• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Unknown Problem

cpd164

Junior Member
I don?t know what has been going on with my laptop. It all started July 4th when I tried to watch Independence Day on my laptop. The video would work for a while, then it would start to get laggy and skippy. My whole computer is that way now. My programs work fine for about 30 seconds to a min, and then they get laggy and skippy. At first I thought it was a video card problem, but now I am convinced that I have some kind of nasty virus. I have run many different virus scanners and many different spyware scanners, and still I have the same problem. My programs will run fine for about 30 seconds to a min, then it?s like all the resources are sucked away from it and it doesn?t work properly. I don?t know if this is hardware related, or software related anymore. Please help me.

I dont know if this will help.

Logfile of HijackThis v1.99.1
Scan saved at 12:53:47 AM, on 7/8/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Google\Gmail Notifier\gnotify.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\system32\CTsvcCDA.EXE
C:\Program Files\ewido anti-spyware 4.0\guard.exe
C:\WINDOWS\system32\LxrJD31s.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\ThreadMaster\ThreadMast.exe
C:\Program Files\HPQ\SHARED\HPQWMI.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\AIM\aim.exe
C:\HJT\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=...ale=EN_US&c=Q105&bd=pavilion&pf=laptop
O2 - BHO: (no name) - {02DCA195-602B-4B1F-83FF-381B7E804BDB} - C:\WINDOWS\system32\HDBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [ATIPTA] "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] "%ProgramFiles%\HPQ\HP Wireless Assistant\HP Wireless Assistant.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DeadAIM] rundll32.exe "C:\PROGRA~1\AIM\\DeadAIM.ocm",ExportedCheckODLs
O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Creative Detector] C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe /R
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\Cain\Start Menu\Programs\IMVU\Run IMVU.lnk (file missing)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://ie.redirect.hp.com/svs/rdr?TYPE=...ale=EN_US&c=Q105&bd=pavilion&pf=laptop
O16 - DPF: {200B3EE9-7242-4EFD-B1E4-D97EE825BA53} (VerifyGMN Class) - http://h20270.www2.hp.com/ediags/gmn/install/hpobjinstaller_gmn.cab
O16 - DPF: {49232000-16E4-426C-A231-62846947304B} - http://ipgweb.cce.hp.com/rdqnbk/downloads/sysinfo.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - https://h17000.www1.hp.com/ewfrf-JAVA/Secure/HPGetDownloadManager.ocx
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.EXE
O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Program Files\ewido anti-spyware 4.0\guard.exe
O23 - Service: HP WMI Interface (hpqwmi) - Hewlett-Packard Development Company, L.P. - C:\Program Files\HPQ\SHARED\HPQWMI.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Imapi Helper - Alex Feinman - C:\Program Files\Alex Feinman\ISO Recorder\ImapiHelper.exe
O23 - Service: Lexar JD31 (LxrJD31s) - Unknown owner - C:\WINDOWS\SYSTEM32\LxrJD31s.exe
O23 - Service: Thread Master (ThreadMaster) - http://threadmaster.tripod.com - threadmaster@europe.com - C:\WINDOWS\system32\ThreadMaster\ThreadMast.exe

<br
 
As a thought.. when I've encountered systems which might already be infected with something and which I thus don't trust that I'll be able to get an accurate reading on if I do proceed to install, I'll then try an online scanner like the one at http://www.stopsign.com

Granted, it costs money if you want your system cleaned, but just an online scan is free, and it may end up at least pointing you in a direction to look if it does find something. 🙂

 
Originally posted by: networkman
As a thought.. when I've encountered systems which might already be infected with something and which I thus don't trust that I'll be able to get an accurate reading on if I do proceed to install, I'll then try an online scanner like the one at http://www.stopsign.com

Granted, it costs money if you want your system cleaned, but just an online scan is free, and it may end up at least pointing you in a direction to look if it does find something. 🙂


Okay, I am going to run that scan. I have done another online scan also when this problem came up. This is what it came up with.


Active Scan
Incident Status Location

Spyware:Cookie/Atwola Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.atwola.com/]
Spyware:Cookie/RealMedia Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.realmedia.com/]
Spyware:Cookie/Searchportal Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[searchportal.informa
ion.com/]
Spyware:Cookie/Peel Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.peel.com/]
Spyware:Cookie/Maxserving Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.maxserving.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.bravenet.com/]
Spyware:Cookie/FortuneCity Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.fortunecity.com/]
Spyware:Cookie/did-it Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.did-it.com/]
Spyware:Cookie/adultfriendfinder Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[searchportal.informa
ion.com/]Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.adultfriendfinder.c
m/]
Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[searchportal.informa
ion.com/]Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.adultfriendfinder.c
m/]Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[adserver.filefront.c
m/]
Spyware:Cookie/Belnk Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.belnk.com/]
Spyware:Cookie/Go Not disinfected C:\Documents and Settings\Cain\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\cookies.txt[.go.com/]
Virus:W32/Bagle.pwdzip Disinfected C:\Documents and Settings\Cain\Local Settings\Application Data\Mozilla\Firefox\Profiles\p8r2j2kz.default\Cache\633285D9d01
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Cain\My Documents\setup files\good fixer\smitRem\Process.exe
Spyware:Spyware/SafeSurf Not disinfected C:\Documents and Settings\Cain\My Documents\setup files\sbrowser.exe[²=\ExtractDLL.dll]
Potentially unwanted tool:Application/Processor Not disinfected C:\Documents and Settings\Cain\My Documents\SmitfraudFix\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\Program Files\Mozilla Firefox\smitRem\Process.exe
Potentially unwanted tool:Application/Processor Not disinfected C:\WINDOWS\system32\Process.exe
 
Originally posted by: networkman
As a thought.. when I've encountered systems which might already be infected with something and which I thus don't trust that I'll be able to get an accurate reading on if I do proceed to install, I'll then try an online scanner like the one at http://www.stopsign.com

Granted, it costs money if you want your system cleaned, but just an online scan is free, and it may end up at least pointing you in a direction to look if it does find something. 🙂


Okay, I ran the scan and it did not come up with anything. What else should I try?
 
I would clear the browser cache and cookies on all browsers you have installed. Open the Java control panel and clear all cache and temp files there. Remove all "objects" from IE (you'll need to reinstall a couple of things if you use them, but no biggee). Download and run CCleaner, run both the cleaner and the issues checker. Check the settings of your cache file (to make sure you have one).

I would also suggest you download Startup.cpl from Mike Lin's website, install and then use it to eliminate several of your startup items. I don't see anything particularly malicious but you are crippling your system with so many startup programs.

You might also try reinstalling your video drivers, they may be corrupted.
 
Back
Top