Farbar Service Scanner Version: 13-09-2013
Ran by Magdy (administrator) on 16-10-2013 at 20:43:31
Running from “C:\Users\Magdy\Desktop”
Microsoft Windows 8 Enterprise (X64)
Boot Mode: Normal
Internet Services:
Connection Status:
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo.com is accessible.
Windows Firewall:
MpsSvc Service is not running. Checking service configuration:
The start type of MpsSvc service is OK.
The ImagePath of MpsSvc service is OK.
The ServiceDll of MpsSvc service is OK.
Firewall Disabled Policy:
System Restore:
System Restore Disabled Policy:
Action Center:
Windows Update:
wuauserv Service is not running. Checking service configuration:
The start type of wuauserv service is set to Demand. The default start type is Auto.
The ImagePath of wuauserv service is OK.
The ServiceDll of wuauserv service is OK.
Windows Autoupdate Disabled Policy:
Windows Defender:
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend: “”%ProgramFiles%\Windows Defender\MsMpEng.exe"".
Windows Defender Disabled Policy:
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
“DisableAntiSpyware”=DWORD:1
Other Services:
File Check:
C:\Windows\System32\nsisvc.dll => MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
C:\Windows\System32\dhcpcore.dll
[2012-07-26 02:07] - [2012-07-26 05:05] - 0331776 ____A (Microsoft Corporation) 6DBE7FE196F8E9D212DCC34EDDF7C3C1
C:\Windows\System32\drivers\afd.sys => MD5 is legit
C:\Windows\System32\drivers\tdx.sys => MD5 is legit
C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
C:\Windows\System32\dnsrslvr.dll
[2012-07-26 02:08] - [2012-07-26 05:05] - 0210432 ____A (Microsoft Corporation) 9ACE7E657107EB51E5E89FD883F2FD2D
C:\Windows\System32\mpssvc.dll
[2012-07-26 01:40] - [2012-07-26 05:06] - 0904704 ____A (Microsoft Corporation) 411EA973A1961C287927DF13891EB41E
C:\Windows\System32\bfe.dll
[2012-07-26 02:00] - [2012-07-26 05:05] - 0718848 ____A (Microsoft Corporation) 407F85D5387EDBB665A7969DF4D4712B
C:\Windows\System32\drivers\mpsdrv.sys
[2012-07-26 04:23] - [2012-07-26 04:23] - 0074752 ____A (Microsoft Corporation) 36BF4D86F166ACBC14F0B8B8F90CBCEA
C:\Windows\System32\SDRSVC.dll => MD5 is legit
C:\Windows\System32\vssvc.exe => MD5 is legit
C:\Windows\System32\wscsvc.dll => MD5 is legit
C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit
C:\Windows\System32\wuaueng.dll
[2012-07-26 01:34] - [2012-07-26 05:08] - 3318784 ____A (Microsoft Corporation) C80DB258C195ACBF86ED42B53554EB28
C:\Windows\System32\qmgr.dll => MD5 is legit
C:\Windows\System32\es.dll => MD5 is legit
C:\Windows\System32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MsMpEng.exe => MD5 is legit
C:\Windows\System32\svchost.exe
[2012-07-26 02:00] - [2012-07-26 05:08] - 0030208 ____A (Microsoft Corporation) 57350BEDE3834915B6145B67C71C7BDA
C:\Windows\System32\rpcss.dll => MD5 is legit
**** End of log ****