--- Search result list --- Avenue A, Inc.: Tracking cookie (Firefox: default) (Cookie, fixed) BFast: Tracking cookie (Firefox: default) (Cookie, fixed) FastClick: Tracking cookie (Firefox: default) (Cookie, fixed) FastClick: Tracking cookie (Firefox: default) (Cookie, fixed) MediaPlex: Tracking cookie (Firefox: default) (Cookie, fixed) --- Spybot - Search & Destroy version: 1.3 .1TX (build: 20040801) --- 2004-05-12 blindman.exe (1.0.0.0) 2004-08-30 SpybotSD.exe (1.3.0.12) 2004-05-12 TeaTimer.exe (1.3.0.12) 2004-06-15 unins000.exe (51.15.0.0) 2004-05-12 Update.exe (1.3.0.0) 2004-10-04 advcheck.dll (1.0.1.0) 2004-05-12 borlndmm.dll (7.0.4.453) 2004-05-12 delphimm.dll (7.0.4.453) 2004-05-12 SDHelper.dll (1.3.0.12) 2004-05-12 Tools.dll (2.0.0.0) 2004-05-12 UnzDll.dll (1.73.1.1) 2004-05-12 ZipDll.dll (1.73.2.0) 2005-03-03 Includes\Cookies.sbi 2005-03-16 Includes\Dialer.sbi 2005-03-17 Includes\Hijackers.sbi 2005-03-17 Includes\Keyloggers.sbi 2004-11-29 Includes\LSP.sbi 2005-03-16 Includes\Malware.sbi 2005-03-17 Includes\PUPS.sbi 2005-03-17 Includes\Revision.sbi 2005-02-09 Includes\Security.sbi 2005-03-17 Includes\Spybots.sbi 2005-02-17 Includes\Tracks.uti 2005-03-16 Includes\Trojans.sbi --- System information --- Windows XP (Build: 2600) Service Pack 1 / Internet Explorer 6 / SP1: Windows XP Hotfix - KB834707 / Windows XP / SP2: Windows XP Hotfix - KB828741 / Windows XP / SP2: Windows XP Hotfix - KB833407 / Windows XP / SP2: Windows XP Hotfix - KB835732 / Windows XP / SP2: Windows XP Hotfix - KB840987 / Windows XP / SP2: Windows XP Hotfix - KB842773 --- Startup entries list --- Located: HK_LM:Run, ashMaiSv command: C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe file: C:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe size: 237616 MD5: c1c111bf59fd3851e8a552937ee820cb Located: HK_LM:Run, ATIPTA command: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe file: C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe size: 335872 MD5: a9d1c3cdb56eab0e19ac41fb9ef8a9fc Located: HK_LM:Run, avast! command: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe file: C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe size: 98352 MD5: b61c42616bc28baec83515246ee450f4 Located: HK_LM:Run, AWMON command: "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe" file: C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe size: 537088 MD5: c65bd446cf1fb284c537357151104bfe Located: HK_LM:Run, WinampAgent command: C:\Program Files\Winamp\winampa.exe file: C:\Program Files\Winamp\winampa.exe size: 33792 MD5: 11aa6662a1be30375afd1a8407811e7e Located: HK_CU:Run, ctfmon.exe command: C:\WINDOWS\System32\ctfmon.exe file: C:\WINDOWS\System32\ctfmon.exe size: 13312 MD5: 414de7cf9d3f19c3ea902f1bb38ec116 Located: HK_CU:Run, SpybotSD TeaTimer command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe size: 1038336 MD5: 58f7e6434d285f4c98ad3621e0bd8c8d Located: HK_CU:Run, SpyEmergency command: "C:\Program Files\Spy Emergency 2005\SpyEmergency.exe" file: C:\Program Files\Spy Emergency 2005\SpyEmergency.exe size: 1060864 MD5: e183a839a6882dad88dbf8643fa1d87a Located: Startup (common), SpySubtract.lnk command: C:\Program Files\interMute\SpySubtract\SpySub.exe file: C:\Program Files\interMute\SpySubtract\SpySub.exe size: 1187840 MD5: 7ac22e17ba963aa54847ba163f75279b Located: Startup (disabled), Ulead Photo Express 4.0 SE Calendar Checker .lnk (DISABLED) command: Located: WinLogon, crypt32chain command: crypt32.dll Located: WinLogon, cryptnet command: cryptnet.dll Located: WinLogon, cscdll command: cscdll.dll Located: WinLogon, ScCertProp command: wlnotify.dll Located: WinLogon, Schedule command: wlnotify.dll Located: WinLogon, sclgntfy command: sclgntfy.dll Located: WinLogon, SensLogn command: WlNotify.dll Located: WinLogon, termsrv command: wlnotify.dll Located: WinLogon, wlballoon command: wlnotify.dll --- Browser helper object list --- {0055C089-8582-441B-A0BF-17B458C2A3A8} (IDM Helper) BHO name: IDM Helper CLSID name: IDMIEHlprObj Class description: Internet Download Manager classification: Legitimate known filename: IDMIECC.dll info link: info source: TonyKlein Path: C:\Program Files\Internet Download Manager\ Long name: IDMIECC.dll Short name: Date (created): 10/08/2004 10:55:08 PM Date (last access): 10/04/2005 4:35:14 PM Date (last write): 9/12/2004 1:02:26 AM Filesize: 45056 Attributes: archive MD5: 671D8DB93C691B35DD501F2E4E724C92 CRC32: E22C87F8 Version: 0.1.0.0 {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class) BHO name: CLSID name: AcroIEHlprObj Class description: Adobe Acrobat reader classification: Legitimate known filename: AcroIEhelper.ocx
AcroIEhelper.dll info link: http://www.adobe.com/products/acrobat/readstep2.html info source: TonyKlein Path: C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\ Long name: AcroIEHelper.dll Short name: ACROIE~1.DLL Date (created): 14/05/2003 11:47:54 PM Date (last access): 10/04/2005 4:35:14 PM Date (last write): 14/05/2003 11:47:54 PM Filesize: 50376 Attributes: archive MD5: 0C0E1B2BCAED8DF401BE94D538BCB412 CRC32: 1D771322 Version: 0.6.0.0 {53707962-6F74-2D53-2644-206D7942484F} () BHO name: CLSID name: description: Spybot-S&D IE Browser plugin classification: Legitimate known filename: SDhelper.dll info link: http://spybot.eon.net.au/ info source: Patrick M. Kolla Path: C:\PROGRA~1\SPYBOT~1\ Long name: SDHelper.dll Short name: Date (created): 12/05/2004 1:03:00 AM Date (last access): 10/04/2005 4:35:14 PM Date (last write): 12/05/2004 1:03:00 AM Filesize: 744960 Attributes: archive MD5: ABF5BA518C6A5ED104496FF42D19AD88 CRC32: 5587736E Version: 0.1.0.3 {9394EDE7-C8B5-483E-8773-474BF36AF6E4} () BHO name: CLSID name: {A5366673-E8CA-11D3-9CD9-0090271D075B} () BHO name: CLSID name: description: FlashGet classification: Open for discussion known filename: Jccatch.dll info link: http://www.amazesoft.com/ info source: TonyKlein {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} () BHO name: CLSID name: {E5A1691B-D188-4419-AD02-90002030B8EE} () BHO name: CLSID name: --- ActiveX list --- ppctlcab () DPF name: CLSID name: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) DPF name: CLSID name: QuickTime Object description: Apple Quicktime classification: Legitimate known filename: QTPLUGIN.OCX info link: info source: Patrick M. Kolla Path: C:\Program Files\QuickTime\ Long name: QTPlugin.ocx Short name: Date (created): 2/03/2005 12:44:32 AM Date (last access): 24/03/2005 7:03:04 AM Date (last write): 2/03/2005 12:44:32 AM Filesize: 360504 Attributes: archive MD5: F88CD154B9627646E9DDA1679155E4E3 CRC32: 5B04FF79 Version: 0.6.0.5 {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) DPF name: CLSID name: Shockwave ActiveX Control description: Macromedia ShockWave Flash Player 7 classification: Unknown known filename: SWDIR.DLL info link: info source: Patrick M. Kolla Path: C:\WINDOWS\system32\Macromed\Director\ Long name: SwDir.dll Short name: Date (created): 15/01/2005 2:18:38 AM Date (last access): 9/04/2005 11:08:30 PM Date (last write): 9/09/2004 2:49:12 PM Filesize: 54488 Attributes: archive MD5: 943193399C341AC34E842CB07B5F29A0 CRC32: 12DEB8F4 Version: 0.10.0.1 {2FC9A21E-2069-4E47-8235-36318989DB13} () DPF name: CLSID name: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) DPF name: CLSID name: MSN Photo Upload Tool Path: C:\WINDOWS\Downloaded Program Files\ Long name: msnpupld.dll Short name: Date (created): 8/10/2004 3:01:22 PM Date (last access): 10/04/2005 5:08:12 PM Date (last write): 8/10/2004 3:01:22 PM Filesize: 372736 Attributes: archive MD5: D2ED523BB0FE94F8F492BEFE1C336040 CRC32: C4677625 Version: 0.10.0.0 {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.4.1_07) DPF name: Java Runtime Environment 1.4.1_07 CLSID name: Java Plug-in 1.4.1_07 description: Sun Java classification: Legitimate known filename: %PROGRAM FILES%\JabaSoft\JRE\*\Bin\npjava131.dll info link: info source: Patrick M. Kolla Path: C:\Program Files\Java\j2re1.4.1_07\bin\ Long name: NPJPI141_07.dll Short name: NPJPI1~1.DLL Date (created): 31/10/2004 4:20:00 PM Date (last access): 10/04/2005 5:09:24 PM Date (last write): 7/12/2003 9:54:56 PM Filesize: 61553 Attributes: archive MD5: AB7190C577EA9916CDABA9D7E12E1B70 CRC32: 9D30637F Version: 0.1.0.4 {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Runtime Environment 1.4.1_02) DPF name: Java Runtime Environment 1.4.1_02 CLSID name: Java Plug-in 1.4.1_02 Path: C:\Program Files\Java\j2re1.4.1_02\bin\ Long name: NPJPI141_02.dll Short name: NPJPI1~1.DLL Date (created): 4/10/2004 10:06:00 PM Date (last access): 10/04/2005 5:09:22 PM Date (last write): 20/02/2003 4:42:34 PM Filesize: 61553 Attributes: archive MD5: E4EFF4ADF1367AA79815A9061E64C0D9 CRC32: A0446F8E Version: 0.1.0.4 {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) DPF name: CLSID name: Shockwave Flash Object description: Macromedia Shockwave Flash Player classification: Legitimate known filename: info link: info source: Patrick M. Kolla Path: C:\WINDOWS\System32\MACROMED\FLASH\ Long name: Flash.ocx Short name: Date (created): 9/06/2004 3:59:26 PM Date (last access): 10/04/2005 4:53:02 PM Date (last write): 9/06/2004 2:59:26 PM Filesize: 939224 Attributes: archive MD5: FC3E17E12C2E31FAC34B416B3DAB829F CRC32: D1CF3A57 Version: 0.7.0.0 --- Process list --- PID: 0 ( 0) [System] PID: 4 ( 0) System PID: 516 (1964) C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Watch.exe PID: 520 (1964) C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe PID: 536 (1964) C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe PID: 544 (1964) C:\Program Files\Winamp\winampa.exe PID: 584 (1964) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe PID: 600 ( 4) \SystemRoot\System32\smss.exe PID: 624 ( 724) C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe PID: 656 ( 600) \??\C:\WINDOWS\system32\csrss.exe PID: 660 ( 724) C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe PID: 680 ( 600) \??\C:\WINDOWS\system32\winlogon.exe PID: 724 ( 680) C:\WINDOWS\system32\services.exe PID: 736 ( 680) C:\WINDOWS\system32\lsass.exe PID: 916 ( 724) C:\WINDOWS\System32\Ati2evxx.exe PID: 936 ( 724) C:\Program Files\Alwil Software\Avast4\ashServ.exe PID: 944 ( 724) C:\WINDOWS\system32\svchost.exe PID: 956 ( 724) C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe PID: 968 (1964) C:\WINDOWS\System32\ctfmon.exe PID: 1004 ( 724) C:\WINDOWS\System32\drivers\CDAC11BA.EXE PID: 1012 (1964) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe PID: 1076 ( 724) C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE PID: 1096 ( 724) C:\WINDOWS\System32\svchost.exe PID: 1136 ( 724) C:\Program Files\Sygate\SPF\smc.exe PID: 1332 ( 724) C:\WINDOWS\System32\svchost.exe PID: 1384 ( 724) C:\WINDOWS\System32\svchost.exe PID: 1480 ( 724) C:\WINDOWS\System32\svchost.exe PID: 1628 ( 724) C:\WINDOWS\System32\wdfmgr.exe PID: 1708 ( 724) C:\WINDOWS\system32\spoolsv.exe PID: 1860 ( 724) C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe PID: 1964 (1932) C:\WINDOWS\Explorer.EXE PID: 2028 ( 724) C:\Program Files\Alwil Software\Avast4\ashWebSv.exe PID: 2096 (1964) C:\Program Files\interMute\SpySubtract\SpySub.exe PID: 2272 (1964) C:\Program Files\Mozilla Firefox\firefox.exe PID: 2572 (1964) C:\Program Files\Spy Emergency 2005\SpyEmergency.exe PID: 2672 ( 944) C:\Program Files\Internet Explorer\iexplore.exe PID: 3232 (1964) C:\Program Files\HijackThis.exe Spybot - Search && Destroy process list report, 10/04/2005 5:14:30 PM --- Browser start & search pages list --- Spybot - Search && Destroy browser pages report, 10/04/2005 5:14:30 PM HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page c:\windows\system32\blank.htm HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page http://www.google.com/ HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@ http://www.google.com/keyword/%s HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page http://www.google.com HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page http://www.google.com/ HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm --- Winsock Layered Service Provider list --- Protocol 0: MSAFD Tcpip [TCP/IP] GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP IP protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD Tcpip [*] Protocol 1: MSAFD Tcpip [UDP/IP] GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP IP protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD Tcpip [*] Protocol 2: MSAFD Tcpip [RAW/IP] GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP IP protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD Tcpip [*] Protocol 3: RSVP UDP Service Provider GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A} Filename: %SystemRoot%\system32\rsvpsp.dll Description: Microsoft Windows NT/2k/XP RVSP DB filename: %SystemRoot%\system32\rsvpsp.dll DB protocol: RSVP * Service Provider Protocol 4: RSVP TCP Service Provider GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A} Filename: %SystemRoot%\system32\rsvpsp.dll Description: Microsoft Windows NT/2k/XP RVSP DB filename: %SystemRoot%\system32\rsvpsp.dll DB protocol: RSVP * Service Provider Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0190AEE1-BD04-4A7F-985D-116C4E932D63}] SEQPACKET 4 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{0190AEE1-BD04-4A7F-985D-116C4E932D63}] DATAGRAM 4 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A6A5236B-F835-490A-8318-37763042433A}] SEQPACKET 3 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{A6A5236B-F835-490A-8318-37763042433A}] DATAGRAM 3 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8D047999-D69A-4CAA-BE72-996CDB952BB2}] SEQPACKET 0 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{8D047999-D69A-4CAA-BE72-996CDB952BB2}] DATAGRAM 0 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{71F051D0-CBD1-4C34-B323-2A50D2679DA1}] SEQPACKET 1 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{71F051D0-CBD1-4C34-B323-2A50D2679DA1}] DATAGRAM 1 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{02E89A12-EA3A-4C5E-8A87-FE1024EF63A5}] SEQPACKET 2 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{02E89A12-EA3A-4C5E-8A87-FE1024EF63A5}] DATAGRAM 2 GUID: {8D5F1830-C273-11CF-95C8-00805F48A192} Filename: %SystemRoot%\system32\mswsock.dll Description: Microsoft Windows NT/2k/XP NetBios protocol DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: MSAFD NetBIOS * Namespace Provider 0: Tcpip GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B} Filename: %SystemRoot%\System32\mswsock.dll Description: Microsoft Windows NT/2k/XP TCP/IP name space provider DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: TCP/IP Namespace Provider 1: NTDS GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC} Filename: %SystemRoot%\System32\winrnr.dll Description: Microsoft Windows NT/2k/XP name space provider DB filename: %SystemRoot%\system32\winrnr.dll DB protocol: NTDS Namespace Provider 2: Network Location Awareness (NLA) Namespace GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83} Filename: %SystemRoot%\System32\mswsock.dll Description: Microsoft Windows NT/2k/XP name space provider DB filename: %SystemRoot%\system32\mswsock.dll DB protocol: NLA-Namespace