Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

web browser lag and adobe lag- never had this problem before


  • Please log in to reply
17 replies to this topic

#1 Mooglebooboo

Mooglebooboo

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 19 July 2012 - 12:59 AM

I never had this problem before and now I have it. I think there is something wrong with my computer. I noticed adobe flash crashes a lot. reinstalling it doesn't work. I've tried firefox troubleshooting and none of them work. When i watch videos, they have extreme lag and sometimes will freeze but the audio continues. Before my computer was fast and no problems but now its extremely slow. I cannot even browse and adobe flash crashes a lot. No matter where i visit i believe it has something to do with adobe flash. when i load a page that has flash contents on it, the computer will lag and takes a longtime to load or never load. I've even go on facebook for flash applications and the lag is really bad. I would have to wait maybe 6 minutes. Usually it only takes a second to load when the computer was normal. A clue maybe i went an unsafe website that has free japanes anime videos. I hear like file swapping sounds in the background. The web browser is where i lag the most.

BC AdBot (Login to Remove)

 


#2 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:06:34 AM

Posted 19 July 2012 - 06:57 AM

Download

TDSSkiller

Launch it.Click on change parameters-Select TDLFS file system

Click on "Scan".Please post the LOG report(log file should be in your C drive)

Do not change the default options on scan results

Download

aswMBR

Launch it, allow it to download latest Avast! virus definitions
Click the "Scan" button to start scan.After scan finishes,click on Save log

Post the log results here

Download

ESET online scanner

Install it

Click on START,it should download the virus definitions
When scan gets completed,click on LIST of found threats

Export the list to desktop,copy the contents of the text file in your reply

#3 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 19 July 2012 - 01:54 PM

1) TDSSKILLER found no threats




2) aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-07-19 09:48:44
-----------------------------
09:48:44.484 OS Version: Windows 5.1.2600 Service Pack 3
09:48:44.484 Number of processors: 2 586 0xE0C
09:48:44.484 ComputerName: XD UserName:
09:48:45.437 Initialize success
09:51:42.234 AVAST engine defs: 12071901
09:54:08.406 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-3
09:54:08.406 Disk 0 Vendor: SAMSUNG_HM120JI YF100-15 Size: 114473MB BusType: 3
09:54:08.593 Disk 0 MBR read successfully
09:54:08.609 Disk 0 MBR scan
09:54:11.828 Disk 0 Windows XP default MBR code
09:54:11.937 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 114463 MB offset 63
09:54:14.796 Disk 0 scanning sectors +234420480
09:54:16.781 Disk 0 scanning C:\WINDOWS\system32\drivers
09:59:33.437 Service scanning
10:00:50.843 Service MpKslee51cbfc c:\Documents and Settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{5D03A4A6-D174-4B89-98E3-22B715152503}\MpKslee51cbfc.sys **LOCKED** 32
10:02:58.984 Modules scanning
10:04:01.906 Disk 0 trace - called modules:
10:04:01.953 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys hal.dll atapi.sys pciide.sys PCIIDEX.SYS
10:04:01.968 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x86d57ab8]
10:04:01.968 3 CLASSPNP.SYS[f759dfd7] -> nt!IofCallDriver -> \Device\0000006a[0x86d08510]
10:04:01.968 5 ACPI.sys[f7414620] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP0T0L0-3[0x86d5b940]
10:04:03.968 AVAST engine scan C:\WINDOWS
10:06:54.812 AVAST engine scan C:\WINDOWS\system32
10:17:26.328 AVAST engine scan C:\WINDOWS\system32\drivers
10:18:16.218 AVAST engine scan C:\Documents and Settings\Ayra1008
10:48:27.812 AVAST engine scan C:\Documents and Settings\All Users
10:51:31.515 Scan finished successfully
11:14:08.640 Disk 0 MBR has been saved successfully to "C:\Documents and Settings\Ayra1008\Desktop\MBR.dat"
11:14:08.671 The log file has been saved successfully to "C:\Documents and Settings\Ayra1008\Desktop\aswMBR.txt"




3) C:\Documents and Settings\Ayra1008\Local Settings\temp\D9qZY0yQ.exe.part a variant of Win32/Adware.iBryte.C application cleaned by deleting - quarantined

C:\RECYCLER\S-1-5-21-790525478-1123561945-725345543-1004\Dc36.exe a variant of Win32/SoftonicDownloader.D application cleaned by deleting - quarantined

#4 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:06:34 AM

Posted 19 July 2012 - 02:11 PM

Download

http://www.techspot.com/downloads/4716-malwarebytes-anti-malware.html

Install,update and run a full scan

Click on SHOW results.Select all infections and remove it

Reboot the PC and scan MBAM once in regular mode until you get a clean log

Download

mini toolbox

Checkmark following boxes:

Flush DNS
Report IE Proxy Settings
Reset IE Proxy Settings
Report FF Proxy Settings
Reset FF Proxy Settings
List content of Hosts
List IP configuration
List Winsock Entries
List last 10 Event Viewer log
List Installed Programs
List Users, Partitions and Memory size

Click Go and post the result.

Download

FSS

Checkmark all the boxes

Click on "Scan".
Please copy and paste the log to your reply.

#5 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 19 July 2012 - 08:12 PM

minitoolbox has been running for a longtime. was i suppose to close all programs?

#6 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:06:34 AM

Posted 19 July 2012 - 08:53 PM

Run one by one

#7 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 19 July 2012 - 09:45 PM

MiniToolBox by Farbar Version: 15-07-2012
Ran by Ayra1008 (administrator) on 19-07-2012 at 22:38:21
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================


Windows IP Configuration



Successfully flushed the DNS Resolver Cache.


========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================

127.0.0.1 localhost

========================= IP Configuration: ================================



# ----------------------------------
# Interface IP Configuration
# ----------------------------------
pushd interface ip


# Interface IP Configuration for "Local Area Connection"

set address name="Local Area Connection" source=dhcp
set dns name="Local Area Connection" source=dhcp register=PRIMARY
set wins name="Local Area Connection" source=dhcp

# Interface IP Configuration for "Wireless Network Connection 2"

set address name="Wireless Network Connection 2" source=dhcp
set dns name="Wireless Network Connection 2" source=dhcp register=PRIMARY
set wins name="Wireless Network Connection 2" source=dhcp


popd
# End of interface IP configuration




Windows IP Configuration



Host Name . . . . . . . . . . . . : XD

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Unknown

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No

DNS Suffix Search List. . . . . . : mc.at.cox.net



Ethernet adapter Local Area Connection:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : Broadcom 440x 10/100 Integrated Controller

Physical Address. . . . . . . . . : 00-19-B9-5F-B7-D7



Ethernet adapter Wireless Network Connection 2:



Connection-specific DNS Suffix . : mc.at.cox.net

Description . . . . . . . . . . . : Dell Wireless 1390 WLAN Mini-Card

Physical Address. . . . . . . . . : 00-1A-92-CF-91-29

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.0.102

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.0.1

DHCP Server . . . . . . . . . . . : 192.168.0.1

DNS Servers . . . . . . . . . . . : 192.168.0.1

Lease Obtained. . . . . . . . . . : Thursday, July 19, 2012 9:41 AM

Lease Expires . . . . . . . . . . : Thursday, July 26, 2012 9:41 AM

Server: UnKnown
Address: 192.168.0.1

Name: google.com
Addresses: 74.125.227.46, 74.125.227.32, 74.125.227.33, 74.125.227.34
74.125.227.35, 74.125.227.36, 74.125.227.37, 74.125.227.38, 74.125.227.39
74.125.227.40, 74.125.227.41



Pinging google.com [74.125.227.41] with 32 bytes of data:



Reply from 74.125.227.41: bytes=32 time=60ms TTL=52

Reply from 74.125.227.41: bytes=32 time=80ms TTL=53



Ping statistics for 74.125.227.41:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 60ms, Maximum = 80ms, Average = 70ms

Server: UnKnown
Address: 192.168.0.1

Name: yahoo.com
Addresses: 209.191.122.70, 72.30.38.140, 98.139.183.24



Pinging yahoo.com [98.139.183.24] with 32 bytes of data:



Reply from 98.139.183.24: bytes=32 time=280ms TTL=54

Reply from 98.139.183.24: bytes=32 time=159ms TTL=54



Ping statistics for 98.139.183.24:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 159ms, Maximum = 280ms, Average = 219ms

Server: UnKnown
Address: 192.168.0.1

Name: bleepingcomputer.com
Address: 208.43.87.2



Pinging bleepingcomputer.com [208.43.87.2] with 32 bytes of data:



Request timed out.

Request timed out.



Ping statistics for 208.43.87.2:

Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),



Pinging 127.0.0.1 with 32 bytes of data:



Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Reply from 127.0.0.1: bytes=32 time<1ms TTL=128



Ping statistics for 127.0.0.1:

Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),

Approximate round trip times in milli-seconds:

Minimum = 0ms, Maximum = 0ms, Average = 0ms

===========================================================================
Interface List
0x1 ........................... MS TCP Loopback interface
0x2 ...00 19 b9 5f b7 d7 ...... Broadcom 440x 10/100 Integrated Controller - Packet Scheduler Miniport
0x3 ...00 1a 92 cf 91 29 ...... Dell Wireless 1390 WLAN Mini-Card - Packet Scheduler Miniport
===========================================================================
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 192.168.0.1 192.168.0.102 25
127.0.0.0 255.0.0.0 127.0.0.1 127.0.0.1 1
169.254.0.0 255.255.0.0 192.168.0.102 192.168.0.102 20
192.168.0.0 255.255.255.0 192.168.0.102 192.168.0.102 25
192.168.0.102 255.255.255.255 127.0.0.1 127.0.0.1 25
192.168.0.255 255.255.255.255 192.168.0.102 192.168.0.102 25
224.0.0.0 240.0.0.0 192.168.0.102 192.168.0.102 25
255.255.255.255 255.255.255.255 192.168.0.102 2 1
255.255.255.255 255.255.255.255 192.168.0.102 192.168.0.102 1
Default Gateway: 192.168.0.1
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 02 C:\Windows\System32\winrnr.dll [16896] (Microsoft Corporation)
Catalog5 03 C:\Windows\System32\mswsock.dll [245248] (Microsoft Corporation)
Catalog5 04 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 02 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 03 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 04 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 05 C:\Windows\system32\rsvpsp.dll [92672] (Microsoft Corporation)
Catalog9 06 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 07 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 08 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 09 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 10 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 11 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 12 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 13 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 14 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 15 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 16 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)
Catalog9 17 C:\Windows\system32\mswsock.dll [245248] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (07/16/2012 04:06:17 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6437

Error: (07/16/2012 04:06:17 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6437

Error: (07/16/2012 04:06:17 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/16/2012 04:06:15 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4468

Error: (07/16/2012 04:06:15 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4468

Error: (07/16/2012 04:06:15 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/16/2012 04:06:13 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2062

Error: (07/16/2012 04:06:13 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2062

Error: (07/16/2012 04:06:13 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/16/2012 03:29:48 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3578


System errors:
=============
Error: (07/19/2012 09:58:38 AM) (Source: 0) (User: )
Description: \Device\Ide\IdePort0

Error: (07/19/2012 09:41:45 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASKUTIL

Error: (07/19/2012 09:41:44 AM) (Source: Service Control Manager) (User: )
Description: The SAS Core Service service failed to start due to the following error:
%%3

Error: (07/18/2012 08:57:46 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASKUTIL

Error: (07/18/2012 08:57:43 PM) (Source: Service Control Manager) (User: )
Description: The SAS Core Service service failed to start due to the following error:
%%3

Error: (07/17/2012 03:41:53 PM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASKUTIL

Error: (07/17/2012 03:41:53 PM) (Source: Service Control Manager) (User: )
Description: The SAS Core Service service failed to start due to the following error:
%%3

Error: (07/16/2012 11:25:48 AM) (Source: Service Control Manager) (User: )
Description: The following boot-start or system-start driver(s) failed to load:
SASKUTIL

Error: (07/16/2012 11:25:45 AM) (Source: Service Control Manager) (User: )
Description: The SAS Core Service service failed to start due to the following error:
%%3

Error: (07/16/2012 11:25:41 AM) (Source: Print) (User: NT AUTHORITY)
Description: Sharing printer failed + 1722, Printer Lexmark 2600 Series share name Printer2.


Microsoft Office Sessions:
=========================
Error: (07/16/2012 04:06:17 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 6437

Error: (07/16/2012 04:06:17 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 6437

Error: (07/16/2012 04:06:17 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/16/2012 04:06:15 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 4468

Error: (07/16/2012 04:06:15 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 4468

Error: (07/16/2012 04:06:15 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/16/2012 04:06:13 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 2062

Error: (07/16/2012 04:06:13 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 2062

Error: (07/16/2012 04:06:13 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (07/16/2012 03:29:48 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 3578


=========================== Installed Programs ============================

7-Zip 9.20
Adobe AIR (Version: 3.1.0.4880)
Adobe Flash Player 10 Plugin (Version: 10.3.183.20)
Adobe Reader X (10.1.3) (Version: 10.1.3)
Adobe Shockwave Player 11.6 (Version: 11.6.4.634)
AIM 7
Apple Application Support (Version: 2.1.7)
Apple Mobile Device Support (Version: 5.1.1.4)
Apple Software Update (Version: 2.1.3.127)
Bonjour (Version: 3.0.0.10)
Broadcom 440x 10/100 Integrated Controller (Version: 10.04.01)
CCleaner (Version: 3.18)
Conexant HDA D110 MDC V.92 Modem
Coupon Printer for Windows (Version: 5.0.0.0)
Dell Driver Download Manager (Version: 2.1.0.0)
Dell Wireless WLAN Card (Version: 4.170.25.12)
DivxToDVD 0.5.2b (Version: 0.5.2b)
Download Updater (AOL LLC)
ESET Online Scanner v3
Facebook Video Calling 1.2.0.159 (Version: 1.2.159)
FeralHeart version 1.13 (Version: 1.13)
GIMP 2.8.0 (Version: 2.8.0)
GoonzuEng (Version: 555)
High Definition Audio Driver Package - KB835221 (Version: 20040219.000000)
HiJackThis (Version: 1.0.0)
HP Deskjet 1000 J110 series Basic Device Software (Version: 22.50.231.0)
HP Deskjet 1000 J110 series Help (Version: 140.0.65.65)
HP Deskjet 1000 J110 series Product Improvement Study (Version: 22.50.231.0)
HP Photo Creations (Version: 1.0.0.3781)
HP Update (Version: 5.002.006.003)
IconArt (Version: 2.0.1)
ijji Auto Installer (Version: 1.00.0000)
Intel® Graphics Media Accelerator Driver
Intel® PROSet/Wireless Software (Version: 11.5.0000)
iTunes (Version: 10.6.1.7)
Java Auto Updater (Version: 2.1.6.0)
Java™ 7 Update 4 (Version: 7.0.40)
JavaFX 2.1.0 (Version: 2.1.0)
K-Lite v2.7
Kalydo Player 3.10.04 (Version: 3.10.04)
Kazaa Lite 2.7
Lexmark 2600 Series
Luminary - Rise of Goonzu 654 (Version: 654)
Malwarebytes Anti-Malware version 1.62.0.1300 (Version: 1.62.0.1300)
Manga Studio Debut 4.0
mCore (Version: 11.02.0000)
mDriver (Version: 11.02.0000)
mDrWiFi (Version: 11.02.0000)
Media Player Codec Pack 3.9.9
mHlpDell (Version: 11.02.0000)
Microsoft .NET Framework 2.0 Service Pack 2 (Version: 2.2.30729)
Microsoft .NET Framework 3.0 Service Pack 2 (Version: 3.2.30729)
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729)
Microsoft Application Error Reporting (Version: 12.0.6012.5000)
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003)
Microsoft Office Professional Edition 2003 (Version: 11.0.8173.0)
Microsoft Security Client (Version: 4.0.1526.0)
Microsoft Security Essentials (Version: 4.0.1526.0)
Microsoft Silverlight (Version: 5.1.10411.0)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (Version: 9.0.21022)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161)
mIWA (Version: 11.02.0000)
mLogView (Version: 11.02.0000)
mMHouse (Version: 11.02.0000)
Mouse Suite for Laptop Computers (Version: 1.00.0000)
Mozilla Firefox 14.0.1 (x86 en-US) (Version: 14.0.1)
Mozilla Maintenance Service (Version: 14.0.1)
Mp3tag v2.51 (Version: v2.51)
mPfMgr (Version: 11.02.0000)
mPfWiz (Version: 11.02.0000)
mProSafe (Version: 9.00.0000)
mSCfg (Version: 11.02.0000)
mSSO (Version: 11.02.0000)
MSXML 6 Service Pack 2 (KB973686) (Version: 6.20.2003.0)
mWlsSafe (Version: 9.00.0000)
mWMI (Version: 11.02.0000)
mZConfig (Version: 11.02.0000)
Nexon Game Manager
Pando Media Booster (Version: 2.3.6.0)
Pen Pad Driver with Macro Key Manager
QuickSet (Version: 8.1.12)
QuickTime (Version: 7.72.80.56)
Revo Uninstaller 1.94 (Version: 1.94)
SigmaTel Audio (Version: 5.10.5210.0)
Skype Click to Call (Version: 6.0.10297)
Skype™ 5.10 (Version: 5.10.114)
SPORE™ (Version: 1.00.0000)
StarCraft
swMSM (Version: 12.0.0.1)
System Requirements Lab for Intel (Version: 4.5.3.0)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1)
Update for Windows XP (KB2345886) (Version: 1)
Update for Windows XP (KB2541763) (Version: 1)
Update for Windows XP (KB2607712) (Version: 1)
Update for Windows XP (KB2616676) (Version: 1)
Update for Windows XP (KB2641690) (Version: 1)
Update for Windows XP (KB2718704) (Version: 1)
Update for Windows XP (KB951978) (Version: 1)
Update for Windows XP (KB955759) (Version: 1)
Update for Windows XP (KB967715) (Version: 1)
Update for Windows XP (KB968389) (Version: 1)
Update for Windows XP (KB971029) (Version: 1)
Update for Windows XP (KB971737) (Version: 1)
Update for Windows XP (KB973687) (Version: 1)
Update for Windows XP (KB973815) (Version: 1)
WebFldrs XP (Version: 9.50.7523)
Windows Driver Package - Ricoh Company (rimsptsk) hdc (11/14/2006 6.00.01.04) (Version: 11/14/2006 6.00.01.04)
Windows Genuine Advantage Validation Tool (KB892130)
Windows Genuine Advantage Validation Tool (KB892130) (Version: 1.7.0069.2)
Windows Imaging Component (Version: 3.0.0.0)
Windows Internet Explorer 8 (Version: 20090308.140743)
Windows XP Service Pack 3 (Version: 20080414.031525)
WinPatrol (Version: 24.6.2012)
WinRAR 4.01 (32-bit) (Version: 4.01.0)
Xilisoft YouTube Video Converter (Version: 3.3.0.20120525)
Zoo Tycoon: Complete Collection

========================= Memory info: ===================================

Percentage of memory in use: 44%
Total physical RAM: 1014.37 MB
Available physical RAM: 564.83 MB
Total Pagefile: 2918.1 MB
Available Pagefile: 2460.7 MB
Total Virtual: 2047.88 MB
Available Virtual: 1974.89 MB

========================= Partitions: =====================================

1 Drive c: () (Fixed) (Total:111.78 GB) (Free:57.29 GB) NTFS

========================= Users: ========================================

User accounts for \\XD

Administrator Ayra1008 Guest
HelpAssistant SUPPORT_388945a0


**** End of log ****

#8 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 19 July 2012 - 09:46 PM

Farbar Service Scanner Version: 19-07-2012
Ran by Ayra1008 (administrator) on 19-07-2012 at 22:46:22
Running from "C:\Documents and Settings\Ayra1008\Desktop"
Microsoft Windows XP Home Edition Service Pack 3 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Yahoo IP is accessible.
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============
Srservice Service is not running. Checking service configuration:
The start type of Srservice service is OK.
The ImagePath of Srservice service is OK.
The ServiceDll of Srservice service is OK.

sr Service is not running. Checking service configuration:
The start type of sr service is set to Disabled. The default start type is Boot.
The ImagePath of sr: "\SystemRoot\system32\DRIVERS\sr.sys".


System Restore Disabled Policy:
========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR"=DWORD:1


Security Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


File Check:
========
C:\WINDOWS\system32\dhcpcsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\afd.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\netbt.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\tcpip.sys => MD5 is legit
C:\WINDOWS\system32\Drivers\ipsec.sys => MD5 is legit
C:\WINDOWS\system32\dnsrslvr.dll => MD5 is legit
C:\WINDOWS\system32\ipnathlp.dll => MD5 is legit
C:\WINDOWS\system32\netman.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\srsvc.dll => MD5 is legit
C:\WINDOWS\system32\Drivers\sr.sys => MD5 is legit
C:\WINDOWS\system32\wscsvc.dll => MD5 is legit
C:\WINDOWS\system32\wbem\WMIsvc.dll => MD5 is legit
C:\WINDOWS\system32\wuauserv.dll => MD5 is legit
C:\WINDOWS\system32\qmgr.dll => MD5 is legit
C:\WINDOWS\system32\es.dll => MD5 is legit
C:\WINDOWS\system32\cryptsvc.dll => MD5 is legit
C:\WINDOWS\system32\svchost.exe => MD5 is legit
C:\WINDOWS\system32\rpcss.dll => MD5 is legit
C:\WINDOWS\system32\services.exe => MD5 is legit

Extra List:
=======
AegisP(8) Gpc(3) IPSec(5) NetBT(6) PSched(7) Tcpip(4)
0x0700000005000000010000000200000003000000040000000600000007000000
IpSec Tag value is correct.

**** End of log ****

#9 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:06:34 AM

Posted 19 July 2012 - 10:06 PM

MBAM log ?

Download

adware cleaner

Launch it click on Delete

post the generated log

#10 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 20 July 2012 - 07:28 PM

for mbam there were no threats found

#11 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 20 July 2012 - 07:34 PM

# AdwCleaner v1.703 - Logfile created 07/20/2012 at 20:30:21
# Updated 20/07/2012 by Xplode
# Operating system : Microsoft Windows XP Service Pack 3 (32 bits)
# User : Ayra1008 - XD
# Running from : C:\Documents and Settings\Ayra1008\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Documents and Settings\Ayra1008\Local Settings\Application Data\Conduit
Folder Deleted : C:\Documents and Settings\All Users\Application Data\InstallMate
Folder Deleted : C:\Program Files\Conduit
Folder Deleted : C:\Program Files\Common Files\Software Update Utility

***** [Registry] *****

[*] Key Deleted : HKLM\SOFTWARE\Classes\Toolbar.CT2790392
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
Key Deleted : HKLM\SOFTWARE\Conduit
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.6001.18702

[OK] Registry is clean.

-\\ Mozilla Firefox v14.0.1 (en-US)

Profile name : default
File : C:\Documents and Settings\Ayra1008\Application Data\Mozilla\Firefox\Profiles\k8s00xl0.default\prefs.js

[OK] File is clean.

*************************

AdwCleaner[S1].txt - [2639 octets] - [20/07/2012 20:30:21]

########## EOF - C:\AdwCleaner[S1].txt - [2767 octets] ##########

#12 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:06:34 AM

Posted 20 July 2012 - 08:28 PM

Any current issues?

#13 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 22 July 2012 - 04:58 PM

nope

#14 narenxp

narenxp

  • BC Advisor
  • 16,371 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:India
  • Local time:06:34 AM

Posted 22 July 2012 - 05:04 PM

That looks good

Download

TFC

Launch it,it will close all running programs

click on START,it should ask for reboot

Turn off your system restore,restart the PC,create a new restore point

http://support.microsoft.com/kb/310405

Update your flash player

Update your JAVA from here

http://java.com/en/download/inc/windows_upgrade_xpi.jsp

Update your antivirus frequently,do not click on suspicious links

Safe surfing :)

Edited by narenxp, 22 July 2012 - 05:05 PM.


#15 Mooglebooboo

Mooglebooboo
  • Topic Starter

  • Members
  • 245 posts
  • OFFLINE
  •  
  • Local time:06:34 AM

Posted 25 July 2012 - 10:38 PM

It seems another problem has appeared:

I can't even use my search engine because it loads a different page and not the link it was suppose to go to. It does it on all search engines. It makes me have to type the link manually, which i don't want to have to keep doing. I even click on links from other pages and an ad loads instead. Sme goes for the search engines.

One that shows most of the time is. It adds itself on my firefox tab on its own. It does it every time i browse. Sometimes it appears every number of minutes and its quite annoying.

One Example i tried to search animeratio.com. Instead of leading me to the main site, I was redirected to:

http://83.133.127.85/_ylt=3648C868A1DB;c2VhcmNoYnVzaW5lc3NsaXN0aW5nLmNvbS93ZWJzZWFyY2gucGhwP3NlYXJjaD1hbmltZXJhdGlvJkJ0blM9U2VhcmNo-ODMuMTMzLjEyNy44NS9Ha2kzWUdreDZ2N21kN2MwZTdlMWEyZThkZDU4MjliNjM5NzkzMzM0MjliOTMyYTAyNUE=

Sometimes when i go browsing a page adds on to one of my tabs in firefox. The same ad every time. SOmething called 'consumer lifestyles'

There's another one as well. Other website links are okay, but not search engines. I also noticed firefox is allowing popups that i didn't give permission to. it usually pops up something asking my permission to allow that popup.

another link that it redirects me to is:
http://businesslistingsearch.biz/websearch.php?search=bleach+english+dub+268&BtnS=Search

and a fake facebook ad

Edited by Mooglebooboo, 25 July 2012 - 11:35 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users