Page 1 of 1

SOLVED! pages loading forever

PostPosted: 31. August 2012 14:10
by frifer
Hi guys!

same problem with 1.7.3, 1.7.7 1.8.0! the pages load forever. i tried to remove the # in the conf file as stated in the help, but 1.8 stopped working with the error messages that the command is not declared or the proper file is not linked (sorry dont remember the exact error message!)

1.7.7 is still working, but with no change at all in the behaviour. the problem persists.. any tipps?

thanks

Frifer

Re: pages loading forever

PostPosted: 31. August 2012 15:37
by JJ_Tagy
My tip would be to get the exact error message.

Re: pages loading forever

PostPosted: 31. August 2012 15:40
by frifer
lets asume i want to stick to 1.7.7 since it has less bugs.. that one has no errors but still the same problem!

Re: pages loading forever

PostPosted: 31. August 2012 17:02
by JJ_Tagy
If you're not getting error messages, it is probably the php error reporting is set high (default of 1.8).

Without knowing what pages are taking a long time to load and what # you removed, guessing would be pointless.

Re: pages loading forever

PostPosted: 03. September 2012 07:08
by frifer
here we go this is an error i am getting now:


[Mon Sep 03 08:03:59 2012] [error] (OS 10038)Tentativo di operazione su un elemento diverso dal socket. : Child 3212: Encountered too many errors accepting client connections. Possible causes: dynamic address renewal, or incompatible VPN or firewall software. Try using the Win32DisableAcceptEx directive.

the pages taking long to load are all of them, even the original index.php!

and i removed the # from the win32disableacceptex directie and that didnt solve anything.

Re: pages loading forever

PostPosted: 04. September 2012 21:03
by JonB
is this installation running only on your local network?

Re: pages loading forever

PostPosted: 10. September 2012 08:57
by frifer
sorry was on vacation!

yes it is running on the local network.

now i tried to reinstall 1.8.

the error log says: Mon Sep 10 09:48:56.048917 2012] [mpm_winnt:error] [pid 7340:tid 1780] (OS 10038)Tentativo di operazione su un elemento diverso dal socket. : AH00332: winnt_accept: getsockname error on listening socket, is IPv6 available?

so i tried to uncomment the last line as stated in the FAQ and now i get this:


Microsoft Windows [Versione 6.1.7601]
Copyright (c) 2009 Microsoft Corporation. Tutti i diritti riservati.
C:\xampp>apache_start
Diese Eingabeforderung nicht waehrend des Running beenden
Bitte erst bei einem gewollten Shutdown schliessen
Please close this command only for Shutdown
Apache 2 is starting ...
AH00526: Syntax error on line 110 of C:/xampp/apache/conf/extra/httpd-mpm.conf:
Invalid command 'Win32DisableAcceptEx', perhaps misspelled or defined by a modul
e not included in the server configuration

Apache konnte nicht gestartet werden
Apache could not be started
Premere un tasto per continuare . . .
C:\xampp>

Re: pages loading forever

PostPosted: 10. September 2012 09:46
by frifer
hey guys i solved!

i had a virus that was not recognized nor by avg nor by malwarebytes! a run of combofix replaced the infected services.exe and now it works!for all the other people i have found having thi ssame issue give it a try! be aware that combofix does autoreboot the system without asking anything (i lost an hour of work because of that crap..) so save before you execute it...

good luck!

Re: SOLVED! pages loading forever

PostPosted: 11. September 2012 02:20
by JonB
Well that is interesting news. Thanks for posting it.
Do you know the virus 'name' by any chance???

Good Luck
8)

Re: SOLVED! pages loading forever

PostPosted: 11. September 2012 09:56
by frifer
nope, unfortunately combofix has sort of a dos-like interface and doesnt tell you too much.. here is part of the log.. maybe it tells you more.. only thing i know is that services.exe was infected!

Code: Select all
ComboFix 12-09-09.02 - ima 10/09/2012  10:29:33.1.8 - x64
Microsoft Windows 7 Ultimate   6.1.7601.1.1252.39.1040.18.16351.11248 [GMT 2:00]
Eseguito da: c:\users\ima\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\15ANBFU0\ComboFix.exe
AV: AVG Internet Security Network Edition *Enabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
SP: AVG Internet Security Network Edition *Enabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((((   Altre eliminazioni   )))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\assembly\GAC_32\Desktop.ini
c:\windows\assembly\GAC_64\Desktop.ini
c:\windows\Downloaded Program Files\IDropPTB.dll
c:\windows\PE_Rom.dll
.
La copia infetta di c:\windows\system32\Services.exe è stata trovata e disinfettata
ipristinata copia da - c:\windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
.
.
.
------- Scansione supplementare -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.it/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local;<local>
IE: E&sporta in Microsoft Excel - c:\progra~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Free YouTube Download - c:\users\ima\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm
IE: I&nvia a OneNote - c:\progra~2\MICROS~1\Office14\ONBttnIE.dll/105
Trusted Zone: autodesk.com
TCP: DhcpNameServer = 10.25.25.13
DPF: {00134F72-5284-44F7-95A8-52A619F70752} - hxxps://sbs01:4343/officescan/console/ClientInstall/WinNTChk.cab
FF - ProfilePath - c:\users\ima\AppData\Roaming\Mozilla\Firefox\Profiles\nkf4722f.default\
.
- - - - CHIAVI ORFANE RIMOSSE - - - -
.
Wow6432Node-HKLM-Run-ArchVision Content Manager User Interface - c:\program files (x86)\ArchVision\ArchVision Content Manager\rpcACMgui.exe
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Akamai]
"ServiceDll"="c:\program files (x86)\common files\akamai/netsession_win_4f7fccd.dll"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_265_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_265.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*]
@="?????????????????? v1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*1*\CLSID]
@="{E23FE9C6-778E-49D4-B537-38FCDE4887D8}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*]
@="?????????????????? v2"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\VideoLAN.VLCPlugin.*2*\CLSID]
@="{9BE31822-FDAD-461B-AD51-BE1D1C159921}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]
@Denied: (A) (Everyone)
"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]
"Key"="ActionsPane3"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
**************************************************************************
.
Ora fine scansione: 2012-09-10  10:42:37 - Il pc è stato riavviato
ComboFix-quarantined-files.txt  2012-09-10 08:42
.
Pre-Run: 64.928.694.272 byte disponibili
Post-Run: 71.239.426.048 byte disponibili
.
- - End Of File - - 75D2590C989B01D9168660BFDB0CEF0F

Re: SOLVED! pages loading forever

PostPosted: 14. September 2012 02:42
by Apophis55
@frifer

That's very interesting. In my case, I too found that pages were extremely slow in loading. I run both Avast and Malware Bytes and neither one found anything awry so I never suspected a virus. I came here to see if anyone else had complained about slow loading pages when using XAMPP and found this thread. I downloaded and ran combofix and now everything is nice and fast.

I should mention that Avast did find one thing but I'm sure it's just the false positive warning I read about on the main page. For some reason it doesn't like C:\xampp\licenses\pdflib\PDFlib-License.pdf

Re: SOLVED! pages loading forever

PostPosted: 17. October 2012 15:27
by frifer
same problem happened again today and solved again the same way. still dont know what virus this is and where i got infected since this is a clean pc used for Work ONLY.

regards

frifer

Re: SOLVED! pages loading forever

PostPosted: 17. October 2012 18:48
by JonB
'ComboFix' is a malware toolkit

http://www.bleepingcomputer.com/download/combofix/

Check the files MD5 signature against the genuine article to see if its masquerading.

it might well 'look like' a piece of malware itself to an AV program. turn heuristics (pattern recognition) off.

Good Luck
8)

Re: SOLVED! pages loading forever

PostPosted: 18. October 2012 07:09
by frifer
yes its genuine, i downloaded it from the combofix homepage wich redirects to the page you linked!

it found and deleted 5 files and now everything works.. and also replaced the services.exe

somehow there is a malware that prevents xampp to work, but i still dont know its name and where it came from....