Comments are available to members only. Sign up or Log in to view these comments.
Main Topics
Browse All TopicsI have a PIII with 512Mb of RAM, running Windows XP Pro with SP2 installed. Antivirus protection is from Avast! Home Edition. Firewall is Zone Alarm (not pro) with the Internet security zone set to "High".
Spyware protection is from Spybot Search and Destroy and Spyware Baster. Trojan protection is Trojan Hunter Guard.
All the above utilities have both engines and definitions up-to-date. Most are set to update automatically where this is an option. None reported problems before or subsequent to the problem I am about to describe (including manually initiated scans with all the above utilities).
The PC connects to the Internet via a NetComm NB1300 Plus 4 modem/router, driven via Ethernet. The Ethernet board is a Realtek RTL8139/810x Family Fast Ethernet NIC. It has the latest drivers from Realtek. Realtek Diagnostics indicate that register access, eeprom access, loopback and link all pass. However, when I try to run Advanced Diagnostics in Initiator mode it responds “Responder not found” and similarly in Responder mode it responds “Initiator not found”.
LAN Connection properties have TCP/IP enabled, with IP and DNS addresses assigned automatically. Client for Microsoft Networks is enabled, but QoS Packets and File and Printer sharing are not. IEEE 802.1x authentication is enabled via “Smart Card or other Certificate”. I assume all these were set by the modem’s install program, since I did not set them myself. The LAN Address is assigned by DHCP.
This set-up worked okay for the past three months or so. Then I began to notice that the PC would slow down immediately on starting. Task Manager revealed that an instance of svchost.exe was using 90 to 100% of CPU.
Investigation with Process Explorer (www.sysinternals.com) showed that the problematic instance of svchost.exe was being used by the DNS service. If logged in as Administrator I am able to kill the process. This causes a disconnection from the net but this appears to re-establish itself and work normally. However, from time to time the problem will occur, resulting in a loss of function – usually at a crucial time. It also means that non-administrator users, who cannot kill the process, face using a slow PC which can’t go online and which eventually sounds and overheat alarm – which can’t be doing the CPU any good!
For the sake of clarity I have edited a netstats –a log and append this below. I have removed the “Foreign Address” column, which read 0.0.0.0:0 for every TCP instance and *:* for every UDP instance; and removed the “State” column which read LISTENING for every TCP instance and was blank for every UDP instance.
Proto Local Address PID
TCP 0.0.0.0:80 1736
TCP 0.0.0.0:135 796
TCP 0.0.0.0:445 4
TCP 0.0.0.0:1027 1560
TCP 0.0.0.0:2522 1560
TCP 0.0.0.0:2901 1560
TCP 0.0.0.0:8103 1560
TCP 0.0.0.0:8500 1560
TCP 0.0.0.0:19997 1540
TCP 0.0.0.0:19998 1612
TCP 0.0.0.0:50300 1700
TCP 127.0.0.1:25 2504
TCP 127.0.0.1:110 2504
TCP 127.0.0.1:143 2504
TCP 127.0.0.1:1032 2748
TCP 211.27.201.49:139 4
UDP 0.0.0.0:445 4
UDP 0.0.0.0:500 548
UDP 0.0.0.0:4500 548
UDP 127.0.0.1:123 840
UDP 127.0.0.1:1446 784
UDP 127.0.0.1:1900 972
UDP 127.0.0.1:2233 3340
UDP 211.27.201.49:68 840
UDP 211.27.201.49:123 840
UDP 211.27.201.49:137 4
UDP 211.27.201.49:138 4
UDP 211.27.201.49:1900 972
HiJack this logfile for above
--------------------------
Logfile of HijackThis v1.99.1
Scan saved at 8:35:07 PM, on 23/02/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\csrss.
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\ALWILS~1\Avast
C:\WINDOWS\system32\RUNDLL
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
C:\WINDOWS\system32\ctfmon
G:\Program Files\Tweak-XP Pro\AdBlocker.exe
G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\WINDOWS\system32\rundll
C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
C:\Program Files\Alwil Software\Avast4\ashServ.ex
G:\CFusionMX\runtime\bin\j
G:\CFusionMX\db\slserver52
G:\CFusionMX\runtime\bin\j
G:\CFusionMX\db\slserver52
G:\CFusionMX\db\slserver52
C:\WINDOWS\system32\nvsvc3
C:\WINDOWS\System32\oodag.
C:\WINDOWS\System32\svchos
C:\WINDOWS\SYSTEM\svchost.
C:\WINDOWS\System32\wdfmgr
C:\WINDOWS\system32\ZoneLa
C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
C:\Program Files\Alwil Software\Avast4\ashWebSv.e
C:\WINDOWS\System32\alg.ex
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\wuaucl
G:\Program Files\Adobe\Acrobat 6.0\Acrobat\Acrobat.exe
G:\Program Files\HiJack This\HijackThis.exe
R0 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
R1 - HKCU\Software\Microsoft\Wi
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCh
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTr
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.ex
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 4.2\THGuard.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [BlockAds] "G:\Program Files\Tweak-XP Pro\AdBlocker.exe"
O4 - HKCU\..\Run: [SpybotSD TeaTimer] G:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Ad
O4 - Global Startup: Microsoft Office.lnk = G:\Program Files\Microsoft Office\Office10\OSA.EXE
O6 - HKCU\Software\Policies\Mic
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Download using Download &Express - file://C:\Program Files\Download Express\Add_Url.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://G:\PROGRA~1\MICROS~1
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: DigiChat Applet - http://albany.digi-net.com
O16 - DPF: {2B323CD9-50E3-11D3-9466-0
O16 - DPF: {2FC9A21E-2069-4E47-8235-3
O16 - DPF: {4C39376E-FA9D-4349-BACC-D
O16 - DPF: {5D9E4B6D-CD17-4D85-99D4-6
O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-0
O16 - DPF: {8E0D4DE5-3180-4024-A327-4
O16 - DPF: {9B03C5F1-F5AB-47EE-937D-A
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.e
O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.ex
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.e
O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.e
O23 - Service: ColdFusion MX Application Server - Macromedia Inc. - G:\CFusionMX\runtime\bin\j
O23 - Service: ColdFusion MX ODBC Agent - Unknown owner - G:\CFusionMX\db\slserver52
O23 - Service: ColdFusion MX ODBC Server - Unknown owner - G:\CFusionMX\db\slserver52
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc3
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\System32\oodag.
O23 - Service: MS Software Generic Host Process for Win32 Services (svchost) - Unknown owner - C:\WINDOWS\SYSTEM\svchost.
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs LLC - C:\WINDOWS\system32\ZoneLa
That's it. If there's any other information you require, ask and I'll do my best to find it.
Thanks for helping!
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Business Accounts
Answer for Membership
by: FalconHawkPosted on 2005-02-25 at 04:28:16ID: 13402187
Comments are available to members only. Sign up or Log in to view these comments.