Hi... here is the report...
Thanks again
--- Search result list ---
--- Spybot - Search && Destroy version: 1.3 ---
2006-12-08 Includes\Cookies.sbi
2006-12-08 Includes\Dialer.sbi
2006-12-08 Includes\DialerC.sbi
2006-11-24 Includes\Hijackers.sbi
2006-12-08 Includes\HijackersC.sbi
2006-10-27 Includes\Keyloggers.sbi
2006-12-08 Includes\KeyloggersC.sbi
2004-05-11 Includes\LSP.sbi
2006-12-08 Includes\Malware.sbi
2006-12-08 Includes\MalwareC.sbi
2006-10-20 Includes\PUPS.sbi
2006-12-08 Includes\PUPSC.sbi
2006-12-08 Includes\Revision.sbi
2006-12-08 Includes\Security.sbi
2006-12-08 Includes\SecurityC.sbi
2006-10-13 Includes\Spybots.sbi
2006-12-08 Includes\SpybotsC.sbi
2005-02-17 Includes\Tracks.uti
2006-12-08 Includes\Trojans.sbi
2006-12-08 Includes\TrojansC.sbi
--- System information ---
Windows XP (Build: 2600) Service Pack 1
/ Windows Media Player: Correctif pour le Lecteur Windows Media [Voir Q828026 pour plus d'informations]
/ Windows Media Player / SP0: Correctif pour le Lecteur Windows Media [Voir Q828026 pour plus d'informations]
/ Windows XP / SP2: Correctif Windows XP - KB822603
/ Windows XP / SP2: Correctif Windows XP - KB823182
/ Windows XP / SP2: Correctif Windows XP - KB824105
/ Windows XP / SP2: Correctif Windows XP - KB824141
/ Windows XP / SP2: Correctif Windows XP - KB825119
/ Windows XP / SP2: Correctif Windows XP - KB826939
/ Windows XP / SP2: Correctif Windows XP - KB828035
/ Windows XP / SP2: Correctif Windows XP - KB828741
/ Windows XP / SP2: Correctif Windows XP - KB835732
/ Windows XP / SP2: Correctif Windows XP - KB837001
/ Windows XP / SP2: Correctif Windows XP - KB840374
/ Windows XP / SP2: Correctif Windows XP (SP2) Q327979
/ Windows XP / SP2: Windows XP Hotfix Package [See Q328145 for more information]
/ Windows XP / SP2: Package du correctif Windows XP [voir Q329692 pour plus de détails]
/ Windows XP / SP2: Package du correctif Windows XP [voir Q331958 pour plus de détails]
/ Windows XP / SP2: Correctif Windows XP (SP2) Q810400
/ Windows XP / SP2: Correctif Windows XP (SP2) Q811114
/ Windows XP / SP2: Correctif Windows XP (SP2) q812415
--- Startup entries list ---
Located: HK_LM:Run, Acrobat Assistant 7.0
command: "E:\Acrobat 7.0\Distillr\Acrotray.exe"
file: E:\Acrobat 7.0\Distillr\Acrotray.exe
size: 483328
MD5: bd99953b6f8b36862b5b86c2fe39a8a3
Located: HK_LM:Run, iTunesHelper
command: "E:\iTunes\iTunesHelper.exe"
file: E:\iTunes\iTunesHelper.exe
size: 229952
MD5: ceccc68b54e8e27c93dbede85f160c96
Located: HK_LM:Run, LVCOMS
command: "C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE"
file: C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
size: 98304
MD5: 2d969f669ffdf2d01e07b2ada484186a
Located: HK_LM:Run, NvCplDaemon
command: "RUNDLL32.EXE" C:\WINDOWS\System32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 32256
MD5: ac0f912ea7571e9c1ad7b64c83f72bd9
Located: HK_LM:Run, QuickTime Task
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 282624
MD5: d2c900031fd445b5464abb5629388be3
Located: HK_LM:Run, SunJavaUpdateSched
command: "C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe"
file: C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
size: 36975
MD5: 61a3a9d5d98bf0331df5b716144a8100
Located: HK_LM:Run, Zone Labs Client
command: "E:\Zone Labs\ZoneAlarm\zlclient.exe"
file: E:\Zone Labs\ZoneAlarm\zlclient.exe
size: 968696
MD5: 71514e2c74d554f5902dc184046eca3b
Located: HK_LM:Run, Acrobat Assistant 7.0 (DISABLED)
command: "E:\Acrobat 7.0\Distillr\Acrotray.exe"
file: E:\Acrobat 7.0\Distillr\Acrotray.exe
size: 483328
MD5: bd99953b6f8b36862b5b86c2fe39a8a3
Located: HK_LM:Run, ccApp (DISABLED)
command: "C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe"
file: C:\Program Files\Fichiers communs\Symantec Shared\ccApp.exe
size: 48752
MD5: 920928fd0b4a1989466912fd138dc708
Located: HK_LM:Run, iTunesHelper (DISABLED)
command: "E:\iTunes\iTunesHelper.exe"
file: E:\iTunes\iTunesHelper.exe
size: 229952
MD5: ceccc68b54e8e27c93dbede85f160c96
Located: HK_LM:Run, NeroFilterCheck (DISABLED)
command: C:\WINDOWS\System32\NeroCheck.exe
file: C:\WINDOWS\System32\NeroCheck.exe
size: 155648
MD5: 3e4c03cefad8de135263236b61a49c90
Located: HK_LM:Run, NvCplDaemon (DISABLED)
command: RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 32256
MD5: ac0f912ea7571e9c1ad7b64c83f72bd9
Located: HK_LM:Run, NvMediaCenter (DISABLED)
command: RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
file: C:\WINDOWS\system32\RUNDLL32.EXE
size: 32256
MD5: ac0f912ea7571e9c1ad7b64c83f72bd9
Located: HK_LM:Run, nwiz (DISABLED)
command: nwiz.exe /install
file: C:\WINDOWS\system32\nwiz.exe
size: 1519616
MD5: 0033ce6494554e47514d3487c9a8f93d
Located: HK_LM:Run, QuickTime Task (DISABLED)
command: "C:\Program Files\QuickTime\qttask.exe" -atboottime
file: C:\Program Files\QuickTime\qttask.exe
size: 282624
MD5: d2c900031fd445b5464abb5629388be3
Located: HK_LM:Run, SunJavaUpdateSched (DISABLED)
command: C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
file: C:\Program Files\Java\j2re1.4.2_04\bin\jusched.exe
size: 32881
MD5: d7b9be63c406103ee1405fe473ac0697
Located: HK_LM:Run, type32 (DISABLED)
command: "C:\Program Files\Microsoft IntelliType Pro\type32.exe"
file: C:\Program Files\Microsoft IntelliType Pro\type32.exe
size: 172032
MD5: 05e10c2c3736e52fe33d16d2f9c73c04
Located: HK_LM:Run, vptray (DISABLED)
command: C:\PROGRA~1\Symantec AntiVirus\VPTray.exe
file: C:\PROGRA~1\Symantec AntiVirus\VPTray.exe
size: 85696
MD5: 78e501d932b2721f0e074886a31af0ba
Located: HK_CU:Run, Gadwin PrintScreen 3.1
command: E:\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
Located: HK_CU:Run, Gadwin PrintScreen 3.1 (DISABLED)
command: E:\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
Located: Startup (common), Adobe Acrobat Speed Launcher.lnk
command: C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
file: C:\WINDOWS\Installer\{AC76BA86-1033-0000-7760-000000000002}\SC_Acrobat.exe
size: 25214
MD5: d6294d59171ac375cd142003566aa89e
--- Browser helper object list ---
{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
BHO name:
CLSID name: AcroIEHlprObj Class
description: Adobe Acrobat reader
classification: Legitimate
known filename: ACROIEHELPER.OCX
info link:
http://www.adobe.com/products/acrobat/readstep2.html
info source: TonyKlein
Path: E:\Acrobat 7.0\ActiveX\
Long name: AcroIEHelper.dll
Short name:
Date (created): 2005-09-24 00:12:08
Date (last access): 2006-03-16 23:00:10
Date (last write): 2005-09-24 00:12:08
Filesize: 63136
Attributes: archive
MD5: B61D5D651ECC6055C29BF826CA7B1141
CRC32: FEF15799
Version: 0.7.0.0
{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDHelper.dll
info link:
http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: C:\PROGRA~1\SPYBOT~1\
Long name: SDHelper.dll
Short name:
Date (created): 2004-05-11 19:03:00
Date (last access): 2006-01-22 07:04:18
Date (last write): 2004-05-11 19:03:00
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3
{5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} (PCTools Site Guard)
BHO name:
CLSID name: PCTools Site Guard
Path: E:\Spyware Doctor\tools\
Long name: iesdsg.dll
Short name:
Date (created): 2006-11-23 19:36:26
Date (last access): 2006-11-23 19:36:26
Date (last write): 2006-05-05 13:55:04
Filesize: 803048
Attributes: archive
MD5: 783E7419950215EA9CA00C1C0C15B386
CRC32: 2EF67EF5
Version: 0.3.0.6
{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
BHO name:
CLSID name: SSVHelper Class
Path: C:\Program Files\Java\jre1.5.0_06\bin\
Long name: ssv.dll
Short name:
Date (created): 2005-11-10 13:03:56
Date (last access): 2005-11-10 13:03:56
Date (last write): 2005-11-10 13:22:10
Filesize: 184423
Attributes: archive
MD5: F01726F7CA8538FDD4663C9DB8FEAEDC
CRC32: 0111B892
Version: 0.5.0.0
{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: Googletoolbar.dll
info link:
http://toolbar.google.com/
info source: TonyKlein
Path: c:\program files\google\
Long name: GoogleToolbar3.dll
Short name:
Date (created): 2006-10-30 17:44:32
Date (last access): 2006-10-30 17:44:32
Date (last write): 2006-10-17 15:04:36
Filesize: 2153536
Attributes: readonly archive
MD5: D7C951510ABB954204A798A21A510D98
CRC32: 5D8D9479
Version: 0.4.0.0
{B56A7D7D-6927-48C8-A975-17DF180C71AC} (PCTools Browser Monitor)
BHO name:
CLSID name: PCTools Browser Monitor
Path: E:\Spyware Doctor\tools\
Long name: iesdpb.dll
Short name:
Date (created): 2006-11-23 19:36:26
Date (last access): 2006-11-23 19:38:20
Date (last write): 2006-11-23 19:38:20
Filesize: 850104
Attributes: archive
MD5: 788BD4FBDC3D24B3D18B582D32EF00EA
CRC32: DD714CB5
Version: 0.3.0.6
--- ActiveX list ---
{00000161-9980-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
{3334504D-9980-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
{33564D57-9980-0010-8000-00AA00389B71} ()
DPF name:
CLSID name:
description: Microsoft WMV Video Codec
classification: Legitimate
known filename: WMV9DMO.CAB
info link:
info source: Patrick M. Kolla
{D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object)
DPF name:
CLSID name: Shockwave Flash Object
description: Macromedia Shockwave Flash Player
classification: Legitimate
known filename:
info link:
info source: Patrick M. Kolla
Path: C:\WINDOWS\System32\Macromed\Flash\
Long name: Flash9b.ocx
Short name:
Date (created): 2006-11-09 14:46:28
Date (last access): 2006-11-09 14:46:28
Date (last write): 2006-11-09 14:46:28
Filesize: 2262648
Attributes: readonly archive
MD5: F3B3EE66CA76C94510555ABE9D00A353
CRC32: A51F3CB4
Version: 0.9.0.0
--- Process list ---
Spybot - Search && Destroy process list report, 2006-12-15 15:54:12
PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 356 ( 296) C:\WINDOWS\Explorer.EXE
PID: 480 ( 704) C:\WINDOWS\System32\svchost.exe
PID: 568 ( 4) \SystemRoot\System32\smss.exe
PID: 628 ( 568) \??\C:\WINDOWS\system32\csrss.exe
PID: 656 ( 568) \??\C:\WINDOWS\system32\winlogon.exe
PID: 704 ( 656) C:\WINDOWS\system32\services.exe
PID: 720 ( 656) C:\WINDOWS\system32\lsass.exe
PID: 764 ( 704) C:\Program Files\iPod\bin\iPodService.exe
PID: 876 ( 704) C:\WINDOWS\system32\svchost.exe
PID: 928 ( 704) C:\WINDOWS\System32\svchost.exe
PID: 992 ( 704) C:\WINDOWS\System32\svchost.exe
PID: 1032 ( 704) C:\Program Files\Fichiers communs\Symantec Shared\ccSetMgr.exe
PID: 1096 ( 704) C:\Program Files\Fichiers communs\Symantec Shared\ccEvtMgr.exe
PID: 1212 ( 704) C:\WINDOWS\system32\spoolsv.exe
PID: 1252 ( 356) E:\Zone Labs\ZoneAlarm\zlclient.exe
PID: 1272 ( 356) C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
PID: 1320 ( 356) C:\Program Files\Fichiers communs\Logitech\QCDriver\LVCOMS.EXE
PID: 1340 ( 356) E:\iTunes\iTunesHelper.exe
PID: 1368 ( 356) E:\Acrobat 7.0\Distillr\Acrotray.exe
PID: 1408 ( 356) E:\Gadwin Systems\PrintScreen\PrintScreen.exe
PID: 1536 ( 704) E:\AVG Anti-Spyware 7.5\guard.exe
PID: 1552 ( 704) C:\Program Files\Symantec AntiVirus\DefWatch.exe
PID: 1616 ( 704) E:\MacDisk\lsdiorw\lsdiorw.exe
PID: 1708 ( 704) C:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
PID: 1724 ( 704) C:\WINDOWS\System32\nvsvc32.exe
PID: 1784 ( 704) e:\Spyware Doctor\sdhelp.exe
PID: 1812 ( 704) C:\WINDOWS\System32\svchost.exe
PID: 1836 ( 704) C:\Program Files\Symantec AntiVirus\Rtvscan.exe
PID: 1872 ( 704) C:\WINDOWS\System32\wdfmgr.exe
PID: 1904 ( 704) C:\WINDOWS\system32\ZoneLabs\vsmon.exe
PID: 2732 ( 356) C:\Program Files\Internet Explorer\IEXPLORE.EXE
PID: 2780 ( 876) C:\Program Files\Google\GoogleToolbarNotifier\1.2.908.5008\GoogleToolbarNotifier.exe
PID: 3840 ( 356) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe
--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 2006-12-15 15:54:12
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.google.com
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Search Bar
http://www.google.com/ie
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://rds.ca/
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.google.com/ie
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://www.google.com/search?q=%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar
http://us.rd.yahoo.com/customize/ie/def ... earch.html
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.yahoo.com/
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Page_URL
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.google.com/ie
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://www.google.com/ie
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]
Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider
Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{24DFA115-9579-41A9-AEE6-1FCF95FC7BF3}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{24DFA115-9579-41A9-AEE6-1FCF95FC7BF3}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F2EC727E-405F-4930-BD50-1CAD5EB0C877}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F2EC727E-405F-4930-BD50-1CAD5EB0C877}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{35BBE09B-61F7-4809-AE9A-4885C14CACD2}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{35BBE09B-61F7-4809-AE9A-4885C14CACD2}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F97CE151-D010-4F58-96A7-7E15EE2AD870}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{F97CE151-D010-4F58-96A7-7E15EE2AD870}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{49E737BC-141E-4943-830E-CD95DBDC2836}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{49E737BC-141E-4943-830E-CD95DBDC2836}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *
Namespace Provider 0: TCP/IP
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP
Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS
Namespace Provider 2: Espace de noms NLA (Network Location Awareness)
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace