System Investigator by OlrikLog Created On: 1334_29-01-2013
SINO Version: 3.1.0.0
Total RAM: 1982 MB |
Free RAM: 1387 MB | Pagefile Size: 3875 MB
C: |
135810 MB out of 190771 MB Free | Local Fixed Disk
E: |
None | Removable Disk
F: |
None | Removable Disk
G: |
None | Removable Disk
H: |
None | CD-ROM Disc
I: |
None | Removable Disk
<<<< System Information >>>>Computer Name: JOHNG-UJRUZGB4N
Username: JohnG
Language Setting: ENU
Windows Directory: C:\WINDOWS
Windows Version: Windows XP Service Pack 3
Windows Mode: Normal
<<<< Tasklist >>>>[System Idle Process] -
Process ID: 0
[System] -
Process ID: 4
[C:\WINDOWS\System32\smss.exe] -
Process ID: 664
[C:\PROGRA~1\AVG\AVG2013\avgrsx.exe] -
Process ID: 696
[C:\Program Files\AVG\AVG2013\avgcsrvx.exe] -
Process ID: 740
[csrss.exe] -
Process ID: 928
[C:\WINDOWS\system32\winlogon.exe] -
Process ID: 952
[C:\WINDOWS\system32\services.exe] -
Process ID: 996
[C:\WINDOWS\system32\lsass.exe] -
Process ID: 1008
[C:\WINDOWS\system32\svchost.exe] -
Process ID: 1180
[svchost.exe] -
Process ID: 1228
[C:\WINDOWS\System32\svchost.exe] -
Process ID: 1324
[C:\WINDOWS\system32\svchost.exe] -
Process ID: 1356
[svchost.exe] -
Process ID: 1500
[svchost.exe] -
Process ID: 1744
[C:\WINDOWS\Explorer.EXE] -
Process ID: 1752
[C:\WINDOWS\system32\spoolsv.exe] -
Process ID: 1908
[svchost.exe] -
Process ID: 272
[C:\Program Files\AVG\AVG2013\avgidsagent.exe] -
Process ID: 328
[C:\Program Files\AVG\AVG2013\avgwdsvc.exe] -
Process ID: 428
[C:\WINDOWS\system32\cisvc.exe] -
Process ID: 460
[C:\WINDOWS\system32\svchost.exe] -
Process ID: 656
[C:\Program Files\Java\jre6\bin\jqs.exe] -
Process ID: 800
[C:\Program Files\Common Files\LightScribe\LSSrvc.exe] -
Process ID: 908
[C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe] -
Process ID: 1588
[C:\Program Files\AVG\AVG2013\avgnsx.exe] -
Process ID: 200
[C:\Program Files\AVG\AVG2013\avgemcx.exe] -
Process ID: 2008
[C:\WINDOWS\System32\svchost.exe] -
Process ID: 540
[C:\WINDOWS\System32\nvsvc32.exe] -
Process ID: 604
[C:\WINDOWS\System32\svchost.exe] -
Process ID: 1284
[C:\WINDOWS\system32\svchost.exe] -
Process ID: 1580
[C:\Program Files\Canon\CAL\CALMAIN.exe] -
Process ID: 2268
[alg.exe] -
Process ID: 2544
[C:\WINDOWS\RTHDCPL.EXE] -
Process ID: 2744
[C:\Program Files\AVG\AVG2013\avgui.exe] -
Process ID: 2752
[C:\WINDOWS\system32\ctfmon.exe] -
Process ID: 2760
[C:\Program Files\Messenger\msmsgs.exe] -
Process ID: 2768
[C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe] -
Process ID: 2852
[C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe] -
Process ID: 3636
[C:\WINDOWS\system32\cidaemon.exe] -
Process ID: 3176
[C:\WINDOWS\system32\wuauclt.exe] -
Process ID: 2556
[C:\Program Files\Internet Explorer\IEXPLORE.EXE] -
Process ID: 3072
[C:\Program Files\Internet Explorer\IEXPLORE.EXE] -
Process ID: 3336
[C:\Program Files\Internet Explorer\IEXPLORE.EXE] -
Process ID: 932
[C:\DOCUME~1\JohnG\LOCALS~1\Temp\SINO\SINO.exe] -
Process ID: 2652
[wmiprvse.exe] -
Process ID: 2104
<<<< Startup Items >>>>[Adobe Gamma Loader.lnk] -
<Common Startup> - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
[HP Digital Imaging Monitor.lnk] -
<Common Startup> - C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
[Microsoft Office.lnk] -
<Common Startup> - C:\Program Files\Microsoft Office\Office10\OSA.EXE
[AvgUninstallURL] -
<HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce> - cmd.exe /c start
http://www.avg.com/w...&"ver=10.0.1424 [QuickTime Task] -
<HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\QuickTime\qttask.exe" -atboottime
[NvCplDaemon] -
<HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
[nwiz] -
<HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - nwiz.exe /install
[NvMediaCenter] -
<HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
[RTHDCPL] -
<HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - RTHDCPL.EXE
[AVG_UI] -
<HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
[ctfmon.exe] -
<HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\ctfmon.exe
[MSMSGS] -
<HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Messenger\msmsgs.exe" /background
<<<< MS Services >>>>Application Layer Gateway Service (ALG) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\alg.exe
Windows Audio (AudioSrv) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Background Intelligent Transfer Service (BITS) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Indexing Service (CiSvc) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\cisvc.exe
Cryptographic Services (CryptSvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
DCOM Server Process Launcher (DcomLaunch) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost -k DcomLaunch
DHCP Client (Dhcp) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Logical Disk Manager (dmserver) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
DNS Client (Dnscache) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k NetworkService
Error Reporting Service (ERSvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Event Log (Eventlog) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\services.exe
COM+ Event System (EventSystem) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Help and Support (helpsvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Server (lanmanserver) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Workstation (lanmanworkstation) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
TCP/IP NetBIOS Helper (LmHosts) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Network Connections (Netman) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Network Location Awareness (NLA) (Nla) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Plug and Play (PlugPlay) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\services.exe
Pml Driver HPZ12 (Pml Driver HPZ12) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k HPZ12
IPSEC Services (PolicyAgent) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Protected Storage (ProtectedStorage) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Remote Access Connection Manager (RasMan) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Registry (RemoteRegistry) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Remote Procedure Call (RPC) (RpcSs) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost -k rpcss
Security Accounts Manager (SamSs) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Task Scheduler (Schedule) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Secondary Logon (seclogon) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
System Event Notification (SENS) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Firewall/Internet Connection Sharing (ICS) (SharedAccess) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Shell Hardware Detection (ShellHWDetection) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Print Spooler (Spooler) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\spoolsv.exe
System Restore Service (srservice) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
SSDP Discovery Service (SSDPSRV) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Image Acquisition (WIA) (stisvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k imgsvc
Telephony (TapiSrv) -
Running [Manual | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Terminal Services (TermService) -
Running [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost -k DComLaunch
Themes (Themes) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Distributed Link Tracking Client (TrkWks) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Time (W32Time) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
WebClient (WebClient) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Management Instrumentation (winmgmt) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Security Center (wscsvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Automatic Updates (wuauserv) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Driver Foundation - User-mode Driver Framework (WudfSvc) -
Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
Wireless Zero Configuration (WZCSVC) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Alerter (Alerter) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Application Management (AppMgmt) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
ASP.NET State Service (aspnet_state) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\aspnet_state.exe
Computer Browser (Browser) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
ClipBook (ClipSrv) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\clipsrv.exe
.NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
COM+ System Application (COMSysApp) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Logical Disk Manager Administrative Service (dmadmin) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\dmadmin.exe /com
Wired AutoConfig (Dot3svc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k dot3svc
Extensible Authentication Protocol Service (EapHost) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k eapsvcs
Fast User Switching Compatibility (FastUserSwitchingCompatibility) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
Human Interface Device Access (HidServ) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Health Key and Certificate Management Service (hkmsvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
HTTP SSL (HTTPFilter) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k HTTPFilter
InstallDriver Table Manager (IDriverT) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"
Windows CardSpace (idsvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
IMAPI CD-Burning COM Service (ImapiService) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\imapi.exe
Messenger (Messenger) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
NetMeeting Remote Desktop Sharing (mnmsrvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\mnmsrvc.exe
Distributed Transaction Coordinator (MSDTC) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\msdtc.exe
Windows Installer (MSIServer) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\msiexec.exe /V
Network Access Protection Agent (napagent) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Network DDE (NetDDE) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\netdde.exe
Network DDE DSDM (NetDDEdsdm) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\netdde.exe
Net Logon (Netlogon) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Net.Tcp Port Sharing Service (NetTcpPortSharing) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - c:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe
NT LM Security Support Provider (NtLmSsp) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Removable Storage (NtmsSvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Office Source Engine (ose) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Remote Access Auto Connection Manager (RasAuto) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Desktop Help Session Manager (RDSessMgr) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\sessmgr.exe
Routing and Remote Access (RemoteAccess) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Procedure Call (RPC) Locator (RpcLocator) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\locator.exe
QoS RSVP (RSVP) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\rsvp.exe
Smart Card (SCardSvr) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\SCardSvr.exe
MS Software Shadow Copy Provider (SwPrv) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\dllhost.exe /Processid:{9FD2E91E-DC99-40E0-A24D-06A33773D6D1}
Performance Logs and Alerts (SysmonLog) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\smlogsvc.exe
Telnet (TlntSvr) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\tlntsvr.exe
Universal Plug and Play Device Host (upnphost) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Uninterruptible Power Supply (UPS) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\ups.exe
Volume Shadow Copy (VSS) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\vssvc.exe
Portable Media Serial Number Service (WmdmPmSN) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Management Instrumentation Driver Extensions (Wmi) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
WMI Performance Adapter (WmiApSrv) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\wbem\wmiapsrv.exe
Windows Media Player Network Sharing Service (WMPNetworkSvc) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Windows Media Player\WMPNetwk.exe"
Network Provisioning Service (xmlprov) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
<<<< Non-MS Services >>>>AVGIDSAgent (AVGIDSAgent) -
Running [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\AVG\AVG2013\avgidsagent.exe"
AVG WatchDog (avgwd) -
Running [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\AVG\AVG2013\avgwdsvc.exe"
Canon Camera Access Library 8 (CCALib8) -
Running [Auto | Stoppable | Not_Pausable] - C:\Program Files\Canon\CAL\CALMAIN.exe
hpqcxs08 (hpqcxs08) -
Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
HP CUE DeviceDiscovery Service (hpqddsvc) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
Java Quick Starter (JavaQuickStarterService) -
Running [Auto | Stoppable | Pausable] - "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
LightScribeService Direct Disc Labeling Service (LightScribeService) -
Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Common Files\LightScribe\LSSrvc.exe"
MBAMScheduler (MBAMScheduler) -
Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe"
Net Driver HPZ12 (Net Driver HPZ12) -
Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k HPZ12
NVIDIA Display Driver Service (NVSvc) -
Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\nvsvc32.exe
Microsoft .NET Framework NGEN v4.0.30319_X86 (clr_optimization_v4.0.30319_32) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
Google Update Service (gupdate) (gupdate) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc
Google Update Service (gupdatem) (gupdatem) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc
MBAMService (MBAMService) -
Stopped [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"
PuranDefrag (PuranDefrag) -
Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\WINDOWS\system32\PuranDefragS.exe"
Windows Presentation Foundation Font Cache 4.0.0.0 (WPFFontCache_v0400) -
Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
<<<< Boot.ini >>>>[boot loader]
timeout=5
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
<<<< Last 5 Application Errors or Warnings >>>>Computer Name: JOHNG-UJRUZGB4N | ID: 1015 | Source: MsiInstaller | Type: Warning | Date: 28-1-13 22:53:18 | Log: Application Message: Failed to connect to server. Error: 0x80070422
Computer Name: JOHNG-UJRUZGB4N | ID: 1001 | Source: MsiInstaller | Type: Warning | Date: 28-1-13 22:53:18 | Log: Application Message: Detection of product '{978C25EE-5777-46E4-8988-732C297CBDBD}', feature 'statusexe' failed during request for component '{1A4D0FBA-CD92-4C4E-8AC7-87C0309976C3}'
Computer Name: JOHNG-UJRUZGB4N | ID: 1004 | Source: MsiInstaller | Type: Warning | Date: 28-1-13 22:53:18 | Log: Application Message: Detection of product '{978C25EE-5777-46E4-8988-732C297CBDBD}', feature 'statusexe', component '{3B694B1F-4410-11D5-A54A-0090278A1BB8}' failed. The resource 'C:\WINDOWS\system32\gdiplus.dll' does not exist.
Computer Name: JOHNG-UJRUZGB4N | ID: 1015 | Source: MsiInstaller | Type: Warning | Date: 28-1-13 22:53:18 | Log: Application Message: Failed to connect to server. Error: 0x80070422
Computer Name: JOHNG-UJRUZGB4N | ID: 1001 | Source: MsiInstaller | Type: Warning | Date: 28-1-13 22:53:18 | Log: Application Message: Detection of product '{978C25EE-5777-46E4-8988-732C297CBDBD}', feature 'statusexe' failed during request for component '{1A4D0FBA-CD92-4C4E-8AC7-87C0309976C3}'
<<<< Last 5 System Errors or Warnings >>>>Computer Name: JOHNG-UJRUZGB4N | ID: 10005 | Source: DCOM | Type: Error | Date: 28-1-13 22:53:19 | Log: System Message: DCOM got error "%1058" attempting to start the service MSIServer with arguments ""
in order to run the server:
{000C101C-0000-0000-C000-000000000046}
Computer Name: JOHNG-UJRUZGB4N | ID: 10005 | Source: DCOM | Type: Error | Date: 28-1-13 22:53:19 | Log: System Message: DCOM got error "%1058" attempting to start the service MSIServer with arguments ""
in order to run the server:
{000C101C-0000-0000-C000-000000000046}
Computer Name: JOHNG-UJRUZGB4N | ID: 10005 | Source: DCOM | Type: Error | Date: 28-1-13 22:53:19 | Log: System Message: DCOM got error "%1058" attempting to start the service MSIServer with arguments ""
in order to run the server:
{000C101C-0000-0000-C000-000000000046}
Computer Name: JOHNG-UJRUZGB4N | ID: 10005 | Source: DCOM | Type: Error | Date: 28-1-13 22:53:19 | Log: System Message: DCOM got error "%1058" attempting to start the service MSIServer with arguments ""
in order to run the server:
{000C101C-0000-0000-C000-000000000046}
Computer Name: JOHNG-UJRUZGB4N | ID: 10005 | Source: DCOM | Type: Error | Date: 28-1-13 22:53:19 | Log: System Message: DCOM got error "%1058" attempting to start the service MSIServer with arguments ""
in order to run the server:
{000C101C-0000-0000-C000-000000000046}
<<<< Special Events >>>>There were no special events found
<<<< Ipconfig >>>>Windows IP Configuration
Host Name . . . . . . . . . . . . : johng-ujruzgb4n
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Unknown
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Local Area Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : NVIDIA nForce Networking Controller
Physical Address. . . . . . . . . : 00-18-F3-41-F2-4D
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.5.107
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.5.1
DHCP Server . . . . . . . . . . . : 192.168.5.1
DNS Servers . . . . . . . . . . . : 192.168.1.1
Lease Obtained. . . . . . . . . . : Tuesday, January 29, 2013 1:06:10 PM
Lease Expires . . . . . . . . . . : Wednesday, January 30, 2013 1:06:10 PM
<<<< Pinging >>>>OpenDNS Domain TestPinging to www.opendns.com [67.215.92.210]:
Response - 94ms
Response - 92ms
Response - 94ms
Response - 93msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 92ms - Maximum = 94ms
OpenDNS IP TestPinging to 208.69.38.150 [208.69.38.150]:
Response - 108ms
Response - 94ms
Response - 93ms
Response - 94msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 93ms - Maximum = 108ms
Kaspersky Domain TestPinging to www.kaspersky.com [195.27.252.18]:
Response - 172ms
Response - 155ms
Response - 157ms
Response - 155msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 155ms - Maximum = 172ms
Kaspersky IP TestPinging to 195.27.181.10 [195.27.181.10]:
Response - 156ms
Response - 155ms
Response - 157ms
Response - 172msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 155ms - Maximum = 172ms
YouTube Domain TestPinging to www.youtube.com [173.194.37.142]:
Response - 46ms
Response - 46ms
Response - 47ms
Response - 46msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 46ms - Maximum = 47ms
YouTube IP TestPinging to 66.102.9.136 [66.102.9.136]:
Response - None
Response - None
Response - None
Response - NonePackets: Sent = 4, Received = 0, Lost = 4
Minimum = 0ms - Maximum = 0ms
localhost TestPinging to 127.0.0.1 [127.0.0.1]:
Response - 0ms
Response - 0ms
Response - 0ms
Response - 0msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 0ms - Maximum = 0ms
<<<< Netstat >>>>Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1228
c:\windows\system32\WS2_32.dll
C:\WINDOWS\system32\RPCRT4.dll
c:\windows\system32\rpcss.dll
C:\WINDOWS\system32\svchost.exe
-- unknown component(s) --
[svchost.exe]
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
[System]
TCP 127.0.0.1:1025 0.0.0.0:0 LISTENING 2544
[alg.exe]
TCP 127.0.0.1:5152 0.0.0.0:0 LISTENING 800
[jqs.exe]
TCP 192.168.5.107:139 0.0.0.0:0 LISTENING 4
[System]
TCP 127.0.0.1:5152 127.0.0.1:1072 CLOSE_WAIT 800
[jqs.exe]
TCP 192.168.5.107:1104 69.163.234.194:80 TIME_WAIT 0
UDP 0.0.0.0:500 *:* 1008
[lsass.exe]
UDP 0.0.0.0:4500 *:* 1008
[lsass.exe]
UDP 0.0.0.0:445 *:* 4
[System]
UDP 127.0.0.1:1073 *:* 932
[IEXPLORE.EXE]
UDP 127.0.0.1:1056 *:* 3336
[IEXPLORE.EXE]
UDP 127.0.0.1:1900 *:* 1744
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 127.0.0.1:123 *:* 1324
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 192.168.5.107:138 *:* 4
[System]
UDP 192.168.5.107:137 *:* 4
[System]
UDP 192.168.5.107:1900 *:* 1744
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\ADVAPI32.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 192.168.5.107:123 *:* 1324
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
<<<< Routing Table >>>>===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 18 f3 41 f2 4d ...... NVIDIA nForce Networking Controller - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.5.1 192.168.5.107 20
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
192.168.5.0 255.255.255.0 192.168.5.107 192.168.5.107 20
192.168.5.107 255.255.255.255 127.0.0.1 127.0.0.1 20
192.168.5.255 255.255.255.255 192.168.5.107 192.168.5.107 20
224.0.0.0 240.0.0.0 192.168.5.107 192.168.5.107 20
255.255.255.255 255.255.255.255 192.168.5.107 192.168.5.107 1
Default Gateway: 192.168.5.1
===========================================================================
Persistent Routes:
None
Route Table
<<<< Hosts File >>>>The HOSTS file is 98 Bytes in size.
There were 0 lines which refer to an external IP address.
<<<< Active Shares >>>>Share: IPC$ -
Path: Share: ADMIN$ -
Path: C:\WINDOWSShare: C$ -
Path: C:\------ End of File ------