Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Sluggish, can't find malware, Vista OS, OTL log include


  • Please log in to reply

#76
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
Actually you appear to have already found the cause of the high WmiPrvSE.exe so you can stop unchecking things. You will see that WmiPrvSE.exe has dropped off the map. I am curious about the

svchost.exe 496 29.23 131,760 K 140,468 K Host Process for Windows Services Microsoft Corporation

If you let it sit for a minute or two then run another process explorer log does it appear to go back down? If it stays up can you right click on it or maybe just hover over it and it should tell you more about what it is.
  • 0

Advertisements


#77
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
:) :unsure: :yes: I have no idea which one you are referring to..these things keep jumping around changing places and there are a bunch of svchost.exe now...


here's the last procep...
Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 84.95 0 K 24 K
WmiPrvSE.exe 3928 6.95 8,692 K 15,452 K WMI Provider Host Microsoft Corporation
dwm.exe 1584 3.09 38,068 K 34,500 K Desktop Window Manager Microsoft Corporation
procexp64.exe 3672 2.32 22,232 K 33,212 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
svchost.exe 556 0.77 31,856 K 44,948 K Host Process for Windows Services Microsoft Corporation
Interrupts n/a 0.77 0 K 0 K Hardware Interrupts and DPCs
plugin-container.exe 4668 < 0.01 14,972 K 19,352 K Plugin Container for Firefox Mozilla Corporation
firefox.exe 4356 < 0.01 137,708 K 150,924 K Firefox Mozilla Corporation
System 4 < 0.01 0 K 5,376 K
csrss.exe 668 < 0.01 3,676 K 7,732 K Client Server Runtime Process Microsoft Corporation
spoolsv.exe 2200 < 0.01 9,880 K 18,096 K Spooler SubSystem App Microsoft Corporation
igfxsrvc.exe 1916 < 0.01 2,916 K 6,940 K igfxsrvc Module Intel Corporation
svchost.exe 1344 < 0.01 19,740 K 21,524 K Host Process for Windows Services Microsoft Corporation
PanelApp.exe 1996 < 0.01 21,184 K 31,520 K
lsass.exe 716 < 0.01 5,624 K 12,716 K Local Security Authority Process Microsoft Corporation
ApMsgFwd.exe 3204 < 0.01 2,052 K 4,256 K ApMsgFwd Alps Electric Co., Ltd.
explorer.exe 1664 < 0.01 31,072 K 48,304 K Windows Explorer Microsoft Corporation
sttray64.exe 1840 < 0.01 9,444 K 18,040 K IDT PC Audio IDT, Inc.
AvastUI.exe 1232 < 0.01 6,300 K 4,128 K avast! Antivirus AVAST Software
wlanext.exe 1544 < 0.01 2,940 K 7,028 K Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation
hkcmd.exe 1828 < 0.01 3,080 K 7,056 K hkcmd Module Intel Corporation
svchost.exe 988 < 0.01 5,856 K 9,768 K Host Process for Windows Services Microsoft Corporation
AvastSvc.exe 1524 < 0.01 27,528 K 31,040 K avast! Service AVAST Software
svchost.exe 1168 < 0.01 11,696 K 19,044 K Host Process for Windows Services Microsoft Corporation
Apoint.exe 1808 < 0.01 4,032 K 9,516 K Alps Pointing-device Driver Alps Electric Co., Ltd.
svchost.exe 3704 < 0.01 4,784 K 8,668 K Host Process for Windows Services Microsoft Corporation
svchost.exe 472 < 0.01 108,900 K 117,544 K Host Process for Windows Services Microsoft Corporation
taskeng.exe 2296 < 0.01 11,560 K 14,760 K Task Scheduler Engine Microsoft Corporation
wmpnscfg.exe 1896 3,104 K 7,648 K Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
WmiPrvSE.exe 4544 4,136 K 7,540 K WMI Provider Host Microsoft Corporation
WLIDSVCM.EXE 3428 2,112 K 4,320 K Microsoft® Windows Live ID Service Monitor Microsoft Corp.
WLIDSVC.EXE 3140 9,092 K 16,720 K Microsoft® Windows Live ID Service Microsoft Corp.
winlogon.exe 804 3,284 K 7,936 K Windows Logon Application Microsoft Corporation
wininit.exe 648 2,328 K 5,848 K Windows Start-Up Application Microsoft Corporation
taskeng.exe 2144 3,328 K 8,344 K Task Scheduler Engine Microsoft Corporation
svchost.exe 400 17,008 K 17,160 K Host Process for Windows Services Microsoft Corporation
svchost.exe 296 74,164 K 42,628 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2840 6,596 K 10,900 K Host Process for Windows Services Microsoft Corporation
svchost.exe 916 4,384 K 8,584 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2224 19,812 K 25,692 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2904 4,084 K 8,372 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1656 3,584 K 7,600 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2020 2,796 K 7,276 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2852 6,728 K 11,844 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1788 5,156 K 8,868 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1112 3,232 K 6,748 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2312 1,876 K 4,516 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1992 1,756 K 4,120 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1156 1,620 K 3,460 K Host Process for Windows Services Microsoft Corporation
sqlwriter.exe 1696 4,884 K 9,512 K SQL Server VSS Writer - 64 Bit Microsoft Corporation
sqlservr.exe 3068 44,712 K 2,432 K SQL Server Windows NT Microsoft Corporation
sqlbrowser.exe 2772 1,828 K 5,032 K SQL Browser Service EXE Microsoft Corporation
smss.exe 544 496 K 1,028 K Windows Session Manager Microsoft Corporation
SLsvc.exe 1128 8,560 K 13,440 K Microsoft Software Licensing Service Microsoft Corporation
services.exe 704 3,792 K 8,892 K Services and Controller app Microsoft Corporation
SeaPort.exe 2496 5,968 K 10,240 K Microsoft SeaPort Search Enhancement Broker Microsoft Corporation
rundll32.exe 3944 3,088 K 4,336 K Windows host process (Rundll32) Microsoft Corporation
procexp.exe 1728 3,792 K 9,672 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
mscorsvw.exe 1188 4,736 K 8,556 K .NET Runtime Optimization Service Microsoft Corporation
lsm.exe 724 3,544 K 5,896 K Local Session Manager Service Microsoft Corporation
inetinfo.exe 3044 11,636 K 19,568 K Internet Information Services Microsoft Corporation
ehtray.exe 1852 2,852 K 2,104 K Media Center Tray Applet Microsoft Corporation
ehmsas.exe 2024 2,528 K 6,404 K Media Center Media Status Aggregator Service Microsoft Corporation
csrss.exe 612 2,828 K 7,476 K Client Server Runtime Process Microsoft Corporation
audiodg.exe 1064 13,856 K 17,068 K Windows Audio Device Graph Isolation Microsoft Corporation
ApntEx.exe 1576 2,916 K 5,824 K Alps Pointing-device Driver for Windows NT/2000/XP/Vista Alps Electric Co., Ltd.
  • 0

#78
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
Desktop doesn't show any problems other than Norton/Symantec which is a real resource hog.

Let's run Combofix on it and see if we see anything.

:!: If you have a previous version of Combofix.exe, delete it and download a fresh copy. :!:

:!: It must be saved to your desktop, do not run it :!:

:!: Disable your Antivirus software when downloading or running Combofix. If it has Script Blocking features, please disable these as well. See: http://www.bleepingc...opic114351.html


Download and Save this file -- to your Desktop -- from either of these two sources:
http://download.blee...Bs/ComboFix.exe
http://subs.geekstogo.com/ComboFix.exe

Rightclick on ComboFix and select Run As Administrator to start the program.



* :!: Important: Have no other programs running. Your Task Bar should be clear of any program entries including your Browser.


* A window may open with a series of Disclaimers. Accept the Disclaimers to start the fix. Allow it to install the Recovery Console then Continue. When the scan completes Notepad will open with with your results log open. Do a File, Exit and answer 'Yes' to save changes.


A caution - Do not run Combofix more than once. Do not touch your mouse/keyboard until the scan has completed, as this may cause the process to stall or your computer to lock. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop. Even when ComboFix appears to be doing nothing, look at your Drive light. If it is flashing, Combofix is still at work.

A file will be created at => C:\Combofix.txt. I'll need to see that in your reply.



Also Vino's:
1. Please download the Event Viewer Tool by Vino Rosso
http://images.malwar...om/vino/VEW.exe
and save it to your Desktop:
2. Right-click VEW.exe (Run As Administrator)
3. Under 'Select log to query', select:

* System
4. Under 'Select type to list', select:
* Error
* Warning


Then use the 'Number of events' as follows:


1. Click the radio button for 'Number of events'
Type 20 in the 1 to 20 box
Then click the Run button.
Notepad will open with the output log.

and Processes Explorer:

Get Process Explorer

http://live.sysinter...com/procexp.exe

Save it to your desktop then run it (Vista or Win7 - right click and Run As Administrator). Click once or twice on the CPU column header to sort things by CPU usage with the big hitters at the top. File, Save As, Save. Open the file Procexp.txt on your desktop and copy and paste the text to a reply.
  • 0

#79
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
LAPTOP
ok I rebooted and ran it again and here's what I got...
Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 55.38 0 K 24 K
svchost.exe 412 28.46 130,932 K 139,860 K Host Process for Windows Services Microsoft Corporation
WmiPrvSE.exe 3852 3.85 8,336 K 13,432 K WMI Provider Host Microsoft Corporation
System 4 2.31 0 K 5,384 K
svchost.exe 264 2.31 76,896 K 40,104 K Host Process for Windows Services Microsoft Corporation
procexp64.exe 3684 2.31 22,244 K 33,064 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
dwm.exe 1588 2.31 36,012 K 31,680 K Desktop Window Manager Microsoft Corporation
Interrupts n/a 1.54 0 K 0 K Hardware Interrupts and DPCs
svchost.exe 492 0.77 26,156 K 40,200 K Host Process for Windows Services Microsoft Corporation
csrss.exe 668 0.77 3,452 K 8,888 K Client Server Runtime Process Microsoft Corporation
igfxsrvc.exe 1952 < 0.01 2,844 K 6,676 K igfxsrvc Module Intel Corporation
ApMsgFwd.exe 1924 < 0.01 2,044 K 4,232 K ApMsgFwd Alps Electric Co., Ltd.
PanelApp.exe 1908 < 0.01 19,340 K 26,280 K
svchost.exe 1292 < 0.01 18,788 K 19,960 K Host Process for Windows Services Microsoft Corporation
sttray64.exe 1804 < 0.01 9,444 K 17,928 K IDT PC Audio IDT, Inc.
lsass.exe 716 < 0.01 5,512 K 12,488 K Local Security Authority Process Microsoft Corporation
svchost.exe 984 < 0.01 5,316 K 9,300 K Host Process for Windows Services Microsoft Corporation
explorer.exe 1656 < 0.01 31,232 K 48,792 K Windows Explorer Microsoft Corporation
hkcmd.exe 1796 < 0.01 2,928 K 6,880 K hkcmd Module Intel Corporation
AvastSvc.exe 1428 < 0.01 19,192 K 18,532 K avast! Service AVAST Software
wlanext.exe 1452 < 0.01 3,096 K 7,132 K Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation
AvastUI.exe 1248 < 0.01 6,368 K 4,008 K avast! Antivirus AVAST Software
svchost.exe 1152 < 0.01 11,236 K 18,524 K Host Process for Windows Services Microsoft Corporation
services.exe 704 < 0.01 3,736 K 8,792 K Services and Controller app Microsoft Corporation
csrss.exe 612 < 0.01 2,696 K 7,320 K Client Server Runtime Process Microsoft Corporation
Apoint.exe 1788 < 0.01 4,016 K 9,504 K Alps Pointing-device Driver Alps Electric Co., Ltd.
svchost.exe 2796 < 0.01 6,836 K 11,820 K Host Process for Windows Services Microsoft Corporation
lsm.exe 724 < 0.01 3,572 K 5,932 K Local Session Manager Service Microsoft Corporation
svchost.exe 332 < 0.01 15,356 K 13,692 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3964 < 0.01 4,824 K 8,652 K Host Process for Windows Services Microsoft Corporation
taskeng.exe 2252 < 0.01 11,368 K 13,980 K Task Scheduler Engine Microsoft Corporation
SeaPort.exe 2524 < 0.01 6,204 K 10,264 K Microsoft SeaPort Search Enhancement Broker Microsoft Corporation
spoolsv.exe 2156 < 0.01 8,604 K 15,504 K Spooler SubSystem App Microsoft Corporation
wmpnscfg.exe 2648 3,060 K 7,336 K Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
WmiPrvSE.exe 2384 4,156 K 7,732 K WMI Provider Host Microsoft Corporation
WLIDSVCM.EXE 3556 2,108 K 4,284 K Microsoft® Windows Live ID Service Monitor Microsoft Corp.
WLIDSVC.EXE 3160 8,964 K 16,532 K Microsoft® Windows Live ID Service Microsoft Corp.
winlogon.exe 796 3,368 K 8,000 K Windows Logon Application Microsoft Corporation
wininit.exe 648 2,324 K 5,860 K Windows Start-Up Application Microsoft Corporation
taskeng.exe 2172 3,364 K 8,336 K Task Scheduler Engine Microsoft Corporation
svchost.exe 2844 3,972 K 8,204 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1840 5,212 K 8,824 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3088 6,644 K 10,864 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2196 13,368 K 18,736 K Host Process for Windows Services Microsoft Corporation
svchost.exe 912 3,860 K 7,908 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2188 3,588 K 7,548 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1100 3,104 K 6,672 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3112 1,620 K 3,444 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2328 1,888 K 4,500 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2628 1,760 K 4,112 K Host Process for Windows Services Microsoft Corporation
sqlwriter.exe 2720 4,936 K 9,488 K SQL Server VSS Writer - 64 Bit Microsoft Corporation
sqlservr.exe 3048 44,772 K 1,188 K SQL Server Windows NT Microsoft Corporation
sqlbrowser.exe 1764 1,828 K 4,924 K SQL Browser Service EXE Microsoft Corporation
smss.exe 480 496 K 1,032 K Windows Session Manager Microsoft Corporation
SLsvc.exe 1116 8,560 K 13,396 K Microsoft Software Licensing Service Microsoft Corporation
rundll32.exe 3784 3,088 K 4,368 K Windows host process (Rundll32) Microsoft Corporation
procexp.exe 828 3,792 K 9,632 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
inetinfo.exe 2960 11,596 K 19,424 K Internet Information Services Microsoft Corporation
ehtray.exe 1812 2,880 K 1,360 K Media Center Tray Applet Microsoft Corporation
ehmsas.exe 1892 2,532 K 6,440 K Media Center Media Status Aggregator Service Microsoft Corporation
audiodg.exe 496 13,804 K 16,956 K Windows Audio Device Graph Isolation Microsoft Corporation
ApntEx.exe 2636 2,868 K 5,804 K Alps Pointing-device Driver for Windows NT/2000/XP/Vista Alps Electric Co., Ltd.
  • 0

#80
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
combofix is running on the desktop as we speak...
  • 0

#81
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
DESKTOP
Another problem we are having is it won't read certain discs in the CD driver but others it will just fine..for example I can't uninstall Office 97 because it can't read the disc that it tells me to insert into the drive...


ComboFix
ComboFix 11-06-22.02 - Charlie 06/22/2011 23:11:23.2.2 - x86
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3006.1778 [GMT -4:00]
Running from: c:\users\Charlie\Desktop\ComboFix.exe
AV: Norton 360 *Disabled/Updated* {88C95A36-8C3B-2F2C-1B8B-30FCCFDC4855}
FW: Norton 360 *Disabled* {B0F2DB13-C654-2E74-30D4-99C9310F0F2E}
SP: Norton 360 *Enabled/Updated* {33A8BBD2-AA01-20A2-213B-0B8EB45B02E8}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\programdata\ntuser.dat
c:\programdata\pswi_preloaded.exe
.
.
((((((((((((((((((((((((( Files Created from 2011-05-23 to 2011-06-23 )))))))))))))))))))))))))))))))
.
.
2011-06-23 03:24 . 2011-06-23 03:26 -------- d-----w- c:\users\Charlie\AppData\Local\temp
2011-06-23 03:24 . 2011-06-23 03:24 -------- d-----w- c:\users\Default\AppData\Local\temp
2011-06-23 03:24 . 2011-06-23 03:24 -------- d-----w- c:\users\Becky\AppData\Local\temp
2011-06-23 03:24 . 2011-06-23 03:24 -------- d-----w- c:\users\Austin\AppData\Local\temp
2011-06-21 05:51 . 2011-06-07 15:55 7074640 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{2697AB4C-9652-4F50-AABA-A7BC11D001D8}\mpengine.dll
2011-06-16 07:05 . 2011-04-22 23:25 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-06-16 07:05 . 2011-04-25 15:29 141104 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2011-06-16 07:05 . 2011-04-22 23:35 1797632 ----a-w- c:\windows\system32\jscript9.dll
2011-06-16 01:33 . 2011-04-14 14:59 75264 ----a-w- c:\windows\system32\drivers\dfsc.sys
2011-06-16 01:33 . 2011-04-21 13:58 273408 ----a-w- c:\windows\system32\drivers\afd.sys
2011-06-16 01:33 . 2011-04-29 13:25 146432 ----a-w- c:\windows\system32\drivers\srv2.sys
2011-06-16 01:33 . 2011-04-29 13:25 102400 ----a-w- c:\windows\system32\drivers\srvnet.sys
2011-06-16 01:33 . 2010-12-20 16:35 563712 ----a-w- c:\windows\system32\oleaut32.dll
2011-06-16 01:33 . 2011-05-02 17:16 739328 ----a-w- c:\windows\system32\inetcomm.dll
2011-06-16 01:33 . 2011-04-29 13:24 214016 ----a-w- c:\windows\system32\drivers\mrxsmb10.sys
2011-06-16 01:33 . 2011-04-29 13:24 79872 ----a-w- c:\windows\system32\drivers\mrxsmb20.sys
2011-06-16 01:33 . 2011-04-29 13:24 106496 ----a-w- c:\windows\system32\drivers\mrxsmb.sys
2011-06-16 01:33 . 2011-05-02 12:02 2409784 ----a-w- c:\program files\Windows Mail\OESpamFilter.dat
2011-06-12 23:49 . 2011-06-14 23:53 -------- d-----w- c:\users\Charlie\AppData\Roaming\Apple Computer
2011-06-12 23:47 . 2011-06-12 23:47 -------- d-----w- c:\program files\iPod
2011-06-12 23:47 . 2011-06-12 23:48 -------- d-----w- c:\programdata\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2011-06-12 23:47 . 2011-06-12 23:48 -------- d-----w- c:\program files\iTunes
2011-06-12 23:44 . 2011-06-12 23:44 -------- d-----w- c:\program files\Bonjour
2011-06-07 16:35 . 2011-06-07 16:35 103864 ----a-w- c:\program files\Mozilla Firefox\plugins\nppdf32.dll
2011-06-07 16:35 . 2011-06-07 16:35 103864 ----a-w- c:\program files\Internet Explorer\plugins\nppdf32.dll
2011-05-27 18:17 . 2011-05-27 18:17 644360 ----a-w- c:\programdata\Microsoft\eHome\Packages\MCESpotlight\MCESpotlight\SpotlightResources.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2011-06-08 10:44 . 2011-05-18 22:02 404640 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
2011-05-29 13:11 . 2011-01-12 02:43 39984 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-05-29 13:11 . 2011-01-12 02:43 22712 ----a-w- c:\windows\system32\drivers\mbam.sys
2011-05-24 23:14 . 2009-10-03 05:55 222080 ------w- c:\windows\system32\MpSigStub.exe
2011-04-06 20:20 . 2011-04-06 20:20 91424 ----a-w- c:\windows\system32\dnssd.dll
2011-04-06 20:20 . 2011-04-06 20:20 75040 ----a-w- c:\windows\system32\jdns_sd.dll
2011-04-06 20:20 . 2011-04-06 20:20 197920 ----a-w- c:\windows\system32\dnssdX.dll
2011-04-06 20:20 . 2011-04-06 20:20 107808 ----a-w- c:\windows\system32\dns-sd.exe
2011-04-29 18:08 . 2011-04-13 12:44 142296 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Weather"="c:\program files\AWS\WeatherBug\Weather.exe" [2006-04-07 1343488]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Mouse Suite 98 Daemon"="ICO.EXE" [2006-09-29 49152]
"TVT Scheduler Proxy"="c:\program files\Common Files\Lenovo\Scheduler\scheduler_proxy.exe" [2008-03-04 487424]
"ISUSScheduler"="c:\program files\Common Files\InstallShield\UpdateService\issch.exe" [2005-08-11 81920]
"NvSvc"="c:\windows\system32\nvsvc.dll" [2007-03-23 86016]
"NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2007-03-23 8425472]
"NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2007-03-23 81920]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2008-03-18 1848648]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2011-06-07 421160]
"TkBellExe"="c:\program files\Real\RealPlayer\update\realsched.exe" [2011-06-17 273544]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-06-08 37296]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920]
.
c:\users\Becky\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Get 2 FREE Audiobooks.lnk - c:\users\Charlie\AppData\Local\Temp\HelpInstaller_StartUp.exe [N/A]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
.
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
.
R0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [x]
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2011-01-10 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files\Google\Update\GoogleUpdate.exe [2011-01-10 136176]
R3 motccgp;Motorola USB Composite Device Driver;c:\windows\system32\DRIVERS\motccgp.sys [2007-04-05 17920]
R3 motccgpfl;MotCcgpFlService;c:\windows\system32\DRIVERS\motccgpfl.sys [2007-01-23 7680]
R3 motport;Motorola USB Diagnostic Port;c:\windows\system32\DRIVERS\motport.sys [2007-05-04 22528]
R3 netr73;Linksys Compact Wireless-G USB Adapter Driver for Vista;c:\windows\system32\DRIVERS\WUSB54GCx86.sys [2007-03-12 256000]
R3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2006-11-02 987648]
R3 VSTHWBS2;VSTHWBS2;c:\windows\system32\DRIVERS\VSTBS23.SYS [2006-11-02 251904]
R3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-03-18 753504]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\N360\0403000.005\SYMDS.SYS [2010-02-04 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\N360\0403000.005\SYMEFA.SYS [2010-04-22 173104]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\BASHDefs\20110616.003\BHDrvx86.sys [2011-05-19 810616]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\N360\0403000.005\ccHPx86.sys [2010-02-26 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_4.1.0.32\Definitions\IPSDefs\20110622.001\IDSvix86.sys [2011-06-03 367736]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\N360\0403000.005\Ironx86.SYS [2010-04-29 116784]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\N360\0403000.005\SYMTDIV.SYS [2010-05-06 339504]
S2 N360;Norton 360;c:\program files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe [2010-02-26 126392]
S2 TVT Backup Protection Service;TVT Backup Protection Service;c:\program files\Lenovo\Rescue and Recovery\rrpservice.exe [2006-12-14 569344]
S3 b57nd60x;%SvcDispName%;c:\windows\system32\DRIVERS\b57nd60x.sys [2008-01-19 179712]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-05-10 105592]
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ FontCache
.
Contents of the 'Scheduled Tasks' folder
.
2011-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-10 04:29]
.
2011-06-22 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2011-01-10 04:29]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.lenovo.com/welcome/3000desktop
mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
mStart Page = hxxp://www.yahoo.com/
uInternet Settings,ProxyOverride = *.local
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
IE: Open with WordPerfect - c:\program files\WordPerfect Office X3\Programs\WPLauncher.hta
TCP: DhcpNameServer = 24.159.64.23 24.178.162.3 97.81.22.195
FF - ProfilePath - c:\users\Charlie\AppData\Roaming\Mozilla\Firefox\Profiles\hgei34s8.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - www.aol.com
.
- - - - ORPHANS REMOVED - - - -
.
HKLM-Run-SunJavaUpdateSched - c:\program files\Java\jre6\bin\jusched.exe
.
.
.
**************************************************************************
.
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-06-22 23:25
Windows 6.0.6002 Service Pack 2 NTFS
.
scanning hidden processes ...
.
scanning hidden autostart entries ...
.
scanning hidden files ...
.
scan completed successfully
hidden files: 0
.
**************************************************************************
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\N360]
"ImagePath"="\"c:\program files\Norton 360\Engine\4.3.0.5\ccSvcHst.exe\" /s \"N360\" /m \"c:\program files\Norton 360\Engine\4.3.0.5\diMaster.dll\" /prefetch:1"
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
--------------------- DLLs Loaded Under Running Processes ---------------------
.
- - - - - - - > 'Explorer.exe'(6244)
c:\windows\System32\NaturalLanguage6.dll
c:\windows\system32\msi.dll
c:\program files\Norton 360\Engine\4.3.0.5\ccIPC.dll
c:\program files\Norton 360\Engine\4.3.0.5\ccGEvt.dll
.
Completion time: 2011-06-22 23:37:40
ComboFix-quarantined-files.txt 2011-06-23 03:37
.
Pre-Run: 129,302,065,152 bytes free
Post-Run: 129,303,134,208 bytes free
.
- - End Of File - - 3D090A5546B02E02F25B0AD03364FE43

PROCEPT
Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 83.49 0 K 24 K
System 4 < 0.01 0 K 28,816 K
Interrupts n/a 0.77 0 K 0 K Hardware Interrupts and DPCs
smss.exe 400 292 K 568 K Windows Session Manager Microsoft Corporation
csrss.exe 532 < 0.01 2,184 K 6,688 K Client Server Runtime Process Microsoft Corporation
wininit.exe 584 1,264 K 3,400 K Windows Start-Up Application Microsoft Corporation
services.exe 628 < 0.01 2,864 K 6,100 K Services and Controller app Microsoft Corporation
svchost.exe 836 < 0.01 3,572 K 6,028 K Host Process for Windows Services Microsoft Corporation
WmiPrvSE.exe 2804 8,148 K 9,504 K WMI Provider Host Microsoft Corporation
dllhost.exe 3096 1,568 K 3,880 K COM Surrogate Microsoft Corporation
unsecapp.exe 7836 3,040 K 6,776 K Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation
WmiPrvSE.exe 7236 3,224 K 6,052 K WMI Provider Host Microsoft Corporation
svchost.exe 896 < 0.01 4,048 K 6,188 K Host Process for Windows Services Microsoft Corporation
svchost.exe 932 75,276 K 37,992 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1024 15,576 K 10,924 K Host Process for Windows Services Microsoft Corporation
audiodg.exe 1200 11,324 K 9,432 K Windows Audio Device Graph Isolation Microsoft Corporation
svchost.exe 1100 < 0.01 93,868 K 93,876 K Host Process for Windows Services Microsoft Corporation
WUDFHost.exe 2992 < 0.01 3,152 K 4,008 K Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation
dwm.exe 3400 0.77 75,600 K 38,176 K Desktop Window Manager Microsoft Corporation
svchost.exe 1136 < 0.01 75,644 K 47,524 K Host Process for Windows Services Microsoft Corporation
taskeng.exe 3648 2,120 K 5,308 K Task Scheduler Engine Microsoft Corporation
taskeng.exe 4192 10,728 K 9,708 K Task Scheduler Engine Microsoft Corporation
taskeng.exe 7572 7,844 K 10,748 K Task Scheduler Engine Microsoft Corporation
svchost.exe 1228 2,212 K 3,956 K Host Process for Windows Services Microsoft Corporation
SLsvc.exe 1244 6,548 K 10,240 K Microsoft Software Licensing Service Microsoft Corporation
svchost.exe 1296 < 0.01 8,604 K 12,480 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1424 < 0.01 23,452 K 18,464 K Host Process for Windows Services Microsoft Corporation
spoolsv.exe 1620 < 0.01 7,484 K 8,724 K Spooler SubSystem App Microsoft Corporation
svchost.exe 1664 13,368 K 9,852 K Host Process for Windows Services Microsoft Corporation
IPSSVC.EXE 200 1,616 K 2,488 K IPS Core Service Lenovo Group Limited
AOLacsd.exe 276 2,244 K 3,464 K AOL Connectivity Service AOL LLC
AppleMobileDeviceService.exe 316 < 0.01 3,116 K 4,020 K MobileDeviceService Apple Inc.
BcmSqlStartupSvc.exe 412 984 K 2,588 K BCM SQL Startup Service Microsoft Corporation
mDNSResponder.exe 500 1,856 K 4,324 K Bonjour Service Apple Inc.
CTSVCCDA.EXE 512 760 K 2,032 K Creative Service for CDROM Access Creative Technology Ltd
DkService.exe 536 < 0.01 22,044 K 25,284 K DKSERVICE.EXE Diskeeper Corporation
DkIcon.exe 3780 < 0.01 1,644 K 5,484 K DKICON.EXE Diskeeper Corporation
ijplmsvc.exe 832 952 K 2,628 K PIXMA Extended Servey Program Service
ccsvchst.exe 1148 14.69 102,548 K 13,872 K Symantec Service Framework Symantec Corporation
ccsvchst.exe 2136 36,716 K 7,504 K Symantec Service Framework Symantec Corporation
svchost.exe 1956 1,652 K 4,228 K Host Process for Windows Services Microsoft Corporation
PSIService.exe 2008 2,248 K 2,756 K nTitles PSIService
svchost.exe 2044 876 K 2,352 K Host Process for Windows Services Microsoft Corporation
sqlbrowser.exe 1936 1,052 K 2,496 K SQL Browser Service EXE Microsoft Corporation
sqlwriter.exe 2096 3,672 K 3,912 K SQL Server VSS Writer Microsoft Corporation
svchost.exe 2168 < 0.01 17,524 K 5,028 K Host Process for Windows Services Microsoft Corporation
tvt_reg_monitor_svc.exe 2188 < 0.01 1,612 K 2,904 K ThinkVantage Registry Monitor Service Lenovo Group Limited
tvttcsd.exe 2232 848 K 2,996 K tvttcsd Application IBM
rrpservice.exe 2264 2,204 K 3,440 K rrpservice Module
rrservice.exe 2296 9,076 K 6,868 K Rescue and Recovery Backup Service Lenovo Group Limited
tvtsched.exe 2352 7,900 K 5,876 K ThinkVantage Scheduler Lenovo Group Limited
svchost.exe 2392 1,056 K 3,244 K Host Process for Windows Services Microsoft Corporation
WLIDSVC.EXE 2408 4,196 K 6,424 K Microsoft® Windows Live ID Service Microsoft Corporation
WLIDSVCM.EXE 3252 848 K 2,128 K Microsoft® Windows Live ID Service Monitor Microsoft Corporation
SearchIndexer.exe 2444 < 0.01 50,432 K 44,296 K Microsoft Windows Search Indexer Microsoft Corporation
SUService.exe 2520 16,968 K 11,360 K ThinkVantage System Update Service Lenovo Group Limited
svchost.exe 3684 2,476 K 5,700 K Host Process for Windows Services Microsoft Corporation
wmpnetwk.exe 2516 < 0.01 13,940 K 12,332 K Windows Media Player Network Sharing Service Microsoft Corporation
iPodService.exe 4648 < 0.01 3,128 K 4,872 K iPodService Module (32-bit) Apple Inc.
lsass.exe 640 < 0.01 3,404 K 4,276 K Local Security Authority Process Microsoft Corporation
lsm.exe 648 1,944 K 3,300 K Local Session Manager Service Microsoft Corporation
csrss.exe 596 < 0.01 2,608 K 7,180 K Client Server Runtime Process Microsoft Corporation
winlogon.exe 760 2,076 K 4,428 K Windows Logon Application Microsoft Corporation
explorer.exe 6244 < 0.01 32,080 K 43,964 K Windows Explorer Microsoft Corporation
procexp.exe 4300 0.77 17,720 K 30,096 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
MSASCui.exe 3840 10,284 K 12,852 K Windows Defender User Interface Microsoft Corporation
ico.exe 3616 1,176 K 3,344 K Mouse Suite 98 Daemon Primax Electronics Ltd.
scheduler_proxy.exe 1440 3,372 K 3,108 K scheduler_proxy Application Lenovo Group Limited
BJMYPRT.EXE 1864 1,716 K 4,016 K Canon My Printer CANON INC.
iTunesHelper.exe 1076 < 0.01 7,184 K 6,972 K iTunesHelper Apple Inc.
QTTask.exe 1992 1,472 K 3,840 K QuickTime Task Apple Inc.
Weather.exe 3756 < 0.01 40,732 K 4,876 K AWS Convergence Technologies, Inc.
wmpnscfg.exe 3776 2,432 K 5,688 K Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
realsched.exe 6192 2,768 K 824 K RealNetworks Scheduler RealNetworks, Inc.
notepad.exe 5412 1,724 K 5,836 K Notepad Microsoft Corporation

VEW Application

Vino's Event Viewer v01c run on Windows Vista in English
Report run at 22/06/2011 11:51:11 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 23/06/2011 3:38:04 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\CF21867.CFXXE> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:35:11 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP00> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:35:11 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP00> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:35:11 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP00> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:35:11 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP00> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:18:46 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP4701> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:18:46 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP4701> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:18:36 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP4700> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:18:36 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP4700> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:16:06 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP0700> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:13:14 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\SOFTAV03> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:13:14 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\SOFTAV02> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:13:14 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\SOFTAV00> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:13:14 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\SOFTAV00> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:13:05 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP0002> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 23/06/2011 3:12:59 AM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\COMBOFIX\TEMP00> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 20/06/2011 1:16:56 PM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\RRBACKUPS\DOCUMENTS AND SETTINGS\AUSTIN\APPDATA\ROAMING\MICROSOFT\PROTECT\S-1-5-21-206110968-517032728-4089512812-1008> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 19/06/2011 8:09:14 PM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\USERS\CHARLIE\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\HGEI34S8.DEFAULT\CACHE\9> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 19/06/2011 8:09:14 PM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\USERS\CHARLIE\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\HGEI34S8.DEFAULT\CACHE\9> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


Log: 'Application' Date/Time: 19/06/2011 8:09:14 PM
Type: Error Category: 3
Event: 3013 Source: Microsoft-Windows-Search
The entry <C:\USERS\CHARLIE\APPDATA\LOCAL\MOZILLA\FIREFOX\PROFILES\HGEI34S8.DEFAULT\CACHE\8> in the hash map cannot be updated.

Context: Application, SystemIndex Catalog

Details:
A device attached to the system is not functioning. (0x8007001f)


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'Application' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'Application' Date/Time: 20/06/2011 3:11:10 PM
Type: Warning Category: 18
Event: 4354 Source: Microsoft-Windows-EventSystem
The COM+ Event System failed to fire the ConnectionMadeNoQOCInfo method on subscription {6F6E2383-D080-442F-9203-A0467B798404}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The subscriber returned HRESULT 80040210.

Log: 'Application' Date/Time: 20/06/2011 1:13:01 PM
Type: Warning Category: 0
Event: 3 Source: SQLBrowser
The configuration of the AdminConnection\TCP protocol in the SQL instance MSSMLBIZ is not valid.

Log: 'Application' Date/Time: 20/06/2011 1:11:20 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 9 user registry handles leaked from \Registry\User\S-1-5-21-206110968-517032728-4089512812-1010:
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010\Software\Lenovo


Log: 'Application' Date/Time: 19/06/2011 8:14:06 PM
Type: Warning Category: 1
Event: 1015 Source: Microsoft-Windows-Search
Event ID 3013 for the Windows Search Service has been suppressed 12 time(s) since 4:09:14 PM. This event is used to suppress Windows Search Service events that have occurred frequently within a short period of time. See Event ID 3013 for further details on this event.

Log: 'Application' Date/Time: 19/06/2011 4:37:56 PM
Type: Warning Category: 0
Event: 3 Source: SQLBrowser
The configuration of the AdminConnection\TCP protocol in the SQL instance MSSMLBIZ is not valid.

Log: 'Application' Date/Time: 19/06/2011 4:35:34 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 9 user registry handles leaked from \Registry\User\S-1-5-21-206110968-517032728-4089512812-1010:
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2152 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010\Software\Lenovo


Log: 'Application' Date/Time: 18/06/2011 10:41:11 PM
Type: Warning Category: 1
Event: 1015 Source: Microsoft-Windows-Search
Event ID 3013 for the Windows Search Service has been suppressed 8 time(s) since 6:11:10 PM. This event is used to suppress Windows Search Service events that have occurred frequently within a short period of time. See Event ID 3013 for further details on this event.

Log: 'Application' Date/Time: 17/06/2011 1:45:44 PM
Type: Warning Category: 0
Event: 3 Source: SQLBrowser
The configuration of the AdminConnection\TCP protocol in the SQL instance MSSMLBIZ is not valid.

Log: 'Application' Date/Time: 17/06/2011 1:43:27 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 8 user registry handles leaked from \Registry\User\S-1-5-21-206110968-517032728-4089512812-1010:
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2096 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010


Log: 'Application' Date/Time: 16/06/2011 12:59:48 PM
Type: Warning Category: 1
Event: 1015 Source: Microsoft-Windows-Search
Event ID 3013 for the Windows Search Service has been suppressed 12 time(s) since 8:48:40 AM. This event is used to suppress Windows Search Service events that have occurred frequently within a short period of time. See Event ID 3013 for further details on this event.

Log: 'Application' Date/Time: 16/06/2011 7:32:55 AM
Type: Warning Category: 0
Event: 3 Source: SQLBrowser
The configuration of the AdminConnection\TCP protocol in the SQL instance MSSMLBIZ is not valid.

Log: 'Application' Date/Time: 16/06/2011 7:29:23 AM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 8 user registry handles leaked from \Registry\User\S-1-5-21-206110968-517032728-4089512812-1010:
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2708 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010


Log: 'Application' Date/Time: 14/06/2011 1:46:01 PM
Type: Warning Category: 18
Event: 4354 Source: Microsoft-Windows-EventSystem
The COM+ Event System failed to fire the ConnectionMadeNoQOCInfo method on subscription {6F6E2383-D080-442F-9203-A0467B798404}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The subscriber returned HRESULT 80040210.

Log: 'Application' Date/Time: 13/06/2011 9:48:37 PM
Type: Warning Category: 18
Event: 4354 Source: Microsoft-Windows-EventSystem
The COM+ Event System failed to fire the ConnectionMadeNoQOCInfo method on subscription {6F6E2383-D080-442F-9203-A0467B798404}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The subscriber returned HRESULT 80040210.

Log: 'Application' Date/Time: 13/06/2011 1:19:46 PM
Type: Warning Category: 18
Event: 4354 Source: Microsoft-Windows-EventSystem
The COM+ Event System failed to fire the ConnectionMadeNoQOCInfo method on subscription {6F6E2383-D080-442F-9203-A0467B798404}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The subscriber returned HRESULT 80040210.

Log: 'Application' Date/Time: 13/06/2011 1:19:43 PM
Type: Warning Category: 0
Event: 3 Source: SQLBrowser
The configuration of the AdminConnection\TCP protocol in the SQL instance MSSMLBIZ is not valid.

Log: 'Application' Date/Time: 13/06/2011 1:18:23 PM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 8 user registry handles leaked from \Registry\User\S-1-5-21-206110968-517032728-4089512812-1010:
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 3316 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010


Log: 'Application' Date/Time: 13/06/2011 11:49:34 AM
Type: Warning Category: 18
Event: 4354 Source: Microsoft-Windows-EventSystem
The COM+ Event System failed to fire the ConnectionMadeNoQOCInfo method on subscription {6F6E2383-D080-442F-9203-A0467B798404}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The subscriber returned HRESULT 80040210.

Log: 'Application' Date/Time: 13/06/2011 11:49:31 AM
Type: Warning Category: 0
Event: 3 Source: SQLBrowser
The configuration of the AdminConnection\TCP protocol in the SQL instance MSSMLBIZ is not valid.

Log: 'Application' Date/Time: 13/06/2011 11:44:10 AM
Type: Warning Category: 0
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 8 user registry handles leaked from \Registry\User\S-1-5-21-206110968-517032728-4089512812-1010:
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2960 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010


VEW SYSTEM
\
Vino's Event Viewer v01c run on Windows Vista in English
Report run at 22/06/2011 11:51:40 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 23/06/2011 3:25:22 AM
Type: Error Category: 0
Event: 7030 Source: Service Control Manager
The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Log: 'System' Date/Time: 23/06/2011 3:16:31 AM
Type: Error Category: 0
Event: 7030 Source: Service Control Manager
The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Log: 'System' Date/Time: 23/06/2011 3:11:11 AM
Type: Error Category: 0
Event: 7030 Source: Service Control Manager
The PEVSystemStart service is marked as an interactive service. However, the system is configured to not allow interactive services. This service may not function properly.

Log: 'System' Date/Time: 21/06/2011 1:58:10 AM
Type: Error Category: 0
Event: 8032 Source: BROWSER
The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{E03824B5-C549-4650-A8F5-ADF45C4E2F9A}. The backup browser is stopping.

Log: 'System' Date/Time: 21/06/2011 1:12:44 AM
Type: Error Category: 0
Event: 1002 Source: Microsoft-Windows-Dhcp-Client
The IP address lease 192.168.1.100 for the Network Card with network address 001617F810EC has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 20/06/2011 1:43:08 PM
Type: Error Category: 0
Event: 8032 Source: BROWSER
The browser service has failed to retrieve the backup list too many times on transport \Device\NetBT_Tcpip_{E03824B5-C549-4650-A8F5-ADF45C4E2F9A}. The backup browser is stopping.

Log: 'System' Date/Time: 20/06/2011 1:17:45 PM
Type: Error Category: 0
Event: 7000 Source: Service Control Manager
The Network Connections service failed to start due to the following error: The service did not respond to the start or control request in a timely fashion.

Log: 'System' Date/Time: 20/06/2011 1:17:45 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Netman service.

Log: 'System' Date/Time: 20/06/2011 1:17:45 PM
Type: Error Category: 0
Event: 10005 Source: Microsoft-Windows-DistributedCOM
DCOM got error "1053" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E}

Log: 'System' Date/Time: 20/06/2011 1:17:15 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioEndpointBuilder service.

Log: 'System' Date/Time: 20/06/2011 1:16:46 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.

Log: 'System' Date/Time: 20/06/2011 1:16:15 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.

Log: 'System' Date/Time: 20/06/2011 1:15:42 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.

Log: 'System' Date/Time: 20/06/2011 1:15:12 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.

Log: 'System' Date/Time: 20/06/2011 1:14:08 PM
Type: Error Category: 0
Event: 7026 Source: Service Control Manager
The following boot-start or system-start driver(s) failed to load: Lbd

Log: 'System' Date/Time: 19/06/2011 4:46:05 PM
Type: Error Category: 0
Event: 7022 Source: Service Control Manager
The Windows Update service hung on starting.

Log: 'System' Date/Time: 19/06/2011 4:44:21 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the ShellHWDetection service.

Log: 'System' Date/Time: 19/06/2011 4:43:02 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.

Log: 'System' Date/Time: 19/06/2011 4:42:32 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the TrkWks service.

Log: 'System' Date/Time: 19/06/2011 4:41:46 PM
Type: Error Category: 0
Event: 7011 Source: Service Control Manager
A timeout (30000 milliseconds) was reached while waiting for a transaction response from the SysMain service.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 23/06/2011 3:50:17 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {6A869075-0AC5-4F6C-B224-6EF06CA41F46} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: driver:PROCEXP141 Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:50:17 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {63AAD1D4-2DF5-432C-A960-AD21BC3D2070} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: service:PROCEXP141 Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:37:55 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {32A922A4-ABBA-455D-9A03-CA47E40D0F24} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: safeboot:HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\{4D36E97D-E325-11CE-BFC1-08002BE10318} Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:25:25 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {0F9C9121-CDFA-4B8D-B373-6660A1D02991} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: service:PEVSystemStart Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:25:25 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {F8180C15-FD84-455B-AB49-7EDC0461A602} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: driver:PEVSystemStart Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:25:18 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {6581DE1B-FF39-4812-92FD-6620FA08FA49} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: file:C:\Windows\system32\drivers\etc\hosts Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:25:13 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {4C55AE84-4A28-4975-8594-E61707A4A4D4} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: iemain:HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Search_Url Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:25:10 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {848F99B4-DAB5-47E6-BB6F-BE20CFC3FB5B} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: iemain:HKCU@S-1-5-21-206110968-517032728-4089512812-1010\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:25:10 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {BE89B232-F964-4A34-B59B-85A32355E843} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: iemain:HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:25:08 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {DA907F4E-7444-45EC-AAF6-E6FCC8997960} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: shellopencmd:HKLM\Software\Classes\scrfile\shell\open\command\\ Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:16:33 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {3C1B6071-4525-4284-B43D-6B71471EF8F4} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: driver:PEVSystemStart Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:16:33 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {5C0411A8-BD2D-4763-A422-FADD3F66C2FB} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: service:PEVSystemStart Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:11:24 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {2D79C702-58A0-4691-9EDD-D9D3827D3674} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: driver:mbr Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:11:14 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {6EBBC46C-4891-463B-8C9F-918CC969DFFB} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: service:PEVSystemStart Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:11:14 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {E6428100-C73A-44A6-8AC1-01506AEDF394} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: driver:catchme Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:11:14 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {EB431E15-C96E-4D42-AEE1-D7CA1492C06F} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: driver:PEVSystemStart Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:07:18 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {2082E724-1B76-4288-9C63-BCC8780AF134} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: driver:PROCEXP113 Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:07:18 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {CB85BBC9-E8B8-49C3-B051-9400D04878C8} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: safeboot:HKLM\System\CurrentControlSet\Control\SafeBoot\Network\procexp90.Sys Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:07:18 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {2C8541DA-0557-4F78-B4A8-A274F888641C} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: safeboot:HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\PEVSystemStart Alert Type: Unclassified software Detection Type:

Log: 'System' Date/Time: 23/06/2011 3:07:18 AM
Type: Warning Category: 0
Event: 3004 Source: Microsoft-Windows-Windows Defender
Windows Defender Real-Time Protection agent has detected changes. Microsoft recommends you analyze the software that made these changes for potential risks. You can use information about how these programs operate to choose whether to allow them to run or remove them from your computer. Allow changes only if you trust the program or the software publisher. Windows Defender can't undo changes that you allow. For more information please see the following: Not Applicable Scan ID: {1FC4A1BA-12C0-44D1-BCF1-0EE711CD0070} User: mainbedroom\Charlie Name: Unknown ID: Severity ID: Category ID: Path Found: safeboot:HKLM\System\CurrentControlSet\Control\SafeBoot\Minimal\procexp90.Sys Alert Type: Unclassified software Detection Type:
  • 0

#82
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
Desktop: You have three services not starting. Could slow the boot by as much as 1.5 minutes.

Superfetch (Sysmain)
Shell Hardware Detection (ShellHWDetection)
Distributed Link Tracking Client (TrkWks)

Right click on Computer and select Manage then services and Applications then Services. Find each and right click and try to start. What error do you get?

I think you can live without all three so you might just change Startup Type to Manual to see if it speeds things up.

Also Windows Search is complaining a lot so I would turn its service to Manual too.

Something form Lenova is causing an error:
Event: 1530 Source: Microsoft-Windows-User Profiles Service
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 9 user registry handles leaked from \Registry\User\S-1-5-21-206110968-517032728-4089512812-1010:
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010
Process 2068 (\Device\HarddiskVolume2\Program Files\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-206110968-517032728-4089512812-1010\Software\Lenovo

tvt_reg_monitor_svc.exe whatever that is. You might look and see if there is a new version.

The process Explorer was not sorted by usage so hard to read. Click twice on the CPU header.

Laptop. The latest process explorer shows a bit hig from the top svchost

Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 55.38 0 K 24 K
svchost.exe 412 28.46 130,932 K 139,860 K Host Process for Windows Services Microsoft Corporation <===This one.Can you find out what it is doing? Right click on it or just run the cursor over it.

WmiPrvSE.exe 3852 3.85 8,336 K 13,432 K WMI Provider Host Microsoft Corporation <===This one is down a bit from before.
  • 0

#83
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
LAPTOP
Honestly that process explorer is jumping so fast I can't hover over it long enough to find out anything ...

"svchost.exe 412 28.46 130,932 K 139,860 K Host Process for Windows Services Microsoft Corporation <===This one.Can you find out what it is doing? Right click on it or just run the cursor over it."

This one and the others are changing places so fast on that list (moving up and down) that I can't hover over it long enough for it to register what it is...I wish there was some way for you to see for yourself...
This morning the top 3 are staying pretty consistent...system idle, firefox and WmiPrvSE although the last one will occasionally drop to 4th on the list... the others are just jumping around.. is the anyway to get them to hold till to get a read on it? (prob not but thought I would ask because without you getting remote access I don't see how you could actually see this)

Edited by BeckyH, 23 June 2011 - 05:31 AM.

  • 0

#84
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
DESKTOP
All 3 of those programs when I went under manage showed they had started. This desktop is the main computer in the network if that makes a difference...
I have uninstalled Norton and installed Avast on this computer as well...here's this morning procep log after i did that

Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 89.67 0 K 24 K
plugin-container.exe 5344 3.09 87,588 K 94,532 K Plugin Container for Firefox Mozilla Corporation
procexp.exe 5012 3.09 20,024 K 29,264 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
dwm.exe 912 1.55 61,564 K 62,328 K Desktop Window Manager Microsoft Corporation
System 4 < 0.01 0 K 34,696 K
AvastSvc.exe 3456 0.77 30,460 K 14,848 K avast! Service AVAST Software
firefox.exe 3624 0.77 433,140 K 447,384 K Firefox Mozilla Corporation
explorer.exe 3176 < 0.01 30,768 K 42,792 K Windows Explorer Microsoft Corporation
csrss.exe 564 < 0.01 1,928 K 8,364 K Client Server Runtime Process Microsoft Corporation
wmpnetwk.exe 1252 < 0.01 13,636 K 20,068 K Windows Media Player Network Sharing Service Microsoft Corporation
svchost.exe 1432 < 0.01 18,752 K 19,208 K Host Process for Windows Services Microsoft Corporation
spoolsv.exe 1664 < 0.01 6,916 K 10,368 K Spooler SubSystem App Microsoft Corporation
mmc.exe 3612 < 0.01 64,372 K 21,412 K Microsoft Management Console Microsoft Corporation
tvt_reg_monitor_svc.exe 2100 < 0.01 1,616 K 3,900 K ThinkVantage Registry Monitor Service Lenovo Group Limited
AvastUI.exe 5988 < 0.01 18,316 K 22,544 K avast! Antivirus AVAST Software
DkService.exe 464 < 0.01 7,924 K 12,392 K DKSERVICE.EXE Diskeeper Corporation
csrss.exe 512 < 0.01 1,892 K 5,364 K Client Server Runtime Process Microsoft Corporation
SearchIndexer.exe 2360 0.77 43,712 K 38,892 K Microsoft Windows Search Indexer Microsoft Corporation
lsass.exe 664 < 0.01 3,012 K 3,168 K Local Security Authority Process Microsoft Corporation
DkIcon.exe 3556 < 0.01 1,196 K 3,760 K DKICON.EXE Diskeeper Corporation
iPodService.exe 4392 < 0.01 2,944 K 5,492 K iPodService Module (32-bit) Apple Inc.
svchost.exe 1116 < 0.01 63,028 K 74,004 K Host Process for Windows Services Microsoft Corporation
WmiPrvSE.exe 2968 3,344 K 6,312 K WMI Provider Host Microsoft Corporation
AppleMobileDeviceService.exe 200 < 0.01 3,120 K 5,408 K MobileDeviceService Apple Inc.
SearchProtocolHost.exe 1284 < 0.01 5,228 K 8,648 K Microsoft Windows Search Protocol Host Microsoft Corporation
svchost.exe 1068 < 0.01 17,420 K 10,872 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1072 < 0.01 70,884 K 73,944 K Host Process for Windows Services Microsoft Corporation
iTunesHelper.exe 3068 < 0.01 6,996 K 10,928 K iTunesHelper Apple Inc.
logmon.exe 2660 3,188 K 5,624 K
Interrupts n/a 0.77 0 K 0 K Hardware Interrupts and DPCs
WUDFHost.exe 2556 3,132 K 4,500 K Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation
wmpnscfg.exe 3472 1,716 K 5,264 K Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
WmiPrvSE.exe 2776 5,176 K 7,356 K WMI Provider Host Microsoft Corporation
WLIDSVCM.EXE 2972 848 K 2,588 K Microsoft® Windows Live ID Service Monitor Microsoft Corporation
WLIDSVC.EXE 2308 4,228 K 8,112 K Microsoft® Windows Live ID Service Microsoft Corporation
winlogon.exe 604 2,024 K 5,096 K Windows Logon Application Microsoft Corporation
wininit.exe 572 1,244 K 3,452 K Windows Start-Up Application Microsoft Corporation
unsecapp.exe 2588 2,292 K 4,840 K Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation
tvttcsd.exe 2124 840 K 2,908 K tvttcsd Application IBM
tvtsched.exe 2232 7,800 K 9,472 K ThinkVantage Scheduler Lenovo Group Limited
taskeng.exe 2796 < 0.01 9,336 K 10,288 K Task Scheduler Engine Microsoft Corporation
taskeng.exe 3408 1,980 K 5,820 K Task Scheduler Engine Microsoft Corporation
svchost.exe 1004 15,280 K 12,464 K Host Process for Windows Services Microsoft Corporation
svchost.exe 868 3,400 K 5,832 K Host Process for Windows Services Microsoft Corporation
svchost.exe 808 3,220 K 5,916 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1272 8,072 K 12,788 K Host Process for Windows Services Microsoft Corporation
svchost.exe 904 73,876 K 45,464 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1208 2,004 K 4,296 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1688 12,116 K 12,956 K Host Process for Windows Services Microsoft Corporation
svchost.exe 436 1,588 K 4,064 K Host Process for Windows Services Microsoft Corporation
svchost.exe 724 868 K 2,428 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2268 1,056 K 3,304 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3488 2,508 K 8,772 K Host Process for Windows Services Microsoft Corporation
SUService.exe 2420 < 0.01 16,536 K 10,044 K ThinkVantage System Update Service Lenovo Group Limited
sqlwriter.exe 348 3,616 K 4,808 K SQL Server VSS Writer Microsoft Corporation
sqlbrowser.exe 968 1,048 K 2,924 K SQL Browser Service EXE Microsoft Corporation
smss.exe 444 544 K 764 K Windows Session Manager Microsoft Corporation
SLsvc.exe 1228 6,140 K 7,212 K Microsoft Software Licensing Service Microsoft Corporation
services.exe 652 2,612 K 6,368 K Services and Controller app Microsoft Corporation
SearchFilterHost.exe 4740 3,920 K 6,496 K Microsoft Windows Search Filter Host Microsoft Corporation
scheduler_proxy.exe 3248 3,368 K 5,020 K scheduler_proxy Application Lenovo Group Limited
rundll32.exe 3400 3,060 K 4,380 K Windows host process (Rundll32) Microsoft Corporation
rundll32.exe 3908 4,524 K 5,488 K Windows host process (Rundll32) Microsoft Corporation
rrservice.exe 2208 9,112 K 11,448 K Rescue and Recovery Backup Service Lenovo Group Limited
rrpservice.exe 2144 3,744 K 5,384 K rrpservice Module
realsched.exe 3716 < 0.01 2,204 K 272 K RealNetworks Scheduler RealNetworks, Inc.
QTTask.exe 3504 980 K 3,052 K QuickTime Task Apple Inc.
PSIService.exe 1956 2,240 K 3,240 K nTitles PSIService
mDNSResponder.exe 380 1,672 K 4,424 K Bonjour Service Apple Inc.
lsm.exe 672 < 0.01 1,888 K 3,588 K Local Session Manager Service Microsoft Corporation
IPSSVC.EXE 2012 1,608 K 2,668 K IPS Core Service Lenovo Group Limited
ijplmsvc.exe 520 952 K 2,900 K PIXMA Extended Servey Program Service
ico.exe 3768 852 K 2,884 K Mouse Suite 98 Daemon Primax Electronics Ltd.
CTSVCCDA.EXE 388 752 K 2,080 K Creative Service for CDROM Access Creative Technology Ltd
BJMYPRT.EXE 3076 1,268 K 3,900 K Canon My Printer CANON INC.
BcmSqlStartupSvc.exe 356 988 K 2,896 K BCM SQL Startup Service Microsoft Corporation
audiodg.exe 1180 11,056 K 11,704 K Windows Audio Device Graph Isolation Microsoft Corporation
AOLacsd.exe 2036 2,244 K 4,160 K AOL Connectivity Service AOL LLC
  • 0

#85
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
View, Update Speed, Pause should stop it. On mine you can just look at it and see what makes up each svchost since they are indented just below. It doesn't jump around at all even without the pause.
  • 0

Advertisements


#86
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
OMG thank you...that makes it so much better

ok here is the one I just did after last reboot about 3 min ago..
Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 55.38 0 K 24 K
svchost.exe 412 28.46 130,932 K 139,860 K Host Process for Windows Services Microsoft Corporation
WmiPrvSE.exe 3852 3.85 8,336 K 13,432 K WMI Provider Host Microsoft Corporation
System 4 2.31 0 K 5,384 K
svchost.exe 264 2.31 76,896 K 40,104 K Host Process for Windows Services Microsoft Corporation
procexp64.exe 3684 2.31 22,244 K 33,064 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
dwm.exe 1588 2.31 36,012 K 31,680 K Desktop Window Manager Microsoft Corporation
Interrupts n/a 1.54 0 K 0 K Hardware Interrupts and DPCs
svchost.exe 492 0.77 26,156 K 40,200 K Host Process for Windows Services Microsoft Corporation
csrss.exe 668 0.77 3,452 K 8,888 K Client Server Runtime Process Microsoft Corporation
igfxsrvc.exe 1952 < 0.01 2,844 K 6,676 K igfxsrvc Module Intel Corporation
ApMsgFwd.exe 1924 < 0.01 2,044 K 4,232 K ApMsgFwd Alps Electric Co., Ltd.
PanelApp.exe 1908 < 0.01 19,340 K 26,280 K
svchost.exe 1292 < 0.01 18,788 K 19,960 K Host Process for Windows Services Microsoft Corporation
sttray64.exe 1804 < 0.01 9,444 K 17,928 K IDT PC Audio IDT, Inc.
lsass.exe 716 < 0.01 5,512 K 12,488 K Local Security Authority Process Microsoft Corporation
svchost.exe 984 < 0.01 5,316 K 9,300 K Host Process for Windows Services Microsoft Corporation
explorer.exe 1656 < 0.01 31,232 K 48,792 K Windows Explorer Microsoft Corporation
hkcmd.exe 1796 < 0.01 2,928 K 6,880 K hkcmd Module Intel Corporation
AvastSvc.exe 1428 < 0.01 19,192 K 18,532 K avast! Service AVAST Software
wlanext.exe 1452 < 0.01 3,096 K 7,132 K Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation
AvastUI.exe 1248 < 0.01 6,368 K 4,008 K avast! Antivirus AVAST Software
svchost.exe 1152 < 0.01 11,236 K 18,524 K Host Process for Windows Services Microsoft Corporation
services.exe 704 < 0.01 3,736 K 8,792 K Services and Controller app Microsoft Corporation
csrss.exe 612 < 0.01 2,696 K 7,320 K Client Server Runtime Process Microsoft Corporation
Apoint.exe 1788 < 0.01 4,016 K 9,504 K Alps Pointing-device Driver Alps Electric Co., Ltd.
svchost.exe 2796 < 0.01 6,836 K 11,820 K Host Process for Windows Services Microsoft Corporation
lsm.exe 724 < 0.01 3,572 K 5,932 K Local Session Manager Service Microsoft Corporation
svchost.exe 332 < 0.01 15,356 K 13,692 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3964 < 0.01 4,824 K 8,652 K Host Process for Windows Services Microsoft Corporation
taskeng.exe 2252 < 0.01 11,368 K 13,980 K Task Scheduler Engine Microsoft Corporation
SeaPort.exe 2524 < 0.01 6,204 K 10,264 K Microsoft SeaPort Search Enhancement Broker Microsoft Corporation
spoolsv.exe 2156 < 0.01 8,604 K 15,504 K Spooler SubSystem App Microsoft Corporation
wmpnscfg.exe 2648 3,060 K 7,336 K Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
WmiPrvSE.exe 2384 4,156 K 7,732 K WMI Provider Host Microsoft Corporation
WLIDSVCM.EXE 3556 2,108 K 4,284 K Microsoft® Windows Live ID Service Monitor Microsoft Corp.
WLIDSVC.EXE 3160 8,964 K 16,532 K Microsoft® Windows Live ID Service Microsoft Corp.
winlogon.exe 796 3,368 K 8,000 K Windows Logon Application Microsoft Corporation
wininit.exe 648 2,324 K 5,860 K Windows Start-Up Application Microsoft Corporation
taskeng.exe 2172 3,364 K 8,336 K Task Scheduler Engine Microsoft Corporation
svchost.exe 2844 3,972 K 8,204 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1840 5,212 K 8,824 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3088 6,644 K 10,864 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2196 13,368 K 18,736 K Host Process for Windows Services Microsoft Corporation
svchost.exe 912 3,860 K 7,908 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2188 3,588 K 7,548 K Host Process for Windows Services Microsoft Corporation
svchost.exe 1100 3,104 K 6,672 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3112 1,620 K 3,444 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2328 1,888 K 4,500 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2628 1,760 K 4,112 K Host Process for Windows Services Microsoft Corporation
sqlwriter.exe 2720 4,936 K 9,488 K SQL Server VSS Writer - 64 Bit Microsoft Corporation
sqlservr.exe 3048 44,772 K 1,188 K SQL Server Windows NT Microsoft Corporation
sqlbrowser.exe 1764 1,828 K 4,924 K SQL Browser Service EXE Microsoft Corporation
smss.exe 480 496 K 1,032 K Windows Session Manager Microsoft Corporation
SLsvc.exe 1116 8,560 K 13,396 K Microsoft Software Licensing Service Microsoft Corporation
rundll32.exe 3784 3,088 K 4,368 K Windows host process (Rundll32) Microsoft Corporation
procexp.exe 828 3,792 K 9,632 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
inetinfo.exe 2960 11,596 K 19,424 K Internet Information Services Microsoft Corporation
ehtray.exe 1812 2,880 K 1,360 K Media Center Tray Applet Microsoft Corporation
ehmsas.exe 1892 2,532 K 6,440 K Media Center Media Status Aggregator Service Microsoft Corporation
audiodg.exe 496 13,804 K 16,956 K Windows Audio Device Graph Isolation Microsoft Corporation
ApntEx.exe 2636 2,868 K 5,804 K Alps Pointing-device Driver for Windows NT/2000/XP/Vista Alps Electric Co., Ltd.


Now when I hover over the top svc one it says the following under services:(these are the abbreviations that was at end of line in parenthesis )
AELoopupSVC
AppInfo
BITS
Browser
EAP Host
IKEEXT
IPHelper
MMCSS
Rasman
Selogin
LanmanServ
ShellHWDetection
SENS
Schedule
Themes
ProfSvc
Winmgmt
Wuauserv
  • 0

#87
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
If yours lools like mine then you should have a list of the individual processes under each svchost.exe. Pick one then right click and Kill Process. Then View, Refresh Now. See if you can find one that makes a big differnce in the amount of CPU time used.

Ron
  • 0

#88
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
I clicked on the top svchost so it was highlighted and then clicked on the process tab at the top of the window which opened a new window. I then clicked on the services tab and it opened a listing of the services assigned to that particular svchost. As I read through them to me it sounded like all but maybe themes were important to the running of the computer ie for AElookupSve it says "processes application compatability cache requests for applications as they are launched" or BITS which "transfers files in the background using idle system bandwidth" so things like windows update can't run with it disabled(I think) or has to do with encryption or something

anyways they all sound like things that are needed to my thinking..so of them I tried to stop it won't let me...

me thinks without you I would be drowning in this info...
  • 0

#89
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,624 posts
  • MVP
We can certainly live without IP Helper. That just makes IPv6 work and no one has it yet. Right click on Computer and select Manage (Continue) then Services and Applications then Services. Find IP Helper and right click and select Properties change Startup Type to Disabled then Apply then STOP the service.

While there go down to Windows Management Instrumentation and right click and select Properties then just STOP the service. Go back to Process Explorer (unpause it) and see if the CPU usage is stable and that most of your usage is System Idle.

Ron
  • 0

#90
BeckyH

BeckyH

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 146 posts
it won't let me stop the windows management instrumentation..it gives me an error saying it can't stop a process others programs that are running are dependent on or something like that...
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP