This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

is my computer infected?

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

G'day,

For about 6 weeks i have been trying to get to the bottom of computer problems including:
* Not being able to use pathping command without getting "no resources" on the first hop where all then stops
* Packet loss (as much as 18%) and a slow and eratic connection that was affecting my on-line gaming

Someone yesterday on a different forum suggested software firewall could be causing the pathping problems. I had previously tried turning off the firewall but with no joy. They suggested booting into "safe mode with networking". Trying this suggestion enabled me to pathping (sort of as the pathping terminated at the third hop thanks to my Thompson 780 router eating everything there after). To ensure that the firewall was not the problem I today uninstalled the software and rebooted. Sadly still unable to pathping…

My ISP has been insisting that i have a virus/malware and I (being anal on this subject!) was not so sure:
* I run (but not today see above) ZoneAlarm Security Suite 7 and update the virus/malware ID files daily
* I have the system set to do a full virus scan every night
* at a minimum I scan with an up to date Adaware weekly
* at a minimum I scan with an up to date Spybot weekly
* I try to only use Mozilla Firefox and Thunderbird
* at a minimum I check for M$ updates weekly on all products installed (auto-update is turned off on all products so they too don't effect my gaming)
* at a minimum I run diskclean and defrag weekly
* I run CCleaner monthly

I have been seeking help for these problems via several different forums and via my ISP (Be Unlimited) and only today remembered HiJackThis… silly me ;)

My system is a Dell Dimension 8400 P4 2.80 GHz, 1 GB RAM, 160 GB HD (75% empty), Radeon X800 XT, Creative SB Audigy 2, Broadcom NetXtreme 57 XX gigabit controller etc

I have just started to use Ethereal packet sniffer as well…

Even though I uninstalled ZA today I think see from the HJT log that it appears that some ZA is still running?

I followed all of the instructions on your sticky posts to create the HiJackThis log below.

Logfile of Trend Micro HiJackThis v2.0.0 (BETA)
Scan saved at 10:16:06, on 23/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\mom.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Roxio\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\taskswitch.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\WINDOWS\SYSTEM32\ati2sgag.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\HJT\HiJackThis_v2.exe
C:\WINDOWS\system32\wuauclt.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Dad/My%20Documents/Our%20Home%20Page.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://10.0.0.2/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Roxio\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O15 - Trusted Zone: http://ati.amd.com
O15 - Trusted Zone: *.ati.com
O15 - Trusted Zone: http://*.ati.de
O15 - Trusted Zone: *.ati.de.com
O15 - Trusted Zone: http://sib1.od2.com
O15 - Trusted Zone: *.roxio.co.uk
O15 - Trusted Zone: *.roxio.com
O15 - Trusted Zone: http://applicationshop.sonyericsson.com
O15 - Trusted Zone: http://www.sonyericsson.com
O15 - Trusted Zone: http://metaservices.windowsmedia.com
O15 - Trusted Zone: http://*.windowsmedia.com
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121176565103
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162059958671
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/s…er/PROFILER.CAB
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://217.155.139.109/AxisCamControl.ocx
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5728D993-3448-4B0A-8F5D-8B565F1433F9}: NameServer = 213.208.106.212,213.208.106.213
O17 - HKLM\System\CCS\Services\Tcpip\..\{8CAF742B-B11F-4A0C-AFAF-E50CEBA45042}: NameServer = 87.194.0.51,87.194.0.66
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 8974 bytes

So is my ISP right and I have an infected computer? Or can you spot another problem?

Any help gratefully received!
Thanks in anticipation for the help?
hi ANZAC, do you have a router in the picture? what about the cmd tracert or ping, they return info? tracert is similair to pathping cmd. log looks ok.
G'day, Yes I have a router Be Box from Be Unlimited my ISP which is actually a Thompson 780 Yes ping and tracert still work just not pathping (but it does from safe mode with networking??? Have posted below just for the halibut! Thanks for trying to help. At least I know that my ISP were trying to blow smoke up me and that i don't have a virus on my PC… SO where do i go what do i try now? me thinks aloud Microsoft Windows XP [Version 5.1.2600] © Copyright 1985-2001 Microsoft Corp. C:\Documents and Settings\Dad>ping www.tomcoyote.org Pinging tomcoyote.org [70.84.70.85] with 32 bytes of data: Reply from 70.84.70.85: bytes=32 time=135ms TTL=52 Reply from 70.84.70.85: bytes=32 time=134ms TTL=52 Reply from 70.84.70.85: bytes=32 time=133ms TTL=52 Reply from 70.84.70.85: bytes=32 time=134ms TTL=52 Ping statistics for 70.84.70.85: Packets: Sent = 4, Received = 4, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 133ms, Maximum = 135ms, Average = 134ms C:\Documents and Settings\Dad>tracert www.tomcoyote.org Tracing route to tomcoyote.org [70.84.70.85] over a maximum of 30 hops: 1 54 ms 99 ms 99 ms 192.168.1.254 2 25 ms 26 ms 25 ms 87-194-200-1.bethere.co.uk [[removed]] 3 572 ms 900 ms 904 ms 10.1.0.245 4 29 ms 28 ms * [removed] 5 35 ms 35 ms 36 ms ae-19-53.ebr1.London1.Level3.net [[removed]] 6 40 ms 36 ms 36 ms ae-1-100.ebr2.London1.Level3.net [[removed]] 7 98 ms 109 ms 107 ms ae-4.ebr1.NewYork1.Level3.net [[removed]] 8 108 ms 109 ms 107 ms ae-3.ebr1.Washington1.Level3.net [[removed]] 9 117 ms 126 ms 125 ms ae-2.ebr1.Atlanta2.Level3.net [[removed]] 10 142 ms 144 ms 143 ms ae-3.ebr1.Dallas1.Level3.net [[removed]] 11 135 ms 135 ms 136 ms ae-14-53.car4.Dallas1.Level3.net [[removed]] 12 134 ms 136 ms 135 ms THE-PLANET.car4.Dallas1.Level3.net [[removed]] 13 136 ms 136 ms 136 ms te7-2.dsr01.dllstx3.theplanet.com [[removed]] 14 136 ms 135 ms 136 ms vl41.dsr01.dllstx4.theplanet.com [[removed]] 15 135 ms 135 ms 136 ms gi1-0-2.car17.dllstx4.theplanet.com [67.18.116.8 5] 16 136 ms 136 ms 135 ms geeks11.geekstogo.com [70.84.70.85] Trace complete. C:\Documents and Settings\Dad>pathping www.tomcoyote.org Unable to resolve target system name www.tomcoyote.org. (Have just binned ZoneAlarm and installed Kaspersky instead (because ZA was robbing 3000 kbps of my bandwidth) and did not click allow quick enough here) C:\Documents and Settings\Dad>pathping www.tomcoyote.org Tracing route to tomcoyote.org [70.84.70.85] over a maximum of 30 hops: 0 No resources. C:\Documents and Settings\Dad>pathping www.tomcoyote.org Tracing route to tomcoyote.org [70.84.70.85] over a maximum of 30 hops: 0 No resources. C:\Documents and Settings\Dad>
hi ANZAC,

not pathping (but it does from safe mode with networking?

thats strange, could it be your firewall? have you checked any router settings or taken the router out of the picture?
have you used ping plotter? a excellent (free version) utility for packet/latency issues, has a paid version also, complete with a forum also.

http://www.pingplotter.com/
G'day Shelf Life, Thanks again for the help. It's appreciated. Strange indeed. Driving me bonkers it is. I don't think it is caused by my hardware firewall because if it was the cause pathping still would not work in safe mode? (or is my logic flawed?) However I did have a problem with this router re DNS and I fixed it with flushDNS and i "think" the problem started around then. But I don't know how to take the router out of the equation for sure because i don't have a spare… It was suggested on another forum that it would be caused by software firewall and to try safe mode with networking (after I told them i had turned it off via sys tray icon and that I still had the problem) However safe mode stops many things from running not just the firewall and I dont know how to rule the other apps out? I binned the zonealarm security suite 7 (after just paying for the annual renewal) cause when i was trying to rule ZA out I unistalled it and got an extra 3000kbs on my bandwith (up to 24MB connection) and when i queried them they tried to blow smoke up me too! 3000kbps to read the headers indeed. Bloated software. Registry cleaned of ZA. I have just installed Kaspersky Internet Security after much research. What a difference. My computer is speeding along like new again; it uses 600kbs worth of bandwidth it appears. But still NO pathping While typing this I remembered that I updated my ATI card about that time… trying to open the app to check to see if there are any settings that might be causing the problem? but it appears to have hung? Will post this now. Check why it's hung. (Maybe conflict with Kaspersky?). Will then try another HJT to make sure ZA has really gone as well I think.
me again

This is from latest HJT

O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab

Is this running? It's part of ZoneAlarm I think? How do i delete it please?

Logfile of Trend Micro HijackThis v2.0.0 (BETA)
Scan saved at 03:14:16, on 25/03/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\mom.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\system32\CTsvcCDA.exe
C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\SM1BG.EXE
C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
C:\Program Files\Roxio\Media Experience\DMXLauncher.exe
C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe
C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe
C:\WINDOWS\CTHELPER.EXE
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\Program Files\Razer\DeathAdder\razerhid.exe
C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
C:\Program Files\Razer\DeathAdder\razertra.exe
C:\Program Files\Razer\DeathAdder\razerofa.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\CPSHelpRunner.exe
C:\HJT\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell.co.uk/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = file:///C:/Documents%20and%20Settings/Dad/My%20Documents/Our%20Home%20Page.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://10.0.0.2/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: WsftpBrowserHelper Class - {601ED020-FB6C-11D3-87D8-0050DA59922B} - C:\Program Files\Ipswitch\WS_FTP Home\wsbho2k0.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Application Accelerator\iaanotif.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\system32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [DMXLauncher] "C:\Program Files\Roxio\Media Experience\DMXLauncher.exe"
O4 - HKLM\..\Run: [CTDVDDet] C:\Program Files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [RoxWatchTray] "C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatchTray9.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Drag-to-Disc\DrgToDsc.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [DeathAdder] C:\Program Files\Razer\DeathAdder\razerhid.exe
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\ie_banner_deny.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\scieplugin.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
O15 - Trusted Zone: http://ati.amd.com
O15 - Trusted Zone: *.ati.com
O15 - Trusted Zone: http://*.ati.de
O15 - Trusted Zone: *.ati.de.com
O15 - Trusted Zone: http://sib1.od2.com
O15 - Trusted Zone: *.roxio.co.uk
O15 - Trusted Zone: *.roxio.com
O15 - Trusted Zone: http://applicationshop.sonyericsson.com
O15 - Trusted Zone: http://www.sonyericsson.com
O15 - Trusted Zone: http://metaservices.windowsmedia.com
O15 - Trusted Zone: http://*.windowsmedia.com
O15 - Trusted Zone: http://download.windowsupdate.com
O15 - Trusted Zone: http://*.windowsupdate.com
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1121176565103
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat…b?1162059958671
O16 - DPF: {90A29DA5-D020-4B18-8660-6689520C7CD7} (DmiReader Class) - http://support.euro.dell.com/global/apps/s…er/PROFILER.CAB
O16 - DPF: {917623D1-D8E5-11D2-BE8B-00104B06BDE3} (CamImage Class) - http://217.155.139.109/AxisCamControl.ocx
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D} (QDiagHUpdateObj Class) - http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?326
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15028/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{5728D993-3448-4B0A-8F5D-8B565F1433F9}: NameServer = 213.208.106.212,213.208.106.213
O17 - HKLM\System\CCS\Services\Tcpip\..\{8CAF742B-B11F-4A0C-AFAF-E50CEBA45042}: NameServer = 87.194.0.51,87.194.0.66
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\adialhk.dll
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\SYSTEM32\ati2sgag.exe
O23 - Service: Kaspersky Internet Security 6.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 6.0\avp.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\system32\CTsvcCDA.exe
O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C:\Program Files\Intel\Intel Application Accelerator\iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUPnPRenderer9.exe
O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Common Files\Sonic Shared\RoxioUpnpService9.exe
O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe
O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
O23 - Service: Roxio Hard Drive Watcher 9 (RoxWatch9) - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxWatch9.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

–
End of file - 9483 bytes
hi ANZAC,

you can get rid of the 016 like this:

scan with HJT, put a checkmark beside the items below, close all windows and click fix checked.

O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A8EDA626F876} (Anonymizer Anti-Spyware Scanner) - http://download.zonelabs.com/bin/promotion…ctor/WebAAS.cab
——————————————-

I don't think it is caused by my hardware firewall because if it was the cause pathping still would not work in safe mode?

i think your right. running in safe mode would only affect hardware/software on your computer. safe mode loads only the bare minimum of stuff. wouldnt affect your router or its firewall. this would make me think it was something on your computer since it dosnt work in normal mode (blocked) but does work in safe mode(not blocked)

However safe mode stops many things from running not just the firewall and I dont know how to rule the other apps out?

i would think it would have to be some kind of security app, iam thinking its blocking a packet. thats only my guess.

Is your XP firewall off?

when i run it, it only displays two hops 0 and 1 hop zero is my internal IP, hop 1 is 0.0.0.0 not sure what to make of that.
G'day shelf life, Have now deleted the last of the zonelabs stuff. Still can't pathping though. I don't have any other security ap apart from the kaspersky (was zonealarm till several days ago), spybot and adaware… that i am aware of ;) Windows firewall (and security centre) are switched off I wonder if a windows security patch may have caused any issues, because i load them on frequently? Are you saying that you cant pathping either? When my pathping was working, sometimes it would get past the router and at other times the router would eat everything… I could find nothing in the ATI GUI that would effect the security settings, but realised that i wasted my time checking because the router is connected to a Broadcom net xtreme and not the ATI; doh Going to try up dating my broadcom card now just in case but am not holding my breath any ideas where i can learn how to, via safemode i guess, to load stuff line by line till i discover what is effecting the pathping, please? Am going bald from pulling my hair out! Thanks once again for the help sir.
hi ANZAC,

Are you saying that you cant pathping either


i only get two hops when i use it. lets try disabling windows firewall service, nothing to lose trying.

if you go to start>run then type in services.msc the windows service panel will open. under the name column look for:

windows firewall/internet connection sharing

right click on it and select properties
under the general tab:
make sure that the service status is: Stopped
and the Startup type is: disabled

reboot once, then try pathping. if it dosnt work i would go back and change the settings back to what they where, just in case you use or play around with windows firewall years from now and it dosnt work because you disabled the service, has happened to me with with disabling services.
you should check out pingplotter for latency issues also. they have a free version.

via safemode i guess, to load stuff line by line till i discover

only thing i can think of is to bring up task manager in normal mode and in safe mode and check the process tab. crtl-alt-delete keys

shelf life
G'day shelf life Turning off the firewall service did not work. Will try comparing the two safe/normal mode vi atask manager when i have more time. Thanks once again for the help
hi ANZAC,

Turning off the firewall service did not work.

oh well, it was worth a try.

i took my router out of the picture and i still couldnt get past the first hop.
iam going to try it in safe mode also to see if its any different.

shelf life
G’day again Shelf Life, I am curious to know whether you got to the bottom of your pathping problems yet… cause I sure have not solved mine? :(
hi again,

you got to the bottom of your pathping problems yet


no i have not. request times out at first hop. my router is set to drop pings. but i took it out of the picture and got the same result. all that leaves is my firewall which has rules to allow pings. dont know whats going on.
i ping (pathping) my router and it stops there. (1)
i ping yahoo and it stops at my NIC (II)
what the hell?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI