PDA

View Full Version : Sudden suspicious internet slowdown


jonny5
07-02-2005, 12:37 PM
In the last couple days I've noticed that my internet (I'm on dialup) has been slowing down monstrously. Maybe somebody here can give me a hand with this?

My HijackThis log runs thus:

Logfile of HijackThis v1.99.1
Scan saved at 4:28:19 PM, on 7/2/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\mHotkey.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\slrundll.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\jonathan\Desktop\Anti-Spyware Utilities\Hijack This\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://v4.windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O4 - HKLM\..\Run: [CHotkey] mHotkey.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{D1915E0D-76AE-4DCE-9BC6-4DFF5724A5F8}: NameServer = 209.198.87.24 209.198.87.40
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exe

I don't notice anything freaky except possibly for the AOL thing - but I think that's necessary to IM.

maynard
07-02-2005, 07:32 PM
I don't see anything freaky either :)

Only one small fix that's not likely to improve your connection any.

We'll take care of that minor thing and then we'll try a more detailed scan.


Now, let's do some work on your log.

Close all open programs(including browser windows) and run HijackThis.
Click Do a system scan only.
Place a check in the box before each of these Items.



Fix the Items by clicking the Fix checked button.

Reboot your computer to complete the fix.

Let's take a more thorough look with an MWAV scan.

Click here (http://www.mwti.net/antivirus/free_utilities.asp) to download mwav scan.

Double-click it to run it.
Read then accept the agreement.
Check Drive, and select all local drives, scan all files, then press 'scan'. (This may take a while and will not fix anything)
Once it finds something, it will prompt you so click OK.
When it is completed, anything found will be displayed in the lower pane.
Highlight it, copy it (CTRL+C), and paste (CTRL+V) it in your next reply. Along with a new HijackThis Log



Sorry for the 7Mg download, but I think in the long run this will be better than doing other online scans which would take even longer :eww
m

jonny5
07-04-2005, 06:34 PM
It appears that you didn't list anything to eliminate. :?

maynard
07-04-2005, 06:47 PM
LOL that is exactly how it appears.
The only thing to eliminate is this item:

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

This will reset you links folder name back to the defaoult.

Like I said, not much hope of improving your connection speed there. :(
The mwav scan is a much more detailed scan that may or may not reveal a problem.

But your HijackThis log looks clean.

m

jonny5
07-05-2005, 09:46 AM
I don't want to be a curmudgeon, but I've never heard of 'MWAV' before. I know that there are many cures worse than the disease in the world of spyware - are you sure that it's trustworthy?

maynard
07-05-2005, 09:50 AM
No Problem, If you are unsure please ask!
MWAV is Micro World Anti Virus. It won't actually fix anything on your computer only identify malware that may not be showing up in HijackThis.
I have downloaded it and run it on my own personal computer.
Also, many reputable spyware fighters routinely use this tool in these circumstances.

While you are right in the fact that there are many bad programs out there (here is a good list: http://www.spywarewarrior.com/rogue_anti-spyware.htm ) Mwav is safe.

m