Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

slow performance with xp pc


  • Please log in to reply

#46
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP
You are connecting with the Wireless (Atheros AR5001X+ Wireless Network Adapter) per Speccy so that's the most likely candidate. If that doesn't help give me the make and mode number of your PC and I will look but we are going off-island in a few minutes and won't be back until late tonight. No Internet access until we get back.
  • 0

Advertisements


#47
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
i haven't been able to locate a driver yet, but i may not be looking for the right thing. i have registered with artheros customer portal and am waiting for a reply. it's a toshiba a20-s259. i am looking at the toshiba web site and this is the list that i sent you.

http://www.csd.toshi...mily=1073768663
  • 0

#48
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP
Try this one from your Toshiba site:

Utility
Wi-Fi Atheros WiFi Client Utility with Cisco/WPA Support for Windows XP/2000(v2.4.2.18; 11-11-2003; 4.66M)


http://www.csd.toshi...ily=1073768663#
  • 0

#49
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
so i need some assistance installing this. it says i need to uninstall the pre-existing client utility which i don't know how to do.

then do i just double click and install this utility or do i do this through device manager, and if so, where? i gather that some or all drivers need to be installed through device manager.

also, this driver is dependent on the adjacent "driver wi-fi". does this need to be re-installed too?

if you can kind of work me through it like you did with the malware programs and scanners that would be greatly appreciated.

Edited by benny_b, 08 February 2012 - 09:39 AM.

  • 0

#50
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP
I don't see an Extras log so can't tell exactly what it is installed. Download the file then look and see if you have anything by Atheros in your uninstall list. If you do uninstall it. Reboot. Install the downloaded file. You shouldn't need device manager for this.
  • 0

#51
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
i did a clean reinstall of the client utility, but it didn't seem to help. DPCs and HIs are spiking from 1.99 to 3.95 and the DPC latency checker absolute maximum spiked to 91847us.
  • 0

#52
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP
If we ignore the results of Process Explorer and windows performance tools how is it running now?
  • 0

#53
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
well... poorly. the browser is slow. i had the whole thing freeze on me earlier today. the boot time has improved, but it used to be faster. my desktop used to load in a few seconds. now it's about 30, but that's better than 2-3 minutes a few weeks ago. i'm still confused why that has improved. other than a disk error check we ran which i tried a few times before.

i had a look in the system event viewer and there are numerous dhcp 1003 warnings, sometimes within 30 sec of one another and one dhcp 1002 error.
  • 0

#54
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP
Run VEW again and let me see what errors you are getting. Also do

Start, Run, cmd, OK

netstat  -an  >  \junk.txt
ipconfig  /all  >>  \junk.txt
notepad  \junk.txt

Copy and paste the text from \junk.txt
  • 0

#55
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
Vino's Event Viewer v01c run on Windows XP in English
Report run at 09/02/2012 9:12:40 AM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 08/02/2012 11:33:51 AM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.106 for the Network Card with network address 009096726AB2 has been denied by the DHCP server 10.0.60.1 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 06/02/2012 3:42:20 PM
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Program Files\AVAST Software\Avast\AvastUI.exe. Reference error message: The operation completed successfully. .

Log: 'System' Date/Time: 06/02/2012 3:42:20 PM
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.VC90.MFC. Reference error message: The referenced assembly is not installed on your system. .

Log: 'System' Date/Time: 06/02/2012 3:42:20 PM
Type: error Category: 0
Event: 32 Source: SideBySide
Dependent Assembly Microsoft.VC90.MFC could not be found and Last Error was The referenced assembly is not installed on your system.

Log: 'System' Date/Time: 06/02/2012 3:41:58 PM
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Program Files\AVAST Software\Avast\AvastUI.exe. Reference error message: The operation completed successfully. .

Log: 'System' Date/Time: 06/02/2012 3:41:58 PM
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.VC90.MFC. Reference error message: The referenced assembly is not installed on your system. .

Log: 'System' Date/Time: 06/02/2012 3:41:58 PM
Type: error Category: 0
Event: 32 Source: SideBySide
Dependent Assembly Microsoft.VC90.MFC could not be found and Last Error was The referenced assembly is not installed on your system.

Log: 'System' Date/Time: 06/02/2012 3:39:33 PM
Type: error Category: 0
Event: 59 Source: SideBySide
Generate Activation Context failed for C:\Program Files\AVAST Software\Avast\avastUI.exe. Reference error message: The operation completed successfully. .

Log: 'System' Date/Time: 06/02/2012 3:39:33 PM
Type: error Category: 0
Event: 59 Source: SideBySide
Resolve Partial Assembly failed for Microsoft.VC90.MFC. Reference error message: The referenced assembly is not installed on your system. .

Log: 'System' Date/Time: 06/02/2012 3:39:33 PM
Type: error Category: 0
Event: 32 Source: SideBySide
Dependent Assembly Microsoft.VC90.MFC could not be found and Last Error was The referenced assembly is not installed on your system.

Log: 'System' Date/Time: 01/02/2012 5:36:36 PM
Type: error Category: 0
Event: 9 Source: atapi
The device, \Device\Ide\IdePort0, did not respond within the timeout period.

Log: 'System' Date/Time: 01/02/2012 5:36:10 PM
Type: error Category: 0
Event: 9 Source: atapi
The device, \Device\Ide\IdePort0, did not respond within the timeout period.

Log: 'System' Date/Time: 01/02/2012 5:35:44 PM
Type: error Category: 0
Event: 9 Source: atapi
The device, \Device\Ide\IdePort0, did not respond within the timeout period.

Log: 'System' Date/Time: 01/02/2012 3:02:20 PM
Type: error Category: 0
Event: 1 Source: sr
The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

Log: 'System' Date/Time: 31/01/2012 9:00:58 PM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.106 for the Network Card with network address 009096726AB2 has been denied by the DHCP server 10.0.60.1 (The DHCP Server sent a DHCPNACK message).

Log: 'System' Date/Time: 31/01/2012 3:11:13 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Log: 'System' Date/Time: 31/01/2012 3:11:12 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Log: 'System' Date/Time: 31/01/2012 3:07:38 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Log: 'System' Date/Time: 31/01/2012 3:01:51 PM
Type: error Category: 0
Event: 10005 Source: DCOM
DCOM got error "%1084" attempting to start the service StiSvc with arguments "" in order to run the server: {A1F4E726-8CF1-11D1-BF92-0060081ED811}

Log: 'System' Date/Time: 30/01/2012 12:23:06 PM
Type: error Category: 0
Event: 1 Source: sr
The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 09/02/2012 9:03:36 AM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The semaphore timeout period has expired. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 8:01:24 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 08/02/2012 7:33:33 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 08/02/2012 5:50:13 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.

Log: 'System' Date/Time: 08/02/2012 5:37:15 PM
Type: warning Category: 0
Event: 1009 Source: Dhcp
A network error occurred when trying to send a message. The error code is: A blocking operation was interrupted by a call to WSACancelBlockingCall. .

Log: 'System' Date/Time: 08/02/2012 5:37:15 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:35:02 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:34:48 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:34:27 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:34:01 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:33:37 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:33:08 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:32:54 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:32:46 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:32:28 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:32:09 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:31:54 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:31:44 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:31:27 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.

Log: 'System' Date/Time: 08/02/2012 5:31:19 PM
Type: warning Category: 0
Event: 1003 Source: Dhcp
Your computer was not able to renew its address from the network (from the DHCP Server) for the Network Card with network address 009096726AB2. The following error occurred: The operation was canceled by the user. . Your computer will continue to try and obtain an address on its own from the network address (DHCP) server.



Active Connections

Proto Local Address Foreign Address State
TCP 0.0.0.0:135 0.0.0.0:0 LISTENING
TCP 0.0.0.0:445 0.0.0.0:0 LISTENING
TCP 127.0.0.1:1025 0.0.0.0:0 LISTENING
TCP 127.0.0.1:1053 127.0.0.1:1054 ESTABLISHED
TCP 127.0.0.1:1054 127.0.0.1:1053 ESTABLISHED
TCP 127.0.0.1:1055 127.0.0.1:1056 ESTABLISHED
TCP 127.0.0.1:1056 127.0.0.1:1055 ESTABLISHED
TCP 127.0.0.1:1097 127.0.0.1:12080 ESTABLISHED
TCP 127.0.0.1:1123 127.0.0.1:12080 TIME_WAIT
TCP 127.0.0.1:1125 127.0.0.1:12080 TIME_WAIT
TCP 127.0.0.1:1127 127.0.0.1:12080 ESTABLISHED
TCP 127.0.0.1:12025 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12080 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12080 127.0.0.1:1097 ESTABLISHED
TCP 127.0.0.1:12080 127.0.0.1:1127 ESTABLISHED
TCP 127.0.0.1:12110 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12119 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12143 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12465 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12563 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12993 0.0.0.0:0 LISTENING
TCP 127.0.0.1:12995 0.0.0.0:0 LISTENING
TCP 192.168.1.106:139 0.0.0.0:0 LISTENING
TCP 192.168.1.106:1039 192.168.1.121:139 ESTABLISHED
TCP 192.168.1.106:1098 72.14.204.100:80 ESTABLISHED
TCP 192.168.1.106:1128 74.125.226.43:80 ESTABLISHED
TCP 192.168.1.106:1129 74.125.226.39:443 ESTABLISHED
UDP 0.0.0.0:445 *:*
UDP 0.0.0.0:500 *:*
UDP 0.0.0.0:4500 *:*
UDP 127.0.0.1:1115 *:*
UDP 127.0.0.1:1900 *:*
UDP 192.168.1.106:137 *:*
UDP 192.168.1.106:138 *:*
UDP 192.168.1.106:1900 *:*


Windows IP Configuration



Host Name . . . . . . . . . . . . : js-dnqv5ud8yble

Primary Dns Suffix . . . . . . . :

Node Type . . . . . . . . . . . . : Broadcast

IP Routing Enabled. . . . . . . . : No

WINS Proxy Enabled. . . . . . . . : No



Ethernet adapter Local Area Connection:



Media State . . . . . . . . . . . : Media disconnected

Description . . . . . . . . . . . : Realtek RTL8139/810x Family Fast Ethernet NIC

Physical Address. . . . . . . . . : 00-08-0D-12-EC-C6



Ethernet adapter Wireless Network Connection:



Connection-specific DNS Suffix . :

Description . . . . . . . . . . . : Atheros AR5001X+ Wireless Network Adapter

Physical Address. . . . . . . . . : 00-90-96-72-6A-B2

Dhcp Enabled. . . . . . . . . . . : Yes

Autoconfiguration Enabled . . . . : Yes

IP Address. . . . . . . . . . . . : 192.168.1.106

Subnet Mask . . . . . . . . . . . : 255.255.255.0

Default Gateway . . . . . . . . . : 192.168.1.1

DHCP Server . . . . . . . . . . . : 192.168.1.1

DNS Servers . . . . . . . . . . . : 192.168.1.1

Lease Obtained. . . . . . . . . . : Wednesday, February 08, 2012 5:37:15 PM

Lease Expires . . . . . . . . . . : Thursday, February 09, 2012 5:37:15 PM
  • 0

Advertisements


#56
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP

Log: 'System' Date/Time: 01/02/2012 5:36:36 PM
Type: error Category: 0
Event: 9 Source: atapi
The device, \Device\Ide\IdePort0, did not respond within the timeout period.

Log: 'System' Date/Time: 01/02/2012 5:36:10 PM
Type: error Category: 0
Event: 9 Source: atapi
The device, \Device\Ide\IdePort0, did not respond within the timeout period.

Log: 'System' Date/Time: 01/02/2012 5:35:44 PM
Type: error Category: 0
Event: 9 Source: atapi
The device, \Device\Ide\IdePort0, did not respond within the timeout period.


This is probably the real cause of the slowness. Try the Quick Solution at http://winhlp.com/node/10

Log: 'System' Date/Time: 08/02/2012 11:33:51 AM
Type: error Category: 0
Event: 1002 Source: Dhcp
The IP address lease 192.168.1.106 for the Network Card with network address 009096726AB2 has been denied by the DHCP server 10.0.60.1 (The DHCP Server sent a DHCPNACK message).


This one is interesting. With an IP address of 192.168.1.106 there is no reason it should be talking to a DHCP server of 10.0.60.1 unless it moved to a different network. Did you move it? Are you using encryption? Is there any chance it is trying to connect to a neighbor's wireless network?

Log: 'System' Date/Time: 08/02/2012 8:01:24 PM
Type: warning Category: 0
Event: 4226 Source: Tcpip
TCP/IP has reached the security limit imposed on the number of concurrent TCP connect attempts.


We usually see this error with Limewire or uTorrent or other P2P program. Make sure you are not running one of them.

The System Restore filter encountered the unexpected error '0xC0000001' while processing the file '' on the volume 'HarddiskVolume1'. It has stopped monitoring the volume.

The recommend action for this error is to turn off System Restore. Wait a minute then Turn it back on. http://support.microsoft.com/kb/310405
  • 0

#57
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
OK. i restarted the system restore. i tried to repair the ide channels, but something is screwy. i checked the setting before i started and they were set to DMA if avaliable and ultra DMA mode 5, but i ran the vbs anyways and it said:

program run successfully
The following channels have been reset:
Master of Secondary IDE Channel
Master of Primary IDE Channel
Please reboot now to reset and redetect the DMA status.

so i rebooted and it said exactly the same thing. i tried it again and it was the same. i tried the next step to manually change to PIO, reboot, manually change to DMA and reboot again. ran the vbs and i got the same result. i ran the script without rebooting and it said there were no channels to change, so it corrects the problem, but this gets wiped out with the reboot.


i have no idea what "DHCP server of 10.0.60.1" is. i don't know if any of this is relevant but i have recently changed my isp, and my neighbor worked on my computer about three year ago. when i started my new isp service i was installing the modem and aborted partways through as my isp told me that all of the gear was pre-configured.
i use WPA encryption, that's all.
  • 0

#58
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP
Probably didn't need the fix if it was using DMA if available and ultra DMA mode 5.

The DHCP server of 10.0.60.1 is a current error. It apparently got a reply back from 10.0.60.1 yesterday. It should not be getting these replies. If it were my router I would get on it and change it to use a unique SSID and WPA or WPA2 encryption. Using the default SSID can result in confusion if a neighbor has the same router tho with WPA encryption it seems unlikely that it could accidentally sync up to your neighbor's. Perhaps the neighbor's router has no encryption and at some time in the past you told it by mistake to connect up.
  • 0

#59
benny_b

benny_b

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 103 posts
so i have a unique ssid and am using wpa. anything else to try?
  • 0

#60
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,001 posts
  • MVP
Let's see what VEW says now.

Let's see if atapi.sys looks right:


Copy the text in the code box:

nnetsvcs
%SYSTEMDRIVE%\*.exe
msconfig
safebootminimal
safebootnetwork
activex
drivers32
%SYSTEMDRIVE%\*.exe
%ALLUSERSPROFILE%\Application Data\*.exe
%APPDATA%\*.
/md5start
atapi.sys
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
consrv.dll
NDIS.sys
sdbus.sys
pcmcia.sys
USBPORT.SYS
VIDEOPRT.SYS
portcls.sys
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
hklm\software\clients\startmenuinternet|command /64 /rs
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\system32\drivers\*.sys /lockedfiles
CREATERESTOREPOINT

Run OTL (Vista or Win 7 => right click and Run As Administrator)

Paste (Ctrl + v) the copied text in the box where it says Custom Scan/Fixes


You should get 1 log. Please copy and paste.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP