Skynet
Topic Starter
I've been around computers since forever (mainframe, servers, pc, etc).
Have a problem I've never had before this way.
A hi-speed broadband connection (5 Meg pkg) is crawling with frequent time outs and in essence no availability at times.
All 3 laptops in the house get affected.
Today after hours with the ISP (cable modem ok, wireless 803.11g super G ok, signal to modem ok, etc) the tech suggested i did a netstat and after seeing 30+ active connections he gracefully signed off and suggested I call symantec and talk to them. After hours w symantec and bouncing me all over the place nothing was resolved. I have to admit that my suspicion upon calling the ISP techline in the first place was to suggest to them that maybe the segment in my neighborhood has slowed down… but the ISP tech wants the "unusually high number of connections resolved before going further". The other PCs show similar high number of connections when I run netstat.
So spent my sunday surfing and I discovered HijackThis and here is my base data:
First the infamous netstat -a (it changes but always 30+ connections)
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.
Active Connections
Proto Local Address Foreign Address State
TCP HPNC8000:epmap HPNC8000:0 LISTENING
TCP HPNC8000:microsoft-ds HPNC8000:0 LISTENING
TCP HPNC8000:990 HPNC8000:0 LISTENING
TCP HPNC8000:2869 HPNC8000:0 LISTENING
TCP HPNC8000:1027 HPNC8000:0 LISTENING
TCP HPNC8000:1030 HPNC8000:0 LISTENING
TCP HPNC8000:1031 HPNC8000:0 LISTENING
TCP HPNC8000:1066 localhost:1067 ESTABLISHED
TCP HPNC8000:1067 localhost:1066 ESTABLISHED
TCP HPNC8000:5679 HPNC8000:0 LISTENING
TCP HPNC8000:7438 HPNC8000:0 LISTENING
TCP HPNC8000:8000 HPNC8000:0 LISTENING
TCP HPNC8000:8001 HPNC8000:0 LISTENING
TCP HPNC8000:8975 HPNC8000:0 LISTENING
TCP HPNC8000:11598 HPNC8000:0 LISTENING
TCP HPNC8000:netbios-ssn HPNC8000:0 LISTENING
UDP HPNC8000:microsoft-ds *:*
UDP HPNC8000:1026 *:*
UDP HPNC8000:1029 *:*
UDP HPNC8000:1088 *:*
UDP HPNC8000:1129 *:*
UDP HPNC8000:ntp *:*
UDP HPNC8000:1025 *:*
UDP HPNC8000:1122 *:*
UDP HPNC8000:1900 *:*
UDP HPNC8000:8008 *:*
UDP HPNC8000:11188 *:*
UDP HPNC8000:ntp *:*
UDP HPNC8000:netbios-ns *:*
UDP HPNC8000:netbios-dgm *:*
UDP HPNC8000:1900 *:*
C:\Documents and Settings\Jorge>
When I add -b to show processes (i.e. netstat -a -
this is what I get
C:\Documents and Settings\Jorge>netstat -a -b
Active Connections
Proto Local Address Foreign Address State PID
TCP HPNC8000:epmap HPNC8000:0 LISTENING 912
[svchost.exe]
TCP HPNC8000:microsoft-ds HPNC8000:0 LISTENING 4
[System]
TCP HPNC8000:990 HPNC8000:0 LISTENING 888
[rapimgr.exe]
TCP HPNC8000:2869 HPNC8000:0 LISTENING 1176
C:\WINDOWS\System32\httpapi.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
TCP HPNC8000:1027 HPNC8000:0 LISTENING 2112
[ccProxy.exe]
TCP HPNC8000:1030 HPNC8000:0 LISTENING 1908
[ccApp.exe]
TCP HPNC8000:1031 HPNC8000:0 LISTENING 4088
[alg.exe]
TCP HPNC8000:5679 HPNC8000:0 LISTENING 176
[wcescomm.exe]
TCP HPNC8000:7438 HPNC8000:0 LISTENING 176
[wcescomm.exe]
TCP HPNC8000:8000 HPNC8000:0 LISTENING 2776
[ventc.exe]
TCP HPNC8000:8001 HPNC8000:0 LISTENING 2776
[ventc.exe]
TCP HPNC8000:8975 HPNC8000:0 LISTENING 2776
[ventc.exe]
TCP HPNC8000:11598 HPNC8000:0 LISTENING 2160
[cgagent.exe]
TCP HPNC8000:netbios-ssn HPNC8000:0 LISTENING 4
[System]
TCP HPNC8000:1066 localhost:1067 ESTABLISHED 3276
[firefox.exe]
TCP HPNC8000:1067 localhost:1066 ESTABLISHED 3276
[firefox.exe]
TCP HPNC8000:1027 localhost:1905 FIN_WAIT_2 2112
[ccProxy.exe]
TCP HPNC8000:1905 localhost:1027 CLOSE_WAIT 1176
[svchost.exe]
TCP HPNC8000:1908 192.168.1.1:http CLOSE_WAIT 2112
[ccProxy.exe]
TCP HPNC8000:1030 localhost:1871 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1909 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1906 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1901 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1885 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1893 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1887 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1879 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1913 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1915 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1911 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1917 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1899 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1891 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1883 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1875 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1897 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1877 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1889 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1881 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1873 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1869 TIME_WAIT 0
TCP HPNC8000:1895 localhost:1030 TIME_WAIT 0
TCP HPNC8000:1870 pop1.us4.outblaze.com:pop3 TIME_WAIT 0
TCP HPNC8000:1872 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1874 pi.ftl.affinity.com:pop3 TIME_WAIT 0
TCP HPNC8000:1876 pop-server1.swfla.rr.com:pop3 TIME_WAIT 0
TCP HPNC8000:1878 pi.ftl.affinity.com:pop3 TIME_WAIT 0
TCP HPNC8000:1880 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1882 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1884 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1888 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1894 mail.charter.net:pop3 TIME_WAIT 0
TCP HPNC8000:1896 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1900 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1902 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1910 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1912 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1914 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1916 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1918 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1919 ipostoffice.worldnet.att.net:995 TIME_WAIT
0
UDP HPNC8000:microsoft-ds *:* 4
[System]
UDP HPNC8000:1088 *:* 1096
[svchost.exe]
UDP HPNC8000:1026 *:* 2776
[ventc.exe]
UDP HPNC8000:1129 *:* 1096
[svchost.exe]
UDP HPNC8000:1029 *:* 1096
[svchost.exe]
UDP HPNC8000:ntp *:* 1016
[svchost.exe]
UDP HPNC8000:1025 *:* 1868
[cgav.exe]
UDP HPNC8000:1122 *:* 3276
[firefox.exe]
UDP HPNC8000:8008 *:* 2776
[ventc.exe]
UDP HPNC8000:11188 *:* 2160
[cgagent.exe]
UDP HPNC8000:1900 *:* 1176
[svchost.exe]
UDP HPNC8000:netbios-dgm *:* 4
[System]
UDP HPNC8000:ntp *:* 1016
[svchost.exe]
UDP HPNC8000:1900 *:* 1176
[svchost.exe]
UDP HPNC8000:netbios-ns *:* 4
[System]
(HPNC8000 is the name of my computer)
Now for the HijackThis (BASELINE) log:
Logfile of HijackThis v1.99.1
Scan saved at 5:57:14 PM, on 10/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\Wnex7DO.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Atheros\ACU\Utility\ACU.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\hphmon04.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~4\wcescomm.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Sonic Shared\CineTray.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper Home Edition\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe
C:\Documents and Settings\Jorge\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://paginacuba.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.worldnet.att.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINDOWS\winres.dll (file missing)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HKCU] C:\WINDOWS\system32\cmd.exe /C Start "HKCU Updates" /MIN "C:\Program Files\current profile updates\hkcu.exe"
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [PassCode] C:\WINDOWS\regedit /s C:\WINDOWS\dp.reg
O4 - HKLM\..\Run: [KeepAlive] C:\WINDOWS\regedit /s C:\WINDOWS\keepaliv.reg
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [Watcher-WatchDog] C:\WINDOWS\System32\Wnex7DO.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [ACU] C:\Program Files\Atheros\ACU\Utility\ACU.exe -nogui
O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [VF0070 STISvc] RunDLL32.exe V0070Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKCU\..\Run: [Magical Gatherings] C:\Program Files\Magical Gatherings\Magical Gatherings.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~4\wcescomm.exe"
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe /S
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Jorge\Application Data\Mozilla\Firefox\Profiles\vq0wwdnm.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Jorge\Application Data\Mozilla\Firefox\Profiles\vq0wwdnm.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: JavaConnect - file://C:\TEMP\SISD\JavaConnect.cab
O16 - DPF: Sametime BC 651 - file://C:\TEMP\SISD\STBroadcastClient.cab
O16 - DPF: Sametime BroadCast Client ST30IF2 - file://C:\TEMP\SISD_30\STBroadcastClient.cab
O16 - DPF: Sametime DA 651 - file://C:\TEMP\SISD\STDirectoryApplet.cab
O16 - DPF: Sametime Directory Applet ST30SP1 - file://C:\TEMP\SISD_30\STDirectoryApplet.cab
O16 - DPF: Sametime Meeting Room Client ST30SP1 - file://C:\TEMP\SISD_30\STMeetingRoomClient.cab
O16 - DPF: Sametime MRC 651 - file://C:\TEMP\SISD\STMeetingRoomClient.cab
O16 - DPF: {00000000-0000-0000-0000-100000000003} - http://code.jcash.biz/l/b3af077ab4115af56b…b7042aeb_13.exe
O16 - DPF: {2226ED4E-6E9A-472E-97ED-B6D54F3B620B} (STURLConnection Control) - file://C:\TEMP\SISD\STUrlConLoader.cab
O16 - DPF: {24CEC0BF-C8BC-4BCB-B804-226326B319EF} (JNILoader Control) - file://C:\TEMP\SISD_30\STJNILoader.cab
O16 - DPF: {53F92AF2-3C1E-4A63-B2EA-2E33DA6286B7} (STAutoAway Control) - file://C:\TEMP\SISD\STAutoAwayLoader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1098282519793
O16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {6CEDB6B5-4859-4E3A-BCA2-FB8E565B8AD9} (JNILoader Control) - file://C:\TEMP\SISD\STJNILoader.cab
O16 - DPF: {6E10F5D1-B3E1-4BC2-8E6F-DD859F10F66F} (CAgentLauncher Class) - http://paginacuba.com/plugin/CGAgentATL.dll
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: winkrg32 - winkrg32.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper Home Edition\DKService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe
I have to confess I've already deleted some of the items above… but I'm waiting direction.
Items deleted:
The TRUSTED ZONE URL's (all)
The SAMETIME ENTRIES
I work on several websites I maintain and the connection slowdowns, and "brickwalls" (eveything slows to the point nothing gets through) make it extremely hard to do the work.
Your help would be greatly appreciated.
Have a problem I've never had before this way.
A hi-speed broadband connection (5 Meg pkg) is crawling with frequent time outs and in essence no availability at times.
All 3 laptops in the house get affected.
Today after hours with the ISP (cable modem ok, wireless 803.11g super G ok, signal to modem ok, etc) the tech suggested i did a netstat and after seeing 30+ active connections he gracefully signed off and suggested I call symantec and talk to them. After hours w symantec and bouncing me all over the place nothing was resolved. I have to admit that my suspicion upon calling the ISP techline in the first place was to suggest to them that maybe the segment in my neighborhood has slowed down… but the ISP tech wants the "unusually high number of connections resolved before going further". The other PCs show similar high number of connections when I run netstat.
So spent my sunday surfing and I discovered HijackThis and here is my base data:
First the infamous netstat -a (it changes but always 30+ connections)
Microsoft Windows XP [Version 5.1.2600]
© Copyright 1985-2001 Microsoft Corp.
Active Connections
Proto Local Address Foreign Address State
TCP HPNC8000:epmap HPNC8000:0 LISTENING
TCP HPNC8000:microsoft-ds HPNC8000:0 LISTENING
TCP HPNC8000:990 HPNC8000:0 LISTENING
TCP HPNC8000:2869 HPNC8000:0 LISTENING
TCP HPNC8000:1027 HPNC8000:0 LISTENING
TCP HPNC8000:1030 HPNC8000:0 LISTENING
TCP HPNC8000:1031 HPNC8000:0 LISTENING
TCP HPNC8000:1066 localhost:1067 ESTABLISHED
TCP HPNC8000:1067 localhost:1066 ESTABLISHED
TCP HPNC8000:5679 HPNC8000:0 LISTENING
TCP HPNC8000:7438 HPNC8000:0 LISTENING
TCP HPNC8000:8000 HPNC8000:0 LISTENING
TCP HPNC8000:8001 HPNC8000:0 LISTENING
TCP HPNC8000:8975 HPNC8000:0 LISTENING
TCP HPNC8000:11598 HPNC8000:0 LISTENING
TCP HPNC8000:netbios-ssn HPNC8000:0 LISTENING
UDP HPNC8000:microsoft-ds *:*
UDP HPNC8000:1026 *:*
UDP HPNC8000:1029 *:*
UDP HPNC8000:1088 *:*
UDP HPNC8000:1129 *:*
UDP HPNC8000:ntp *:*
UDP HPNC8000:1025 *:*
UDP HPNC8000:1122 *:*
UDP HPNC8000:1900 *:*
UDP HPNC8000:8008 *:*
UDP HPNC8000:11188 *:*
UDP HPNC8000:ntp *:*
UDP HPNC8000:netbios-ns *:*
UDP HPNC8000:netbios-dgm *:*
UDP HPNC8000:1900 *:*
C:\Documents and Settings\Jorge>
When I add -b to show processes (i.e. netstat -a -
C:\Documents and Settings\Jorge>netstat -a -b
Active Connections
Proto Local Address Foreign Address State PID
TCP HPNC8000:epmap HPNC8000:0 LISTENING 912
[svchost.exe]
TCP HPNC8000:microsoft-ds HPNC8000:0 LISTENING 4
[System]
TCP HPNC8000:990 HPNC8000:0 LISTENING 888
[rapimgr.exe]
TCP HPNC8000:2869 HPNC8000:0 LISTENING 1176
C:\WINDOWS\System32\httpapi.dll
c:\windows\system32\ssdpsrv.dll
C:\WINDOWS\system32\RPCRT4.dll
[svchost.exe]
TCP HPNC8000:1027 HPNC8000:0 LISTENING 2112
[ccProxy.exe]
TCP HPNC8000:1030 HPNC8000:0 LISTENING 1908
[ccApp.exe]
TCP HPNC8000:1031 HPNC8000:0 LISTENING 4088
[alg.exe]
TCP HPNC8000:5679 HPNC8000:0 LISTENING 176
[wcescomm.exe]
TCP HPNC8000:7438 HPNC8000:0 LISTENING 176
[wcescomm.exe]
TCP HPNC8000:8000 HPNC8000:0 LISTENING 2776
[ventc.exe]
TCP HPNC8000:8001 HPNC8000:0 LISTENING 2776
[ventc.exe]
TCP HPNC8000:8975 HPNC8000:0 LISTENING 2776
[ventc.exe]
TCP HPNC8000:11598 HPNC8000:0 LISTENING 2160
[cgagent.exe]
TCP HPNC8000:netbios-ssn HPNC8000:0 LISTENING 4
[System]
TCP HPNC8000:1066 localhost:1067 ESTABLISHED 3276
[firefox.exe]
TCP HPNC8000:1067 localhost:1066 ESTABLISHED 3276
[firefox.exe]
TCP HPNC8000:1027 localhost:1905 FIN_WAIT_2 2112
[ccProxy.exe]
TCP HPNC8000:1905 localhost:1027 CLOSE_WAIT 1176
[svchost.exe]
TCP HPNC8000:1908 192.168.1.1:http CLOSE_WAIT 2112
[ccProxy.exe]
TCP HPNC8000:1030 localhost:1871 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1909 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1906 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1901 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1885 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1893 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1887 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1879 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1913 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1915 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1911 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1917 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1899 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1891 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1883 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1875 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1897 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1877 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1889 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1881 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1873 TIME_WAIT 0
TCP HPNC8000:1030 localhost:1869 TIME_WAIT 0
TCP HPNC8000:1895 localhost:1030 TIME_WAIT 0
TCP HPNC8000:1870 pop1.us4.outblaze.com:pop3 TIME_WAIT 0
TCP HPNC8000:1872 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1874 pi.ftl.affinity.com:pop3 TIME_WAIT 0
TCP HPNC8000:1876 pop-server1.swfla.rr.com:pop3 TIME_WAIT 0
TCP HPNC8000:1878 pi.ftl.affinity.com:pop3 TIME_WAIT 0
TCP HPNC8000:1880 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1882 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1884 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1888 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1894 mail.charter.net:pop3 TIME_WAIT 0
TCP HPNC8000:1896 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1900 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1902 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1910 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1912 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1914 abell.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1916 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1918 biham.lunarpages.com:pop3 TIME_WAIT 0
TCP HPNC8000:1919 ipostoffice.worldnet.att.net:995 TIME_WAIT
0
UDP HPNC8000:microsoft-ds *:* 4
[System]
UDP HPNC8000:1088 *:* 1096
[svchost.exe]
UDP HPNC8000:1026 *:* 2776
[ventc.exe]
UDP HPNC8000:1129 *:* 1096
[svchost.exe]
UDP HPNC8000:1029 *:* 1096
[svchost.exe]
UDP HPNC8000:ntp *:* 1016
[svchost.exe]
UDP HPNC8000:1025 *:* 1868
[cgav.exe]
UDP HPNC8000:1122 *:* 3276
[firefox.exe]
UDP HPNC8000:8008 *:* 2776
[ventc.exe]
UDP HPNC8000:11188 *:* 2160
[cgagent.exe]
UDP HPNC8000:1900 *:* 1176
[svchost.exe]
UDP HPNC8000:netbios-dgm *:* 4
[System]
UDP HPNC8000:ntp *:* 1016
[svchost.exe]
UDP HPNC8000:1900 *:* 1176
[svchost.exe]
UDP HPNC8000:netbios-ns *:* 4
[System]
(HPNC8000 is the name of my computer)
Now for the HijackThis (BASELINE) log:
Logfile of HijackThis v1.99.1
Scan saved at 5:57:14 PM, on 10/1/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\acs.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\CYBERG~1\cgahelp.exe
C:\PROGRA~1\CYBERG~1\cgav.exe
C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\Wnex7DO.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
C:\Program Files\Atheros\ACU\Utility\ACU.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\WINDOWS\system32\RunDLL32.exe
C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINDOWS\system32\hphmon04.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRA~1\MICROS~4\wcescomm.exe
C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Common Files\Sonic Shared\CineTray.exe
C:\PROGRA~1\MICROS~4\rapimgr.exe
C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\PROGRA~1\CYBERG~1\cgasvc.exe
C:\PROGRA~1\CYBERG~1\cgagent.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
C:\Program Files\Executive Software\Diskeeper Home Edition\DKService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Dantz\Retrospect\retrorun.exe
C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
C:\WINDOWS\system32\DllHost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\cmd.exe
C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe
C:\Documents and Settings\Jorge\Desktop\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://paginacuba.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.worldnet.att.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.2020search.com/search/9884/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchURL = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.2020search.com/search/9884/search.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = prosearching.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page_bak = prosearching.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: Windows Resources - {2D38A51A-23C9-48a1-A33C-48675AA2B494} - C:\WINDOWS\winres.dll (file missing)
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [eabconfg.cpl] C:\Program Files\HPQ\Quick Launch Buttons\EabServr.exe /Start
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [HKCU] C:\WINDOWS\system32\cmd.exe /C Start "HKCU Updates" /MIN "C:\Program Files\current profile updates\hkcu.exe"
O4 - HKLM\..\Run: [CgaHelper] C:\PROGRA~1\CYBERG~1\cgahelp.exe -check
O4 - HKLM\..\Run: [CgaViewer] C:\PROGRA~1\CYBERG~1\cgav.exe -check
O4 - HKLM\..\Run: [PassCode] C:\WINDOWS\regedit /s C:\WINDOWS\dp.reg
O4 - HKLM\..\Run: [KeepAlive] C:\WINDOWS\regedit /s C:\WINDOWS\keepaliv.reg
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [Watcher-WatchDog] C:\WINDOWS\System32\Wnex7DO.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~2\VPTray.exe
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_01\bin\jusched.exe
O4 - HKLM\..\Run: [AdobeVersionCue] C:\Program Files\Adobe\Adobe Version Cue\ControlPanel\VersionCueTray.exe
O4 - HKLM\..\Run: [ACU] C:\Program Files\Atheros\ACU\Utility\ACU.exe -nogui
O4 - HKLM\..\Run: [VF0060 STISvc] RunDLL32.exe V0060Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [VF0070 STISvc] RunDLL32.exe V0070Pin.dll,RunDLL32EP 513
O4 - HKLM\..\Run: [Acrobat Assistant 7.0] "C:\Program Files\Adobe\Acrobat 7.0\Distillr\Acrotray.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\system32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Program Files\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKCU\..\Run: [Magical Gatherings] C:\Program Files\Magical Gatherings\Magical Gatherings.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\PROGRA~1\MICROS~4\wcescomm.exe"
O4 - HKCU\..\Run: [Creative Detector] "C:\Program Files\Creative\MediaSource\Detector\CTDetect.exe" /R
O4 - HKCU\..\Run: [Uniblue Registry Booster] C:\Program Files\Uniblue\Registry Booster\RegistryBooster.exe /S
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C:\Program Files\Common Files\Sonic Shared\CineTray.exe
O8 - Extra context menu item: &eBay Search - res://C:\Program Files\eBay\eBay Toolbar2\eBayTb.dll/RCSearch.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Open Link Target in Firefox - file://C:\Documents and Settings\Jorge\Application Data\Mozilla\Firefox\Profiles\vq0wwdnm.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewlink.html
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: View This Page in Firefox - file://C:\Documents and Settings\Jorge\Application Data\Mozilla\Firefox\Profiles\vq0wwdnm.default\extensions\{5D558C43-550F-4b12-84AB-0D8ABDA9F975}\firefoxviewpage.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_01\bin\npjpi150_01.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra 'Tools' menuitem: Create Mobile Favorite… - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~4\INetRepl.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O14 - IERESET.INF: START_PAGE_URL=http://www.hp.com
O15 - Trusted Zone: *.flingstone.com
O15 - Trusted Zone: *.i-lookup.com
O15 - Trusted Zone: *.offshoreclicks.com
O15 - Trusted Zone: *.teensguru.com
O15 - Trusted Zone: *.xxxtoolbar.com
O16 - DPF: JavaConnect - file://C:\TEMP\SISD\JavaConnect.cab
O16 - DPF: Sametime BC 651 - file://C:\TEMP\SISD\STBroadcastClient.cab
O16 - DPF: Sametime BroadCast Client ST30IF2 - file://C:\TEMP\SISD_30\STBroadcastClient.cab
O16 - DPF: Sametime DA 651 - file://C:\TEMP\SISD\STDirectoryApplet.cab
O16 - DPF: Sametime Directory Applet ST30SP1 - file://C:\TEMP\SISD_30\STDirectoryApplet.cab
O16 - DPF: Sametime Meeting Room Client ST30SP1 - file://C:\TEMP\SISD_30\STMeetingRoomClient.cab
O16 - DPF: Sametime MRC 651 - file://C:\TEMP\SISD\STMeetingRoomClient.cab
O16 - DPF: {00000000-0000-0000-0000-100000000003} - http://code.jcash.biz/l/b3af077ab4115af56b…b7042aeb_13.exe
O16 - DPF: {2226ED4E-6E9A-472E-97ED-B6D54F3B620B} (STURLConnection Control) - file://C:\TEMP\SISD\STUrlConLoader.cab
O16 - DPF: {24CEC0BF-C8BC-4BCB-B804-226326B319EF} (JNILoader Control) - file://C:\TEMP\SISD_30\STJNILoader.cab
O16 - DPF: {53F92AF2-3C1E-4A63-B2EA-2E33DA6286B7} (STAutoAway Control) - file://C:\TEMP\SISD\STAutoAwayLoader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5co…b?1098282519793
O16 - DPF: {6632A7E9-FE1F-43D2-A04A-A15951ED63E0} - http://mediaplayer.walmart.com/installer/install.cab
O16 - DPF: {6CEDB6B5-4859-4E3A-BCA2-FB8E565B8AD9} (JNILoader Control) - file://C:\TEMP\SISD\STJNILoader.cab
O16 - DPF: {6E10F5D1-B3E1-4BC2-8E6F-DD859F10F66F} (CAgentLauncher Class) - http://paginacuba.com/plugin/CGAgentATL.dll
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol/unagi/ampx_en_dl.cab
O18 - Protocol: widimg - {EE7C2AFF-5742-44FF-BD0E-E521B0D3C3BA} - C:\WINDOWS\system32\btxppanel.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\System32\NavLogon.dll
O20 - Winlogon Notify: winkrg32 - winkrg32.dll (file missing)
O23 - Service: Atheros Configuration Service (ACS) - Unknown owner - C:\WINDOWS\system32\acs.exe
O23 - Service: AdobeVersionCue - Adobe Sytems - C:\Program Files\Adobe\Adobe Version Cue\service\VersionCue.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: CyberGatekeeper Agent (CGAgent) - InfoExpress - C:\PROGRA~1\CYBERG~1\cgasvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\DefWatch.exe
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Program Files\Executive Software\Diskeeper Home Edition\DKService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\system32\HPHipm11.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Retrospect Launcher (RetroLauncher) - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\retrorun.exe
O23 - Service: Retrospect Helper - Dantz Development Corporation - C:\Program Files\Dantz\Retrospect\rthlpsvc.exe
O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec Client Security\Symantec AntiVirus\SavRoam.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec AntiVirus\Rtvscan.exe
O23 - Service: Symantec SecurePort (SymSecurePort) - Symantec Corporation - C:\Program Files\Symantec Client Security\Symantec Client Firewall\SymSPort.exe
O23 - Service: Venturi Client (Venturi2) - Venturi Wireless - c:\program files\verizon wireless\venturi\Client\ventc.exe
I have to confess I've already deleted some of the items above… but I'm waiting direction.
Items deleted:
The TRUSTED ZONE URL's (all)
The SAMETIME ENTRIES
I work on several websites I maintain and the connection slowdowns, and "brickwalls" (eveything slows to the point nothing gets through) make it extremely hard to do the work.
Your help would be greatly appreciated.