Computing.Net > Forums > Security and Virus > Download rate coming from nowhere

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Download rate coming from nowhere

Reply to Message Icon

Name: Mycorrhiz
Date: January 18, 2009 at 07:04:14 Pacific
OS: Windows Vista
CPU/Ram: E8500/4GB DDR2
Product: Asus mainboard / P5Q
Subcategory: General
Comment:

I am suffering from a vey weird problem.

My download rate is displayed as 300-600kb/s although I am downloading nothing.
It is contant and restarting, cutting the cable or anything doesn't help

I also let AVG as well as Bitdefender Online run over my whole system without any result.

Does anyone have any clue what this could be?

Here is a list of running processes:

bbildname PID Sitzungsname Sitz.-Nr. Speichernutzung
========================= ======== ================ =========== ===============
System Idle Process 0 Services 0 24 K
System 4 Services 0 15.304 K
smss.exe 416 Services 0 668 K
csrss.exe 516 Services 0 5.024 K
csrss.exe 568 Console 1 10.992 K
wininit.exe 576 Services 0 3.852 K
winlogon.exe 636 Console 1 5.600 K
services.exe 712 Services 0 6.500 K
lsass.exe 724 Services 0 8.828 K
lsm.exe 732 Services 0 4.080 K
svchost.exe 888 Services 0 6.368 K
nvvsvc.exe 936 Services 0 3.276 K
svchost.exe 964 Services 0 6.604 K
svchost.exe 996 Services 0 30.972 K
svchost.exe 1092 Services 0 12.080 K
svchost.exe 1124 Services 0 98.460 K
svchost.exe 1144 Services 0 61.292 K
audiodg.exe 1228 Services 0 17.160 K
SLsvc.exe 1264 Services 0 9.544 K
svchost.exe 1296 Services 0 11.712 K
svchost.exe 1444 Services 0 20.736 K
rundll32.exe 1620 Console 1 6.880 K
spoolsv.exe 1668 Services 0 8.704 K
svchost.exe 1692 Services 0 13.884 K
taskeng.exe 2008 Console 1 12.696 K
dwm.exe 192 Console 1 124.564 K
explorer.exe 360 Console 1 104.144 K
taskeng.exe 680 Services 0 5.480 K
MSASCui.exe 1996 Console 1 12.460 K
rundll32.exe 692 Console 1 5.144 K
avgwdsvc.exe 1984 Services 0 2.716 K
VolPanlu.exe 1420 Console 1 10.968 K
svchost.exe 1504 Services 0 3.472 K
XBoxStat.exe 2984 Console 1 6.228 K
avgrsx.exe 3120 Services 0 72.700 K
itype.exe 3292 Console 1 1.932 K
PnkBstrA.exe 3360 Services 0 3.584 K
PnkBstrB.exe 3452 Services 0 3.880 K
svchost.exe 3464 Services 0 4.932 K
SetClockService.exe 3480 Services 0 11.624 K
CTHELPER.EXE 3552 Console 1 5.872 K
CTXFIHLP.EXE 3580 Console 1 7.252 K
MagicPvt.exe 3604 Console 1 7.472 K
svchost.exe 3620 Services 0 6.976 K
svchost.exe 3652 Services 0 2.028 K
SearchIndexer.exe 3680 Services 0 18.916 K
WUDFHost.exe 3772 Services 0 5.844 K
UnlockerAssistant.exe 3796 Console 1 3.364 K
razerhid.exe 3860 Console 1 5.296 K
sidebar.exe 3872 Console 1 31.640 K
CTSched.exe 3888 Console 1 2.596 K
msnmsgr.exe 3920 Console 1 73.900 K
resizer.exe 3932 Console 1 5.660 K
ehtray.exe 3940 Console 1 3.080 K
avgemc.exe 3956 Services 0 1.620 K
ehmsas.exe 4084 Console 1 4.052 K
dpupdchk.exe 2236 Console 1 3.644 K
razerofa.exe 2272 Console 1 3.108 K
ehsched.exe 2516 Services 0 4.504 K
CTXFISPI.EXE 1340 Console 1 7.988 K
razertra.exe 3052 Console 1 6.064 K
ehrecvr.exe 1312 Services 0 23.104 K
sidebar.exe 2856 Console 1 50.048 K
WmiPrvSE.exe 3156 Services 0 11.328 K
wlcomm.exe 3644 Console 1 25.200 K
conime.exe 5216 Console 1 68 K
conime.exe 5504 Console 1 3.856 K
razercfg.exe 4664 Console 1 17.088 K
notepad.exe 5032 Console 1 9.448 K
opera.exe 4128 Console 1 178.164 K
taskmgr.exe 1824 Console 1 13.952 K
ehrec.exe 5196 Services 0 43.708 K
ehshell.exe 4760 Console 1 133.200 K
TrustedInstaller.exe 3588 Services 0 8.596 K
cmd.exe 5736 Console 1 2.216 K
taskeng.exe 4184 Services 0 3.984 K
tasklist.exe 2088 Console 1 4.728 K



Sponsored Link
Ads by Google

Response Number 1
Name: guapo
Date: January 18, 2009 at 07:56:14 Pacific
Reply:

That's a list of services. Run Hijack This to get all the running processes.


0

Response Number 2
Name: Mycorrhiz
Date: January 19, 2009 at 01:00:06 Pacific
Reply:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:55:05, on 19.01.2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Microsoft IntelliType Pro\itype.exe
C:\Windows\System32\CTHELPER.exe
C:\Windows\System32\CTXFIHLP.exe
C:\Program Files\MagicRotation\MagicPvt.exe
C:\Program Files\Unlocker\UnlockerAssistant.exe
C:\Program Files\Razer\Lachesis\razerhid.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Creative\Shared Files\CTSched.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Microsoft IntelliType Pro\dpupdchk.exe
C:\Program Files\reSizer\resizer.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Razer\Lachesis\OSD.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\SYSTEM32\CTXFISPI.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Windows\System32\mobsync.exe
C:\Program Files\Razer\Lachesis\razertra.exe
C:\Program Files\Razer\Lachesis\razerofa.exe
C:\Windows\ehome\ehshell.exe
C:\Program Files\Opera\opera.exe
C:\Windows\system32\conime.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?Lin...
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?Lin...
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: PDF-XChange Viewer IE-Plugin - {C5D07EB6-BBCE-4DAE-ACBB-D13A8D28CB1F} - C:\Program Files\Tracker Software\PDF-XChange Viewer\pdf-viewer\PDFXCviewIEPlugin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.exe C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [VolPanel] "C:\Program Files\Creative\Sound Blaster X-Fi\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"
O4 - HKLM\..\Run: [CTHelper] CTHELPER.exe
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.exe
O4 - HKLM\..\Run: [MagicRotation] C:\Program Files\MagicRotation\MagicPvt.exe
O4 - HKLM\..\Run: [UnlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"
O4 - HKLM\..\Run: [Lachesis] C:\Program Files\Razer\Lachesis\razerhid.exe
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [CreativeTaskScheduler] "C:\Program Files\Creative\Shared Files\CTSched.exe" /logon
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [resizer] C:\Program Files\reSizer\resizer.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe
O13 - Gopher Prefix:
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/res...
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/g...
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8e mc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exe
O23 - Service: Set Clock Service 2.0 (SetClockService) - Aqua Computer - C:\Program Files\Aqua Computer\aquasuite\SetClockService.exe
O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe

--
End of file - 6844 bytes

There is no program there that I see to be there although it shouldn't.

Another weird thing is that after hours of contant downloading the problem suddenly stopped yesterday and hasn't reoccured.

If you can find anything suspicious, please let me know anyhow.

Thank You!


0

Response Number 3
Name: guapo
Date: January 19, 2009 at 07:00:35 Pacific
Reply:

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

That's the only thing I see that doesn't belong but I see what is supposedly the uninstall file for Bit Defender.

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

Are you running Bit Defender? If not uninstall it.


0

Response Number 4
Name: guapo
Date: January 19, 2009 at 07:16:46 Pacific
Reply:

O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)

That's the only thing I see that doesn't belong but I see what is supposedly the uninstall file for Bit Defender.

O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\Windows\bdoscandel.exe

Are you running Bit Defender? If not uninstall it.


0

Response Number 5
Name: Mycorrhiz
Date: January 19, 2009 at 07:28:13 Pacific
Reply:

those processes are now gone anyway.

The problem has also not reocurred... Still very strange!

Thank for the help!


0

Related Posts

See More



Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: Download rate coming from nowhere

PopUps from nowhere www.computing.net/answers/security/popups-from-nowhere/15394.html

Where are viruses coming from? www.computing.net/answers/security/where-are-viruses-coming-from/2888.html

where this worm come from? www.computing.net/answers/security/where-this-worm-come-from/5777.html