System Investigator by Olrik
Log Created On: 1551_18-02-2013
SINO Version: 3.1.0.0
Total RAM: 893 MB | Free RAM: 239 MB | Pagefile Size: 2164 MB
C: | 3924 MB out of 76308 MB Free | Local Fixed Disk
D: | None | CD-ROM Disc
Z: | None | Network Connection
<<<< System Information >>>>
Computer Name: JERRY-1A1033F2B
Username: Jerry
Language Setting: ENU
Windows Directory: C:\WINDOWS
Windows Version: Windows XP Service Pack 3
Windows Mode: Normal
<<<< Tasklist >>>>
[System Idle Process] - Process ID: 0
[System] - Process ID: 4
[C:\WINDOWS\System32\smss.exe] - Process ID: 1156
[C:\PROGRA~1\AVG\AVG2013\avgrsx.exe] - Process ID: 1220
[C:\Program Files\AVG\AVG2013\avgcsrvx.exe] - Process ID: 1260
[csrss.exe] - Process ID: 1448
[C:\WINDOWS\system32\winlogon.exe] - Process ID: 1476
[C:\WINDOWS\system32\services.exe] - Process ID: 1520
[C:\WINDOWS\system32\lsass.exe] - Process ID: 1532
[C:\WINDOWS\system32\Ati2evxx.exe] - Process ID: 1696
[C:\WINDOWS\system32\svchost.exe] - Process ID: 1716
[svchost.exe] - Process ID: 1788
[C:\WINDOWS\System32\svchost.exe] - Process ID: 1832
[C:\WINDOWS\system32\svchost.exe] - Process ID: 1872
[svchost.exe] - Process ID: 1996
[C:\WINDOWS\system32\Ati2evxx.exe] - Process ID: 192
[svchost.exe] - Process ID: 280
[C:\WINDOWS\System32\WLTRYSVC.EXE] - Process ID: 536
[C:\WINDOWS\System32\bcmwltry.exe] - Process ID: 548
[C:\WINDOWS\system32\spoolsv.exe] - Process ID: 604
[svchost.exe] - Process ID: 728
[C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe] - Process ID: 872
[C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe] - Process ID: 884
[C:\Program Files\AVG\AVG2013\avgidsagent.exe] - Process ID: 916
[C:\Program Files\AVG\AVG2013\avgwdsvc.exe] - Process ID: 952
[C:\Program Files\Bonjour\mDNSResponder.exe] - Process ID: 980
[C:\Program Files\Motorola Media Link\Lite\NServiceEntry.exe] - Process ID: 1168
[C:\WINDOWS\system32\svchost.exe] - Process ID: 1428
[C:\WINDOWS\system32\svchost.exe] - Process ID: 1452
[C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe] - Process ID: 1852
[C:\Program Files\Java\jre6\bin\jqs.exe] - Process ID: 1972
[C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe] - Process ID: 2020
[C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe] - Process ID: 2148
[C:\Program Files\AVG\AVG2013\avgnsx.exe] - Process ID: 2172
[C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE] - Process ID: 2272
[C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe] - Process ID: 2344
[C:\WINDOWS\System32\svchost.exe] - Process ID: 2400
[C:\WINDOWS\System32\svchost.exe] - Process ID: 2424
[C:\WINDOWS\Explorer.EXE] - Process ID: 496
[C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe] - Process ID: 708
[C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperAgent.exe] - Process ID: 3804
[svchost.exe] - Process ID: 3392
[C:\WINDOWS\system32\svchost.exe] - Process ID: 800
[C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe] - Process ID: 3132
[C:\WINDOWS\ehome\ehtray.exe] - Process ID: 3772
[C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe] - Process ID: 684
[C:\WINDOWS\stsystra.exe] - Process ID: 2100
[C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE] - Process ID: 2720
[C:\WINDOWS\system32\WLTRAY.exe] - Process ID: 2872
[C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe] - Process ID: 3236
[C:\Program Files\Common Files\AOL\1246745595\ee\AOLSoftware.exe] - Process ID: 3364
[C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe] - Process ID: 3824
[C:\Program Files\HP\HP Software Update\HPWuSchd2.exe] - Process ID: 2848
[C:\Program Files\Wireless-G Portable USB Adapter Wireless Network Monitor\InfoMyCa.exe] - Process ID: 2956
[C:\WINDOWS\system32\LVCOMSX.EXE] - Process ID: 3184
[C:\Program Files\Citrix\ICA Client\concentr.exe] - Process ID: 3716
[C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe] - Process ID: 424
[C:\Program Files\Citrix\ICA Client\wfcrun32.exe] - Process ID: 3872
[C:\Program Files\AVG\AVG2013\avgui.exe] - Process ID: 3576
[C:\Program Files\Common Files\Java\Java Update\jusched.exe] - Process ID: 2348
[C:\Program Files\AVG SafeGuard toolbar\vprot.exe] - Process ID: 3084
[C:\Program Files\Spotify\Data\SpotifyWebHelper.exe] - Process ID: 2976
[C:\Program Files\Messenger\msmsgs.exe] - Process ID: 3068
[C:\Program Files\Hawking\HWU8DD\HWU8DD.exe] - Process ID: 3960
[C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe] - Process ID: 2432
[C:\WINDOWS\eHome\ehmsas.exe] - Process ID: 2708
[alg.exe] - Process ID: 4060
[C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe] - Process ID: 3532
[C:\WINDOWS\system32\svchost.exe] - Process ID: 3108
[C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe] - Process ID: 5764
[C:\Program Files\HP\Digital Imaging\bin\hpqbam08.exe] - Process ID: 4712
[C:\Program Files\HP\Digital Imaging\bin\hpqgpc01.exe] - Process ID: 2860
[C:\Program Files\ATI Technologies\ATI.ACE\cli.exe] - Process ID: 460
[C:\WINDOWS\system32\wuauclt.exe] - Process ID: 5716
[C:\Program Files\Mozilla Firefox\firefox.exe] - Process ID: 2928
[C:\Program Files\WinZip\WINZIP32.EXE] - Process ID: 656
[C:\DOCUME~1\Jerry\LOCALS~1\Temp\SINO\SINO.exe] - Process ID: 1936
[wmiprvse.exe] - Process ID: 2684
<<<< Startup Items >>>>
[Hawking Wireless Utility.lnk] - <Common Startup> - C:\Program Files\Hawking\HWU8DD\HWU8DD.exe
[HP Digital Imaging Monitor.lnk] - <Common Startup> - C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
[ehTray] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\ehome\ehtray.exe
[ATICCC] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
[SigmatelSysTrayApp] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - stsystra.exe
[Broadcom Wireless Manager UI] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\WLTRAY.exe
[ISUSPM Startup] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
[ISUSScheduler] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
[HostManager] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Common Files\AOL\1246745595\ee\AOLSoftware.exe
[RoxWatchTray] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
[hpqSRMon] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
[WUSB54GPv4] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Wireless-G Portable USB Adapter Wireless Network Monitor\InvokeSvc3.exe
[HP Software Update] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
[LVCOMSX] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\WINDOWS\system32\LVCOMSX.EXE
[ConnectionCenter] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Citrix\ICA Client\concentr.exe" /startup
[AppleSyncNotifier] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
[GrooveMonitor] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
[Adobe Reader Speed Launcher] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
[Adobe ARM] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
[AVG_UI] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
[SunJavaUpdateSched] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
[APSDaemon] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
[QuickTime Task] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\QuickTime\QTTask.exe" -atboottime
[vProt] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\AVG SafeGuard toolbar\vprot.exe"
[DWQueuedReporting] - <HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t
[MotoCast] - <HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Motorola Mobility\MotoCast\MotoLauncher.lnk"
[Spotify Web Helper] - <HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Spotify\Data\SpotifyWebHelper.exe"
[replay_telecorder_skype] - <HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run> - C:\Program Files\Replay Telecorder for Skype\replay_telecorder_skype.exe /start_context sys_auto
[MSMSGS] - <HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run> - "C:\Program Files\Messenger\msmsgs.exe" /background
<<<< MS Services >>>>
Application Layer Gateway Service (ALG) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\alg.exe
Ati HotKey Poller (Ati HotKey Poller) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\Ati2evxx.exe
Windows Audio (AudioSrv) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
BITS (BITS) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Computer Browser (Browser) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
CryptSvc (CryptSvc) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
DCOM Server Process Launcher (DcomLaunch) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k DcomLaunch
DHCP Client (Dhcp) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Logical Disk Manager (dmserver) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
DNS Client (Dnscache) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k NetworkService
Error Reporting Service (ERSvc) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Event Log (Eventlog) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\services.exe
COM+ Event System (EventSystem) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Fast User Switching Compatibility (FastUserSwitchingCompatibility) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Help and Support (helpsvc) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
HID Input Service (HidServ) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Server (lanmanserver) - Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Workstation (lanmanworkstation) - Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
TCP/IP NetBIOS Helper (LmHosts) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Machine Debug Manager (MDM) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE"
Network Connections (Netman) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Network Location Awareness (NLA) (Nla) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Plug and Play (PlugPlay) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\services.exe
Pml Driver HPZ12 (Pml Driver HPZ12) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k HPZ12
IPSEC Services (PolicyAgent) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Protected Storage (ProtectedStorage) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Remote Access Connection Manager (RasMan) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Registry (RemoteRegistry) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Remote Procedure Call (RPC) (RpcSs) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k rpcss
Security Accounts Manager (SamSs) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Task Scheduler (Schedule) - Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Secondary Logon (seclogon) - Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
System Event Notification (SENS) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
SharedAccess (SharedAccess) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Shell Hardware Detection (ShellHWDetection) - Running [Auto | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Print Spooler (Spooler) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\spoolsv.exe
System Restore Service (srservice) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
SSDP Discovery Service (SSDPSRV) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Image Acquisition (WIA) (stisvc) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k imgsvc
Telephony (TapiSrv) - Running [Manual | Stoppable | Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Terminal Services (TermService) - Running [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k DComLaunch
Themes (Themes) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Distributed Link Tracking Client (TrkWks) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Time (W32Time) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
WebClient (WebClient) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Windows Management Instrumentation (winmgmt) - Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
wscsvc (wscsvc) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Automatic Updates (wuauserv) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Windows Driver Foundation - User-mode Driver Framework (WudfSvc) - Running [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
Alerter (Alerter) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Application Management (AppMgmt) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
ASP.NET State Service (aspnet_state) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe
Indexing Service (CiSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\cisvc.exe
ClipBook (ClipSrv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\clipsrv.exe
.NET Runtime Optimization Service v2.0.50727_X86 (clr_optimization_v2.0.50727_32) - Stopped [Manual | Not_Stoppable | Not_Pausable] - c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe
COM+ System Application (COMSysApp) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235}
Logical Disk Manager Administrative Service (dmadmin) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\dmadmin.exe /com
Wired AutoConfig (Dot3svc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k dot3svc
Extensible Authentication Protocol Service (EapHost) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k eapsvcs
Windows Presentation Foundation Font Cache 3.0.0.0 (FontCache3.0.0.0) - Stopped [Manual | Not_Stoppable | Not_Pausable] - c:\WINDOWS\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe
Health Key and Certificate Management Service (hkmsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
HTTP SSL (HTTPFilter) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k HTTPFilter
InstallDriver Table Manager (IDriverT) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe"
Windows CardSpace (idsvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe"
IMAPI CD-Burning COM Service (ImapiService) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\imapi.exe
Messenger (Messenger) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
MHN (MHN) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Microsoft Office Groove Audit Service (Microsoft Office Groove Audit Service) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Microsoft Office\Office12\GrooveAuditService.exe"
NetMeeting Remote Desktop Sharing (mnmsrvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\mnmsrvc.exe
Distributed Transaction Coordinator (MSDTC) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\msdtc.exe
Windows Installer (MSIServer) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\msiexec.exe /V
Network Access Protection Agent (napagent) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Network DDE (NetDDE) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\netdde.exe
Network DDE DSDM (NetDDEdsdm) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\netdde.exe
Net Logon (Netlogon) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Net.Tcp Port Sharing Service (NetTcpPortSharing) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "c:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe"
NT LM Security Support Provider (NtLmSsp) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\lsass.exe
Removable Storage (NtmsSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Microsoft Office Diagnostics Service (odserv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Microsoft Shared\OFFICE12\ODSERV.EXE"
Office Source Engine (ose) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE"
Remote Access Auto Connection Manager (RasAuto) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Desktop Help Session Manager (RDSessMgr) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\sessmgr.exe
Routing and Remote Access (RemoteAccess) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k netsvcs
Remote Procedure Call (RPC) Locator (RpcLocator) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\locator.exe
QoS RSVP (RSVP) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\rsvp.exe
Smart Card (SCardSvr) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\SCardSvr.exe
MS Software Shadow Copy Provider (SwPrv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\dllhost.exe /Processid:{B36A6832-91C4-41CD-A051-17B53819F660}
Performance Logs and Alerts (SysmonLog) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\smlogsvc.exe
Telnet (TlntSvr) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\tlntsvr.exe
Universal Plug and Play Device Host (upnphost) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k LocalService
Uninterruptible Power Supply (UPS) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\ups.exe
Volume Shadow Copy (VSS) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\vssvc.exe
Portable Media Serial Number Service (WmdmPmSN) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Windows Management Instrumentation Driver Extensions (Wmi) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
WMI Performance Adapter (WmiApSrv) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\wbem\wmiapsrv.exe
Windows Media Player Network Sharing Service (WMPNetworkSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Windows Media Player\WMPNetwk.exe"
Wireless Zero Configuration (WZCSVC) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
Network Provisioning Service (xmlprov) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k netsvcs
<<<< Non-MS Services >>>>
AOL Connectivity Service (AOL ACS) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exe"
Apple Mobile Device (Apple Mobile Device) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe"
AVGIDSAgent (AVGIDSAgent) - Running [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\AVG\AVG2013\avgidsagent.exe"
AVG WatchDog (avgwd) - Running [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\AVG\AVG2013\avgwdsvc.exe"
Bonjour Service (Bonjour Service) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Bonjour\mDNSResponder.exe"
DeviceMonitorService (DeviceMonitorService) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Motorola Media Link\Lite\NServiceEntry.exe"
hpqcxs08 (hpqcxs08) - Running [Manual | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
HP CUE DeviceDiscovery Service (hpqddsvc) - Running [Auto | Stoppable | Pausable] - C:\WINDOWS\system32\svchost.exe -k hpdevmgmt
HP Network Devices Support (HPSLPSVC) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\system32\svchost.exe -k HPService
Intuit Update Service v4 (IntuitUpdateServiceV4) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Intuit\Update Service v4\IntuitUpdateService.exe"
Java Quick Starter (JavaQuickStarterService) - Running [Auto | Stoppable | Pausable] - "C:\Program Files\Java\jre6\bin\jqs.exe" -service -config "C:\Program Files\Java\jre6\lib\deploy\jqs\jqs.conf"
MBAMScheduler (MBAMScheduler) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe"
MBAMService (MBAMService) - Running [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe"
Motorola Device Manager Service (Motorola Device Manager) - Running [Auto | Stoppable | Not_Pausable] - C:\Program Files\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe
Net Driver HPZ12 (Net Driver HPZ12) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\svchost.exe -k HPZ12
vToolbarUpdater14.2.0 (vToolbarUpdater14.2.0) - Running [Auto | Stoppable | Not_Pausable] - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe
Dell Wireless WLAN Tray Service (wltrysvc) - Running [Auto | Stoppable | Not_Pausable] - C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe
Yahoo! Updater (YahooAUService) - Running [Auto | Stoppable | Not_Pausable] - "C:\Program Files\Yahoo!\SoftwareUpdate\YahooAUService.exe"
Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\system32\Macromed\Flash\FlashPlayerUpdateService.exe
AVG Security Toolbar Service (AVG Security Toolbar Service) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
Microsoft .NET Framework NGEN v4.0.30319_X86 (clr_optimization_v4.0.30319_32) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe
iPod Service (iPod Service) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\iPod\bin\iPodService.exe"
Mozilla Maintenance Service (MozillaMaintenance) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
Roxio UPnP Renderer 9 (Roxio UPnP Renderer 9) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe"
Roxio Upnp Server 9 (Roxio Upnp Server 9) - Stopped [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe"
LiveShare P2P Server 9 (RoxLiveShare9) - Stopped [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe"
RoxMediaDB9 (RoxMediaDB9) - Stopped [Manual | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe"
Roxio Hard Drive Watcher 9 (RoxWatch9) - Stopped [Auto | Not_Stoppable | Not_Pausable] - "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe"
vToolbarUpdater13.2.0 (vToolbarUpdater13.2.0) - Stopped [Auto | Not_Stoppable | Not_Pausable] - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\13.2.0\ToolbarUpdater.exe
Windows Presentation Foundation Font Cache 4.0.0.0 (WPFFontCache_v0400) - Stopped [Manual | Not_Stoppable | Not_Pausable] - C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
WUSB54GPv4SVC (WUSB54GPv4SVC) - Stopped [Disabled | Not_Stoppable | Not_Pausable] - "C:\Program Files\Wireless-G Portable USB Adapter Wireless Network Monitor\WLService.exe" "WUSB54GPv4.exe"
<<<< Boot.ini >>>>
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
C:\CMDCONS\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows XP Media Center Edition" /noexecute=optin /fastdetect
<<<< Last 5 Application Errors or Warnings >>>>
Computer Name: JERRY-1A1033F2B | ID: 11500 | Source: MsiInstaller | Type: Error | Date: 18-2-13 15:17:25 | Log: Application
Message: Product: Java 6 Update 39 -- Error 1500.Another installation is in progress. You must complete that installation before continuing this one.
Computer Name: JERRY-1A1033F2B | ID: 5000 | Source: NativeWrapper | Type: Error | Date: 18-2-13 15:16:14 | Log: Application
Message: <The description for Event ID ( 5000 ) in Source ( u'NativeWrapper' ) could not be found. It contains the following insertion string(s):u'visualstudio7x80update, msiexec.exe, 1.0.1716.5060, kb2742597, 1033, 643, f, install, x86, 5.1.2600.2.3.0.256, 0'.>
Computer Name: JERRY-1A1033F2B | [color=#CC6600]ID: 1023[/color] | [color=#CC6600]Source: MsiInstaller[/color] | Type: Error | Date: 18-2-13 15:16:12 | Log: Application
Message: Product: Microsoft .NET Framework 1.1 - Update '{6C298884-91FD-408C-9D90-5A59D2C29FD1}' could not be installed. Error code 1603. Additional information is available in the log file C:\DOCUME~1\Jerry\LOCALS~1\Temp\NDP1.1sp1-KB2742597-X86\NDP1.1sp1-KB2742597-X86-msi.0.log.
[color=#0000FF]Computer Name: JERRY-1A1033F2B[/color] | [color=#CC6600]ID: 11706[/color] | [color=#CC6600]Source: MsiInstaller[/color] | Type: Error | Date: 18-2-13 15:16:10 | Log: Application
Message: Product: Microsoft .NET Framework 1.1 -- Error 1706.No valid source could be found for product Microsoft .NET Framework 1.1. The Windows installer cannot continue.
[color=#0000FF]Computer Name: JERRY-1A1033F2B[/color] | [color=#CC6600]ID: 1103[/color] | [color=#CC6600]Source: .NET Runtime Optimization Service[/color] | Type: Error | Date: 18-2-13 14:53:49 | Log: Application
Message: .NET Runtime Optimization Service (clr_optimization_v2.0.50727_32) - Tried to start a service that wasn't the latest version of CLR Optimization service. Will shutdown
[color=#FF0000]<<<< Last 5 System Errors or Warnings >>>>[/color]
[color=#0000FF]Computer Name: JERRY-1A1033F2B[/color] | [color=#CC6600]ID: 20[/color] | [color=#CC6600]Source: Windows Update Agent[/color] | Type: Error | Date: 18-2-13 15:16:23 | Log: System
Message: Installation Failure: Windows failed to install the following update with error 0x80070643: Security Update for Microsoft .NET Framework 1.1 SP1 on Windows XP, Windows Vista, and Windows Server 2008 x86 (KB2742597).
[color=#0000FF]Computer Name: JERRY-1A1033F2B[/color] | [color=#CC6600]ID: 7000[/color] | [color=#CC6600]Source: Service Control Manager[/color] | Type: Error | Date: 18-2-13 14:53:40 | Log: System
Message: The vToolbarUpdater13.2.0 service failed to start due to the following error:
%%2
[color=#0000FF]Computer Name: JERRY-1A1033F2B[/color] | [color=#CC6600]ID: 7006[/color] | [color=#CC6600]Source: Service Control Manager[/color] | Type: Error | Date: 18-2-13 14:53:40 | Log: System
Message: The ScRegSetValueExW call failed for FailureActions with the following error:
%%5
[color=#0000FF]Computer Name: JERRY-1A1033F2B[/color] | [color=#CC6600]ID: 7006[/color] | [color=#CC6600]Source: Service Control Manager[/color] | Type: Error | Date: 18-2-13 14:53:40 | Log: System
Message: The ScRegSetValueExW call failed for FailureActions with the following error:
%%5
[color=#0000FF]Computer Name: JERRY-1A1033F2B[/color] | [color=#CC6600]ID: 7011[/color] | [color=#CC6600]Source: Service Control Manager[/color] | Type: Error | Date: 18-2-13 14:28:16 | Log: System
Message: Timeout (30000 milliseconds) waiting for a transaction response from the SENS service.
[color=#FF0000]<<<< Special Events >>>>[/color]
There were no special events found
[color=#FF0000]<<<< Ipconfig >>>>[/color]
Windows IP Configuration
Host Name . . . . . . . . . . . . : jerry-1a1033f2b
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Description . . . . . . . . . . . : Broadcom 440x 10/100 Integrated Controller
Physical Address. . . . . . . . . : 00-15-C5-C3-A0-51
Ethernet adapter Wireless Network Connection:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Dell Wireless 1490 Dual Band WLAN Mini-Card
Physical Address. . . . . . . . . : 00-16-CF-C2-74-A6
Dhcp Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IP Address. . . . . . . . . . . . : 192.168.0.5
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Default Gateway . . . . . . . . . : 192.168.0.1
DHCP Server . . . . . . . . . . . : 192.168.0.1
DNS Servers . . . . . . . . . . . : 192.168.1.254
Lease Obtained. . . . . . . . . . : Monday, February 18, 2013 2:56:53 PM
Lease Expires . . . . . . . . . . : Tuesday, February 19, 2013 2:56:53 PM
[color=#FF0000]<<<< Pinging >>>>[/color]
[color=#4169E1]OpenDNS Domain Test[/color]
Pinging to www.opendns.com [67.215.92.210]:
Response - 108ms
Response - 93ms
Response - 94ms
Response - 92msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 92ms - Maximum = 108ms
[color=#4169E1]OpenDNS IP Test[/color]
Pinging to 208.69.38.150 [208.69.38.150]:
Response - 94ms
Response - 93ms
Response - 94ms
Response - 92msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 92ms - Maximum = 94ms
[color=#4169E1]Kaspersky Domain Test[/color]
Pinging to www.kaspersky.com [195.27.252.18]:
Response - 140ms
Response - 125ms
Response - 125ms
Response - 125msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 125ms - Maximum = 140ms
[color=#4169E1]Kaspersky IP Test[/color]
Pinging to 195.27.181.10 [195.27.181.10]:
Response - 140ms
Response - 125ms
Response - 125ms
Response - 141msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 125ms - Maximum = 141ms
[color=#4169E1]YouTube Domain Test[/color]
Pinging to www.youtube.com [74.125.139.93]:
Response - 30ms
Response - 16ms
Response - 15ms
Response - 15msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 15ms - Maximum = 30ms
[color=#4169E1]YouTube IP Test[/color]
Pinging to 66.102.9.136 [66.102.9.136]:
Response - None
Response - None
Response - None
Response - NonePackets: Sent = 4, Received = 0, Lost = 4
Minimum = 0ms - Maximum = 0ms
[color=#4169E1]localhost Test[/color]
Pinging to 127.0.0.1 [127.0.0.1]:
Response - 0ms
Response - 0ms
Response - 0ms
Response - 0msPackets: Sent = 4, Received = 4, Lost = 0
Minimum = 0ms - Maximum = 0ms
[color=#FF0000]<<<< Netstat >>>>[/color]
Active Connections
Proto Local Address Foreign Address State PID
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING 1788
c:\windows\system32\WS2_32.dll
C:\WINDOWS\system32\RPCRT4.dll
c:\windows\system32\rpcss.dll
C:\WINDOWS\system32\svchost.exe
-- unknown component(s) --
[svchost.exe]
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING 4
[System]
TCP 127.0.0.1:1031 0.0.0.0:0 LISTENING 2720
[CLI.EXE]
TCP 127.0.0.1:4370 0.0.0.0:0 LISTENING 2976
[SpotifyWebHelper.exe]
TCP 127.0.0.1:4380 0.0.0.0:0 LISTENING 2976
[SpotifyWebHelper.exe]
TCP 127.0.0.1:4479 0.0.0.0:0 LISTENING 460
[cli.exe]
TCP 127.0.0.1:4573 0.0.0.0:0 LISTENING 2344
[MotoHelperService.exe]
TCP 127.0.0.1:5152 0.0.0.0:0 LISTENING 1972
[jqs.exe]
TCP 127.0.0.1:5354 0.0.0.0:0 LISTENING 980
[mDNSResponder.exe]
TCP 127.0.0.1:27015 0.0.0.0:0 LISTENING 884
[AppleMobileDeviceService.exe]
TCP 192.168.0.5:139 0.0.0.0:0 LISTENING 4
[System]
TCP 127.0.0.1:1030 127.0.0.1:4573 ESTABLISHED 3804
[MotoHelperAgent.exe]
TCP 127.0.0.1:4252 127.0.0.1:4253 ESTABLISHED 2928
[firefox.exe]
TCP 127.0.0.1:4253 127.0.0.1:4252 ESTABLISHED 2928
[firefox.exe]
TCP 127.0.0.1:4573 127.0.0.1:1030 ESTABLISHED 2344
[MotoHelperService.exe]
TCP 192.168.0.5:1047 192.168.0.3:445 ESTABLISHED 4
[System]
UDP 0.0.0.0:1027 *:* 980
[mDNSResponder.exe]
UDP 0.0.0.0:500 *:* 1532
[lsass.exe]
UDP 0.0.0.0:4500 *:* 1532
[lsass.exe]
UDP 0.0.0.0:427 *:* 1452
C:\WINDOWS\system32\WS2_32.dll
c:\program files\hp\digital imaging\bin\hpslpsvc32.dll
-- unknown component(s) --
[svchost.exe]
UDP 0.0.0.0:445 *:* 4
[System]
UDP 127.0.0.1:1025 *:* 884
[AppleMobileDeviceService.exe]
UDP 127.0.0.1:1026 *:* 884
[AppleMobileDeviceService.exe]
UDP 127.0.0.1:1972 *:* 656
[WINZIP32.EXE]
UDP 127.0.0.1:1900 *:* 3392
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 127.0.0.1:123 *:* 1832
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
-- unknown component(s) --
[svchost.exe]
UDP 192.168.0.5:427 *:* 1452
C:\WINDOWS\system32\WS2_32.dll
c:\program files\hp\digital imaging\bin\hpslpsvc32.dll
-- unknown component(s) --
[svchost.exe]
UDP 192.168.0.5:138 *:* 4
[System]
UDP 192.168.0.5:1900 *:* 3392
c:\windows\system32\WS2_32.dll
c:\windows\system32\ssdpsrv.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
UDP 192.168.0.5:5353 *:* 980
[mDNSResponder.exe]
UDP 192.168.0.5:137 *:* 4
[System]
UDP 192.168.0.5:123 *:* 1832
c:\windows\system32\WS2_32.dll
c:\windows\system32\w32time.dll
ntdll.dll
C:\WINDOWS\system32\kernel32.dll
[svchost.exe]
[color=#FF0000]<<<< Hosts File >>>>[/color]
The HOSTS file is 27 Bytes in size.
There were 0 lines which refer to an external IP address.
------ End of File ------