This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow Internet, Spy-bot not updating

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Everything had been fine, then all the sudden the Internet slowed way down, and as I was going throught all the things I would normally do, Spy-bot would not update, it would see the update, but not download it. It would say: Checksum after it failed loading it.

So basically slow internet, Spybot not updating. I have run multitudes of things to try and find a culprit. Nothing yet. I have been able in the past to use other's logs and your solutions to fix things…..but this time I need help.

I know you will have me repost this once you get to me, but here it is…..and maybe I will be fixed by then. Thanks


Logfile of HijackThis v1.99.1
Scan saved at 12:24:40 AM, on 9/15/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\WINNT\system32\svchost.exe
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
f:\PROGRA~1\mcafee.com\agent\mctskshd.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
F:\WINNT\system32\nvsvc32.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\MSTask.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\Explorer.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
F:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
F:\Program Files\Netropa\Touch Manager\TouchMgr.exe
F:\Program Files\DIGStream\digstream.exe
F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
F:\Program Files\McAfee.com\VSO\mcvsshld.exe
F:\PROGRA~1\mcafee.com\agent\mcagent.exe
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\Program Files\Netropa\Touch Manager\MEDIACTR.EXE
F:\PROGRA~1\NETROPA\ONSCRE~1\OSD.EXE
F:\Program Files\QuickTime\qttask.exe
F:\Program Files\McAfee.com\VSO\oasclnt.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\Program Files\Trillian\trillian.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
F:\Documents and Settings\Douglas\Desktop\hijackthis\HijackThis.exe
F:\Program Files\Maxthon\Maxthon.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.sprint.earthlink.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINNT\system32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] F:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Touch Manager] F:\Program Files\Netropa\Touch Manager\TouchMgr.exe
O4 - HKLM\..\Run: [DIGStream] F:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [VSOCheckTask] "F:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] F:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [NeroCheck] F:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [OASClnt] F:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - Startup: Trillian.lnk = F:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - F:\WINNT\system32\shdocvw.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/09b8ddde919eea…ip/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup143.cab
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - F:\WINNT\System32\dmadmin.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - f:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - f:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - F:\WINNT\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe
Hi Douglas, Sorry about the wait, if you still need help and are not being helped elsewhere do this in the posted order.

1) First Spybot: Unless you are aware of it, next to Search for Updates, is the download site, and it can be changed. I had the same problem at Safer#1 Europe and changed to MalwareBytes(USA) and it worked perfectly. If that does not work, try another mirror. Do this first because Spybot is the first program I want you to run. If you still can't get it, post here: http://forums.net-integration.net/index.php?showforum=28 and ask for help. For our purpose, run Spybot without the updates this time. Thanks.

2) Download CCleaner from this link: http://www.ccleaner.com/ Review the instructions http://www.ccleaner.com/help/tour1.asp and please do not run it until I ask you to.

3) Download, update, configure and run these two programs: http://tomcoyote.org/aawsb.php
The newest version of Ad-aware is 1.06 and Spybot 1.04. Even if you have these programs, use the link to get the newest version, update and configure them as in the link. Run Spybot first, reboot then run Ad-aware. Both programs back up what they remove so delete anything the programs say should be removed.

4) Ewido scan:
Please download Ewido Security Suite it is a trial version of the program.
  • Install ewido security suite
  • Launch ewido, there should be an icon on your desktop double-click it.
  • The program will now go to the main screen
You will need to update ewido to the latest definition files.
  • On the left hand side of the main screen click update
  • Then click on Start Update
The update will start and a progress bar will show the updates being installed.
If you are having problems with the updater, you can use this link to manually update Ewido.
Ewido manual updates

Once the updates are installed do the following:
  • Click on scanner
  • Click on Complete System Scan and the scan will begin.
  • NOTE: During some scans with ewido it is finding cases of false positives.**
    • You will need to step through the process of cleaning files one-by-one.
    • If ewido detects a file you KNOW to be legitimate, select none as the action.
    • DO NOT select "Perform action on all infections"
    • If you are unsure of any entry found select none for now.
  • Once the scan has completed, there will be a button located on the bottom of the screen named Save report
  • Click Save report.
  • Save the report .txt file to your desktop.
Now close ewido security suite.
**(Ewido for example has been flagging parts of AVG Anti-Virus, pcAnywhere and the game "Risk")

5) Open HijackThis and choose "Do a system scan only" then check the box in front of these line items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/…://my.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/…//www.yahoo.com
O9 - Extra button: SideStep - {3E230861-5C87-11D3-A1C6-00105A1B41B8} - F:\WINNT\system32\shdocvw.dll
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/09b8ddde919eea…ip/RdxIE601.cab

Close all programs but HJT and all browser windows, then click on "Fix Checked"

RIGHT Click on Start then click on Explore

C:\Windows\Prefetch: Locate this folder and delete all of the contents (NOT THE FOLDER) This information will tell you more about Prefetch:
http://www.windowsnetworking.com/articles_…refetch-XP.html

6) Run CCleaner,Windows and Applications, when you run the registry cleaner (Issues) you will be prompted to backup before you can remove stuff, make sure you do. Then restart the computer and post a new HJT log and the Ewido scan results in this same thread along with any feedback you have. Let me know how you are running now.

Douglas, you need some spyware programs, a firewall and antivirus is just not enough anymore. Pay close attention to the links I provide once you are clean.

Thanks…pskelley
TomCoyote forum
Slyware Warrior
Thanks for looking. I know my issues are small compared to some of the logs I see on here….

I did get spybot to update. I re-downloaded it, and it updated fine. (never noticed the mirror sites before, good to know)

After I had tried "everything" I finally tried turning the DSL modem off and the back on again. That helped the super slow problem alot.


I have just finished your list of things.

The last reboot seemed to take a real long time. But the internet may actually be more crisp and "speedy"

The only thing I could not do was delete the items in the Windows\prefetch folder.
I looked and searched for it but could not find it.


What could I do do speed up the startup some? I know there is some stuff that must not be needed at start up. Is it just taking stuff off the desktop?


New scans below

Logfile of HijackThis v1.99.1
Scan saved at 11:19:09 PM, on 9/19/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
F:\WINNT\System32\smss.exe
F:\WINNT\system32\winlogon.exe
F:\WINNT\system32\services.exe
F:\WINNT\system32\lsass.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\system32\spoolsv.exe
F:\WINNT\system32\svchost.exe
F:\Program Files\ewido\security suite\ewidoctrl.exe
F:\Program Files\ewido\security suite\ewidoguard.exe
f:\PROGRA~1\mcafee.com\vso\mcshield.exe
f:\PROGRA~1\mcafee.com\agent\mctskshd.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
F:\WINNT\system32\nvsvc32.exe
F:\WINNT\system32\regsvc.exe
F:\WINNT\system32\MSTask.exe
F:\WINNT\system32\stisvc.exe
F:\WINNT\System32\WBEM\WinMgmt.exe
F:\WINNT\system32\svchost.exe
F:\WINNT\Explorer.EXE
F:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe
F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
F:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
F:\Program Files\Netropa\Touch Manager\TouchMgr.exe
F:\Program Files\DIGStream\digstream.exe
F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
F:\Program Files\McAfee.com\VSO\mcvsshld.exe
f:\program files\mcafee.com\agent\mcagent.exe
f:\progra~1\mcafee.com\vso\mcvsescn.exe
F:\Program Files\McAfee.com\VSO\oasclnt.exe
F:\Program Files\Netropa\Touch Manager\MEDIACTR.EXE
F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
F:\Program Files\QuickTime\qttask.exe
F:\PROGRA~1\NETROPA\ONSCRE~1\OSD.EXE
F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
F:\PROGRA~1\McAfee.com\PERSON~1\MpfAgent.exe
F:\Program Files\Trillian\trillian.exe
F:\Program Files\Maxthon\Maxthon.exe
F:\Documents and Settings\Douglas\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.sprint.earthlink.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - F:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - F:\WINNT\system32\msdxm.ocx
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - f:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [CamMonitor] F:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] F:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [Touch Manager] F:\Program Files\Netropa\Touch Manager\TouchMgr.exe
O4 - HKLM\..\Run: [DIGStream] F:\Program Files\DIGStream\digstream.exe
O4 - HKLM\..\Run: [VSOCheckTask] "F:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] F:\Program Files\McAfee.com\VSO\mcvsshld.exe
O4 - HKLM\..\Run: [MCAgentExe] f:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] F:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [NeroCheck] F:\WINNT\system32\\NeroCheck.exe
O4 - HKLM\..\Run: [OASClnt] F:\Program Files\McAfee.com\VSO\oasclnt.exe
O4 - HKLM\..\Run: [MPFExe] F:\PROGRA~1\McAfee.com\PERSON~1\MpfTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - Startup: Trillian.lnk = F:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = F:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/m…84/mcinsctl.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/200312…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/m…,21/mcgdmgr.cab
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
O16 - DPF: {E7DBFB6C-113A-47CF-B278-F5C6AF4DE1BD} - http://download.abacast.com/download/files/abasetup143.cab
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - F:\WINNT\System32\dmadmin.exe
O23 - Service: ewido security suite control - ewido networks - F:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - F:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - f:\PROGRA~1\mcafee.com\vso\mcshield.exe
O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - f:\PROGRA~1\mcafee.com\agent\mctskshd.exe
O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - F:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee Corporation - F:\PROGRA~1\McAfee.com\PERSON~1\MpfService.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - F:\WINNT\system32\nvsvc32.exe
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - F:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe




———————————————————
ewido security suite - Scan report
———————————————————

+ Created on: 10:54:49 PM, 9/19/2005
+ Report-Checksum: 39AFF1D0

+ Scan result:

HKLM\SOFTWARE\Classes\CLSID\{2B96D5CC-C5B5-49A5-A69D-CC0A30F9028C} -> Spyware.MiniBug : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\douglas@2o7[2].txt -> Spyware.Cookie.2o7 : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Masterstats : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Liveperson : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Clickhype : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][1].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup
F:\Documents and Settings\Douglas\Cookies\[removed][2].txt -> Spyware.Cookie.Esomniture : Cleaned with backup


::Report End
Hi, I am very interested in the fact your DSL modem or ISP may have been the reason for the slowdown. I have DSL/Verizon and I know to reset the modem and sometimes the router also when the signal goes completely. If you get more information about why that happens I would sure like to know.
Don't concern yourself with Prefetchthat's my fault. I am so used to working on XP computers, none on yours…sorry :( I'll look at what you have running and give you some tips after I review the logs. Icons on Desktop won't make a difference, it's all about how much stuff you have booting at Startup that is not needed.

Ewido scan results: As you can see it was mostly cookies, anything bad hiding would have showed up. Note where those cookies are hiding and put that on your list of cookies to clean. http://support.microsoft.com/default.aspx?…b;EN-US;q283185

HJT: Scan saved at 11:19:09 PM, on 9/19/2005: Use HJT to remove this line: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = (just clutter) besides that I see no malware so here is some great information from Tony Klein, Texruss, ChrisRLG and Grinler to help you stay clean and safe online:
http://forums.net-integration.net/index.php?showtopic=3051
http://russelltexas.com/malware/allclear.htm
http://forum.malwareremoval.com/viewtopic.php?t=14
http://www.bleepingcomputer.com/forums/topict2520.html

Use MSCONFIG: http://netsquirrel.com/msconfig/ to turn of programs you rarely use to speed bootup.

F:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
http://castlecops.com/startuplist-1670.html

O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
Do you use this feature? http://support.microsoft.com/default.aspx?…kb;en-us;256139

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
http://castlecops.com/startuplist-2564.html

O4 - HKLM\..\Run: [CamMonitor] F:\Program Files\Hewlett-Packard\Digital Imaging\\Unload\hpqcmon.exe
http://castlecops.com/startuplist-507.html Not sure about this one, but you should investigate. If you do not use it all of the time, it is running everytime you boot, you may be able to turn it off in msconfig or within the program and start it manually when needed.

O4 - HKLM\..\Run: [DIGStream] F:\Program Files\DIGStream\digstream.exe
http://castlecops.com/startuplist-921.html Not familiar with this one, you will have to investigate? Running every time you startup.

O4 - HKLM\..\Run: [QuickTime Task] "F:\Program Files\QuickTime\qttask.exe" -atboottime Do you use this? If not you may consider uninstalling it.

the 016 DPF items, you can use HJT to remove any you wish. If you visit the site again you will be prompted to download them again.
I suggest you try the above one or two at a time to see if it makes anything negative occur. Easier to know what caused it. If all works fine, continue until all are off autostart.

Some tips from others:
http://vlaurie.com/computers2/Articles/runbetter.htm
http://www.linkgrinder.com/tutorials/10_Ea…rs_article.html
http://web.ukonline.co.uk/cook/maintain.htm 2M

Hope this information helps…Phil

Thanks…pskelley
TomCoyote forum
Slyware Warrior
If you are reading this information…thank a teacher, If you are reading it in English…thank a soldier.
Thanks, All seems cleaned up and working. (as well as a 6 year old computer can) I have no idea about the modem reseting, and what that would have done or why it fixed it or why it went "bad" My computer had been on for over a week but many people leave the computers on 24 hours aday 7 days a week…….I was just trying to work throught the problem. I work In theatre in Fort Myers FL, and that is how we trouble shoot things, check all the wiring and connections before you mess with "settings" in a program. or sound board or what ever is not working. Topic complete! Thanks Again
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI