Windows XP Machine
[CODE]
BEARDIAG ISSUES - brief summary: (Extracted on 2007/02/21 11:15:46) 

ZoneAlarm firewall found - unsuitable for use with BearShare - too slow and unstable!
 Refer to http://nh2.nohold.net/noHoldCust25/Prod_1/Articles55646/CompleteUninstallNonNT.html for un-installation instructions
Adobe Reader Speed Launch entry present in startups - not necessary. Use the inbuilt Microsoft program MSCONFIG to disable from the startup list
BearShare version 4.5.0.63 found. We recommend the 5.1.0.b25 beta version - see [URL=http://www.technutopia.com/forum/showthread.php?t=2002]Recommended BearShare downloads[/URL]

More technical diagnostic troubleshooting information follows:[/CODE][CODE]
BEARDIAG: Bearcare for BearShare.
Details collected on 2007/02/21 11:13:36, BEARDIAG Version 01.99.16.0 beta, expires 2007/07/30 (159 days), running from C:\Documents and Settings\Gary Coulter\My Documents\z Temp\BearDiag.exe

System Hardware Information
CPU Type is: AMD Athlon(tm) XP 2100+, CPU speed is approx: 1733Mhz, System BIOS date is: 2003/02/24
OS Version is: WIN_XP, Service pack: Service Pack 2, OS Build: 2600, Computer Name: xxx
Browser name: C:\Program Files\Internet Explorer\iexplore.exe, version: 6.0.2900.2180, Admin user? YES

System Memory Parameters: 	Memory in use: 	33%
Total Physical RAM: 	1.5Gb	Available Physical RAM: 	1020.5Mb
Total Pagefile:   		2.9Gb	Available Pagefile: 		2.5Gb

Internet IP Address 67.58.xxx.xxx  Local IP Address 192.168.0.101  You are behind a NAT firewall and/or router.

File Locations
Program files are at: C:\Program Files, System Temporary files are at: C:\DOCUME~1\GARYCO~1\LOCALS~1\Temp, Common desktop is at:C:\Documents and Settings\All Users\Desktop
BearShare version installed is: 4.5.0.63, Gnutella servent BearShare full path is: C:\Program Files\BearShare\
Temporary downloads at: C:\Program Files\BearShare\Temp\, Completed downloads at: C:\Documents and Settings\Gary Coulter\My Documents\My Music\

Disk statistics
Drive C:	Total space: 111.78Gb	Free: 64.06Gb	Full: 42.7%	Vol type: NTFS

Folder Statistics
Temporary downloads folder:  Space used: 0, 	File count: 0, 	Write access allowed? YES,  # of DAT files: 0, #BAK: 0, #TIGER: 0, #TMP: 0, Other: 0
Completed downloads folder:  Space used: 629.9Kb, 	File count: 6, 	Write access allowed? YES
BearShare library file 'library.db' size is 0, '/db' library folder size is 129.6Kb, console log size is 0

FreePeers.ini settings
The freepeers.ini file is found at C:\Program Files\BearShare\FreePeers.ini. The extracted settings are as follows:

ProductLogic
NOT AVAILABLE	: bAlwaysUpdate; Always Download and announce latest signaled BearShare program updates from FreePeers.inc

Network
1	: connectionType; Network connection type
(0=Modem/AOL/ISDN, 1=Broadband/Cable/DSL/Wireless, 2=Satellite, 3=T1/T3/LAN/OC3/Microwave, 4=Custom values)
6346	: listenPort; TCP/IP port number to listen on

Hosts
No	: bNeverBecomeUltrapeer; Disable UltraPeer mode

Authentication
No	bAuthenticateHosts; Authenticate host connections
No	bAuthenticateDownloads; Authenticate search results and downloads

GBandwidthLogic
No	: bSymmetric; Is Internet connection symmetric
1024	: totalKbps; Maximum bandwidth for symmetric connections
256	: sendKbps; Maximum outbound bandwidth for asymmetric connections
1024	: recvKbps; Maximum inbound bandwidth for asymmetric connections
No	: bMaxHostsKbps; Limit host bandwidth
0	: maxHostsKbps; Kbps of send/receive bandwidth to limit hosts
No	: bMaxUploadsKbps; Limit upload bandwidth
0	: maxUploadsKbps; Kbps of send bandwidth to limit uploads
No	: bMaxDownloadsKbps; Limit download bandwidth
0	: maxDownloadsKbps; Kbps of receive bandwidth to limit downloads

HostLogic
No	: m_bEverUltrapeerCapable; Has client ever been an UltraPeer?

FirewallLogic
NOT AVAILABLE	: bTcpNFW; yes if TCP is not firewalled
NOT AVAILABLE	: bUdpNFW; yes if UDP is not firewalled
NOT AVAILABLE	: UDP Port; UDP port

Downloads
C:\Documents and Settings\Gary Coulter\My Documents\My Music	: szDownloadsDir; Directory where completed and hashed downloads are moved to
C:\Program Files\BearShare\Temp	: szTempDir; Directory where partial downloads are kept
8	: dlMaxFiles; Maximum files to download at once
20	: dlMaxStreams; Maximum connections total
8	: dlMaxStreamsFile; Maximum connections per file
No	: bDelCompletedDownloads;  ; Automatically remove completed downloads
NOT AVAILABLE	: bEnableSparseFiles; Enable Sparse files for temporary files
NOT AVAILABLE	: bDisablePushSources; Never send Push messages
NOT AVAILABLE	: bDisablePushProxySources; Never send Push Proxy requests

Uploads
8	: maxTotUploads; Maximum files to upload at once
0	: lastSendBpsMaxAvg; last session average outgoing bandwidth


C:\Program Files\BearShare\db\BearShareHostiles.zip: 1246215 bytes transferred over 18.69 seconds. Download speed is 533Kbps.
LSPFix.exe: 186880 bytes transferred over 6.49 seconds. Download speed is 230Kbps.

[/CODE]
[CODE]
StartupList report, 2/21/2007, 11:14:34 AM
StartupList version: 1.52
Started from : C:\Documents and Settings\Gary Coulter\My Documents\z Temp\StartupList.EXE
Detected: Windows XP SP2 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP2 (6.00.2900.2180)
* Using default options
==================================================

Running processes:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp4.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinPortrait\floater.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\PW Manager\PwTrkr.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Gateway\EzTune\dtsslsrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Gateway\EzTune\dtsrvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Gary Coulter\My Documents\z Temp\BearDiag.exe
C:\Documents and Settings\Gary Coulter\My Documents\z Temp\StartupList.exe

--------------------------------------------------

Listing of startup folders:

Shell folders Startup:
[C:\Documents and Settings\Gary Coulter\Start Menu\Programs\Startup]
Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
Password Tracker.lnk = C:\Program Files\PW Manager\PwTrkr.exe

Shell folders Common Startup:
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
Adobe Gamma Loader.lnk = ?
Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run

ATICCC = "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay

--------------------------------------------------

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

RunAlert = C:\Program Files\MSI\PC Alert III\AService.exe

--------------------------------------------------

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run

Creative Detector = C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
(Default) = 
ATI Launchpad = 
ATI DeviceDetect = C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
ctfmon.exe = C:\WINDOWS\system32\ctfmon.exe

--------------------------------------------------

Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:

Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------


Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
Popup Manager - C:\Program Files\Popup Manager\PopupMgr_1.0.1.5.dll - {08E74C67-99A6-45C7-94DA-A397A8FD8082}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}

--------------------------------------------------

Enumerating Task Scheduler jobs:

HP Usg Daily FY04.job
MP Scheduled Scan.job

--------------------------------------------------

Enumerating Download Program Files:

[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\system32\legitcheckcontrol.dll
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[WUWebControl Class]
InProcServer32 = C:\WINDOWS\System32\wuweb.dll
CODEBASE = http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138128609466

[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\system32\Macromed\Flash\Flash9b.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll

--------------------------------------------------
End of report, 6,663 bytes
Report generated in 0.031 seconds

Command line options:
   /verbose  - to add additional info on each section
   /complete - to include empty sections and unsuspicious data
   /full     - to include several rarely-important sections
   /force9x  - to include Win9x-only startups even if running on WinNT
   /forcent  - to include WinNT-only startups even if running on Win9x
   /forceall - to include all Win9x and WinNT startups, regardless of platform
   /history  - to list version history only

[/CODE]
[CODE]
Current task list information for xxx, running WIN_XP, Service Pack 2, build 2600
Details collected on 2007/02/21 11:14:30

 PID  Process Name            File Version  Pk Mem Usg. Command line that invoked task
    0 System Idle Process          0.0.0.0         0Mb  ><
    4 System                       0.0.0.0      6.09Mb  ><
  444 smss.exe               5.1.2600.2180      0.84Mb  >\SystemRoot\System32\smss.exe<
  500 csrss.exe                    0.0.0.0      4.07Mb  ><
  532 winlogon.exe           5.1.2600.2180     18.06Mb  >winlogon.exe<
  576 services.exe           5.1.2600.2180      4.35Mb  >C:\WINDOWS\system32\services.exe<
  588 lsass.exe              5.1.2600.2180      6.02Mb  >C:\WINDOWS\system32\lsass.exe<
  752 ati2evxx.exe            6.14.10.4124      2.04Mb  >C:\WINDOWS\System32\Ati2evxx.exe<
  776 svchost.exe            5.1.2600.2180      4.87Mb  >C:\WINDOWS\system32\svchost -k DcomLaunch<
  844 svchost.exe                  0.0.0.0      4.05Mb  ><
  908 MsMpEng.exe               1.1.1593.0     34.91Mb  >"C:\Program Files\Windows Defender\MsMpEng.exe"<
  952 InCDsrv.exe                 4.3.23.2      3.04Mb  >"C:\Program Files\Ahead\InCD\InCDsrv.exe"<
 1128 ati2evxx.exe            6.14.10.4124      3.91Mb  >Ati2evxx.exe -Client<
 1180 explorer.exe           6.0.2900.2180     30.41Mb  >C:\WINDOWS\Explorer.EXE<
 1204 svchost.exe            5.1.2600.2180     31.97Mb  >C:\WINDOWS\System32\svchost.exe -k netsvcs<
 1232 svchost.exe                  0.0.0.0      3.18Mb  ><
 1300 svchost.exe                  0.0.0.0      7.07Mb  ><
 1428 spoolsv.exe            5.1.2600.2696      5.56Mb  >C:\WINDOWS\system32\spoolsv.exe<
 1604 CLI.exe                     1.11.0.0     26.39Mb  >"C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay<
 1612 wpctrl.exe                   7.0.0.0      4.82Mb  >"C:\Program Files\WinPortrait\wpctrl.exe" <
 1624 hpztsb11.exe               2.327.1.0      2.96Mb  >"C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe" <
 1676 hpwuSchd2.exe               2.0.39.0       2.2Mb  >"C:\Program Files\HP\HP Software Update\HPWuSchd2.exe" <
 1688 hpcmpmgr.exe                 2.1.1.0      7.86Mb  >"C:\Program Files\HP\hpcoretech\hpcmpmgr.exe" <
 1716 hphmon06.exe                6.0.72.0      7.91Mb  >"C:\WINDOWS\system32\hphmon06.exe" <
 1728 avgcc.exe                  7.5.0.438      6.45Mb  >"C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe" /STARTUP<
 1764 zlclient.exe               4.5.594.0      9.14Mb  >"C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe" <
 1788 fpdisp4.exe                 4.79.0.0      4.09Mb  >"C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp4.exe" <
 1796 InCD.exe                    4.3.23.2      4.52Mb  >"C:\Program Files\Ahead\InCD\InCD.exe" <
 1844 MSASCui.exe               1.1.1593.0      8.02Mb  >"C:\Program Files\Windows Defender\MSASCui.exe" -hide<
 1852 CTDetect.exe                 3.0.2.0      3.75Mb  >"C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R<
 1864 atidtct.exe                  9.2.0.4         3Mb  >"C:\Program Files\ATI Multimedia\main\ATIDtct.EXE" <
 1876 ctfmon.exe             5.1.2600.2180      3.57Mb  >"C:\WINDOWS\system32\ctfmon.exe" <
 2012 floater.exe                  7.0.0.0      3.63Mb  >"C:\Program Files\WinPortrait\floater.exe"<
 2024 FINDFAST.EXE              8.0.0.3425      3.43Mb  >"C:\Program Files\Microsoft Office\Office\FINDFAST.EXE" <
 2032 PwTrkr.exe                 3.22.0.49      4.02Mb  >"C:\Program Files\PW Manager\PwTrkr.exe" <
  188 devldr32.exe                1.0.0.17      3.22Mb  >C:\WINDOWS\system32\devldr32.exe<
  424 dtsslsrv.exe                 0.0.0.0       4.9Mb  >"C:\Program Files\Gateway\EzTune\dtsslsrv.exe"<
  496 avgamsvr.exe               7.5.0.435      4.25Mb  >C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe<
  704 avgupsvc.exe               7.5.0.420      2.08Mb  >C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe<
  892 avgemc.exe                 7.5.0.434      6.36Mb  >C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe<
  980 CTSVCCDA.EXE                 1.0.1.0      1.25Mb  >C:\WINDOWS\system32\CTsvcCDA.EXE<
 1008 DTSRVC.exe                   0.0.0.0      1.09Mb  >"C:\Program Files\Gateway\EzTune\dtsrvc.exe"<
 1160 ULCDRSvr.exe                 1.0.0.4      0.84Mb  >"C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe"<
 1528 wdfmgr.exe                   0.0.0.0      1.69Mb  ><
 1712 vsmon.exe                  4.5.594.0      6.94Mb  >C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service<
 2552 HPZipm12.exe                 8.0.0.0      1.98Mb  >C:\WINDOWS\system32\HPZipm12.exe<
 2844 alg.exe                      0.0.0.0      3.36Mb  ><
 3436 svchost.exe            5.1.2600.2180      3.26Mb  >C:\WINDOWS\System32\svchost.exe -k HTTPFilter<
 3780 msimn.exe              6.0.2900.2180     48.55Mb  >"C:\Program Files\Outlook Express\msimn.exe" <
 3880 firefox.exe          1.8.20061.20418     47.51Mb  >"C:\Program Files\Mozilla Firefox\firefox.exe" <
 2796 BearDiag.exe               1.99.16.0     10.12Mb  >"C:\Documents and Settings\Gary Coulter\My Documents\z Temp\BearDiag.exe" <
 3756 wmiprvse.exe                 0.0.0.0      5.35Mb  ><


BearShare library folder information for xxx, running WIN_XP, Service Pack 2, build 2600
Details collected on 2007/02/21 11:15:46

 Volume in drive C has no label.
 Volume Serial Number is 1C15-ABD7

 Directory of C:\Program Files\BearShare\db

02/21/2007  11:15 AM    <DIR>          .
02/21/2007  11:15 AM    <DIR>          ..
02/21/2007  11:15 AM         1,246,215 BearShareHostiles.zip
06/18/2004  04:37 PM            94,211 connect.txt
06/01/2004  05:52 PM            16,463 gnucache.dat
02/20/2007  11:56 AM             2,008 gwebcache.dat
06/01/2004  05:52 PM            16,342 hbcache.dat
01/25/2006  07:16 PM             1,952 Hostiles.old
02/16/2007  02:18 AM         9,295,723 Hostiles.txt
02/20/2007  11:56 AM             1,768 library.dat
               8 File(s)     10,674,682 bytes
               2 Dir(s)  68,768,329,728 bytes free
[/CODE]
[CODE]
Firewall information for xxx, running WIN_XP, Service Pack 2, build 2600
Details collected on 2007/02/21 11:15:57

Default gateway is 192.168.0.1
Valid Firewall exception for program C:\Program Files\BearShare\BearShare.exe found


Domain profile configuration:
-------------------------------------------------------------------
Operational mode                  = Enable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                 = Enable

Service configuration for Domain profile:
Mode     Customized  Name
-------------------------------------------------------------------
Enable   No          File and Printer Sharing

Allowed programs configuration for Domain profile:
Mode     Name / Program
-------------------------------------------------------------------
Enable   Remote Assistance / C:\WINDOWS\system32\sessmgr.exe
Enable   SiSoftware Sandra Lite / C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\sandra.exe
Enable   SiSoftware Sandra Lite / C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
Enable   SiSoftware Sandra Lite / C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
Enable   Network Diagnostics for Windows XP / C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

Port configuration for Domain profile:
Port   Protocol  Mode     Name
-------------------------------------------------------------------
139    TCP       Enable   NetBIOS Session Service
445    TCP       Enable   SMB over TCP
137    UDP       Enable   NetBIOS Name Service
138    UDP       Enable   NetBIOS Datagram Service

Standard profile configuration (current):
-------------------------------------------------------------------
Operational mode                  = Disable
Exception mode                    = Enable
Multicast/broadcast response mode = Enable
Notification mode                 = Enable

Service configuration for Standard profile:
Mode     Customized  Name
-------------------------------------------------------------------
Enable   No          File and Printer Sharing

Allowed programs configuration for Standard profile:
Mode     Name / Program
-------------------------------------------------------------------
Enable   Remote Assistance / C:\WINDOWS\system32\sessmgr.exe
Enable   avginet.exe / C:\Program Files\Grisoft\AVG Free\avginet.exe
Enable   avgemc.exe / C:\Program Files\Grisoft\AVG Free\avgemc.exe
Enable   BearShare / C:\Program Files\BearShare\BearShare.exe
Enable   Kazaa Lite / C:\Program Files\Kazaa Lite\KazaaLite.kpp
Enable   AVG Free Edition for Windows / C:\Program Files\Grisoft\AVG Free\avgw.exe
Enable   AVG Free Control Center / C:\Program Files\Grisoft\AVG Free\avgcc.exe
Enable   SiSoftware Sandra Lite / C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\sandra.exe
Enable   SiSoftware Sandra Lite / C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
Enable   SiSoftware Sandra Lite / C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
Enable   Network Diagnostics for Windows XP / C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
Enable   avgamsvr.exe / C:\Program Files\Grisoft\AVG Free\avgamsvr.exe

Port configuration for Standard profile:
Port   Protocol  Mode     Name
-------------------------------------------------------------------
139    TCP       Enable   NetBIOS Session Service
445    TCP       Enable   SMB over TCP
137    UDP       Enable   NetBIOS Name Service
138    UDP       Enable   NetBIOS Datagram Service

Log configuration:
-------------------------------------------------------------------
File location   = C:\WINDOWS\pfirewall.log
Max file size   = 4096 KB
Dropped packets = Disable
Connections     = Disable

Local Area Connection firewall configuration:
-------------------------------------------------------------------
Operational mode                  = Enable

[/CODE]
[CODE]
Logfile of HijackThis v1.99.1
Scan saved at 11:14:38 AM, on 2/21/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\Program Files\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\WinPortrait\wpctrl.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINDOWS\system32\hphmon06.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp4.exe
C:\Program Files\Ahead\InCD\InCD.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\WinPortrait\floater.exe
C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
C:\Program Files\PW Manager\PwTrkr.exe
C:\WINDOWS\system32\devldr32.exe
C:\Program Files\Gateway\EzTune\dxxxlsrv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\Gateway\EzTune\dtsrvc.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Gary Coulter\My Documents\z Temp\BearDiag.exe
C:\Documents and Settings\Gary Coulter\My Documents\z Temp\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Popup Manager - {08E74C67-99A6-45C7-94DA-A397A8FD8082} - C:\Program Files\Popup Manager\PopupMgr_1.0.1.5.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\WinPortrait\wpctrl.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb11.exe
O4 - HKLM\..\Run: [HPHUPD06] C:\Program Files\HP\{AAC4FC36-8F89-4587-8DD3-EBC57C83374D}\hphupd06.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [HPHmon06] C:\WINDOWS\system32\hphmon06.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [FinePrint Dispatcher v4] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\fpdisp4.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\RunServices: [RunAlert] C:\Program Files\MSI\PC Alert III\AService.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - HKCU\..\Run: [ATI DeviceDetect] C:\Program Files\ATI Multimedia\main\ATIDtct.EXE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft Office\Office\FINDFAST.EXE
O4 - Startup: Password Tracker.lnk = C:\Program Files\PW Manager\PwTrkr.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = ?
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe
O8 - Extra context menu item: &ieSpell Options - res://C:\Program Files\ieSpell\iespell.dll/SPELLOPTION.HTM
O8 - Extra context menu item: Check &Spelling - res://C:\Program Files\ieSpell\iespell.dll/SPELLCHECK.HTM
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell - {0E17D5B7-9F5D-4fee-9DF6-CA6EE38B68A8} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: (no name) - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra 'Tools' menuitem: ieSpell Options - {1606D6F9-9D3B-4aea-A025-ED5B2FD488E7} - C:\Program Files\ieSpell\iespell.dll
O9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\tv\EXPLBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1138128609466
O23 - Service: Asset Management Daemon - Unknown owner - C:\Program Files\Gateway\EzTune\dxxxlsrv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Unknown owner - C:\Program Files\Gateway\EzTune\dtsrvc.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\Win32\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2007.SP1\RpcSandraSrv.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


.[/CODE]

