This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Possible Malware [Solved]

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi,

My laptop has been running slow for a while and now it is constantly disconnecting from the internet. I have also noticed that my anti virus causes a disconnection when trying to update. I suspect I have some Malware. Can someone take a look at the DDS reports and give me some direction please.

DDS (Ver_2011-08-26.01) - NTFSx86
Internet Explorer: 9.0.8112.16421
Run by [removed] at 20:34:22 on 2012-09-25
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.44.1033.18.2037.950 [GMT 1:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Trusteer\Rapport\bin\RapportMgmtService.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\svchost.exe -k GPSvcGroup
C:\Windows\system32\SLsvc.exe
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\WLANExt.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\aestsrv.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Trusteer\Rapport\bin\RapportService.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\DellTPad\Apoint.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Sigmatel\C-Major Audio\WDM\sttray.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\taskeng.exe
C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe
C:\Windows\system32\STacSV.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Windows\System32\svchost.exe -k WerSvcGroup
C:\Windows\system32\SearchIndexer.exe
C:\Windows\system32\DRIVERS\xaudio.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Program Files\DellTPad\ApMsgFwd.exe
C:\Program Files\DellTPad\HidFind.exe
C:\Program Files\DellTPad\Apntex.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Users\Lizbeth\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lizbeth\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lizbeth\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lizbeth\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Lizbeth\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\DllHost.exe
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = https://retail.santander.co.uk/LOGSUK_NS_EN…ationName=LOGON
uWindow Title = Internet Explorer provided by Dell
uSearchURL,(Default) = hxxp://uk.search.yahoo.com/search?fr=mcafee&p=%s
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll
BHO: Java™ Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\program files\google\google toolbar\GoogleToolbar_32.dll
uRun: [swg] "c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
uRun: [Google Update] "c:\users\lizbeth\appdata\local\google\update\GoogleUpdate.exe" /c
mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
mRun: [ECenter] c:\dell\e-center\EULALauncher.exe
mRun: [Apoint] c:\program files\delltpad\Apoint.exe
mRun: [IgfxTray] c:\windows\system32\igfxtray.exe
mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe
mRun: [Persistence] c:\windows\system32\igfxpers.exe
mRun: [ISUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start
mRun: []
mRun: [RoxWatchTray] "c:\program files\common files\roxio shared\9.0\sharedcom\RoxWatchTray9.exe"
mRun: [Google Desktop Search] "c:\program files\google\google desktop search\GoogleDesktop.exe" /startup
mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"
mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe"
mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe"
mRun: [ISUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup
mRun: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime
mRun: [avast] "c:\program files\alwil software\avast5\avastUI.exe" /nogui
mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe"
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe
StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\windows\installer\{7f0c4457-8e64-491b-8d7b-991504365d1e}\NewShortcut2_53A01CC614B04512A2E710D39BF83DC4.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Trusted Zone: alliance-leicester.co.uk\www.mybank
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_35-windows-i586.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: DhcpNameServer = 192.168.1.1
TCP: Interfaces\{07985FFF-73D5-474C-9162-281F0489E4BF} : DhcpNameServer = [removed] [removed]
TCP: Interfaces\{C75EBECB-99C2-48D0-8BC0-F6139C87B0CB} : DhcpNameServer = 192.168.1.1
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - c:\progra~1\common~1\skype\SKYPE4~1.DLL
Notify: igfxcui - igfxdev.dll
AppInit_DLLs: c:\progra~1\google\google~2\GOEC62~1.DLL
.
============= SERVICES / DRIVERS ===============
.
R0 RapportKELL;RapportKELL;c:\windows\system32\drivers\RapportKELL.sys [2012-7-29 65848]
R1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2011-10-30 442200]
R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2010-11-1 320856]
R1 RapportCerberus_42020;RapportCerberus_42020;c:\programdata\trusteer\rapport\store\exts\rapportcerberus\baseline\RapportCerberus32_42020.sys [2012-8-9 228376]
R1 RapportEI;RapportEI;c:\program files\trusteer\rapport\bin\RapportEI.sys [2012-7-29 71480]
R1 RapportPG;RapportPG;c:\program files\trusteer\rapport\bin\RapportPG.sys [2012-7-29 166840]
R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-3-26 73728]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2010-11-1 20568]
R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2010-11-1 54616]
R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-1 44768]
R2 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2010-11-11 21504]
R2 RapportMgmtService;Rapport Management Service;c:\program files\trusteer\rapport\bin\RapportMgmtService.exe [2012-7-29 976728]
R2 Skype C2C Service;Skype C2C Service;c:\programdata\skype\toolbars\skype c2c service\c2c_service.exe [2012-8-13 3064000]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-11-1 136176]
S2 SkypeUpdate;Skype Updater;c:\program files\skype\updater\Updater.exe [2012-6-5 160944]
S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-5-6 250288]
S3 GoogleDesktopManager-051210-111108;Google Desktop Manager 5.9.1005.12335;c:\program files\google\google desktop search\GoogleDesktop.exe [2008-3-26 30192]
S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-11-1 136176]
S3 s1018bus;Sony Ericsson Device 1018 driver (WDM);c:\windows\system32\drivers\s1018bus.sys [2011-5-2 86824]
S3 s1018mdfl;Sony Ericsson Device 1018 USB WMC Modem Filter;c:\windows\system32\drivers\s1018mdfl.sys [2011-5-2 15016]
S3 s1018mdm;Sony Ericsson Device 1018 USB WMC Modem Driver;c:\windows\system32\drivers\s1018mdm.sys [2011-5-2 114728]
S3 s1018mgmt;Sony Ericsson Device 1018 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s1018mgmt.sys [2011-5-2 106208]
S3 s1018nd5;Sony Ericsson Device 1018 USB Ethernet Emulation (NDIS);c:\windows\system32\drivers\s1018nd5.sys [2011-5-2 26024]
S3 s1018obex;Sony Ericsson Device 1018 USB WMC OBEX Interface;c:\windows\system32\drivers\s1018obex.sys [2011-5-2 104744]
S3 s1018unic;Sony Ericsson Device 1018 USB Ethernet Emulation (WDM);c:\windows\system32\drivers\s1018unic.sys [2011-5-2 109864]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
.
=============== Created Last 30 ================
.
2012-09-25 11:00:40 6980552 —-a-w- c:\programdata\microsoft\windows defender\definition updates\{ce9a14cf-df24-4342-bfdf-a929d4778b07}\mpengine.dll
.
==================== Find3M ====================
.
2012-09-20 17:43:19 73136 —-a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2012-09-20 17:43:19 696240 —-a-w- c:\windows\system32\FlashPlayerApp.exe
2012-08-28 19:24:56 477168 —-a-w- c:\windows\system32\npdeployJava1.dll
2012-08-28 19:24:53 473072 —-a-w- c:\windows\system32\deployJava1.dll
2012-08-24 06:59:17 1800704 —-a-w- c:\windows\system32\jscript9.dll
2012-08-24 06:51:27 1129472 —-a-w- c:\windows\system32\wininet.dll
2012-08-24 06:51:02 1427968 —-a-w- c:\windows\system32\inetcpl.cpl
2012-08-24 06:47:26 142848 —-a-w- c:\windows\system32\ieUnatt.exe
2012-08-24 06:47:12 420864 —-a-w- c:\windows\system32\vbscript.dll
2012-08-24 06:43:58 2382848 —-a-w- c:\windows\system32\mshtml.tlb
2012-07-29 19:52:38 65848 —-a-w- c:\windows\system32\drivers\RapportKELL.sys
2012-07-04 14:02:46 2047488 —-a-w- c:\windows\system32\win32k.sys
.
============= FINISH: 20:35:25.15 ===============
Hello St3liz and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:
  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested

I am looking at your log now and will reply with instructions shortly.

Satchfan
Hi again

I see nothing immediately but while I have a better look please run a couple more scans that might help to shed some light on the problem.

Run Farbar Service Scanner

Please download Farbar Service Scanner and run it on the computer with the issue.
  • make sure the following options are checked:
    • Internet Services
    • Windows Firewallsfc
    • System Restore
    • Security Center
    • Windows Update
  • press "Scan".
  • it will create a log (FSS.txt) in the same directory the tool is run.
  • please copy and paste the log to your reply.
===================================================

Run aswMBR
  • download aswMBR.exe to your desktop.
  • double click the aswMBR.exe to run it
  • if asked, accept the AVAST virus definition download
  • click the "Scan" button to start scan
  • on completion of the scan click Save log, save it to your desktop and post in your next reply
Logs to include with next post:

FSS.txt
aswMBR log


Could you also send the Attach.txt log that was produced when you ran DDS.

Thanks

Satchfan
Hi Satchfan, thanks for the help, here are the logs. . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 26/03/2008 22:07:34 System Uptime: 25/09/2012 18:27:23 (2 hours ago) . Motherboard: Dell Inc. | | 0HX769 Processor: Intel® Celeron® CPU 550 @ 2.00GHz | Microprocessor | 1995/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 136 GiB total, 83.969 GiB free. D: is FIXED (NTFS) - 10 GiB total, 4.787 GiB free. E: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP351: 03/08/2012 19:12:15 - Windows Update RP352: 07/08/2012 16:50:52 - Windows Update RP354: 09/08/2012 17:00:21 - Installed Rapport RP355: 10/08/2012 20:49:47 - Windows Update RP356: 15/08/2012 20:49:20 - Windows Update RP357: 16/08/2012 16:04:52 - Windows Update RP358: 21/08/2012 20:53:15 - Windows Update RP359: 21/08/2012 20:59:44 - Removed Dell Support Center. RP360: 21/08/2012 21:08:12 - Removed IMinent Toolbar RP361: 27/08/2012 21:15:15 - Windows Update RP362: 31/08/2012 20:11:02 - Windows Update RP363: 04/09/2012 20:57:45 - Windows Update RP364: 10/09/2012 20:40:41 - Scheduled Checkpoint RP365: 11/09/2012 19:17:31 - Windows Update RP366: 12/09/2012 18:37:54 - Windows Update RP367: 13/09/2012 18:37:22 - Installed Java™ 6 Update 35 RP368: 18/09/2012 16:36:58 - Windows Update RP369: 22/09/2012 14:20:52 - Windows Update RP370: 23/09/2012 16:22:04 - Windows Update . ==== Installed Programs ====================== . Adobe Flash Player 11 ActiveX Adobe Reader 8.1.0 Adobe Shockwave Player 11.6 µTorrent Avanquest update avast! Free Antivirus Broadcom Management Programs Compatibility Pack for the 2007 Office system Conexant HDA D330 MDC V.92 Modem Dell Support Center Dell Touchpad Digital Line Detect Free M4a to MP3 Converter 6.2 Google Chrome Google Desktop Google Toolbar for Internet Explorer Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel® PROSet/Wireless Software Java Auto Updater Java™ 6 Update 35 Java™ SE Runtime Environment 6 mCore Media Go MediaDirect mHelp Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 4 Client Profile Microsoft Office PowerPoint Viewer 2007 (English) Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Works mMHouse Modem Diagnostic Tool mPfMgr MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) mWMI NetWaiting OutlookAddinSetup QuickSet QuickTime Rapport Roxio Creator Audio Roxio Creator BDAV Plugin Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler Roxio MyDVD DE Roxio Update Manager Security Update for Microsoft .NET Framework 3.5 SP1 (KB2604111) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2657424) Security Update for Microsoft .NET Framework 4 Client Profile (KB2446708) Security Update for Microsoft .NET Framework 4 Client Profile (KB2478663) Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2539636) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2604121) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368v2) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656405) Security Update for Microsoft .NET Framework 4 Client Profile (KB2686827) Skype Click to Call Skype™ 5.9 Sonic Activation Module SpywareBlaster 4.4 swMSM Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) User's Guides . ==== Event Viewer Messages From Past Week ======== . 25/09/2012 19:02:13, Error: bowser [8003] - The master browser has received a server announcement from the computer STELIZ-LAPTOP that believes that it is the master browser for the domain on transport NetBT_Tcpip_{C75EBECB-99C2-48D0-8BC0-F613. The master browser is stopping or an election is being forced. 25/09/2012 16:24:13, Error: Microsoft-Windows-Dhcp-Client [1001] - Your computer was not assigned an address from the network (by the DHCP Server) for the Network Card with network address 001F3C2CAC3F. The following error occurred: The operation was canceled by the user.. Your computer will continue to try and obtain an address on its own from the network address (DHCP) server. 25/09/2012 11:58:07, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Windows Media Player Network Sharing Service service to connect. 25/09/2012 11:58:07, Error: Service Control Manager [7000] - The Windows Media Player Network Sharing Service service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 24/09/2012 18:22:46, Error: Service Control Manager [7000] - The Google Update Service (gupdate) service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion. 24/09/2012 18:22:45, Error: Service Control Manager [7009] - A timeout was reached (30000 milliseconds) while waiting for the Google Update Service (gupdate) service to connect. 24/09/2012 18:22:42, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1053" attempting to start the service gupdate with arguments "/comsvc" in order to run the server: {4EB61BAC-A3B6-4760-9581-655041EF4D69} . ==== End Of File =========================== aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software Run date: 2012-09-25 22:10:12 —————————– 22:10:12.767 OS Version: Windows 6.0.6002 Service Pack 2 22:10:12.767 Number of processors: 1 586 0x1601 22:10:12.767 ComputerName: LIZBETH-PC UserName: Lizbeth 22:10:14.731 Initialize success 22:10:15.006 AVAST engine defs: 12092501 22:11:17.480 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 22:11:17.480 Disk 0 Vendor: ST916082 3.CD Size: 152627MB BusType: 3 22:11:17.496 Disk 0 MBR read successfully 22:11:17.511 Disk 0 MBR scan 22:11:17.511 Disk 0 Windows VISTA default MBR code 22:11:17.511 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 117 MB offset 63 22:11:17.527 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 10240 MB offset 241664 22:11:17.543 Disk 0 Partition 3 80 (A) 07 HPFS/NTFS NTFS 139707 MB offset 21213184 22:11:17.543 Disk 0 Partition - 00 0F Extended LBA 2560 MB offset 307335168 22:11:17.621 Disk 0 Partition 4 00 DD MSDOS5.0 2559 MB offset 307337216 22:11:17.652 Disk 0 scanning sectors +312578048 22:11:17.761 Disk 0 scanning C:\Windows\system32\drivers 22:11:29.305 Service scanning 22:11:59.101 Modules scanning 22:12:31.221 Disk 0 trace - called modules: 22:12:31.315 ntkrnlpa.exe CLASSPNP.SYS disk.sys iastor.sys hal.dll 22:12:31.315 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x8936bac8] 22:12:31.331 3 CLASSPNP.SYS[8b9b58b3] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-0[0x883be030] 22:13:07.819 AVAST engine scan C:\Windows 22:13:14.340 AVAST engine scan C:\Windows\system32 22:17:13.566 AVAST engine scan C:\Windows\system32\drivers 22:17:38.994 AVAST engine scan C:\Users\Lizbeth 22:19:48.989 Disk 0 MBR has been saved successfully to "C:\Users\Lizbeth\Desktop\MBR.dat" 22:19:49.004 The log file has been saved successfully to "C:\Users\Lizbeth\Desktop\aswMBR.txt" Farbar Service Scanner Version: 19-09-2012 Ran by [removed] (administrator) on 25-09-2012 at 22:31:06 Running from "C:\Users\Lizbeth\Downloads" Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo IP is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Security Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Other Services: ============== File Check: ======== C:\Windows\system32\nsisvc.dll => MD5 is legit C:\Windows\system32\Drivers\nsiproxy.sys => MD5 is legit C:\Windows\system32\dhcpcsvc.dll => MD5 is legit C:\Windows\system32\Drivers\afd.sys => MD5 is legit C:\Windows\system32\Drivers\tdx.sys => MD5 is legit C:\Windows\system32\Drivers\tcpip.sys => MD5 is legit C:\Windows\system32\dnsrslvr.dll => MD5 is legit C:\Windows\system32\mpssvc.dll => MD5 is legit C:\Windows\system32\bfe.dll => MD5 is legit C:\Windows\system32\Drivers\mpsdrv.sys => MD5 is legit C:\Windows\system32\SDRSVC.dll => MD5 is legit C:\Windows\system32\vssvc.exe => MD5 is legit C:\Windows\system32\wscsvc.dll => MD5 is legit C:\Windows\system32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\system32\wuaueng.dll => MD5 is legit C:\Windows\system32\qmgr.dll => MD5 is legit C:\Windows\system32\es.dll => MD5 is legit C:\Windows\system32\cryptsvc.dll => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit **** End of log **** Thanks
Thanks for the logs.

I'm not sure this is a malware issue but before asking for another scan to make sure, I’d like you to check something.

Click on Control Panel -> Administrative Tools -> Services.

Scroll down to Computer Browser and let me know what it says under “Startup Type”

Can you also tell me if this is a company computer or a home computer on a private network.

BTW, I'm in the UK and it's late now so I won't reply until tomorrow..

Satchfan
Hi, Start Up Type is set to 'Automatic'. This is a home laptop on a private network with one other laptop, both wireless. One laptop (mine) has no issues but the other (my wife's) slows down and regularly but only temporarily loses its internet connection particularly when on sites such as facebook and bbc iplayer. I am also in the UK. St3liz
Hi

Something worth mentioning:

P2P - I see you have P2P software, (uTorrent), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to the situation.

Please note: even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these days, are more often than not, infected. The bad guys use P2P file-sharing as a major vehicle to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Programs, and then Programs and Features.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

Some things that are affecting computer speed and eating up resources

First

Click on Control Panel -> Administrative Tools -> Services.

Scroll down to Computer Browser and double-click on it. Change the “Startup Type” to Manual

Keep this window open.

Next

There are two processes running that can take up to 30% of processor usage at times: this may also be affecting usage.

Still in the "Services" window, scroll down to Windows Search and double-click on it. Change the “Startup Type” to Automatic (Delayed Start)l

Let me know if there are any changes. If not, we’ll have to run a couple more scans.

Satchfan
Hi St3liz It has been a few days since I replied with instructions to help diagnose your computer problems. Please let me know if you are having problems and still need help. Thanks Satchfan
Hi, I made the changes you suggested and this has definitely made the boot time quicker. However, I a still having issues with the internet disconnections. I have looked at my network centre when the disconnection happens and it indicates it is between the router and the outside but it doesn't disconnect long enough to allow me to perform a diagnosis of the problem. I have tried to establish a common denominator when the problem occurs and I think it something to do with the facebook website. My wife plays games on it and it is during this that the disconnections most often occur. This may be a common scenario shared by many people, I don't know. Hopefully not and there is something that can be done about it. St3liz
I'm glad that your computer is a bit quicker.

I can't find any malware on this system and according to the scan that we ran to check your Internet connection, there doesn't appear to be a problem there either.

I don't know enough about the Internet and know even less about Facebook as I don't use it :)

I would suggest that you start a topic in our Browsers, Internet and email forum and see if they can shed some light on it.

Please let me know what you want to do and if you want me to keep this topic open..

Thanks

Satchfan
:thumbup: Good luck and if you srill have problems after visiting rhe other forum, open a new ropic here and we'll have another look. Regards Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI