Author Topic: really slow HJ file  (Read 502 times)

Offline Gummbee25

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
really slow HJ file
« on: June 13, 2006, 08:24:02 PM »
my computer is usally really fast to open programs and good online speeds, but everything i open takes about 15 sec to open and my connection speed and refresh is like 15 kb 30 max..... i have cable connection with no one on my wireless network... i run all my clean up stuff and nothing detected but i feel like something is wrong with my system still...i play an online game and im super laggy irregular spikes very unusal..i dont down load music or anytthing like that... the server i play on i have admin to so i know its secure does my HJ file look iffy? what can i do.. i would take any suggestions

Logfile of HijackThis v1.99.1
Scan saved at 9:21:00 PM, on 6/13/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
C:\DRIVERS\PRINTER\540\StatMon.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe
C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\program files\steam\steam.exe
C:\Program Files\Dell AIO Printer A920\dlbkbmon.exe
C:\Program Files\FinePixViewer\QuickDCF.exe
C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe
C:\Program Files\Opera\opera.exe
C:\HJT\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.myspace.com/
F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\Userinit.exe
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [IntelMeM] C:\Program Files\Intel\Modem Event Monitor\IntelMEM.exe
O4 - HKLM\..\Run: [REGSHAVE] C:\Program Files\REGSHAVE\REGSHAVE.EXE /AUTORUN
O4 - HKLM\..\Run: [DellStatusMonitor] "C:\DRIVERS\PRINTER\540\StatMon.exe"
O4 - HKLM\..\Run: [Dell AIO Printer A920] "C:\Program Files\Dell AIO Printer A920\dlbkbmgr.exe"
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [Steam] "c:\program files\steam\steam.exe" -silent
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Exif Launcher.lnk = ?
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O15 - Trusted Zone: *.musicmatch.com
O15 - Trusted Zone: *.musicmatch.com (HKLM)
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/m...,21/mcgdmgr.cab
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\SYSTEM32\ZoneLabs\vsmon.exe

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
really slow HJ file
« Reply #1 on: June 13, 2006, 11:37:04 PM »
Log looks good
As a double check

Download GMER from here:
http://www.gmer.net/gmer.zip

Unzip it and start GMER.exe
Click the rootkit-tab and click scan.

Once done, click the Copy button.
This will copy the results to clipboard.
Paste the results in your next reply.

If the log is too big to post it all, save it to a text file on desktop then try and upload as an attachment
or I can supply an email addy for you to send it too

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Gummbee25

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
really slow HJ file
« Reply #2 on: June 18, 2006, 08:09:28 AM »
GMER 1.0.10.10122 - http://www.gmer.net
Rootkit 2006-06-18 08:49:01
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.10 ----

SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwConnectPort
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwCreateFile
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwCreateKey
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwCreateProcess
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwCreateProcessEx
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwCreateSection
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwDeleteFile
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwDeleteKey
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwDeleteValueKey
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwDuplicateObject
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwLoadKey
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwOpenFile
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwOpenProcess
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwOpenThread
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwReplaceKey
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwRequestWaitReplyPort
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwRestoreKey
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwSecureConnectPort
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwSetInformationFile
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwSetValueKey
SSDT    \SystemRoot\System32\vsdatant.sys                                            ZwTerminateProcess

---- Devices - GMER 1.0.10 ----

Device  \Driver\Tcpip \Device\Ip IRP_MJ_CREATE                                       [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Ip IRP_MJ_CLOSEIRP_MJ_READ                             [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Ip IRP_MJ_INTERNAL_DEVICE_CONTROL                      [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Ip IRP_MJ_SHUTDOWN                                     [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Ip IRP_MJ_CREATE_MAILSLOT                              [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE                                      [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Tcp IRP_MJ_CLOSEIRP_MJ_READ                            [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Tcp IRP_MJ_INTERNAL_DEVICE_CONTROL                     [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Tcp IRP_MJ_SHUTDOWN                                    [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Tcp IRP_MJ_CREATE_MAILSLOT                             [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Udp IRP_MJ_CREATE                                      [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Udp IRP_MJ_CLOSEIRP_MJ_READ                            [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Udp IRP_MJ_INTERNAL_DEVICE_CONTROL                     [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Udp IRP_MJ_SHUTDOWN                                    [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\Udp IRP_MJ_CREATE_MAILSLOT                             [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE                                    [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\RawIp IRP_MJ_CLOSEIRP_MJ_READ                          [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\RawIp IRP_MJ_INTERNAL_DEVICE_CONTROL                   [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\RawIp IRP_MJ_SHUTDOWN                                  [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\RawIp IRP_MJ_CREATE_MAILSLOT                           [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE                              [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CLOSEIRP_MJ_READ                    [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_INTERNAL_DEVICE_CONTROL             [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_SHUTDOWN                            [B7DBA230] vsdatant.sys
Device  \Driver\Tcpip \Device\IPMULTICAST IRP_MJ_CREATE_MAILSLOT                     [B7DBA230] vsdatant.sys
Device  \FileSystem\Fastfat \Fat IRP_MJ_CREATE                                       B20DCC8A

---- Files - GMER 1.0.10 ----

File    C:\System Volume Information\MountPointManagerRemoteDatabase                
File    C:\System Volume Information\tracking.log                                    
File    C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}  

---- EOF - GMER 1.0.10 ----

before this i also got the blue screen of death while running ad-aware se.. i also woke up to this screen after i had left the computer fine lat night


Offline Gummbee25

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
really slow HJ file
« Reply #3 on: June 18, 2006, 08:56:04 PM »
and another one??

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
really slow HJ file
« Reply #4 on: June 19, 2006, 06:38:38 AM »
It definetly sounds like a hardware problem
Can't  rule out a software problem
Lot's of users having the same problem on the net
Google
One user reporting the return of the system to Dell was the only course of action

Check on Dell's website, that appears to be the makers of your system for Any latest drivers for your system
and/or try Intel's site in relation too Intel Application Accelerator and the error iastor.sys
http://www.intel.com/support/chipsets/iaa_raid/

Personally, the problems appear to be escalating
I would definitely backup any important files and documents
Maybe even resort to a clean install of the system
Ensure to have ALL latest drivers for your system
Video drivers>>Make sure to uninstall the old ones from add/remove before installing the new ones
You can try troubleshooting steps by disabling programs on startup and see if the issues continue

Or if hardware, start removing any hardware in your computer you don't require to have the system boot
If you can pinpoint it down to which piece of hardware, you found your culprit
« Last Edit: June 19, 2006, 06:46:59 AM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline Gummbee25

  • Newbie
  • *
  • Posts: 36
  • Karma: +0/-0
    • View Profile
really slow HJ file
« Reply #5 on: June 25, 2006, 09:40:49 PM »
i did a restore of my system to the "factory setting" via f11 button on start up and its like whne i got it out the box... everythin was fine but i got the blue screen again when i download a video game i bought COUNTER STRIKE.. so i was thinking that it was my video driver.. how do i update that like you said... also uninstall it from my ad remove section

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
really slow HJ file
« Reply #6 on: June 25, 2006, 11:59:59 PM »
Here's your other post?
http://www.thetechguide.com/forum/index.php?showtopic=35808

Have you tried that?

What is the make and model of computer????

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here