Page 1 of 3 123 LastLast
Results 1 to 10 of 22

Thread: Snail Alert!

  1. #1
    Senior Member
    Join Date
    Dec 2004
    Posts
    3,171

    Snail Alert!

    Finally! Been here three times...been having a few problems lately...pages taking an extremely long time to load...or not completely loading at all...errors on firefox...no data errors...page errors...

    AVG reports nothing
    AdWareSE reports nothing
    Disk Defrag does not need defragging
    Disk clean-up...tried twice...either it was taking a very long time to work ( I didn't have the patience to wait )...or it wasn't scanning at all ( it said it was scanning but that little brush was not sweeping )
    just cleared my browswer cache and history yesterday
    ran hijackthis and nothing unusual...

    C:\WINNT\System32\smss.exe Safe.
    Safe. running process. (smss.exe)
    Systemprozess - Anwendung, die benutzt wird um Sitzungen zu starten, verwalten und löschen.
    C:\WINNT\system32\winlogon.exe Safe.
    Safe. running process. (winlogon.exe)
    Systemprozess - Windows Login Routine
    C:\WINNT\system32\services.exe Safe.
    Safe. running process. (services.exe)
    Systemprozess - Verwaltet die Systemdienste.
    C:\WINNT\system32\lsass.exe Safe.
    Safe. running process. (lsass.exe)
    Systemprozess
    C:\WINNT\system32\svchost.exe Safe.
    Safe. running process. (svchost.exe)
    Systemprozess - Allgemeiner Hostprozessname für Dienste.
    C:\WINNT\system32\LEXBCES.EXE Safe.
    Safe. running process. (LEXBCES.EXE)
    Lexmark LexBce Service
    C:\WINNT\system32\LEXPPS.EXE Safe.
    Safe. running process. (LEXPPS.EXE)

    C:\WINNT\system32\spoolsv.exe Safe.
    Safe. running process. (spoolsv.exe)
    Systemprozess
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe AV-Scanner
    Safe. running process. (avgamsvr.exe)
    Antivirensoftware
    Possibly nasty! According to our database this process runs normally in c:\program files\grisoft\avg free! Check if you know this process and arrange a viruscheck where required.
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe AV-Scanner
    Safe. running process. (avgupsvc.exe)
    Antivirensoftware
    Possibly nasty! According to our database this process runs normally in c:\progra~1\grisoft\avgfre~1! Check if you know this process and arrange a viruscheck where required.
    C:\WINNT\system32\svchost.exe Safe.
    Safe. running process. (svchost.exe)
    Systemprozess - Allgemeiner Hostprozessname für Dienste.
    C:\WINNT\system32\MSTask.exe Safe.
    Safe. running process. (MSTask.exe)
    Gehört zu den Windows Powertoys von MS.
    C:\WINNT\system32\stisvc.exe Safe.
    Safe. running process. (stisvc.exe)

    C:\WINNT\system32\ZoneLabs\vsmon.exe Firewall
    Safe. running process. (vsmon.exe)
    ZoneAlarm Firewall
    C:\WINNT\Explorer.EXE Safe.
    Safe. running process. (Explorer.EXE)
    Systemprozess für Desktop und Taskleiste.
    C:\WINNT\System32\WBEM\WinMgmt.exe Safe.
    Safe. running process. (WinMgmt.exe)

    C:\WINNT\system32\svchost.exe Safe.
    Safe. running process. (svchost.exe)
    Systemprozess - Allgemeiner Hostprozessname für Dienste.
    C:\Program Files\Common Files\Real\Update_OB\realsched.exe Safe.
    Safe. running process. (realsched.exe)

    C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe Safe.
    Safe. running process. (lxbkbmgr.exe)

    C:\WINNT\essspk.exe Unknown
    Unknown running process. (essspk.exe)
    ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets This is a unknown process.
    C:\Program Files\QuickTime\qttask.exe Safe.
    Safe. running process. (qttask.exe)
    Part of QuickTime
    C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe AV-Scanner
    Safe. running process. (avgcc.exe)
    Antivirensoftware
    Possibly nasty! According to our database this process runs normally in c:\program files\grisoft\avg free! Check if you know this process and arrange a viruscheck where required.
    C:\Program Files\Lexmark X1100 Series\lxbkbmon.exe Safe.
    Safe. running process. (lxbkbmon.exe)

    C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe AV-Scanner
    Safe. running process. (avgemc.exe)
    Antivirensoftware
    Possibly nasty! According to our database this process runs normally in c:\program files\grisoft\avg free! Check if you know this process and arrange a viruscheck where required.
    C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe Safe.
    Safe. running process. (jusched.exe)
    Java Runtime
    C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe Safe.
    Safe. running process. (zlclient.exe)
    Zone Alarm
    C:\WINNT\system32\svchost.exe Safe.
    Safe. running process. (svchost.exe)
    Systemprozess - Allgemeiner Hostprozessname für Dienste.
    C:\WINNT\system32\wuauclt.exe Safe.
    Safe. running process. (wuauclt.exe)
    Windows Update AutoUpdate Client
    C:\WINNT\system32\cleanmgr.exe Safe.
    Safe. running process. (cleanmgr.exe)
    Windows Cleanmanager
    C:\WINNT\system32\cleanmgr.exe Safe.
    Safe. running process. (cleanmgr.exe)
    Windows Cleanmanager
    D:\WinZip\WINZIP32.EXE Safe.
    Safe. running process. (WINZIP32.EXE)

    Possibly nasty! According to our database this process runs normally in c:\programme\winzip\! Check if you know this process and arrange a viruscheck where required.
    C:\unzipped\hijackthis\HijackThis.exe Safe.
    Safe. running process. (HijackThis.exe)
    Tool, mit dem sie dieses Logfile erzeugt haben. Remember that Hijackthis must be run in an own folder. Only if Hijackthis run in an own folder it will create backups!
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx Safe.
    Safe. Entries found in this registry zone are potentially nasty. This application ([06849E9F-C8D7-4D59-B87D-784B7D6BE0B3] - Result: 06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) has been checked. Hit rate: 99 %
    O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll Safe.
    Safe. Entries found in this registry zone are potentially nasty. This application ([AA58ED58-01DD-4d91-8333-CF10577473F7] - Result: AA58ED58-01DD-4d91-8333-CF10577473F7) has been checked. Hit rate: 99 %
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx Safe.
    Safe. Entries found in this registry zone are potentially nasty. This application ([8E718888-423F-11D2-876E-00A0C9082467] - Result: 8E718888-423F-11D2-876E-00A0C9082467) has been checked. If the name is made up of random letters, found in the folder 'Application Data' and the kind is 'Unknown' , it should be fixed. Hit rate: 99 %
    O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll Safe.
    Safe. Entries found in this registry zone are potentially nasty. This application ([2318C2B1-4965-11d4-9B18-009027A5CD4F] - Result: 2318C2B1-4965-11D4-9B18-009027A5CD4F) has been checked. If the name is made up of random letters, found in the folder 'Application Data' and the kind is 'Unknown' , it should be fixed. Hit rate: 96 %
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon Safe.
    Safe. Find more information about its use here
    Hit rate: 99 % (result) Not dangerous, but unnecessary.
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot Safe.
    Safe. Part of RealPlayer
    Hit rate: 99 % (result)
    O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\system32\\NeroCheck.exe Safe.
    Safe. Associated with "Nero Burning Rom" CD writing software. Checks for driver issues
    Hit rate: 91 % (result)
    O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Program Files\Lexmark X1100 Series\lxbkbmgr.exe" Safe.
    Safe. Lexmark X1100 Series
    Hit rate: 99 % (result)
    O4 - HKLM\..\Run: [EssSpkPhone] essspk.exe Safe.
    Safe. ESS Technologies Call waiting, which gets installed by the drivers for V92 modems based on ESS Technologies chipsets
    Hit rate: 99 % (result)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime Safe.
    Safe. QuickTime
    Hit rate: 99 % (result) Not dangerous, but unnecessary.
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP Safe.
    Safe. AVG Anti-Virus 7.0 Control Center. Allows you to manage and control all AVG Anti-Virus components, settings and updates
    Hit rate: 71 % (result)
    O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe Safe.
    Safe. AVG Anti-Virus 7.0 Email Cleaner. Scans incoming and outgoing email for viruses
    Hit rate: 69 % (result)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe Safe.
    Safe. Java von Sun
    Hit rate: 99 % (result)
    O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" Safe.
    Safe. Firewall program from Zonelabs. Pro version inlcudes other online security options
    Hit rate: 85 % (result)
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE Safe.
    Safe.
    Hit rate: 93 % (result)
    O4 - Global Startup: WinZip Quick Pick.lnk = D:\WinZip\WZQKPICK.EXE Safe.
    Safe. Added with WinZip version 8.1. "The new WinZip Quick Pick taskbar tray icon gives you instant access to WinZip and your Zip files. Just left click the icon to open WinZip, or right click it to instantly reopen recently used Zip files, access your Favorite Zip Folders, open WinZip Help, or start WinZip itself.". You can right-click and close it - choosing to not re-load it at start-up
    Hit rate: 93 % (result) Not dangerous, but unnecessary.
    O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html Safe.
    Safe. The entry &Google Search has been identified as safe. If the entry '&Google Search ' is not needed anymore, it should be fixed.
    O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html Safe.
    Safe. The entry Backward Links has been identified as safe. If the entry 'Backward Links ' is not needed anymore, it should be fixed.
    O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html Safe.
    Safe. The entry Cached Snapshot of Page has been identified as safe. If the entry 'Cached Snapshot of Page ' is not needed anymore, it should be fixed.
    O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html Safe.
    Safe. The entry Similar Pages has been identified as safe. If the entry 'Similar Pages ' is not needed anymore, it should be fixed.
    O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html Safe.
    Safe. The entry Translate into English has been identified as safe. If the entry 'Translate into English ' is not needed anymore, it should be fixed.
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll Safe.
    Safe. The entry has been identified as safe. If the entry '' is not needed anymore, it should be fixed.
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_06\bin\npjpi142_06.dll Safe.
    Safe. The entry Sun Java Console has been identified as safe. If the entry 'Sun Java Console ' is not needed anymore, it should be fixed.
    O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll Safe.
    Safe. Most of the entries present in this registry area are safe. Only OnFlow adds an unwanted plugins can be found here. OnFlow-Plugins have the following extension *.ofb.
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/24080c34...p/RdxIE601.cab Safe.
    Safe. This entry has been identified as safe.
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe AV-Scanner
    Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it. This service (avgamsvr.exe) was identified as a good one.
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe AV-Scanner
    Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it. This service (avgupsvc.exe) was identified as a good one.
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe Safe.
    Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it. This service (dmadmin.exe) was identified as a good one.
    O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINNT\system32\LEXBCES.EXE Safe.
    Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it. This service (LEXBCES.EXE) was identified as a good one.
    O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINNT\system32\ZoneLabs\vsmon.exe Firewall
    Safe. These entries shows all services which are not from Microsoft. Often malware is starting as a systemservice and it's not easy to detect it. This service (vsmon.exe) was identified as a good one.

    Any suggestions why my normal snail seems to be facing gail force winds?

    For those who don't know...

    Windows 2000 Pro
    80GB with 93% free space
    384MB Ram with 170MB free at last look
    service pack 4

    Thanks,


    Eg

  2. #2
    Senior Member
    Join Date
    Jul 2004
    Posts
    469
    Run a memory checker on the system. Sounds hardware related to me.

  3. #3
    Senior Member
    Join Date
    Dec 2004
    Posts
    3,171
    Could these problems be stemming from my ISP ?

    About a week ago their phone line was down and I couldn't even get on the net...everytime I would try I would get the phone message " this line is not in service " they said they fixed the problem and the line was back up in an hour.

    P.S. Does my log look OK ?

    Thanks,

    Eg

  4. #4
    ********** |ceWriterguy
    Join Date
    Aug 2004
    Posts
    1,608
    Ok, first check the obvious -
    Clear browser cache, clean out the cookies, clear history, defrag, try again.

    If this isn't successful, since you've let us know you're on dialup, try rebuilding your dialup adaptor/disabling re-enabling tcp/ip. Sometimes it needs a swift kick to get it up and running right again. If you're using one of the 'big' isp's that has their own software (aohell, earthlink, etc) just delete the adaptor entirely but have your cd on hand when you restart it - the software will rebuild the adaptor for you.

    If this isn't successful, it could be a browser issue (any changes to your browser lately?) or a hardware issue like Zenger suggested - hardware is the last check in the chain on this, but if you get that far, check memory, check video drivers then video card. Good luck!

    [edit]oh, from what I read your log looks fine. I still hate that bloody Google toolbar though...

    Here's the other thing to suspect:
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -

    Again, I'm suspicious of all toolbars and bho's not pertaining to software I've directly installed. If that toolbar is something you want, you're clean.
    [/edit]

    [moredit] I saw where you were having probs with disk cleanup - this is usually indicative of a lot of stuff to be cleaned or a problem with that software. Try cleaning your cache manually through firefox>tools>options, and your cookies manually (search: cookie), and try it again. There might be more to this than just slow browsing.[/moredit]
    Even a broken watch is correct twice a day.

    Which coder said that nobody could outcode Microsoft in their own OS? Write a bit and make a fortune!

  5. #5
    Senior Member
    Join Date
    Jul 2004
    Posts
    469
    Yeah, log looks good. I took a second look through your stuff. Are you saying you're only have problem web browsing? I took it initially that your machine was running slow. If its just web browsing I would say an ISP problem is a high possiblity.

  6. #6
    They call me the Hunted foxyloxley's Avatar
    Join Date
    Nov 2003
    Location
    3rd Rock from Sun
    Posts
    2,534
    How is the RAM configured ?
    256 + 128 ??

    If so, remove ONE stick, and try to boot.
    Then replace stick, and remove OTHER one.

    Boot and see if there is any NOTICABLE differences ........

    Speed of OS load
    response time for Apps to load

    Now re-instate ALL RAM, check its in properly.
    boot and check as above.

    Possibly RAM is failing / unseated

    HDD's also fail, although you would expect some other indictions [noisy whine etc]

    [edit]
    was here as it first appeared ................... post #6 !!!!
    My typing, and my diagnostic skill by the look of the thread are, up to their usual standard ..................
    so now I'm in my SIXTIES FFS
    WTAF, how did that happen, so no more alterations to the sig, it will remain as is now

    Beware of Geeks bearing GIF's
    come and waste the day :P at The Taz Zone

  7. #7
    Senior Member Spyrus's Avatar
    Join Date
    Oct 2002
    Posts
    741
    Who is your ISP? I have comcast and I know that they have been having a LOT of dns problems as of late. I had to use an alternate public DNS server so that i could get pages to resolve for me. May be your problem. Try adding a new DNS server other than the one your ISP is using.

    Cheers
    Duct tape.....A whole lot of Duct Tape
    Spyware/Adaware problem click
    here

  8. #8
    Senior Member kr5kernel's Avatar
    Join Date
    Mar 2004
    Posts
    347
    Amen to that! Comcast DNS blows hard, see if you can still get to webpages by putting in there ip addresses.

    Could very well be a memory issue as was stated above.
    kr5kernel
    (kr5kernel at hotmail dot com)
    Linux: Making Penguins Cool Since 1994.

  9. #9
    Senior Member
    Join Date
    Dec 2004
    Posts
    3,171
    I'll try to do half now and half later ( in ten minutes I have to pick up one of my daughters from school )...

    Hi l3lacklce,

    Already cleared cache.

    Not AOL or other major ISP...on Primus...and no CD...connected via phone through a walk-through with their techs.

    No recent changes to browser. Did however recently download three Windows 2000 updates from the Update Ctr.

    According to System Specs there are no conflicts with drivers, video, or memory...and says system healthy.

    Toolbar? I use firefox...I do have a google toolbar on IE but I never use it except for update.

    Hi zENGER,

    You know...machines been slow off-line too but maybe it just seems that way because I'm more aware of the slowness now with this...I'll check.

    Hi foxyloxley,

    Yes 256+128!

    I never have opened the box and done anything to it...I've always paid a professional to do that...too worried I'd muck it up! But if necessary I will.

    Hi Spyrus,

    Primus...how do you add a new DNS server?

    Thanks everybody!!!

    Eg

  10. #10
    Senior Member
    Join Date
    Dec 2004
    Posts
    3,171
    Hi Everybody,

    Here's the memory specs...

    System Information report written at: 04/14/2005 04:05:05 PM
    [Memory]

    Range Device Status
    0xA0000-0xBFFFF PCI bus OK
    0xA0000-0xBFFFF PCI standard PCI-to-PCI bridge OK
    0xA0000-0xBFFFF SiS 530/620 OK
    0xC8000-0xDFFFF PCI bus OK
    0x17800000-0xFFDFFFFF PCI bus OK
    0x81300000-0x81300FFF SiS 7001 PCI to USB Open Host Controller OK
    0x80500000-0x805FFFFF PCI standard PCI-to-PCI bridge OK
    0x80500000-0x805FFFFF SiS 530/620 OK
    0x80600000-0x810FFFFF PCI standard PCI-to-PCI bridge OK
    0x80800000-0x80FFFFFF SiS 530/620 OK
    0x80100000-0x801000FF AcerLAN ALN-325 10/100 Base-PX Fast Ethernet Adapter OK
    0x0000-0x9FFFF Motherboard resources OK
    0xE0000-0xFFFFF Motherboard resources OK
    0xFFFE0000-0xFFFFFFFF Motherboard resources OK
    0x100000-0xFFFFFF Motherboard resources OK
    0x1000000-0x177FFFFF Motherboard resources OK

    Does this help?

    Eg

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •