Slow Internet Speed - Suspected Trojan

Discussion in 'Malware Help (A Specialist Will Reply)' started by Jazper, May 27, 2005.

  1. Jazper

    Jazper Private E-2

    I have 128/64 ADSL and have been getting speeds from 32-112 depending upon the test. The phone company sent a technician with his laptop and he is able to get a 132 speed from his machine using my modem consistently and has indicated that I may have malware causing my problem. I have two computers on LAN. When I connect either computer individually directly through modem I have same speed problem on each computer which indicates both machines have same problem. I have run/installed Spybot S&D, Ad-Aware SE, Spysubtract, Spywareblaster, Nod32, Zone Alarm Pro.

    When I run Ad-Aware, Nod 32 displayes the following warnings:
    File: C:\DOCUME~1\.....\Mein.class
    Threat: Java/Exploit.Bytverify.I trojan
    File: C:\DOCUME~1...\ProbeLoader.class
    Threat: Java/Exploit.Bytverify.I trojan
    File: C:\DOCUME~1...\Dummy.class
    Threat: Java/Exploit.Bytverify.I trojan
    File: C:\DOCUME~1...\Beyond.class
    Threat: Java/TrojanDownloader.Beyond.D trojan
    File: C:\DOCUME~1...\GetAccess.class
    Threat: Java/Exploit.Bytverify.F trojan
    File: C:\DOCUME~1...\InsecureClassLoader.class trojan
    Threat: Java/Exploit.Bytverify.F trojan
    File: C:\DOCUME~1...\Dummy.class
    Threat: JS/IEStart trojan
    File: C:\DOCUME~1...\Installer.class
    Threat: Java/OpenConnection.F trojan

    Event occured on a new file created by Ad-Aware.exe
    The file has been moved to quarantine.

    Please advise!

    Edit by chaslang: Unrequested inline log removed
     
    Last edited by a moderator: May 27, 2005
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the announcement and sticky threads. HJT logs should only be posted when requested and then they must be attachments to your message.

    Please follow the steps below:

    - Run ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.
    Also to get you started and to reduce the size of your HJT log. Do the following:




    After doing ALL of the above you still have a problem, boot into normal mode and:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  3. Jazper

    Jazper Private E-2

    chaslang, thank you for helping me.

    System Restore is disabled.

    None of these services were running, so no action taken: Network Security, Workstation Netlogon Services & Remote Procedure Call (RPC) Helper

    Hidden files are set to view

    I was able to download all the tools, install and update when directed.

    After Boot to Safe Mode

    Trend Virus Scan detected two virus and fixed.
    HTML_MHTREDIR.AP C:\RECYCLERS
    JAVA_BYTEVER.A C:\RECYCLERS

    I could not get Symantic Security Check to run. Only a blank screen would open when the scan was initated. I tried several times. Sometimes, after 5-10 min a message would be displayed saying that ZoneAlrarm had shut down my internet activity because of a security threat. This is in safe mode, and zonealarm should not be loaded. Also, after each attempt I would have to reboot because the internet would stop working.

    Ran McAfee Avert Stinger, no virus found.

    I ran all the other tools
    hsremove said it found 8 and removed.
    Spybot found a toolbar item and one other and fixed them.
    Ad-Aware and others indicated nothing found.
    CC Cleaner was run.

    Closed open programs and also ended non-essential processes.
    Ran HiJack this from root folder, attacked log.


    Hope I haven't missed anything.

    After reboot, I ran internet speed test and was able to get 101-124 speed which may be some improvement. This is the test the telephone company pulled 132 consistently on yesterday.

    In the other test I have been running, I am getting 30-80 which may be a little improvement also.
     

    Attached Files:

  4. Jazper

    Jazper Private E-2

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You should go to Add/Remove programs and uninstall WeatherBug

    Do you use Viewpoint Manager (junk from AOL)? If not, uninstall it too.

    Why are the below lines in your Trusted Zone?
    O15 - Trusted IP range: http://192.168.1.1
    O15 - Trusted IP range: 192.168.254.254

    Nothing belongs in the Trusted Zone unless absolutely necessary which is almost never the case. You can have HJT fix those lines along with the below remant of running HSremove (which you did not need to run):

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    Would not expect any of the above to be reasons for any slow downs. Other then those you are clean other that a bunch of processes that you may not need to be loading all the time.

    Did you ever wonder if NetAnts is actually slowing you down? You could try uninstalling it and then reinstalling if not difference is seen.
     
  6. Jazper

    Jazper Private E-2

    chaslang,
    Again thank you for helping me.

    I followed your suggestions for fixing and removing programs.

    I did a speed test and am still getting 80-112. I needed your help to rule out that it is not a virus causing my speed problems. It seemed odd to me that both computers on the LAN would have the same speed problems. There has been some improvement. I do not have to click my email more than once to get it now and I can watch a small video on a news site, so maybe I did get some small viri and I can live with it like it is if I have to.

    I will call the telephone technician and direct him to this thread and see what they have to say. I had told them Friday that I would do this and the technician thought this was a good step. They said they are willing to work with me to get the problem solved.

    If you would like, I could post a follow-up if I am able to get a solution. This could be useful to you for similar problems.

    Again, thanks for helping.

    Jazper
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It could be that other applications that you have installed are just impacting your overall speed. The technician who previously ran tests with his own PC does not have your software installed on his PC. For example your firewall, antivirus program, spyware blocking tools etc. You could try a temporary disable of these tools to see if you notice a speed improvement. The protection these tools provide (which is necessary) does not come without a price.

    Also note a DSL contract for 64k upstream and 128 k downstream is still pretty slow. DSL connections can (based upon how far you are from a Central Office and the quality of your telephone lines) provide higher rates but do not compete with Cable unless you get ADSL2+ . Get a cable connection if you can.
     
  8. Jazper

    Jazper Private E-2

    Today, I am able to get the proper speed. The two tests I have been running have been giving me 132/134 consistently. This is the first time this has occured since I started checking two weeks ago.

    I can not explain why I did not see these results yesterday. Perhaps there is some healing windows does on its own that occured overnight.

    I know there is some variation in the internet, but I doubt this can account for the improvement.

    I did try disabling Zonealarm and my antivirus and noted no difference.

    This is good news, and I thought you would like to know.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds