-489F-9853-E191A457A6AA}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{224D8088-EDC9-4A67-8F62-862ED93E601D}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{224D8088-EDC9-4A67-8F62-862ED93E601D}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B4F909F-6A65-4066-80F8-2BCF31443C4B}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B4F909F-6A65-4066-80F8-2BCF31443C4B}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DA62558F-B4E5-4E76-9ABC-59C74F4931A5}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DA62558F-B4E5-4E76-9ABC-59C74F4931A5}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
-------------------------
Any help would be so awesome~
How do i restore the RPC Server and its functions back to normal?
After i cleared up my computer processes,at 100% cpu at all times, but i tweaked something that is not allowing RPC server to function, thus my WindowsInstaller\Sheild is not responding, and the NETWORKING console isnt working right either,when i used the help and support to diagnose the networking issue, nothing was correct, everything needed WMI ... I know this might take a while, so any help from anyone would be very apreciated!
I have tried restore , didnt work,undo-the spybot-and adaware spyblaster, everything i thought i removed, i put back,but i cant uninstall anything that uses the RPC server, or install the cdrom that would give me DSLfor the first time, ya dial up is my curse~
Here is my spybot breakdown:
--- Search result list ---
--- Spybot - Search && Destroy version: 1.3 ---
2004-11-29 Includes\LSP.sbi
2006-11-24 Includes\Hijackers.sbi
2006-10-27 Includes\Keyloggers.sbi
2006-12-15 Includes\Malware.sbi
2006-10-20 Includes\PUPS.sbi
2006-12-08 Includes\Security.sbi
2006-10-13 Includes\Spybots.sbi
2006-12-08 Includes\Trojans.sbi
2006-12-08 Includes\Dialer.sbi
2006-12-15 Includes\Cookies.sbi
2006-12-15 Includes\Revision.sbi
2005-02-17 Includes\Tracks.uti
2006-12-15 Includes\TrojansC.sbi
2006-12-15 Includes\SpybotsC.sbi
2006-12-15 Includes\SecurityC.sbi
2006-12-15 Includes\PUPSC.sbi
2006-12-15 Includes\MalwareC.sbi
2006-12-15 Includes\KeyloggersC.sbi
2006-12-15 Includes\HijackersC.sbi
2006-12-15 Includes\DialerC.sbi
--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution
/ MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
/ Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734)
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899589)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Update for Windows XP (KB900485)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Update for Windows XP (KB904942)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Security Update for Windows XP (KB908531)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Security Update for Windows XP (KB911280)
/ Windows XP / SP3: Security Update for Windows XP (KB911562)
/ Windows XP / SP3: Security Update for Windows XP (KB911567)
/ Windows XP / SP3: Security Update for Windows XP (KB911927)
/ Windows XP / SP3: Security Update for Windows XP (KB912812)
/ Windows XP / SP3: Security Update for Windows XP (KB912919)
/ Windows XP / SP3: Security Update for Windows XP (KB913446)
/ Windows XP / SP3: Security Update for Windows XP (KB913580)
/ Windows XP / SP3: Security Update for Windows XP (KB914388)
/ Windows XP / SP3: Security Update for Windows XP (KB914389)
/ Windows XP / SP3: Hotfix for Windows XP (KB914440)
/ Windows XP / SP3: Hotfix for Windows XP (KB915865)
/ Windows XP / SP3: Security Update for Windows XP (KB916281)
/ Windows XP / SP3: Update for Windows XP (KB916595)
/ Windows XP / SP3: Security Update for Windows XP (KB917159)
/ Windows XP / SP3: Security Update for Windows XP (KB917344)
/ Windows XP / SP3: Security Update for Windows XP (KB917422)
/ Windows XP / SP3: Security Update for Windows XP (KB917953)
/ Windows XP / SP3: Security Update for Windows XP (KB918439)
/ Windows XP / SP3: Security Update for Windows XP (KB918899)
/ Windows XP / SP3: Security Update for Windows XP (KB919007)
/ Windows XP / SP3: Security Update for Windows XP (KB920213)
/ Windows XP / SP3: Security Update for Windows XP (KB920214)
/ Windows XP / SP3: Security Update for Windows XP (KB920670)
/ Windows XP / SP3: Security Update for Windows XP (KB920683)
/ Windows XP / SP3: Security Update for Windows XP (KB920685)
/ Windows XP / SP3: Update for Windows XP (KB920872)
/ Windows XP / SP3: Security Update for Windows XP (KB921398)
/ Windows XP / SP3: Security Update for Windows XP (KB921883)
/ Windows XP / SP3: Update for Windows XP (KB922582)
/ Windows XP / SP3: Security Update for Windows XP (KB922616)
/ Windows XP / SP3: Security Update for Windows XP (KB922819)
/ Windows XP / SP3: Security Update for Windows XP (KB923191)
/ Windows XP / SP3: Security Update for Windows XP (KB923414)
/ Windows XP / SP3: Security Update for Windows XP (KB923980)
/ Windows XP / SP3: Security Update for Windows XP (KB924191)
/ Windows XP / SP3: Security Update for Windows XP (KB924270)
/ Windows XP / SP3: Security Update for Windows XP (KB924496)
--- Startup entries list ---
Located: HK_LM:Run, AOLT4
command: F:\AOLSETUP.EXE -ACS
Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 53408
MD5: 8c5d5b71e4e8a1fb8f1fa6cc57fe411e
Located: HK_LM:Run, HostManager
command: C:\Program Files\Common Files\AOL\1160364451\EE\AOLHostManager.exe
file: C:\Program Files\Common Files\AOL\1160364451\EE\AOLHostManager.exe
size: 125528
MD5: 2e6ed35c3e2374bc63c8b91b90da72e2
Located: HK_LM:Run, HP Component Manager
command: "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
file: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
size: 221184
MD5: c130eae1da69ac31208880ef5e0bec4c
Located: HK_LM:Run, HP Software Update
command: "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
file: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
size: 49152
MD5: 4575c69bc34b111c99a5dfbe8af10ebb
Located: HK_LM:Run, HPDJ Taskbar Utility
command: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
file: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
size: 188416
MD5: 1d2f88932715651eec76dde73a981a93
Located: HK_LM:Run, HPHmon05
command: C:\WINDOWS\system32\hphmon05.exe
file: C:\WINDOWS\system32\hphmon05.exe
size: 483328
MD5: ec273d5f06235f8f003316003f518ee3
Located: HK_LM:Run, HPHUPD05
command: C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
file: C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
size: 49152
MD5: 671f926abfabfb767d708bbee49df45d
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: c74c7963eec07af49dce44d64819b2bf
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
file: C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
size: 49263
MD5: ffb2d7833002457d3801aa4422ffb44f
Located: HK_LM:Run, USRpdA
command: C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
file: C:\WINDOWS\SYSTEM32\USRmlnkA.exe
size: 77891
MD5: 3455e6fbf1a7c0e97666b874642c75be
Located: HK_LM:Run, Adaptec DirectCD (DISABLED)
command: C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE
Located: HK_LM:Run, CreateCD (DISABLED)
command: C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
file: C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE
size: 262144
MD5: a3f4c80f595f73c7e250a7971124a9c9
Located: HK_LM:Run, EnsoniqMixer (DISABLED)
command: starter.exe
file: C:\WINDOWS\starter.exe
size: 32768
MD5: 768978e0a8cf41212bbb87edf8d3a070
Located: HK_LM:Run, HPDJ Taskbar Utility (DISABLED)
command: C:\WINDOWS\SYSTEM\hpztsb05.exe
Located: HK_LM:Run, HPHmon04 (DISABLED)
command: C:\WINDOWS\SYSTEM\HPHMON04.EXE
Located: HK_LM:Run, HPHUPD04 (DISABLED)
command: "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
Located: HK_LM:Run, LapLink Scheduler (DISABLED)
command: "C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE"
file: C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE
size: 126976
MD5: a4865cff062014ef2b24be9d338d4795
Located: HK_LM:Run, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\system32\Rundll32.exe
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Located: HK_LM:Run, LoadQM (DISABLED)
command: loadqm.exe
file: C:\WINDOWS\loadqm.exe
size: 7536
MD5: 69d7217f9d7f49d6706baf90f52b472b
Located: HK_LM:Run, Logitech Utility (DISABLED)
command: LOGI_MWX.EXE
file: C:\WINDOWS\LOGI_MWX.EXE
size: 19968
MD5: 83c41797e4e981237704a6fce42d25d8
Located: HK_LM:Run, MMTray (DISABLED)
command: C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
Located: HK_LM:Run, NAV Agent (DISABLED)
command: C:\PROGRA~1\NORTON~2\NORTON~1\NAVAPW32.EXE
Located: HK_LM:Run, NPROTECT (DISABLED)
command: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
file: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408d8b6263f3c6fb992b6d2b4bda6
Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: c74c7963eec07af49dce44d64819b2bf
Located: HK_LM:Run, RealTray (DISABLED)
command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
Located: HK_LM:Run, Share-to-Web Namespace Daemon (DISABLED)
command: C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
Located: HK_LM:Run, SystemTray (DISABLED)
command: SysTray.Exe
file: C:\WINDOWS\system32\SysTray.Exe
size: 3072
MD5: 46e07fd3a40760fda18cf6b4fc691742
Located: HK_LM:Run, TaskMonitor (DISABLED)
command: C:\WINDOWS\taskmon.exe
Located: HK_LM:Run, WhenUSave (DISABLED)
command: C:\PROGRA~1\SAVE\Save.exe
Located: HK_LM:Run, zBrowser Launcher (DISABLED)
command: C:\Program Files\Logitech\iTouch\iTouch.exe
Located: HK_LM:RunServices, AolAcsDaemon1 (DISABLED)
command: "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
file: C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
size: 34392
MD5: 82ad514a15f8223fe67d656c088bbdcf
Located: HK_LM:RunServices, GoBack Polling Service (DISABLED)
command: C:\Program Files\Wild File\GoBack\GBPoll.exe
Located: HK_LM:RunServices, KB891711 (DISABLED)
command: C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
file: C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
size: 9088
MD5: cbd841775a04e82b2828fc301aafee70
Located: HK_LM:RunServices, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\system32\Rundll32.exe
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff
Located: HK_LM:RunServices, NPROTECT (DISABLED)
command: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
file: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408d8b6263f3c6fb992b6d2b4bda6
Located: HK_LM:RunServices, SchedulingAgent (DISABLED)
command: mstask.exe
Located: HK_LM:RunServices, ScriptBlocking (DISABLED)
command: "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg
Located: HK_LM:RunServices, SymTray - Norton SystemWorks (DISABLED)
command: C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"
Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8
Located: HK_CU:Run, Uniblue SpeedUpMyPC
command:
Located: HK_CU:Run, Yahoo! Pager
command: "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
Located: HK_CU:Run, BeachHead2000.exe (DISABLED)
command: C:\DOCUME~1\Travis\Desktop\BEACHH~1.EXE /r
Located: HK_CU:Run, LDM (DISABLED)
command: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
file: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
size: 16384
MD5: 32f2fec86fd01e8f12590b79d751edee
Located: HK_CU:Run, MoneyAgent (DISABLED)
command: "C:\Program Files\Microsoft Money\System\Money Express.exe"
Located: HK_CU:Run, Taskbar Display Controls (DISABLED)
command: RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY
Located: HK_CU:Run, Uniblue SpeedUpMyPC (DISABLED)
command:
Located: HK_CU:Run, zzgshp (DISABLED)
command: C:\WINDOWS\gshp.vbs
Located: Startup (common), America Online Tray Icon.lnk
command: C:\Program Files\America Online 8.0\aoltray.exe
file: C:\Program Files\America Online 8.0\aoltray.exe
size: 36940
MD5: 5c7a3ffd590793388856b5fafb77c9c4
Located: Startup (common), AOL Companion.lnk
command: C:\Program Files\AOL Companion\companion.exe
file: C:\Program Files\AOL Companion\companion.exe
size: 229450
MD5: 063fd98c07665762ff189aa6cbca4c08
--- Browser helper object list ---
{02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
BHO name:
CLSID name: Yahoo! Toolbar Helper
description: Yahoo Companion!
classification: Legitimate
known filename: ycomp5_0_2_7.dll
info link: info source: TonyKlein
Path: C:\Program Files\Yahoo!\Companion\Installs\cpn\
Long name: yt.dll
Short name:
Date (created): 08/04/2006 1:17:38 PM
Date (last access): 12/26/2006
Date (last write): 07/07/2006 12:52:12 PM
Filesize: 439872
Attributes: archive
MD5: EAEEA6DDC9924A49FA047D66DBBFF665
CRC32: 500EF533
Version: 7.214.0.7
{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDHelper.dll
info link: info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 05/12/2004 1:03:00 AM
Date (last access): 12/26/2006
Date (last write): 05/12/2004 1:03:00 AM
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
BHO name:
CLSID name: SSVHelper Class
{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} (AOL Toolbar Launcher)
BHO name: AOL Toolbar Launcher
CLSID name: AOL Toolbar Launcher
Path: C:\Program Files\AOL\AOL Toolbar 4.0\
Long name: aoltb.dll
Short name:
Date (created): 11/13/2006 1:47:10 PM
Date (last access): 12/26/2006
Date (last write): 11/13/2006 1:47:10 PM
Filesize: 968240
Attributes: archive
MD5: 94788D5B3F1A8CEBE94A1E460D8236ED
CRC32: D11C0396
Version: 0.4.0.0
{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (NAV Helper)
BHO name: NAV Helper
CLSID name: CNavExtBho Class
Path: C:\Program Files\Norton AntiVirus\
Long name: NavShExt.dll
Short name: NAVSHEXT.DLL
Date (created): 09/23/2005 5:37:48 PM
Date (last access): 12/26/2006
Date (last write): 10/17/2006 1:44:30 PM
Filesize: 140960
Attributes: archive
MD5: BE517CE3FCE02A4701DC63D0C9949C0F
CRC32: F60FBE38
Version: 0.12.0.6
{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: Googletoolbar.dll
info link: info source: TonyKlein
Path: c:\program files\google\
Long name: GoogleToolbar3.dll
Short name: GOOGLE~3.DLL
Date (created): 10/16/2006 7:11:00 PM
Date (last access): 12/26/2006
Date (last write): 10/12/2006 11:38:04 AM
Filesize: 2108480
Attributes: readonly archive
MD5: 4CB9CC5E19F70337BFE200A4DAD58025
CRC32: 07D15995
Version: 0.4.0.0
--- ActiveX list ---
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla
Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla
Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla
{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class)
DPF name:
CLSID name: McAfee.com Operating System Class
Path: C:\WINDOWS\SYSTEM32\
Long name: mcinsctl.dll
Short name:
Date (created): 10/30/2003 12:48:12 PM
Date (last access): 12/26/2006
Date (last write): 10/30/2003 12:48:12 PM
Filesize: 339968
Attributes:
MD5: 0D72FDD4645706AF21B7105EF2124854
CRC32: 83BADCC5
Version: 0.4.0.0
{644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class)
DPF name:
CLSID name: Symantec RuFSI Utility Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: rufsi.dll
Short name:
Date (created): 05/17/2006 2:32:42 PM
Date (last access): 12/26/2006
Date (last write): 05/17/2006 2:32:42 PM
Filesize: 161480
Attributes: archive
MD5: D9021B7C1D765851774FD9A753AEC435
CRC32: 6D65423F
Version: 7.214.0.2
{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0
{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0
{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Flash\
Long name: Flash9.ocx
Short name: FLASH9.OCX
Date (created): 06/22/2006 1:44:22 PM
Date (last access): 12/26/2006
Date (last write): 06/22/2006 1:44:22 PM
Filesize: 2201224
Attributes: readonly archive
MD5: 99F80CA1EBE95677668F54CAC6F4AD6D
CRC32: B7385E3B
Version: 0.9.0.0
--- Process list ---
Spybot - Search && Destroy process list report, 12/26/2006 1:08:52 PM
PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 144 ( 476) ALG.EXE
PID: 208 ( 476) C:\WINDOWS\System32\svchost.exe
PID: 300 ( 4) \SystemRoot\System32\smss.exe
PID: 408 ( 300) CSRSS.EXE
PID: 432 ( 300) \??\C:\WINDOWS\system32\winlogon.exe
PID: 476 ( 432) C:\WINDOWS\system32\services.exe
PID: 480 (1480) C:\WINDOWS\SYSTEM32\USRmlnkA.exe
PID: 488 ( 432) C:\WINDOWS\system32\lsass.exe
PID: 668 ( 476) SVCHOST.EXE
PID: 724 ( 476) C:\WINDOWS\System32\svchost.exe
PID: 796 ( 476) SVCHOST.EXE
PID: 864 ( 476) SVCHOST.EXE
PID: 924 ( 476) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 968 ( 476) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 1040 ( 476) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PID: 1052 ( 476) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PID: 1076 ( 476) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PID: 1232 ( 476) C:\WINDOWS\system32\spoolsv.exe
PID: 1332 ( 476) C:\WINDOWS\system32\netdde.exe
PID: 1376 ( 476) C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
PID: 1388 ( 476) C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PID: 1404 ( 476) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
PID: 1424 (1388) AOLTPSPD.EXE
PID: 1460 ( 476) C:\WINDOWS\system32\clipsrv.exe
PID: 1480 ( 372) C:\WINDOWS\Explorer.EXE
PID: 1500 ( 476) C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
PID: 1512 ( 476) C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
PID: 1656 ( 476) C:\WINDOWS\system32\svchost.exe
PID: 1680 ( 476) C:\WINDOWS\system32\tlntsvr.exe
PID: 1748 ( 476) C:\WINDOWS\wanmpsvc.exe
PID: 2052 (1480) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 2060 (1480) C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
PID: 2088 (1480) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PID: 2096 (1480) C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
PID: 2120 (1480) C:\WINDOWS\system32\hphmon05.exe
PID: 2128 (1480) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PID: 2136 ( 480) C:\WINDOWS\SYSTEM32\USRshutA.exe
PID: 2160 (1480) C:\WINDOWS\system32\ctfmon.exe
PID: 2184 ( 480) C:\WINDOWS\SYSTEM32\USRmlnkA.exe
PID: 2304 (1480) C:\Program Files\AOL Companion\companion.exe
PID: 2312 (1480) C:\Program Files\America Online 8.0\aoltray.exe
PID: 2408 ( 476) C:\WINDOWS\system32\HPZipm12.exe
PID: 3652 (1480) C:\Program Files\Common Files\AOL\System Information\sinf.exe
PID: 3676 (1480) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 12/26/2006 1:08:52 PM
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\First Home Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C863E098-BDE5-4837-989A-8F0B9504877D}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C863E098-BDE5-4837-989A-8F0B9504877D}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{89962E66-6C1B-440B-A791-5CC35B551662}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{89962E66-6C1B-440B-A791-5CC35B551662}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F942E102-3A22-489F-9853-E191A457A6AA}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F942E102-3A22-489F-9853-E191A457A6AA}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{224D8088-EDC9-4A67-8F62-862ED93E601D}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{224D8088-EDC9-4A67-8F62-862ED93E601D}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B4F909F-6A65-4066-80F8-2BCF31443C4B}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B4F909F-6A65-4066-80F8-2BCF31443C4B}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DA62558F-B4E5-4E76-9ABC-59C74F4931A5}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DA62558F-B4E5-4E76-9ABC-59C74F4931A5}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
-------------------------
Any help would be so awesome~