Cyber Tech Help Support Forums

Cyber Tech Help Support Forums (https://www.cybertechhelp.com/index.php)
-   Internet / Browsers (https://www.cybertechhelp.com/forumdisplay.php?f=19)
-   -   Please HELP! IE extremely slow (https://www.cybertechhelp.com/showthread.php?t=25894)

K McK November 27th, 2003 07:28 AM

Please HELP! IE extremely slow
 
I posted on another site, got a few of suggestions, all but one of which I've already tried, which is Hijack This--and I will try that when I get back to school after the holidays. So, this is the problem: The browser was fine when school was out in May, but since school has started this year, it has been unbearably slow!! taking approx 10 sec. on each page. We have a T1 connection, Novell network; my OS is Windows 98. I also have a peer to peer network in my room with 3 other computers sharing my printer and one software application. The other computers are browsing fine. There have been no changes that I am aware of. What I have tried: clear cache, empty temp browser files and offline content, scandisk, defrag, memory check, hard drive space check, disk cleanup, browser update, windows update, Spybot scan, and I think that's about it. I also thought today to try my internet cable on a different pc, so I'll try that as well when I get back to school next week. Any other suggestions are welcome!!!

Steven.Bentley November 27th, 2003 08:21 AM

Hi K McK

you say you're on a LAN, have you checked the other machines with spybot etc? If you're all sharing the same connection it could be one of those that has something nasty which is hogging all the bandwidth

K McK November 27th, 2003 08:41 AM

Thanks, I have not checked, but...
 
We are also on a server/client domain. We each have our own internet connection cable. In that case, even though there is also a peer to peer in the classroom, one of the other pc's couldn't hog the bandwidth, could it? All three of the other pc's are having no browser problems. I will use spybot and/or other software if I need to on the other computers just to make sure if necessary. I will be sure to post results next week, whether successful or not.

K McK December 3rd, 2003 01:14 AM

HiJackThis log file
 
Quote:

Originally Posted by K McK
We are also on a server/client domain. We each have our own internet connection cable. In that case, even though there is also a peer to peer in the classroom, one of the other pc's couldn't hog the bandwidth, could it? All three of the other pc's are having no browser problems. I will use spybot and/or other software if I need to on the other computers just to make sure if necessary. I will be sure to post results next week, whether successful or not.

Here is the HijackThis log file:

Logfile of HijackThis v1.97.5
Scan saved at 4:01:24 PM, on 12/02/03
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\NOVELL\CLIENT32\NWPOPUP.EXE
C:\WINDOWS\SYSTEM\DRMON\SMARTAGT\SMARTAGT.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\LLASS.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\ATITASK.EXE
C:\WINDOWS\SYSTEM\ATICWD32.EXE
C:\PROGRAM FILES\CHEYENNE\ANTIVIRUS\ISRV95.EXE
C:\PROGRAM FILES\CHEYENNE\ANTIVIRUS\REALMON.EXE
C:\PROGRAM FILES\CHEYENNE\ANTIVIRUS\GETBBS95.EXE
C:\WINDOWS\SYSTEM\XSTOP95.EXE
C:\WINDOWS\SYSTEM\DPMW32.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\HPZTSB07.EXE
C:\ATI\ATIDESK\ATISCHED.EXE
C:\PROGRAM FILES\TEXTBRIDGE CLASSIC\BIN\TBMENU.EXE
C:\WINDOWS\OPTIONS\CABS\PWS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.searchalot.com
O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [Atikey] Atitask.exe
O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
O4 - HKLM\..\Run: [COMSMDEXE] comsmd.exe -off
O4 - HKLM\..\Run: [Cheyenne Scanning Service] C:\Program
Files\Cheyenne\AntiVirus\isrv95.exe
O4 - HKLM\..\Run: [Cheyenne Realtime Monitor] C:\Program
Files\Cheyenne\AntiVirus\realmon.exe
O4 - HKLM\..\Run: [Cheyenne AutoDownload] C:\Program
Files\Cheyenne\AntiVirus\getbbs95.exe
O4 - HKLM\..\Run: [XStop95] C:\WINDOWS\SYSTEM\XStop95.exe 0
O4 - HKLM\..\Run: [NDPS] c:\windows\SYSTEM\dpmw32.exe
O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\SYSTEM\hpztsb07.exe
O4 - HKLM\..\Run: [lar] C:\WINDOWS\LLASS.EXE
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe
powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [dRMON SmartAgent]
drmon\SmartAgt\SmartAgt.exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [lar] C:\WINDOWS\LLASS.EXE
O4 - Startup: ATI Scheduler.lnk = C:\ati\atidesk\atisched.exe
O4 - Startup: Microsoft Find Fast.lnk = C:\Program Files\Microsoft
Office\Office\FINDFAST.EXE
O4 - Startup: TextBridge Instant Access OCR.lnk = C:\Program
Files\TextBridge Classic\Bin\TBMenu.exe
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Search the Internet (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O14 - IERESET.INF: START_PAGE_URL=
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
(Shockwave Flash Object) -
http://download.macromedia.com/pub/s...s/flash/swflas
h.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update
Class) -
http://v4.windowsupdate.microsoft.co...i/iuctl.CAB?37
935.3827777778
O16 - DPF: {EB387D2F-E27B-4D36-979E-847D1036C65D}
(QDiagHUpdateObj Class) -
http://h30043.www3.hp.com/hpdj/en/check/qdiagh.cab?312

Steven.Bentley December 3rd, 2003 09:00 PM

Looks like you have the Troj/Inor-A trojan

Fix the following entries in HijackThis, making sure that Internet Explorer is closed, then reboot and save and new log and post that to this thread.

C:\WINDOWS\LLASS.EXE
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
http://www.searchalot.com
O4 - HKLM\..\Run: [lar] C:\WINDOWS\LLASS.EXE


Also follow the instructions in the sophos.com page linked above about the trojan - there are a couple of registry entries that you may need to remove manually to completely rid yourself of this trojan, but do heed the warnings about backing up the registry.


All times are GMT +1. The time now is 09:45 AM.

Copyright © Cyber Tech Help. All rights reserved. All other trademarks are the property of their respective owners.