Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Not sure if i have a virus or something  (Read 27026 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Not sure if i have a virus or something
« Reply #15 on: April 19, 2012, 12:09:38 PM »
Ok. First, we'll work on the internet connection problem which will probably solve the other problem.

Please download MiniToolBox to Desktop and run it.



Checkmark the following boxes:

    • Flush DNS
    • Report IE Proxy Settings
    • Reset IE Proxy Settings
    • List content of Hosts
    • List IP Configuration
    • Lst Last 10 Event Viewer Errors
    • List Users, Partitions and Memory Size
    • [/b]
    Click Go and copy/paste the log (Result.txt) into your next post.
    *************************************************************
    Please download Farbar Service Scanner and run it on the computer with the issue.
    • Press "Scan".
    • It will create a log (FSS.txt) in the same directory the tool is run.
    • Please copy and paste the log to your reply.
    Windows 8 and Windows 10 dual boot with two SSD's

    michalpaladin

      Topic Starter


      Rookie

      • Experience: Familiar
      • OS: Windows 7
      Re: Not sure if i have a virus or something
      « Reply #16 on: April 19, 2012, 06:40:00 PM »
      MiniToolBox by Farbar  Version: 18-01-2012
      Ran by Michal (administrator) on 19-04-2012 at 19:38:49
      Windows 7 Ultimate  (X64)
      Boot Mode: Normal
      ***************************************************************************

      ========================= Flush DNS: ===================================

      Windows IP Configuration

      Successfully flushed the DNS Resolver Cache.

      ========================= IE Proxy Settings: ==============================

      Proxy is not enabled.
      No Proxy Server is set.

      "Reset IE Proxy Settings": IE Proxy Settings were reset.
      ========================= Hosts content: =================================

      127.0.0.1       localhost

      ========================= IP Configuration: ================================



      # ----------------------------------
      # IPv4 Configuration
      # ----------------------------------
      pushd interface ipv4

      reset
      set global


      popd
      # End of IPv4 configuration



      Windows IP Configuration

         Host Name . . . . . . . . . . . . : Michal-PC
         Primary Dns Suffix  . . . . . . . :
         Node Type . . . . . . . . . . . . : Hybrid
         IP Routing Enabled. . . . . . . . : No
         WINS Proxy Enabled. . . . . . . . : No

      Ethernet adapter Local Area Connection:

         Connection-specific DNS Suffix  . :
         Description . . . . . . . . . . . : Realtek PCIe GBE Family Controller
         Physical Address. . . . . . . . . : 1C-6F-65-44-BD-7C
         DHCP Enabled. . . . . . . . . . . : Yes
         Autoconfiguration Enabled . . . . : Yes
         Link-local IPv6 Address . . . . . : fe80::49dc:6bd9:c334:af66%13(Preferred)
         IPv4 Address. . . . . . . . . . . : 192.168.0.14(Preferred)
         Subnet Mask . . . . . . . . . . . : 255.255.255.0
         Lease Obtained. . . . . . . . . . : Thursday, April 19, 2012 11:53:21 AM
         Lease Expires . . . . . . . . . . : Friday, April 20, 2012 2:22:41 PM
         Default Gateway . . . . . . . . . : 192.168.0.1
         DHCP Server . . . . . . . . . . . : 192.168.0.1
         DHCPv6 IAID . . . . . . . . . . . : 320630629
         DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-16-28-B3-BF-1C-6F-65-44-BD-7C
         DNS Servers . . . . . . . . . . . : 209.18.47.61
                                             209.18.47.62
         NetBIOS over Tcpip. . . . . . . . : Enabled

      Tunnel adapter isatap.{AB9A3967-9594-4881-8F89-5FD219C10889}:

         Media State . . . . . . . . . . . : Media disconnected
         Connection-specific DNS Suffix  . :
         Description . . . . . . . . . . . : Microsoft ISATAP Adapter
         Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
         DHCP Enabled. . . . . . . . . . . : No
         Autoconfiguration Enabled . . . . : Yes

      Tunnel adapter Teredo Tunneling Pseudo-Interface:

         Media State . . . . . . . . . . . : Media disconnected
         Connection-specific DNS Suffix  . :
         Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
         Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
         DHCP Enabled. . . . . . . . . . . : No
         Autoconfiguration Enabled . . . . : Yes
      Server:  dns-cac-lb-01.rr.com
      Address:  209.18.47.61

      Name:    google.com
      Addresses:  74.125.228.64
           74.125.228.65
           74.125.228.66
           74.125.228.67
           74.125.228.68
           74.125.228.69
           74.125.228.70
           74.125.228.71
           74.125.228.72
           74.125.228.73
           74.125.228.78


      Pinging google.com [72.14.204.138] with 32 bytes of data:
      Reply from 72.14.204.138: bytes=32 time=36ms TTL=54
      Reply from 72.14.204.138: bytes=32 time=23ms TTL=54

      Ping statistics for 72.14.204.138:
          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
      Approximate round trip times in milli-seconds:
          Minimum = 23ms, Maximum = 36ms, Average = 29ms
      Server:  dns-cac-lb-01.rr.com
      Address:  209.18.47.61

      Name:    yahoo.com
      Addresses:  98.139.183.24
           209.191.122.70
           72.30.38.140


      Pinging yahoo.com [209.191.122.70] with 32 bytes of data:
      Reply from 209.191.122.70: bytes=32 time=76ms TTL=51
      Reply from 209.191.122.70: bytes=32 time=59ms TTL=51

      Ping statistics for 209.191.122.70:
          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
      Approximate round trip times in milli-seconds:
          Minimum = 59ms, Maximum = 76ms, Average = 67ms
      Server:  dns-cac-lb-01.rr.com
      Address:  209.18.47.61

      Name:    bleepingcomputer.com
      Address:  208.43.87.2


      Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:
      Reply from 208.43.87.2: Destination host unreachable.
      Reply from 208.43.87.2: Destination host unreachable.

      Ping statistics for 208.43.87.2:
          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

      Pinging 127.0.0.1 with 32 bytes of data:
      Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
      Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

      Ping statistics for 127.0.0.1:
          Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
      Approximate round trip times in milli-seconds:
          Minimum = 0ms, Maximum = 0ms, Average = 0ms
      ===========================================================================
      Interface List
       13...1c 6f 65 44 bd 7c ......Realtek PCIe GBE Family Controller
        1...........................Software Loopback Interface 1
       11...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter
       12...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
      ===========================================================================

      IPv4 Route Table
      ===========================================================================
      Active Routes:
      Network Destination        Netmask          Gateway       Interface  Metric
                0.0.0.0          0.0.0.0      192.168.0.1     192.168.0.14     20
              127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
              127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
        127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
            192.168.0.0    255.255.255.0         On-link      192.168.0.14    276
           192.168.0.14  255.255.255.255         On-link      192.168.0.14    276
          192.168.0.255  255.255.255.255         On-link      192.168.0.14    276
              224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
              224.0.0.0        240.0.0.0         On-link      192.168.0.14    276
        255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
        255.255.255.255  255.255.255.255         On-link      192.168.0.14    276
      ===========================================================================
      Persistent Routes:
        None

      IPv6 Route Table
      ===========================================================================
      Active Routes:
       If Metric Network Destination      Gateway
        1    306 ::1/128                  On-link
       13    276 fe80::/64                On-link
       13    276 fe80::49dc:6bd9:c334:af66/128
                                          On-link
        1    306 ff00::/8                 On-link
       13    276 ff00::/8                 On-link
      ===========================================================================
      Persistent Routes:
        None

      ========================= Event log errors: ===============================

      Application errors:
      ==================
      Error: (04/19/2012 07:42:32 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:38:31 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:34:29 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:30:27 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:26:26 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:22:25 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:18:23 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:14:21 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:10:19 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:06:17 PM) (Source: Windows Search Service) (User: )
      Description: Unable to initialize the filter host process. Terminating.

      Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)


      System errors:
      =============
      Error: (04/19/2012 11:56:55 AM) (Source: WMPNetworkSvc) (User: )
      Description: WMPNetworkSvc0x80004002

      Error: (04/19/2012 11:56:53 AM) (Source: Service Control Manager) (User: )
      Description: The Background Intelligent Transfer Service service depends on the COM+ Event System service which failed to start because of the following error:
      %%0

      Error: (04/19/2012 11:56:53 AM) (Source: DCOM) (User: )
      Description: 1068BITS{4991D34B-80A1-4291-83B6-3328366B9097}

      Error: (04/19/2012 11:54:49 AM) (Source: Service Control Manager) (User: )
      Description: The Internet Connection Sharing (ICS) service hung on starting.

      Error: (04/19/2012 11:53:20 AM) (Source: Service Control Manager) (User: )
      Description: The System Event Notification Service service depends on the COM+ Event System service which failed to start because of the following error:
      %%0

      Error: (04/19/2012 11:53:19 AM) (Source: EventLog) (User: )
      Description: The previous system shutdown at 11:49:35 AM on ?4/?19/?2012 was unexpected.

      Error: (04/19/2012 11:51:01 AM) (Source: Service Control Manager) (User: )
      Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.

      Error: (04/19/2012 11:50:31 AM) (Source: Service Control Manager) (User: )
      Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.

      Error: (04/19/2012 11:50:01 AM) (Source: Service Control Manager) (User: )
      Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.

      Error: (04/19/2012 11:49:31 AM) (Source: Service Control Manager) (User: )
      Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WerSvc service.


      Microsoft Office Sessions:
      =========================
      Error: (04/19/2012 07:42:32 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:38:31 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:34:29 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:30:27 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:26:26 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:22:25 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:18:23 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:14:21 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:10:19 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)

      Error: (04/19/2012 07:06:17 PM) (Source: Windows Search Service)(User: )
      Description: Details:
         This operation returned because the timeout period expired.  (HRESULT : 0x800705b4) (0x800705b4)


      ========================= Memory info: ===================================

      Percentage of memory in use: 26%
      Total physical RAM: 3959.49 MB
      Available physical RAM: 2905.25 MB
      Total Pagefile: 7917.13 MB
      Available Pagefile: 6296.39 MB
      Total Virtual: 4095.88 MB
      Available Virtual: 3970.79 MB

      ========================= Partitions: =====================================

      1 Drive c: () (Fixed) (Total:97.56 GB) (Free:23.37 GB) NTFS
      2 Drive d: () (Fixed) (Total:99.61 GB) (Free:99.39 GB) NTFS
      3 Drive e: () (Fixed) (Total:734.25 GB) (Free:733.21 GB) NTFS

      ========================= Users: ========================================

      User accounts for \\MICHAL-PC

      Administrator            Guest                    Michal                   


      **** End of log ****






      Farbar Service Scanner Version: 16-04-2012
      Ran by Michal (administrator) on 19-04-2012 at 20:40:24
      Running from "C:\Users\Michal\Desktop"
      Windows 7 Ultimate  (X64)
      Boot Mode: Normal
      ****************************************************************

      Internet Services:
      ============

      Connection Status:
      ==============
      Localhost is accessible.
      LAN connected.
      Google IP is accessible.
      Yahoo IP is accessible.


      File Check:
      ========
      C:\Windows\System32\nsisvc.dll => MD5 is legit
      C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit
      C:\Windows\System32\dhcpcore.dll => MD5 is legit
      C:\Windows\System32\drivers\afd.sys
      [2012-03-24 12:05] - [2011-12-27 23:59] - 0499200 ____A (Microsoft Corporation) DB9D6C6B2CD95A9CA414D045B627422E

      C:\Windows\System32\drivers\tdx.sys => MD5 is legit
      C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit
      C:\Windows\System32\dnsrslvr.dll => MD5 is legit
      C:\Windows\System32\svchost.exe => MD5 is legit
      C:\Windows\System32\rpcss.dll => MD5 is legit


      **** End of log ****

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Not sure if i have a virus or something
      « Reply #17 on: April 20, 2012, 12:14:17 PM »
      Quote
      But I can still access the Internet, although any type of video from Youtube, Facebook etc. is extremely choppy, not even watchable.
      That would indicate a lack of enough memory. Please run the program below. It's supposed to fix a number of problems.

      Please download and run MS Fix-it from here.

      There is a program in Windows 7 that is specifically made to diagnose and repair problems with Windows updates. Could you please run it?
      Windows 8 and Windows 10 dual boot with two SSD's

      michalpaladin

        Topic Starter


        Rookie

        • Experience: Familiar
        • OS: Windows 7
        Re: Not sure if i have a virus or something
        « Reply #18 on: April 23, 2012, 05:25:50 PM »
        I keep getting an error when trying to run Fix It  >:(

        There is a program in Windows 7 that is specifically made to diagnose and repair problems with Windows updates. Could you please run it?


        I'm no sure what this is either   ???

        Yeah I'm clueless.

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Not sure if i have a virus or something
        « Reply #19 on: April 24, 2012, 11:44:58 AM »
        Can you please try running Action Center?
        Windows 8 and Windows 10 dual boot with two SSD's