Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: Rodney78 on November 07, 2010, 09:57:45 AM

Title: Have I got infected?
Post by: Rodney78 on November 07, 2010, 09:57:45 AM
Hello,  my laptop seems to have slowed down considerably in terms of browser speed and typing latency.  I have done numerous Avast and SAS scans, nothing is found by Avast and SAS just finds cookies which I delete.

I'm really concerned that I have an infection which is maybe deep routed which have not got the experience to find.

Help!!
Title: Re: Have I got infected?
Post by: Omid Farhang on November 07, 2010, 10:00:26 AM
Please attach a HijackThis log in your next reply so I will know a few more about your computer and running process.

http://www.omidfarhang.com/computer/how-to/hijackthis (http://www.omidfarhang.com/computer/how-to/hijackthis)

To attach a log: Additonal Options, Attach-> Browse for log
Title: Re: Have I got infected?
Post by: Asyn on November 07, 2010, 10:01:12 AM
1. If you are on a 32bit system, run a boot time scan with avast.
2. Run a scan with free Mbam. http://www.malwarebytes.org/mbam.php
Title: Re: Have I got infected?
Post by: SafeSurf on November 07, 2010, 10:04:01 AM
Hello Rodney78 and welcome to the forum.  :)

Have you cleaned your machine recently with something like CCleaner, a freeware system optimization, privacy and cleaning tool.  There is a Slim version available as well at http://www.piriform.com/ccleaner/builds (http://www.piriform.com/ccleaner/builds) - 4th option down.  It removes unused files (cache, temporary Internet files, etc.) from your system - allowing Windows to run faster and freeing up valuable hard disk space.  It also cleans traces of your online activities such as your Internet history.  Additionally it contains a fully featured registry cleaner. 

1.   What is your OS, 32 or 64-bit?
2.   What version of Avast did you install?  5.0.677 is the latest version.
3.   What product of Avast did you install?  Free, Pro, AIS?
Title: Re: Have I got infected?
Post by: DigiDis on November 07, 2010, 10:52:06 AM
I would do a careful check with Malwarebytes and Hitman Pro. You can also download the Kapsersky rescue CD and run that, just make sure to update it before you do the scan. If clean run CCleaner and do a defrag of your harddrive if it is more than 15% defragmented.

Last point is to get your computer back to its perfect running state and then do a full system image with something like Macrium or Paragon's imaging software. Then do a backup every two or so weeks and before changing anything related to the OS or security software. It's much easier to fall back a couple of days or a week with a disk image than to have to reinstall the OS and all software. Just remember to do frequent back ups of your documents and email data to somewhere else so that you can keep those current. Microsoft's SyncToy is good for that.
Title: Re: Have I got infected?
Post by: SafeSurf on November 07, 2010, 11:01:30 AM
This OP is getting too many suggestions yet we have no information about his system until he/she responds.  You may be confused with all the posts.

Jumping into running full diagnostic scans is not necessary until we have more information from the OP at this point, then usually a simple MBAM scan is required if we think it may be malware related.

@ Rodney78, do you have any questions?
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 11:03:50 AM
Wow, thanks for the really quick and detailed replies!!!

I have installed the latest version of free Avast.  I have defragged the HD and used XP disk cleaning utility.  I'm using 32 bitXp.

I'll try the cc cleaner 1st but ideally I don't want to be fiddling with the registry if I can help it as I don't think I'm competent enough!
Title: Re: Have I got infected?
Post by: SafeSurf on November 07, 2010, 11:11:30 AM
You will find that CCleaner will work better than the XP disk cleaning tool; many of us use it here regularly.  If you are not comfortable with the Registry cleaner portion, that is fine.  What I recommend if you do want to use it and it asks you to "fix" something is to make a back up in My Documents and keep it for a few weeks as a "just in case."

Did you reboot after doing all of this?  Is your system running better/fixed?
Title: Re: Have I got infected?
Post by: SafeSurf on November 07, 2010, 11:28:08 AM
If after robooting your machine is not fixed, please do the following:

1. Check your computer for malware with Malwarebytes’ Anti-Malware (MBAM).
·   Download free http://www.malwarebytes.org/ (http://www.malwarebytes.org/) (the blue button) for an on-demand scanner.
·   Double Click mbam-setup.exe to install the application.
·   After install, click update so you have latest database before scanning.
·   Under Settings:
o   General: Automatically Save File After Scan Completes is checked off
o   Scanner SettingsCheck all boxes
o   Updater: Download and install update if available is checked off
·   Once the program has loaded, select "Perform FULL Scan", then click Scan.
·   The scan may take some time to finish, so please be patient.
·   When the disinfection scan is complete, a log will appear in Notepad and you may be prompted to Restart. (See Extra Note).
·   Click the “remove selected” button to quarantine anything found.  You will find the infection details under the Quarantine tab.
·   The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
·   Copy & Paste the entire report in your next reply.

2. Then make sure your Avast definitions are up to date and run a Boot-time scan.  Post back if Avast finds anything.

Please let me know if you have any questions.  Thank you.
Title: Re: Have I got infected?
Post by: Omid Farhang on November 07, 2010, 11:59:57 AM
Rodney78, I'm still awaiting

Please attach a HijackThis log in your next reply so I will know a few more about your computer and running process.

http://www.omidfarhang.com/computer/how-to/hijackthis (http://www.omidfarhang.com/computer/how-to/hijackthis)

To attach a log: Additonal Options, Attach-> Browse for log
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 12:11:33 PM
Ok, I've just run CC cleaner and although it seemed to have removed a lot of files, hasn't made a difference to my original problem.  I'm in the process of running a MB scan, so will post results when completed.

Omid, once I've done this I'll see if I can post a HT log.

Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 12:46:09 PM
Ok MB scan completed and nothing found ???

I'm now going to run a Avast boot time scan.
Title: Re: Have I got infected?
Post by: Omid Farhang on November 07, 2010, 01:04:12 PM
Ok MB scan completed and nothing found ???

I'm now going to run a Avast boot time scan.
Rondy, HijackThis log will take only less than a minutes, maybe your computer is clean and only something is conflicting or running on background which can be solved quickly.
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 02:08:25 PM
Ok, so result of boot time scan is I'm infected in C:/windows/installer with win32:adware-gen.  I was going to move move it to the chest but am unsure as it's inthe windows folder.  What should I do?
Title: Re: Have I got infected?
Post by: DigiDis on November 07, 2010, 02:33:41 PM
Quarantine it and reboot. If it reboots fine then you're OK. If it doesn't reboot then try to boot into Safe Mode and restore it from quarantine. Most likely putting it in quarantine will do nothing to your system, and Avast isn't that bad at all with false positives.
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 02:49:33 PM
When I go to move the file to the chest I get error 4211- the operation is not supported  for this type of archive!
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 02:58:10 PM
Tried to quarantine it but I get " Error 4211'- the operation is not supported for this type of archive". Help!
Title: Re: Have I got infected?
Post by: Omid Farhang on November 07, 2010, 03:27:05 PM
Rodny78, unless you come with us step by step, we will not be able to help you.

CCleaner and MBAM and avast! boot scan did not help, so are you still avoiding reply my questions?
I don't know what's your reason...

I guess that detection might be a False Positive, by you may try another scanner and see what it says:
http://www.omidfarhang.com/computer/security/avira-rescuecd (http://www.omidfarhang.com/computer/security/avira-rescuecd)
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 04:01:33 PM
Omit I'm not quite sure were your coming from.  I have carried out every scan that has been suggested, except for a HT log.  So saying that "if I don't come with us step by step" doesn't make much sense.

In addition to that, saying that Avast scan hasn't found anything when the boot time scan has found something when it has, also confuses me.

I'd really like to know how I can check what the boot time scan has found is a false positive?
Title: Re: Have I got infected?
Post by: Omid Farhang on November 07, 2010, 04:05:31 PM
Omit I'm not quite sure were your coming from.  I have carried out every scan that has been suggested, except for a HT log.  So saying that "if I don't come with us step by step" doesn't make much sense.
Sorry, I did not mean to offend you, if I said that in a wrong word, Excuse Me!  :-[
You just ignored that log file, which is most important for me to see an overall of your system without your personal info.

I'd really like to know how I can check what the boot time scan has found is a false positive?
Can you again find that file? In the Report/Logs or if you rmember file path, Find it and upload the file to http://www.virustotal.com/ and see the result, it would be nice if you share the link to result here too.

In addition to that, saying that Avast scan hasn't found anything when the boot time scan has found something when it has, also confuses me.
Some time it happen, because of running malware or similar problem, or Rootkits.
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 06:12:45 PM
No worries dude 8)

Ok, I had to run a 2nd boot scan to find the folder path ( C:\WINDOWS\Installer\d44d761.msp|>PCW_CAB_H15317_1|>EXCEL.EXE )

I submitted to virus total

http://www.virustotal.com/file-scan/report.html?id=f457907d05a4d2dd71efb2890434fbdc7738a3b9f1ff1518811dd2d7ec1653ab-1289149572

and after analysis, Avast, Avast5, G Data identified it as Win32:Adware-gen.

Avast will not move it to the chest for some reason.  Would it be OK to delete this file and would it cause me any problems and would it come back?
Title: Re: Have I got infected?
Post by: DigiDis on November 07, 2010, 07:07:15 PM
Can you move the file? To me it seems you can just delete that file, but to be sure try to rename it and even put it in some other location and restart your computer. If all seems fine then just delete it.

If for some reason you can't rename it, move it or delete it, download a linux Ubuntu ISO and burn it to disk and start Ubuntu in LiveCD mode and then you can delete it from the Ubuntu file browser. And this live CD will come in very handy for many other things, especially since you can always boot to it and it has a web browser already to go.

 
Title: Re: Have I got infected?
Post by: MAG on November 07, 2010, 07:46:23 PM
G data uses avast engine I believe, so I would be inclined to submit to avast first before doing anything else to the file. It may be an FP (rare with avast, but not unknown) if nothing else is detecting it.
Title: Re: Have I got infected?
Post by: Rodney78 on November 07, 2010, 07:54:33 PM
I was thinking of submittting to Avast.  I've copied the file from the Windows installer folder to another folder in the C drive which I've labled suspect.

How do I upload it to Avast?
Title: Re: Have I got infected?
Post by: MAG on November 07, 2010, 08:57:09 PM
Never had to do it! ;D

This is what it says on the avast site.

If you've sent the virus to the ’Virus Chest’ , open the ’Virus Chest’, right-click on the entry for the virus, and select 'Email to AVAST Software'. Alternatively, you can send it in a password-protected zip file to virus@avast.com making sure the password is included in the body of the email.
Title: Re: Have I got infected?
Post by: Omid Farhang on November 07, 2010, 09:01:12 PM
I was thinking of submittting to Avast.  I've copied the file from the Windows installer folder to another folder in the C drive which I've labled suspect.

How do I upload it to Avast?

You can compress this file password protected using WinRAR, 7Zip or WinZIP. attach it to an email (Don't forget to write password in email body) send to virus@ avast.com (without space)


But, did you notice you still did not give us an overview of your computer? like your installed programs and their version, your windows and...? ;)
Title: Re: Have I got infected?
Post by: DigiDis on November 07, 2010, 09:01:49 PM
Does your computer seem back to normal?
Title: Re: Have I got infected?
Post by: Rodney78 on November 08, 2010, 01:23:27 PM
Nope my computer isn't back to normal.

When I get home I'm going to submit file to Avast and carry out a HT log.

Thanks for all the replies so far 8)
Title: Re: Have I got infected?
Post by: Rodney78 on November 08, 2010, 08:25:12 PM
Ok, so I submitted the file to Avast to see what they think.
Title: Re: Have I got infected?
Post by: Rodney78 on November 08, 2010, 08:26:28 PM
Here is my HJT log:

C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\PC Tools Firewall Plus\FWService.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe
C:\Program Files\Dell\MediaDirect\PCMService.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Program Files\SigmaTel\C-Major Audio\WDM\stsystra.exe
C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\Program Files\Dell\QuickSet\Quickset.exe
C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe
C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Intel\Wireless\Bin\Dot1XCfg.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://news.bbc.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.virginmedia.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [00PCTFW] "C:\Program Files\PC Tools Firewall Plus\FirewallGUI.exe" -s
O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\MediaDirect\PCMService.exe"
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\stsystra.exe
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe"
O4 - HKLM\..\Run: [IntelWireless] "C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\Quickset.exe
O4 - HKLM\..\Run: [Monitor] "C:\Program Files\LeapFrog\LeapFrog Connect\Monitor.exe"
O4 - HKLM\..\Run: [avast5] C:\PROGRA~1\ALWILS~1\Avast5\avastUI.exe /nogui
O4 - HKLM\..\Run: [OSSelectorReinstall] C:\Program Files\Common Files\Acronis\Acronis Disk Director\oss_reinstall.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
O16 - DPF: {22945A69-1191-4DCF-9E6F-409BDE94D101} - http://louk.solidworks.com/htdocs/pdownload/edrawings/e2009sp01/cab/eModelsStandard.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194638823500
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194639021109
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E77F23EB-E7AB-4502-8F37-247DBAF1A147} (Windows Live Hotmail Photo Upload Tool) - http://gfx2.hotmail.com/mail/w4/pr01/photouploadcontrol/MSNPUpld.cab
O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Mail Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: avast! Web Scanner - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Roxio\Roxio MyDVD DE\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: PC Tools Firewall Plus (PCToolsFirewallPlus) - Unknown owner - C:\Program Files\PC Tools Firewall Plus\FWService.exe
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SolidWorks Licensing Service - SolidWorks - C:\Program Files\Common Files\SolidWorks Shared\Service\SolidWorksLicensing.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Intel(R) PROSet/Wireless SSO Service (WLANKEEPER) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\WLKeeper.exe



Title: Re: Have I got infected?
Post by: Omid Farhang on November 08, 2010, 08:34:49 PM
Rodney78, Thanks! but this is not all, please save the log on desktop, come back here and click on reply, click on 'Additional Options' in here bottom-left, browse the file and write something and click post
Title: Re: Have I got infected?
Post by: Rodney78 on November 08, 2010, 08:41:21 PM
Here we go:
Title: Re: Have I got infected?
Post by: Omid Farhang on November 08, 2010, 10:07:26 PM
Here we go:

Your  HijackThis log looks clean and without common unnecessary programs.

Is slow-down your only problem? If it is, well, if I was you I would check if PC Tools Firewall is causing the problem or not, because in my own test I had many performance issues with myself, just for testing propose, when you had free time, you may try to uninstall it and see how it affect your computer performance. [If it solved problem, you can try another free firewall, like Outpost Firewall]
Title: Re: Have I got infected?
Post by: Rodney78 on November 08, 2010, 10:37:33 PM
Thanks Omid.

Yeah I'm only experiencing typing latency in all applicaitons.  It si really frustrating and am considering re-installing XP as its driving me nuts!
Title: Re: Have I got infected?
Post by: Omid Farhang on November 08, 2010, 11:28:47 PM
Thanks Omid.

Yeah I'm only experiencing typing latency in all applicaitons.  It si really frustrating and am considering re-installing XP as its driving me nuts!

You are welcome.

Have you tried Firefox or Google Chrome too?
Did you reset Internet Explorer settings? (Control Panel -> Internet options -> Advanced (tab) -> Reset)
Also you can try to disable those addon you don't need. (Control Panel -> Internet options -> Programs (tab) -> Manage Add-ons)

Microsoft has Fixit tool for that:
*Improve performance, safety and security in Internet Explorer (http://support.microsoft.com/gp/ie_performance_and_safety)
Automatically diagnose issues that may reduce safety in Internet Explorer or cause Internet Explorer to respond slowly or crash.

*Fix Internet Explorer add-on problems when IE hangs or freezes (http://support.microsoft.com/gp/ie_freezes_or_crashes)
Automatically troubleshoot Internet Explorer problems when the browser crashes, freezes, hangs or stops responding caused by IE browser add-ons.

And here is more fixit tool for windows and other Microsoft programs: http://support.microsoft.com/fixit (http://support.microsoft.com/fixit)
Title: Re: Have I got infected?
Post by: DigiDis on November 09, 2010, 09:10:24 AM
Hey Rodney, sorry for your frustration. If you end up reinstalling XP I encourage you to adopt a system image backup routine. There are very good freeware programs like Paragon Backup and Recovery and Macrium Reflect. Paragon's free version allows differential backups to save a little space. On any new machine I usually install the OS and configure it to my liking and immediately do an image. Then I install the security software, attach the computer to the net and do updates to the OS and security software. Then do a differential backup. Then install all programs and get it running how you want and do a third image. From that point on do full or incremental images whenever you change stuff. Do a full backup every month. You can keep these images on external drives to free up space on your main drives.

Its much easier to rollback to a previous image than go through what you are going through now.

Last thought: Omid has a good point about PC Tools FW. I would suggest uninstalling that and Avast free and then putting the Avast Internet Security suite on as a trial to see if your computer behaves normally before you reinstall the OS. It's a great suite and has pretty much zero impact on computer performance.
Title: Re: Have I got infected?
Post by: Rodney78 on November 10, 2010, 08:36:21 PM
Thanks for everyone's efforts, alas it looks like I'm going to have to do an XP re-install as I've tried all the fixes/getting rid of PC tools firewall etc and the latency is still there.

One thing I will do, is go down the image route.  What would be the best freeware imaging software?  My only experience with this is with Norton Ghost and Acronis back up software, both of them I found very user unfriendly.
Title: Re: Have I got infected?
Post by: Omid Farhang on November 10, 2010, 09:32:49 PM
Thanks for everyone's efforts, alas it looks like I'm going to have to do an XP re-install as I've tried all the fixes/getting rid of PC tools firewall etc and the latency is still there.

One thing I will do, is go down the image route.  What would be the best freeware imaging software?  My only experience with this is with Norton Ghost and Acronis back up software, both of them I found very user unfriendly.
Windows 7 comes with built-in back tools which has ability with taking Image from Windows Installation Partition to an external hard drive or network drive (also DVD too, but you know how many DVD it would be...).

It takes backup very smooth in background. without need to reboot computer, also let you create a recovery disc (to let you boot your computer and restore image when windows don't boot anymore.

I've no opinion about XP...
Title: Re: Have I got infected?
Post by: scythe944 on November 10, 2010, 09:44:16 PM
Sounds like you could possibly have a hard drive failing.

If you do a re-install and it's still slow, I'd be running some tests on it.
Title: Re: Have I got infected?
Post by: DigiDis on November 11, 2010, 01:10:40 PM
As for imaging software for XP, free and good are Paragon Backup and Restore and Macrium Reflect. Both offer a free version. Macrium free only does full backups so uses more disk space. Paragon does differential backups but not incremental backups. Both have good reputations at the moment. You can use both if you have the disk space and time!

Norton and Acronis I don't think offer a free version and the paid versions get a lot, and I mean a lot, of criticism from users. Overall I think Macrium's paid version sounds like a winner but I do just fine with Paragon's free version.



Title: Re: Have I got infected?
Post by: Rodney78 on December 19, 2010, 01:39:09 PM
Quick update.

I re-installed XP and all was working well till today when the typing lag came back out of no where!

By chance, I did a quick Google search and found a post by someone having the same problems as myself.  The answer was to disable PCMservice.exe which as I understand is a component of Dell's Media Direct.  Low and behold, typing latency has gone!!

If only I had found this post before went through the trauma of re-installing!

One thing it has taught me though, is the Avast internet security suite is the business.

Whilst trying to re-install XP, some of the programs that I was installing including Window's updates kept hanging, and I'd find myself doing hard re-sets.

After I un-installed PC Tools firewall and coughed up for the Avast suite, my laptop runs like a dream (touch wood).

So thankyou to everyone who tried to help me with this problem, but like most things in life, you have to learn the hard way!