Super Slow LAN/Downloads(RESOLVED)

  1. #1
    rpmorrow is offline Valued Member

    Super Slow LAN/Downloads(RESOLVED)

    Hi these are the hijackthis logs related to my questions in this post

    To summarize the problem(s):
    Trying to acess exe files over lan causes explorer to temporarily lock. Even if i just right click such a file the lock occurs. Acessing same files from a different PC with same login credentials is not problematic.
    Not hardware issue as it works fine when booting to secondary windows install.
    Have run CCleaner, Avira Antivir (full), Malwarebytes.

    I would really appreciate some help, I even tried reinstalling windows (repair) but to no avail.


    I notice that it shows explorer.exe twice under running processes. Since the problem is directly related to explorer, could this be related?


    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 13:23:35, on 18/01/2009
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
    Boot mode: Normal

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    C:\WINDOWS\system32\svchost.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    C:\WINDOWS\system32\vshost.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
    C:\WINDOWS\system32\winsmss.exe
    C:\Program Files\Griffin Technology\PowerMate\PowerMate.exe
    C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe
    C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe
    C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
    C:\Program Files\Screen Saver Control\ScreenSaverControl.exe
    C:\WINDOWS\system32\ctfmon.exe
    C:\Program Files\Portrait Displays\Pivot Software\floater.exe
    C:\Program Files\MSI\Core Center\CoreCenter.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Windows Live\Messenger\usnsvc.exe
    C:\Program Files\Mozilla Firefox\firefox.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\system32\taskmgr.exe
    C:\Program Files\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
    O4 - HKLM\..\Run: [PowerMate] C:\Program Files\Griffin Technology\PowerMate\\PowerMate.exe
    O4 - HKLM\..\Run: [PivotSoftware] "C:\Program Files\Portrait Displays\Pivot Software\wpctrl.exe"
    O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Premium\avgnt.exe" /min
    O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
    O4 - HKCU\..\Run: [Screen Saver Control] C:\Program Files\Screen Saver Control\ScreenSaverControl.exe -quiet
    O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
    O4 - Global Startup: CoreCenter.lnk = C:\Program Files\MSI\Core Center\CoreCenter.exe
    O4 - Global Startup: Task Manager.lnk = C:\WINDOWS\system32\taskmgr.exe
    O8 - Extra context menu item: Download with GetRight - C:\Program Files\GetRight\GRdownload.htm
    O8 - Extra context menu item: Open with GetRight Browser - C:\Program Files\GetRight\GRdownload.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1147339479875
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsof...?1147340104718
    O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
    O23 - Service: Avira AntiVir Premium MailGuard (AntiVirMailService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avmailc.exe
    O23 - Service: Avira AntiVir Premium Scheduler (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\sched.exe
    O23 - Service: Avira AntiVir Premium Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avguard.exe
    O23 - Service: Avira AntiVir Premium WebGuard (antivirwebservice) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\AVWEBGRD.EXE
    O23 - Service: Avira AntiVir Premium MailGuard helper service (AVEService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Premium\avesvc.exe
    O23 - Service: BCL easyPDF SDK 5 Loader (bepldr) - Unknown owner - C:\Program Files\Common Files\BCL Technologies\easyPDF 5\bepldr.exe
    O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: lmab_device - Lexmark International, Inc. - C:\WINDOWS\system32\LMabcoms.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm1 2.exe

    --
    End of file - 5620 bytes






    Uninstall List:

    Site Map Maker 1.4
    1.0.0.1
    1st Page 2000 2.00 Free
    3ivx D4 4.1a16 Decoder (remove only)
    AA SiteBuilder 2.4.0
    Account Preview 1.1
    Ace PDF Rebrander
    ActiveSpeed
    ActiveState ActiveTcl 8.4.15.0
    Ad Words Digger
    Adabas D 13.01.00
    Add2it PostIt Pro
    Adobe Flash Player 10 Plugin
    Adobe Flash Player 9 ActiveX
    Adobe Reader 7.0.5
    Adsense Buddy V1.12
    Adsense Cash Machine 1.4
    Adsense Travel Pages Generator 1.08 (remove only)
    AdSenseAccelerator 1.0
    AdsenseFinder
    Advanced File Organizer 3.0
    Adwordiser 1.0
    Adwords Micro-Nicher
    Affiliate AdWizard
    Affiliate ToolBox Creator
    Affiliates Alert 1.1.134
    aqler
    Armand Morin's Header Generator
    Article Assistance 1.5
    Article Content Spinner 1.0
    Article Engineer
    Article Helper Pro
    Article Indexer
    Article Infuser
    Article Innovator 2.8.0
    Article Page Machine 1.0
    Article Recon Lite V1.0.1
    Article Recon Pro V1.0.1
    Article Spotter
    Article Submitter 1.4
    ArticleAnalyzer
    articlesubmitgenius
    ATI - Software Uninstall Utility
    ATI Display Driver
    Automatic Website Audio For Newbies 1.0
    AutoStreamer
    autoyahoo
    Avira AntiVir Premium
    Awe Video Files 1.0
    AWE Video Player V 1.6
    b2eblogger
    BannerGeneratorSetup
    BizAutomator (remove only)
    Blog Announcer Pro 1.0
    BlueVoda Website Builder 8.0
    BookMarkingDemon
    Brain Builder 3.0
    BuildAToolBar
    Campaigner
    CamStudio
    CB Niche Builder
    CB Text Ad Generator 1.1
    CBCourier Version 1.0
    CCleaner (remove only)
    CDBurnerXP Pro 3
    ClickAdEqualizer
    Clickbank Elite
    Cloaker Buzz
    CometEditor 3.06
    Comment Hut Lite v.0.2.3
    Comment Hut v.0.2.2
    Comment Sniper
    CommentKahuna
    Competition Dominator
    Core Center
    craigslistgenius
    CuteFTP 8 Professional
    CutePDF Writer 2.7
    D2D BIZwise
    Daddy Keword Tool
    Dave and Aarons' Project Manager Pro
    DeskPile Pro
    DeskPile Pro
    DeskPile Shuffle
    Desktop Marketer
    Desktop URL Shrinker 1.2
    DFextractor
    Diginamic Compiler 2.0.0
    Directory Submitter 1.0.20
    directorysubmitter
    Directory-Submitter
    DiscMojo
    Diskeeper 2009 Professional
    Drop Down Wizard
    drupalblogger
    DupeFree Pro
    Duplicate Content Detonator 2.0
    Easy Adsense Cash 1.5
    Easy Ad-Splitter
    EasySEO
    Ebook Librarian
    EdwinSoft Semi-Auto Bookmarking
    Email Automator
    EVEREST Home Edition v2.20
    eWriter pro
    EZ Graphics Viewer
    EZI-Search 1.0
    EzKeyword
    Fast Blog Finder 2.10
    Fast Content Producer
    Feedback Analyzer
    FileZilla Client 3.1.1-rc1
    FirstClass® Client
    FLV Player 2.0, build 24
    FLV Producer Lite
    ForexTrader.Meta 4.00
    Forum Submitter Pro Full
    Free Monitor for Google 2.0
    Front Office Pro v1.3
    GetByMail 2.0.1.18
    GetRight
    GiPo@MoveOnBoot 1.9.5
    Golden Cash Compass
    Good Keywords v2.0.072205
    Google Rank Analyzer
    googlegroupgenius
    GooglePageBacklinkGen
    gpage
    GSiteCrawler
    HavAdsSoftware
    HijackThis 2.0.2
    Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
    HP Officejet 9100 series
    HP Officejet 9100 series
    HP Officejet 9100 series
    HTML Password Lock 3.2.9
    HTML-Crypto PC Version
    Hyperlink Creator
    Hyperlink Maker Pro 2008
    HyperVRE 1.7
    IAW20
    IBC Article Submitter 1.4
    IBP 10.2
    icqsubmitter
    IMO Toolbar - Toolbar
    IMO Toolbar Toolbar (remove only)
    Impact PopUp 1.0
    Instant Article Submitter 1.0.6
    Instant Blog and Ping
    Instant Book Proposal™
    Instant Press Release Creator
    Instant Query Letters
    Instant ShortStory Creator
    Ipswitch WS_FTP Professional 2007
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment, SE v1.4.1_02
    Java Web Start
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) 6 Update 7
    Joel Christopher eCentral
    Joint Venture Manager
    JV eCentral TPLRV
    KAZ (Keyboard A-Z) Version 17 TL31.12.07 for The Open University
    Keyword Anywhere 1.0
    Keyword Buzz
    keyword clean up 1.0
    Keyword Dig
    Keyword Harvester
    Keyword Magnet 1.0.0
    Keyword Manipulator v0.9
    Keyword Niche Miner
    Keyword Niche Power
    Keyword Ninja 1.0
    Keyword Spider 1.0
    Keyword Spy Tool 1.0
    Keyword Station
    Kim Enders' Sales Page Rapid-Fire 1.0
    LaserBeam Marketing Quick Paste 1.0
    Launchy 1.0
    Lexmark Software Uninstall
    Link Buzz
    Logitech Desktop Messenger
    Macromedia Dreamweaver 8
    Macromedia Extension Manager
    Magic Subscriber
    MagniBar - The Magnificant Toolbar
    Mailloop 6
    Mailloop 6
    Malwarebytes' Anti-Malware
    Map Button (Windows Live Toolbar)
    Meta Whiz 1.0
    Michael Cheney's Fortune With 500
    Micro Niche Finder
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1
    Microsoft .NET Framework 1.1 Hotfix (KB928366)
    Microsoft .NET Framework 2.0 Service Pack 2
    Microsoft .NET Framework 3.0 Service Pack 2
    Microsoft .NET Framework 3.5 SP1
    Microsoft .NET Framework 3.5 SP1
    Microsoft Office Standard Edition 2003
    Microsoft SQL Server Desktop Engine (MAILLOOP6)
    Mozilla (1.7.3)
    Mozilla Firefox (3.0.5)
    Mozilla Thunderbird (2.0.0.19)
    MRU Wizard 1.0
    MSN
    MSXML 4.0 SP2 (KB927978)
    MSXML 4.0 SP2 (KB936181)
    MSXML 4.0 SP2 (KB954430)
    MSXML 6 Service Pack 2 (KB954459)
    My Blog Announcer 1.0
    My Free Web Site Builder
    myAffiliateAssistant Pro Edition 1.3
    MyODBC
    MySQL Server 5.0
    NetWaiting
    Niche Browser 1.0
    Niche Free Content Searcher ver 2.0
    Niche Inspector
    Niche Page Builder
    NicheEmpires.com Blog Link Generator
    Niches-In-A-Box Installer v1.0
    NicheSponder
    NinjaLinkCloaker
    Nitro PDF Professional
    NVIDIA Drivers
    Nvu 1.0
    OmniScope Search 1.0
    OneCare Advisor (Windows Live Toolbar)
    Ontrack® Fix-It Utilities 4.0
    Optin Acellerator v4.3
    Optin Voodoo 1.33 Final
    Orwell
    PADGen 3.0.1.35
    Page Brand 1.00
    Page Generator 1.0
    Page Rank Explorer Pro
    PageBuilder Elite Version 2.30
    Pawsoft Fass
    PC ScanAndSweep
    PDF Compiler
    PDF Locker v2.0
    PDF Printer Pro
    Philips SPC 900NC PC Camera
    PHP Page Generator v 0.2.0
    PingSlinger
    pingslingergen2
    Pivot Software
    PLR Dashboard 1.0
    PLR Integrator 1.4
    Podcast Assistant In A Box 1.0
    Podcast Teleprompter 1.4
    Poker Bobby (Beta 0.8)
    Popup Blocker (Windows Live Toolbar)
    PowerDVD
    PowerMate Driver 1.5.3
    PowerQuest Drive Image 2002
    PPC Landing Page Builder
    PR Ninja
    PR Plug
    PrintKey2000
    Private Mail Reader
    ProfitGadget 1.1
    Promobuddy2
    proxygenius
    PsychicSalesLetter 2.10
    Public Domain Reports
    QuickTime
    RapidFormatter Videos
    RealPlayer
    RedMon - Redirection Port Monitor
    Registry Mechanic 8.0
    Resellers Niche Newsticker V1.0.2.3
    Resellfire.com Google Sitemap Creator 1.0
    RSS Announcer 1.4
    RSS Traffic Detonator 1.0.0
    RssReader
    Sales Letter Creator 1.4
    Sales Page Examiner
    Sales Page Machine Version 2.0
    Scott's Box Shot Maker 2.0
    Script Smart
    seclicker
    Secret Article Submitter 1.0.0.1
    Security Update for Windows XP (KB913433)
    SEO Diamond Article Submitter 1.4
    SEO Equalizer 1.0
    SEO smArticle Composer
    SEO Spider 1.0
    seoESP PRO v1.0
    SEOSurf® v 0.7.0
    shoutboxsubmitter
    Simple Search-Replace
    Simple Search-Replace
    Site Searcher
    Site Wizard PRO 1.5.1
    Skype 2.5
    Smart Menus (Windows Live Toolbar)
    SnagIt 7
    Social PR Booster 1.0
    Software Bomber v1.6
    SoftwareDesignerPro 2.0
    Sonic Opt-In v1.1.1
    soscp
    Sp5TTIntXP
    Special Report Generator 1.0a
    SpellingBee
    SpyZooka
    Squeeze Page Generator
    StarOffice 8
    StealthAdvertiser
    StealthAdvertiser
    stealthbannergenerator
    SubliminalEzy
    T183 Design and the web
    Tabbed Browsing (Windows Live Toolbar)
    TAGandPINGmaster
    tapmaster
    Text To Speech Converter 1.0
    T-Genesis Keyword List Builder
    The Agency, LLC Teleprompter Pro 1.4
    The Loan Bank
    The Loan Bank
    The Web Army Knife (remove only)
    TheDowser for Overture Suggest v1.1
    TheDowser Keyword Harvester Professional v1.1
    TheDowser Professional v5.3.0
    Think Right Now 1.7
    Traffic Equalizer
    Traffic Travis 1.1.3
    Traffic Travis 3.0.0
    Traffic Tycoons V 2.3
    Tweak UI
    Ultimate Content Creator
    unautoblogger
    Undelete Plus 2.71
    videopopin
    VideoWebWizard
    VIGOS Gsitemap 0.97a
    Viral Article Publisher
    Viral Instigator3
    Viral PDF Classic Edition v3.0
    vsearchvoodoo
    Web Audio Plus
    Web Audio Plus
    Web CEO 6.0
    WebFerret
    WebsiteArticleWizard
    WFX Website Builder
    Windows Live Favorites for Windows Live Toolbar
    Windows Live installer
    Windows Live Messenger
    Windows Live OneCare safety scanner
    Windows Live Outlook Toolbar (Windows Live Toolbar)
    Windows Live Sign-in Assistant
    Windows Live Toolbar
    Windows Live Toolbar
    Windows Live Toolbar Extension (Windows Live Toolbar)
    Windows Live Toolbar Feed Detector (Windows Live Toolbar)
    Windows Media Format 11 runtime
    Windows Media Format Runtime
    Windows Media Player 10
    Windows Media Player 11
    Windows Presentation Foundation
    WinRAR archiver
    WinZip
    WinZip Command Line Support Add-On 1.1 SR-1
    WordFlood (remove only)
    WordPageBuilder.com Version 1.0.8
    wordpressblogger
    WPSmart Desktop Tool
    ResellFire.com - Make Money With Resell Rights Info Products My Article Submitter 1.00
    XMailWrite
    XSite Pro
    Xyber Email Assistant
    Yahoo! Extras
    Yahoo! Internet Mail
    Yahoo! Messenger
    Yahoo! Toolbar
    Your Affiliate Link Cloaker Ver 1.0
    Your Article Submitter Pro 1.0
    youtubegenius
    Zoom V.92 PCI Voice Faxmodem
    Last edited by rpmorrow; 18-01-2009 at 02:38 PM.


  2. #2
    rpmorrow is offline Valued Member
    Oh, and when i press Alt+Tab therer is some "Form1" thing showing up, but seems to be totally invisible.

  3. #3
    Neal is offline Dedicated Member
    If you still need help please post a new hijackthis log.

  4. #4
    rpmorrow is offline Valued Member
    Same as above. Not used PC since.

  5. #5
    Neal is offline Dedicated Member
    Visit this page below to familiarize yourself to the tool below and download from one of the links provided.

    A guide and tutorial on using ComboFix




    If you have previously downloaded ComboFix,please delete that version now.



    It is IMPORTANT that it is saved directly to your desktop

    Close any open browsers.

    Disconnect from the Internet.

    Please do not re-connect your machine back to the Internet until Combofix has completely finished.

    Disable your antivirus program and any realtime malware scanners and script blockers now


    How To Disable



    Double click on combofix.exe and follow the prompts.

    When it's finished it will produce a log.
    Post the entire contents of C:\ComboFix.txt into your next reply.

    Note:
    Do not mouseclick combofix's window while it's running.

    That may cause the program to freeze/hang.

    Do NOT post the ComboFix-quarantined-files.txt unless I ask.

    Re-enable your anti-virus and re-connect back to the internet and post the combofix log.



    *Note*
    In case your Antivirus or any other realtime scanner is displaying an alert after you downloaded Combofix or while you use Combofix,please disable your scanner and redownload Combofix again.
    Some scanners may see some combofix related components as suspicious and block or delete them while there's nothing wrong with them.


    ComboFix SHOULD NOT be used unless requested by a forum helper.

  6. #6
    rpmorrow is offline Valued Member
    Hi,

    I ran it, It immediately began deleting several exe files and ini files. It got to about stage 50 where it said "deleting c:/windows/system32/winsmss.exe" and it just seemed to get stuck there.

    I'd already seen it say it was deleting this file several times. I closed the program since it seemed to have crashed, opened task manager and ran explorer.exe. I then navigated to the system 32 folder and found that that file had been deleted successfully.

    I rebooted my machine and found that my problem seems to be gone!

    Unfortunately it did not create a log file that I can find. Should I run it again?

    Thanks

  7. #7
    Neal is offline Dedicated Member
    If things seem back to normal, no need to run it again. Let me know.

  8. #8
    rpmorrow is offline Valued Member
    Save 20% on AVG Internet Security 2012 Suite!
    Yes, all seems fine now, Thanks

+ Reply to Thread