Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

RCP Server unavailable...and more

Status
Not open for further replies.

TwiztedPair

Technical User
Nov 20, 2006
7
US
Ok Well i learned a leason, never mess with things you dont understand, My Question is this:

How do i restore the RPC Server and its functions back to normal?
After i cleared up my computer processes,at 100% cpu at all times, but i tweaked something that is not allowing RPC server to function, thus my WindowsInstaller\Sheild is not responding, and the NETWORKING console isnt working right either,when i used the help and support to diagnose the networking issue, nothing was correct, everything needed WMI ... I know this might take a while, so any help from anyone would be very apreciated!
I have tried restore , didnt work,undo-the spybot-and adaware spyblaster, everything i thought i removed, i put back,but i cant uninstall anything that uses the RPC server, or install the cdrom that would give me DSLfor the first time, ya dial up is my curse~

Here is my spybot breakdown:


--- Search result list ---

--- Spybot - Search && Destroy version: 1.3 ---
2004-11-29 Includes\LSP.sbi
2006-11-24 Includes\Hijackers.sbi
2006-10-27 Includes\Keyloggers.sbi
2006-12-15 Includes\Malware.sbi
2006-10-20 Includes\PUPS.sbi
2006-12-08 Includes\Security.sbi
2006-10-13 Includes\Spybots.sbi
2006-12-08 Includes\Trojans.sbi
2006-12-08 Includes\Dialer.sbi
2006-12-15 Includes\Cookies.sbi
2006-12-15 Includes\Revision.sbi
2005-02-17 Includes\Tracks.uti
2006-12-15 Includes\TrojansC.sbi
2006-12-15 Includes\SpybotsC.sbi
2006-12-15 Includes\SecurityC.sbi
2006-12-15 Includes\PUPSC.sbi
2006-12-15 Includes\MalwareC.sbi
2006-12-15 Includes\KeyloggersC.sbi
2006-12-15 Includes\HijackersC.sbi
2006-12-15 Includes\DialerC.sbi


--- System information ---
Windows XP (Build: 2600) Service Pack 2
/ DataAccess: Microsoft Data Access Components KB870669
/ DataAccess: Buffer Overrun in Microsoft Data Access Components Could Lead to Code Execution
/ MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2
/ Windows Media Player 10: Security Update for Windows Media Player 10 (KB917734)
/ Windows Media Player 9: Security Update for Windows Media Player 9 (KB917734)
/ Windows XP / SP3: Windows XP Hotfix - KB873339
/ Windows XP / SP3: Windows XP Hotfix - KB885250
/ Windows XP / SP3: Windows XP Hotfix - KB885835
/ Windows XP / SP3: Windows XP Hotfix - KB885836
/ Windows XP / SP3: Windows XP Hotfix - KB886185
/ Windows XP / SP3: Windows XP Hotfix - KB887472
/ Windows XP / SP3: Windows XP Hotfix - KB887742
/ Windows XP / SP3: Windows XP Hotfix - KB888113
/ Windows XP / SP3: Windows XP Hotfix - KB888302
/ Windows XP / SP3: Security Update for Windows XP (KB890046)
/ Windows XP / SP3: Windows XP Hotfix - KB890859
/ Windows XP / SP3: Windows XP Hotfix - KB891781
/ Windows XP / SP3: Security Update for Windows XP (KB893066)
/ Windows XP / SP3: Security Update for Windows XP (KB893756)
/ Windows XP / SP3: Windows Installer 3.1 (KB893803)
/ Windows XP / SP3: Update for Windows XP (KB894391)
/ Windows XP / SP3: Security Update for Windows XP (KB896358)
/ Windows XP / SP3: Security Update for Windows XP (KB896422)
/ Windows XP / SP3: Security Update for Windows XP (KB896423)
/ Windows XP / SP3: Security Update for Windows XP (KB896424)
/ Windows XP / SP3: Security Update for Windows XP (KB896428)
/ Windows XP / SP3: Update for Windows XP (KB898461)
/ Windows XP / SP3: Security Update for Windows XP (KB899587)
/ Windows XP / SP3: Security Update for Windows XP (KB899589)
/ Windows XP / SP3: Security Update for Windows XP (KB899591)
/ Windows XP / SP3: Update for Windows XP (KB900485)
/ Windows XP / SP3: Security Update for Windows XP (KB900725)
/ Windows XP / SP3: Security Update for Windows XP (KB901017)
/ Windows XP / SP3: Security Update for Windows XP (KB901214)
/ Windows XP / SP3: Security Update for Windows XP (KB902400)
/ Windows XP / SP3: Security Update for Windows XP (KB904706)
/ Windows XP / SP3: Update for Windows XP (KB904942)
/ Windows XP / SP3: Security Update for Windows XP (KB905414)
/ Windows XP / SP3: Security Update for Windows XP (KB905749)
/ Windows XP / SP3: Security Update for Windows XP (KB905915)
/ Windows XP / SP3: Security Update for Windows XP (KB908519)
/ Windows XP / SP3: Security Update for Windows XP (KB908531)
/ Windows XP / SP3: Update for Windows XP (KB910437)
/ Windows XP / SP3: Security Update for Windows XP (KB911280)
/ Windows XP / SP3: Security Update for Windows XP (KB911562)
/ Windows XP / SP3: Security Update for Windows XP (KB911567)
/ Windows XP / SP3: Security Update for Windows XP (KB911927)
/ Windows XP / SP3: Security Update for Windows XP (KB912812)
/ Windows XP / SP3: Security Update for Windows XP (KB912919)
/ Windows XP / SP3: Security Update for Windows XP (KB913446)
/ Windows XP / SP3: Security Update for Windows XP (KB913580)
/ Windows XP / SP3: Security Update for Windows XP (KB914388)
/ Windows XP / SP3: Security Update for Windows XP (KB914389)
/ Windows XP / SP3: Hotfix for Windows XP (KB914440)
/ Windows XP / SP3: Hotfix for Windows XP (KB915865)
/ Windows XP / SP3: Security Update for Windows XP (KB916281)
/ Windows XP / SP3: Update for Windows XP (KB916595)
/ Windows XP / SP3: Security Update for Windows XP (KB917159)
/ Windows XP / SP3: Security Update for Windows XP (KB917344)
/ Windows XP / SP3: Security Update for Windows XP (KB917422)
/ Windows XP / SP3: Security Update for Windows XP (KB917953)
/ Windows XP / SP3: Security Update for Windows XP (KB918439)
/ Windows XP / SP3: Security Update for Windows XP (KB918899)
/ Windows XP / SP3: Security Update for Windows XP (KB919007)
/ Windows XP / SP3: Security Update for Windows XP (KB920213)
/ Windows XP / SP3: Security Update for Windows XP (KB920214)
/ Windows XP / SP3: Security Update for Windows XP (KB920670)
/ Windows XP / SP3: Security Update for Windows XP (KB920683)
/ Windows XP / SP3: Security Update for Windows XP (KB920685)
/ Windows XP / SP3: Update for Windows XP (KB920872)
/ Windows XP / SP3: Security Update for Windows XP (KB921398)
/ Windows XP / SP3: Security Update for Windows XP (KB921883)
/ Windows XP / SP3: Update for Windows XP (KB922582)
/ Windows XP / SP3: Security Update for Windows XP (KB922616)
/ Windows XP / SP3: Security Update for Windows XP (KB922819)
/ Windows XP / SP3: Security Update for Windows XP (KB923191)
/ Windows XP / SP3: Security Update for Windows XP (KB923414)
/ Windows XP / SP3: Security Update for Windows XP (KB923980)
/ Windows XP / SP3: Security Update for Windows XP (KB924191)
/ Windows XP / SP3: Security Update for Windows XP (KB924270)
/ Windows XP / SP3: Security Update for Windows XP (KB924496)


--- Startup entries list ---
Located: HK_LM:Run, AOLT4
command: F:\AOLSETUP.EXE -ACS

Located: HK_LM:Run, ccApp
command: "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
file: C:\Program Files\Common Files\Symantec Shared\ccApp.exe
size: 53408
MD5: 8c5d5b71e4e8a1fb8f1fa6cc57fe411e

Located: HK_LM:Run, HostManager
command: C:\Program Files\Common Files\AOL\1160364451\EE\AOLHostManager.exe
file: C:\Program Files\Common Files\AOL\1160364451\EE\AOLHostManager.exe
size: 125528
MD5: 2e6ed35c3e2374bc63c8b91b90da72e2

Located: HK_LM:Run, HP Component Manager
command: "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
file: C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
size: 221184
MD5: c130eae1da69ac31208880ef5e0bec4c

Located: HK_LM:Run, HP Software Update
command: "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
file: C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
size: 49152
MD5: 4575c69bc34b111c99a5dfbe8af10ebb

Located: HK_LM:Run, HPDJ Taskbar Utility
command: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
file: C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
size: 188416
MD5: 1d2f88932715651eec76dde73a981a93

Located: HK_LM:Run, HPHmon05
command: C:\WINDOWS\system32\hphmon05.exe
file: C:\WINDOWS\system32\hphmon05.exe
size: 483328
MD5: ec273d5f06235f8f003316003f518ee3

Located: HK_LM:Run, HPHUPD05
command: C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
file: C:\Program Files\Hewlett-Packard\{45B6180B-DCAB-4093-8EE8-6164457517F0}\hphupd05.exe
size: 49152
MD5: 671f926abfabfb767d708bbee49df45d

Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: c74c7963eec07af49dce44d64819b2bf

Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe"
file: C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
size: 49263
MD5: ffb2d7833002457d3801aa4422ffb44f

Located: HK_LM:Run, USRpdA
command: C:\WINDOWS\SYSTEM32\USRmlnkA.exe RunServices \Device\3cpipe-USRpdA
file: C:\WINDOWS\SYSTEM32\USRmlnkA.exe
size: 77891
MD5: 3455e6fbf1a7c0e97666b874642c75be

Located: HK_LM:Run, Adaptec DirectCD (DISABLED)
command: C:\PROGRA~1\ADAPTEC\DIRECTCD\DIRECTCD.EXE

Located: HK_LM:Run, CreateCD (DISABLED)
command: C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE -r
file: C:\PROGRA~1\ADAPTEC\EASYCD~1\CREATECD\CREATECD.EXE
size: 262144
MD5: a3f4c80f595f73c7e250a7971124a9c9

Located: HK_LM:Run, EnsoniqMixer (DISABLED)
command: starter.exe
file: C:\WINDOWS\starter.exe
size: 32768
MD5: 768978e0a8cf41212bbb87edf8d3a070

Located: HK_LM:Run, HPDJ Taskbar Utility (DISABLED)
command: C:\WINDOWS\SYSTEM\hpztsb05.exe

Located: HK_LM:Run, HPHmon04 (DISABLED)
command: C:\WINDOWS\SYSTEM\HPHMON04.EXE

Located: HK_LM:Run, HPHUPD04 (DISABLED)
command: "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"

Located: HK_LM:Run, LapLink Scheduler (DISABLED)
command: "C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE"
file: C:\Program Files\Common Files\LapLink\Scheduler\LLSCHED.EXE
size: 126976
MD5: a4865cff062014ef2b24be9d338d4795

Located: HK_LM:Run, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\system32\Rundll32.exe
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:Run, LoadQM (DISABLED)
command: loadqm.exe
file: C:\WINDOWS\loadqm.exe
size: 7536
MD5: 69d7217f9d7f49d6706baf90f52b472b

Located: HK_LM:Run, Logitech Utility (DISABLED)
command: LOGI_MWX.EXE
file: C:\WINDOWS\LOGI_MWX.EXE
size: 19968
MD5: 83c41797e4e981237704a6fce42d25d8

Located: HK_LM:Run, MMTray (DISABLED)
command: C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe

Located: HK_LM:Run, NAV Agent (DISABLED)
command: C:\PROGRA~1\NORTON~2\NORTON~1\NAVAPW32.EXE

Located: HK_LM:Run, NPROTECT (DISABLED)
command: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
file: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408d8b6263f3c6fb992b6d2b4bda6

Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 155648
MD5: c74c7963eec07af49dce44d64819b2bf

Located: HK_LM:Run, RealTray (DISABLED)
command: C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER

Located: HK_LM:Run, Share-to-Web Namespace Daemon (DISABLED)
command: C:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe

Located: HK_LM:Run, SystemTray (DISABLED)
command: SysTray.Exe
file: C:\WINDOWS\system32\SysTray.Exe
size: 3072
MD5: 46e07fd3a40760fda18cf6b4fc691742

Located: HK_LM:Run, TaskMonitor (DISABLED)
command: C:\WINDOWS\taskmon.exe

Located: HK_LM:Run, WhenUSave (DISABLED)
command: C:\PROGRA~1\SAVE\Save.exe

Located: HK_LM:Run, zBrowser Launcher (DISABLED)
command: C:\Program Files\Logitech\iTouch\iTouch.exe

Located: HK_LM:RunServices, AolAcsDaemon1 (DISABLED)
command: "C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE"
file: C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
size: 34392
MD5: 82ad514a15f8223fe67d656c088bbdcf

Located: HK_LM:RunServices, GoBack Polling Service (DISABLED)
command: C:\Program Files\Wild File\GoBack\GBPoll.exe

Located: HK_LM:RunServices, KB891711 (DISABLED)
command: C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
file: C:\WINDOWS\SYSTEM\KB891711\KB891711.EXE
size: 9088
MD5: cbd841775a04e82b2828fc301aafee70

Located: HK_LM:RunServices, LoadPowerProfile (DISABLED)
command: Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
file: C:\WINDOWS\system32\Rundll32.exe
size: 33280
MD5: da285490bbd8a1d0ce6623577d5ba1ff

Located: HK_LM:RunServices, NPROTECT (DISABLED)
command: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
file: C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
size: 135168
MD5: 236408d8b6263f3c6fb992b6d2b4bda6

Located: HK_LM:RunServices, SchedulingAgent (DISABLED)
command: mstask.exe

Located: HK_LM:RunServices, ScriptBlocking (DISABLED)
command: "C:\Program Files\Common Files\Symantec Shared\Script Blocking\SBServ.exe" -reg

Located: HK_LM:RunServices, SymTray - Norton SystemWorks (DISABLED)
command: C:\Program Files\Common Files\Symantec Shared\SymTray.exe "Norton SystemWorks"

Located: HK_CU:Run, ctfmon.exe
command: C:\WINDOWS\system32\ctfmon.exe
file: C:\WINDOWS\system32\ctfmon.exe
size: 15360
MD5: 24232996a38c0b0cf151c2140ae29fc8

Located: HK_CU:Run, Uniblue SpeedUpMyPC
command:

Located: HK_CU:Run, Yahoo! Pager
command: "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet

Located: HK_CU:Run, BeachHead2000.exe (DISABLED)
command: C:\DOCUME~1\Travis\Desktop\BEACHH~1.EXE /r

Located: HK_CU:Run, LDM (DISABLED)
command: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
file: C:\Program Files\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe
size: 16384
MD5: 32f2fec86fd01e8f12590b79d751edee

Located: HK_CU:Run, MoneyAgent (DISABLED)
command: "C:\Program Files\Microsoft Money\System\Money Express.exe"

Located: HK_CU:Run, Taskbar Display Controls (DISABLED)
command: RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY

Located: HK_CU:Run, Uniblue SpeedUpMyPC (DISABLED)
command:

Located: HK_CU:Run, zzgshp (DISABLED)
command: C:\WINDOWS\gshp.vbs

Located: Startup (common), America Online Tray Icon.lnk
command: C:\Program Files\America Online 8.0\aoltray.exe
file: C:\Program Files\America Online 8.0\aoltray.exe
size: 36940
MD5: 5c7a3ffd590793388856b5fafb77c9c4

Located: Startup (common), AOL Companion.lnk
command: C:\Program Files\AOL Companion\companion.exe
file: C:\Program Files\AOL Companion\companion.exe
size: 229450
MD5: 063fd98c07665762ff189aa6cbca4c08



--- Browser helper object list ---
{02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
BHO name:
CLSID name: Yahoo! Toolbar Helper
description: Yahoo Companion!
classification: Legitimate
known filename: ycomp5_0_2_7.dll
info link: info source: TonyKlein
Path: C:\Program Files\Yahoo!\Companion\Installs\cpn\
Long name: yt.dll
Short name:
Date (created): 08/04/2006 1:17:38 PM
Date (last access): 12/26/2006
Date (last write): 07/07/2006 12:52:12 PM
Filesize: 439872
Attributes: archive
MD5: EAEEA6DDC9924A49FA047D66DBBFF665
CRC32: 500EF533
Version: 7.214.0.7

{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDHelper.dll
info link: info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name: SDHELPER.DLL
Date (created): 05/12/2004 1:03:00 AM
Date (last access): 12/26/2006
Date (last write): 05/12/2004 1:03:00 AM
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3

{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
BHO name:
CLSID name: SSVHelper Class

{7C554162-8CB7-45A4-B8F4-8EA1C75885F9} (AOL Toolbar Launcher)
BHO name: AOL Toolbar Launcher
CLSID name: AOL Toolbar Launcher
Path: C:\Program Files\AOL\AOL Toolbar 4.0\
Long name: aoltb.dll
Short name:
Date (created): 11/13/2006 1:47:10 PM
Date (last access): 12/26/2006
Date (last write): 11/13/2006 1:47:10 PM
Filesize: 968240
Attributes: archive
MD5: 94788D5B3F1A8CEBE94A1E460D8236ED
CRC32: D11C0396
Version: 0.4.0.0

{A8F38D8D-E480-4D52-B7A2-731BB6995FDD} (NAV Helper)
BHO name: NAV Helper
CLSID name: CNavExtBho Class
Path: C:\Program Files\Norton AntiVirus\
Long name: NavShExt.dll
Short name: NAVSHEXT.DLL
Date (created): 09/23/2005 5:37:48 PM
Date (last access): 12/26/2006
Date (last write): 10/17/2006 1:44:30 PM
Filesize: 140960
Attributes: archive
MD5: BE517CE3FCE02A4701DC63D0C9949C0F
CRC32: F60FBE38
Version: 0.12.0.6

{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: Googletoolbar.dll
info link: info source: TonyKlein
Path: c:\program files\google\
Long name: GoogleToolbar3.dll
Short name: GOOGLE~3.DLL
Date (created): 10/16/2006 7:11:00 PM
Date (last access): 12/26/2006
Date (last write): 10/12/2006 11:38:04 AM
Filesize: 2108480
Attributes: readonly archive
MD5: 4CB9CC5E19F70337BFE200A4DAD58025
CRC32: 07D15995
Version: 0.4.0.0



--- ActiveX list ---
DirectAnimation Java Classes (DirectAnimation Java Classes)
DPF name: DirectAnimation Java Classes
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\dajava.cab
info link:
info source: Patrick M. Kolla

Internet Explorer Classes for Java (Internet Explorer Classes for Java)
DPF name: Internet Explorer Classes for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\iejava.cab
info link:
info source: Patrick M. Kolla

Microsoft XML Parser for Java (Microsoft XML Parser for Java)
DPF name: Microsoft XML Parser for Java
CLSID name:
description:
classification: Legitimate
known filename: %WINDIR%\Java\classes\xmldso.cab
info link:
info source: Patrick M. Kolla

{4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class)
DPF name:
CLSID name: McAfee.com Operating System Class
Path: C:\WINDOWS\SYSTEM32\
Long name: mcinsctl.dll
Short name:
Date (created): 10/30/2003 12:48:12 PM
Date (last access): 12/26/2006
Date (last write): 10/30/2003 12:48:12 PM
Filesize: 339968
Attributes:
MD5: 0D72FDD4645706AF21B7105EF2124854
CRC32: 83BADCC5
Version: 0.4.0.0

{644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class)
DPF name:
CLSID name: Symantec RuFSI Utility Class
Path: C:\WINDOWS\Downloaded Program Files\
Long name: rufsi.dll
Short name:
Date (created): 05/17/2006 2:32:42 PM
Date (last access): 12/26/2006
Date (last write): 05/17/2006 2:32:42 PM
Filesize: 161480
Attributes: archive
MD5: D9021B7C1D765851774FD9A753AEC435
CRC32: 6D65423F
Version: 7.214.0.2

{8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
description: Sun Java
classification: Legitimate
known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll
info link:
info source: Patrick M. Kolla
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0

{CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0

{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} (Java Runtime Environment 1.5.0)
DPF name: Java Runtime Environment 1.5.0
CLSID name: Java Plug-in 1.5.0_08
Path: C:\Program Files\Java\jre1.5.0_08\bin\
Long name: NPJPI150_08.dll
Short name: NPJPI1~1.DLL
Date (created): 07/26/2006 3:03:18 AM
Date (last access): 12/26/2006
Date (last write): 07/26/2006 3:17:56 AM
Filesize: 69746
Attributes: archive
MD5: C10D603F2BD3B0A2EAC4EC5B743430D3
CRC32: 1EB99B36
Version: 0.5.0.0

{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\system32\Macromed\Flash\
Long name: Flash9.ocx
Short name: FLASH9.OCX
Date (created): 06/22/2006 1:44:22 PM
Date (last access): 12/26/2006
Date (last write): 06/22/2006 1:44:22 PM
Filesize: 2201224
Attributes: readonly archive
MD5: 99F80CA1EBE95677668F54CAC6F4AD6D
CRC32: B7385E3B
Version: 0.9.0.0



--- Process list ---
Spybot - Search && Destroy process list report, 12/26/2006 1:08:52 PM

PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 144 ( 476) ALG.EXE
PID: 208 ( 476) C:\WINDOWS\System32\svchost.exe
PID: 300 ( 4) \SystemRoot\System32\smss.exe
PID: 408 ( 300) CSRSS.EXE
PID: 432 ( 300) \??\C:\WINDOWS\system32\winlogon.exe
PID: 476 ( 432) C:\WINDOWS\system32\services.exe
PID: 480 (1480) C:\WINDOWS\SYSTEM32\USRmlnkA.exe
PID: 488 ( 432) C:\WINDOWS\system32\lsass.exe
PID: 668 ( 476) SVCHOST.EXE
PID: 724 ( 476) C:\WINDOWS\System32\svchost.exe
PID: 796 ( 476) SVCHOST.EXE
PID: 864 ( 476) SVCHOST.EXE
PID: 924 ( 476) C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
PID: 968 ( 476) C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
PID: 1040 ( 476) C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
PID: 1052 ( 476) C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
PID: 1076 ( 476) C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
PID: 1232 ( 476) C:\WINDOWS\system32\spoolsv.exe
PID: 1332 ( 476) C:\WINDOWS\system32\netdde.exe
PID: 1376 ( 476) C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe
PID: 1388 ( 476) C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exe
PID: 1404 ( 476) C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe
PID: 1424 (1388) AOLTPSPD.EXE
PID: 1460 ( 476) C:\WINDOWS\system32\clipsrv.exe
PID: 1480 ( 372) C:\WINDOWS\Explorer.EXE
PID: 1500 ( 476) C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
PID: 1512 ( 476) C:\Program Files\Common Files\Symantec Shared\Security Console\NSCSRVCE.EXE
PID: 1656 ( 476) C:\WINDOWS\system32\svchost.exe
PID: 1680 ( 476) C:\WINDOWS\system32\tlntsvr.exe
PID: 1748 ( 476) C:\WINDOWS\wanmpsvc.exe
PID: 2052 (1480) C:\Program Files\Common Files\Symantec Shared\ccApp.exe
PID: 2060 (1480) C:\Program Files\Java\jre1.5.0_08\bin\jusched.exe
PID: 2088 (1480) C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
PID: 2096 (1480) C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
PID: 2120 (1480) C:\WINDOWS\system32\hphmon05.exe
PID: 2128 (1480) C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb09.exe
PID: 2136 ( 480) C:\WINDOWS\SYSTEM32\USRshutA.exe
PID: 2160 (1480) C:\WINDOWS\system32\ctfmon.exe
PID: 2184 ( 480) C:\WINDOWS\SYSTEM32\USRmlnkA.exe
PID: 2304 (1480) C:\Program Files\AOL Companion\companion.exe
PID: 2312 (1480) C:\Program Files\America Online 8.0\aoltray.exe
PID: 2408 ( 476) C:\WINDOWS\system32\HPZipm12.exe
PID: 3652 (1480) C:\Program Files\Common Files\AOL\System Information\sinf.exe
PID: 3676 (1480) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe


--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 12/26/2006 1:08:52 PM

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\First Home Page
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch


--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C863E098-BDE5-4837-989A-8F0B9504877D}] SEQPACKET 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{C863E098-BDE5-4837-989A-8F0B9504877D}] DATAGRAM 5
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{89962E66-6C1B-440B-A791-5CC35B551662}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{89962E66-6C1B-440B-A791-5CC35B551662}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F942E102-3A22-489F-9853-E191A457A6AA}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F942E102-3A22-489F-9853-E191A457A6AA}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{224D8088-EDC9-4A67-8F62-862ED93E601D}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{224D8088-EDC9-4A67-8F62-862ED93E601D}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B4F909F-6A65-4066-80F8-2BCF31443C4B}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{6B4F909F-6A65-4066-80F8-2BCF31443C4B}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 15: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DA62558F-B4E5-4E76-9ABC-59C74F4931A5}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 16: MSAFD NetBIOS [\Device\NetBT_Tcpip_{DA62558F-B4E5-4E76-9ABC-59C74F4931A5}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Namespace Provider 0: Tcpip
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: Network Location Awareness (NLA) Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace

-------------------------

Any help would be so awesome~
 
What is the startup type for the RPC service set to? Should be set to automatic. What state is it currently in? Can you manually start it?

Right click My Computer, select Manage, then select services and applications and then services. Look for Remote Procedure Call (RPC).

Jeff~

"Once you can accept the universe as matter expanding into nothing that is something, wearing stripes with plaid comes easy"
Albert Einstein
 
Im not sure what they had been set to, .....even still i used command prompt to start them, as of now this is what settings they are at:

RCP STARTED AUTO NETWORKSERVICE
RCP LOCATOR <NOT STARTED> MAN LOCALSYSTEM



 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top