Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
access acer asus batch bios bsod crash desktop driver drivers error ethernet excel freeze gaming gpu hard drive hardware hdmi internet laptop malware memory modem monitor motherboard netgear network printer problem ram registry router slow software sound trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
MSN Video Call = 99% Cpu Usage (In Progress)

Reply  
Thread Tools
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 01:35 AM #1
MSN Video Call = 99% Cpu Usage
Hi, I've been having a problem lately with Window's Live Messenger. I say lately because I recently visited a relative for a couple weeks, and prior to that, I didn't have the problem.

The issue is: After a few minutes of using "Video Call" in messenger, which is essentially just webcam w/ sound, msnmsgr.exe's process shoots to 99% cpu usage, totally locking up my computer.

This behavior is also emulated in a game I play. (which, similarly, didn't occur prior to my visit). It's also worth noting that the cpu usage does NOT go up in the game, untill I actually connect with other players, not even if left on for hours.

I've been trying desperately to fix it for about a week now.. It's a very important matter to me and I have absolutely no idea what to try next short of a full reformat..

I Run Windows XP, 756 RAM, 2.5 Single-Core Processor, and a x700 Pro ATI Video Card. It's a Dimension 8200.

I have updated the drivers on the Video card and the NIC, and the tried rolling them back to previous versions, with no change. I've system restored to prehistoric dates, with no luck there as well.

Please, someone help me.. I'm in a long distance relationship, and any strain on our ability to communicate is a strain directly on the relationship.

My HJT log:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:40:23 PM, on 11/15/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\FREEDO~1\fdm.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://global.netmarble.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files\AIM Toolbar\aimtb.dll
O1 - Hosts: 66.98.148.65 auto.search.msn.es
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files\Microsoft\Search Enhancement Pack\Search Helper\SearchHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~4\Office12\GRA8E1~1.DLL
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: FDMIECookiesBHO Class - {CC59E0F9-7E43-44FA-9FAA-8377850BF205} - C:\Program Files\Free Download Manager\iefdm2.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: DAEMON Tools Toolbar - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files\DAEMON Tools Toolbar\DTToolbar.dll
O3 - Toolbar: (no name) - {35065594-9169-4A34-B167-FC4865038E53} - (no file)
O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files\Windows Live\Toolbar\wltcore.dll
O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background
O8 - Extra context menu item: &AIM Toolbar Search - C:\Documents and Settings\All Users.WINDOWS\Application Data\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O8 - Extra context menu item: Download all with Free Download Manager - file://C:\Program Files\Free Download Manager\dlall.htm
O8 - Extra context menu item: Download selected with Free Download Manager - file://C:\Program Files\Free Download Manager\dlselected.htm
O8 - Extra context menu item: Download video with Free Download Manager - file://C:\Program Files\Free Download Manager\dlfvideo.htm
O8 - Extra context menu item: Download with Free Download Manager - file://C:\Program Files\Free Download Manager\dllink.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O15 - Trusted Zone: http://global.netmarble.com
O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolb...lerControl.cab
O16 - DPF: {10365E63-8510-444A-87F9-AECEE4B50A8A} (GlbNetmarbleGameStarter Class) - http://nmweb.cdn.global.netmarble.co...bNMStarter.cab
O16 - DPF: {5C1B293E-DA77-4AFF-8B52-63DEF8C8A071} (NetmarbleAutoUpdater Class) - http://nmweb.cdn.global.netmarble.co...utoUpdateX.cab
O16 - DPF: {7623BE59-D4CF-4379-ABC4-B39E11854D66} - http://avatar.mabinogi.jp/3drender/r...b.2007.4.4.cab
O16 - DPF: {89F434A7-4A49-4394-AC02-007480331AE2} (NetmarbleSystemIDInfo Class) - http://download.netmarble.net/Active...fo_1.0.0.1.cab
O16 - DPF: {BCBE34D4-BCCD-4326-9957-C809324D15DD} (GlbNetmarbleWebMessenger Class) - http://nmweb.cdn.global.netmarble.co...bMessenger.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
O16 - DPF: {D1F81895-5BB4-49C4-A886-58A5708F4250} (glbNMDownloadCtrl Class) - http://nmweb.cdn.global.netmarble.co...Downloader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/ge...nt/swflash.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~4\Office12\GR99D3~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

--End of file - 7547 bytes

Uninstall Manager Log


Acrobat.com
Adobe Download Manager
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 9.2
Adobe Shockwave Player 11.5
AIM 6
AIM Toolbar
Apple Software Update
ATI - Software Uninstall Utility
ATI Catalyst Control Center
ATI Display Driver
Audiosurf
avast! Antivirus
Band-in-a-Box 2007 Demo
BCM V.92 56K Modem
BSR Screen Recorder 4
Call of Duty(R) 4 - Modern Warfare(TM)
CamStudio
Canon i860
CCleaner
Collab
Crayon Physics Deluxe - release 51
Critical Update for Windows Media Player 11 (KB959772)
CryptIt v1.300
DAEMON Tools Toolbar
DFOLauncher
Direct MIDI to MP3 Converter version 6.1.0.32
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Web Player
Driver Sweeper 2.0.5
Easy GIF Animator 4.8
Easy Gif Animator Extension
FL Studio 8
FLV Player 2.0 (build 25)
Francesco's leveled creatures-items mod 4.5b
Fraps (remove only)
Free Download Manager 3.0
Frets On Fire
GCFScape 1.7.2
getPlus(R) for Adobe
GhostX Global
GTK+ Runtime 2.14.7 rev a (remove only)
GTW V.92 Voicemodem
Guitar Pro 5.2
High Definition Audio Driver Package - KB888111
HijackThis 2.0.2
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB926239)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954708)
IL Download Manager
Intel(R) Network Connections 14.7.23.0
Intel(R) PRO Ethernet Adapter and Software
Japanese Language Support
Java(TM) 6 Update 15
Junk Mail filter update
Kamishibai
K-Lite Codec Pack 4.5.3 (Basic)
Left 4 Dead
Microsoft .NET Framework 2.0
Microsoft .NET Framework 3.0
Microsoft .NET Framework 3.0
Microsoft Choice Guard
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Office Access MUI (English) 2007
Microsoft Office Access Setup Metadata MUI (English) 2007
Microsoft Office Enterprise 2007
Microsoft Office Enterprise 2007
Microsoft Office Excel MUI (English) 2007
Microsoft Office Groove MUI (English) 2007
Microsoft Office Groove Setup Metadata MUI (English) 2007
Microsoft Office InfoPath MUI (English) 2007
Microsoft Office Live Add-in 1.3
Microsoft Office OneNote MUI (English) 2007
Microsoft Office Outlook Connector
Microsoft Office Outlook MUI (English) 2007
Microsoft Office PowerPoint MUI (English) 2007
Microsoft Office Proof (English) 2007
Microsoft Office Proof (French) 2007
Microsoft Office Proof (Spanish) 2007
Microsoft Office Proofing (English) 2007
Microsoft Office Publisher MUI (English) 2007
Microsoft Office Shared MUI (English) 2007
Microsoft Office Shared Setup Metadata MUI (English) 2007
Microsoft Office Word MUI (English) 2007
Microsoft Search Enhancement Pack
Microsoft SQL Server 2005 Compact Edition [ENU]
Microsoft Sync Framework Runtime Native v1.0 (x86)
Microsoft Sync Framework Services Native v1.0 (x86)
Microsoft User-Mode Driver Framework Feature Pack 1.0
Microsoft VC9 runtime libraries
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
Microsoft XNA Framework Redistributable 3.0
Mozilla Firefox (3.5.5)
MSVCRT
Network Stumbler 0.4.0 (remove only)
Oblivion
Oblivion - BTmod 2.20
OpenAL
Operation Optimization v1.1.1
Penumbra Black Plague
PFPortChecker 1.0.32
Picasa 3
Pidgin
QuickTime
Santa Cruz
ScreenShot Wizard 1.0
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB944338-v2)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958215)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960714)
Security Update for Windows XP (KB960715)
Segoe UI
Sony USB Driver
Sophos Anti-Rootkit 1.5.0
Spybot - Search & Destroy
Star Wars JK II Jedi Outcast
Steam
SuddenAttackNA
Tag - IGF Professional 2008
Team Fortress 2
Total Screen Recorder Gold 1.5
Trine Demo
Update for Windows Internet Explorer 8 (KB972636)
Update for Windows XP (KB898461)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC80CRTRedist - 8.0.50727.762
Vegas Pro 9.0
Ventrilo Client
Virtual Audio Cable 4.9
VLC media player 1.0.0
Voyetra Record Producer MIDI Edition
VTFEdit 1.2.5
Winamp
Windows Communication Foundation
Windows Imaging Component
Windows Installer 3.1 (KB893803)
Windows Internet Explorer 8
Windows Live Call
Windows Live Communications Platform
Windows Live Essentials
Windows Live Essentials
Windows Live Family Safety
Windows Live Mail
Windows Live Messenger
Windows Live OneCare safety scanner
Windows Live Photo Gallery
Windows Live Sign-in Assistant
Windows Live Sync
Windows Live Toolbar
Windows Live Upload Tool
Windows Live Writer
Windows Media Format 11 runtime
Windows Media Format 11 runtime
Windows Media Player 11
Windows Media Player 11
Windows Presentation Foundation
Windows Workflow Foundation
Windows XP Hotfix - KB884020
WinRAR archiver
Xfire (remove only)
xp-AntiSpy 3.97-5
XPMedic
Xvid 1.1.3 final uninstall
Yahoo! Messenger

Also, I do not have a webcam myself, so I don't believe there's a driver issue there.

Last edited by dvk01; 16-Nov-2009 at 01:43 PM.. Reason: remove code tags so I can read the logs
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 03:31 AM #2
Okay.. what on EARTH is going on here:



From speedtest.net

The last time i checked, which was very recently, I had 20 mb d/l and 6mb upload...

is it possible a virus or something is sapping my connecting?

Last edited by MBows; 16-Nov-2009 at 09:25 AM..
TerryNet's Avatar
Computer Specs
Moderator with 48,403 posts.
 
Join Date: Mar 2005
Location: Ottawa, IL
Experience: Intermediate to Advanced
16-Nov-2009, 10:43 AM #3
If those speed results are when the CPU is at 99% they are probably meaningless. But if that is what you are getting when the computer is pretty much idle thenI think this is what we need to focus on. Messenger (and the game) is probably just spinning its wheels waiting for input.

If you are using wireless please try with an ethernet connection to see if results (speedtest and Messenger) are the same.

I'll have some suggestions to try, but want to hear about the "realness" of those results, and if there is any wired/wireless difference.

EDIT: If malware were involved Byteman would have probably spotted something in your HijackThis log (in your other thread).

Last edited by TerryNet; 16-Nov-2009 at 10:46 AM.. Reason: Add comment
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 10:50 AM #4
That was without 99 percent cpu. And I've got repeated similar results, and from other speedtest sites..

And i'm connected by ethernet. I just upgraded my router firmware- to no effect.
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
16-Nov-2009, 11:01 AM #5
Are you the one who has edited your HOSTS file?

O1 - Hosts: 66.98.148.65 auto.search.msn.es
TerryNet's Avatar
Computer Specs
Moderator with 48,403 posts.
 
Join Date: Mar 2005
Location: Ottawa, IL
Experience: Intermediate to Advanced
16-Nov-2009, 11:02 AM #6
Try with a direct connection to the modem (if your router and modem are separate devices); remember to power cycle the modem when switching devices.

Make sure you have the latest ethernet driver--from your PC manufacturer if possible. Second choice is motherboard manufacturer, with 3rd choice being the NIC manufacturer. If you already have the latest use Device Manager to uninstall it; reboot and let Windows discover the adapter and reinstall the driver. (This procedure in case the installed driver is corrupted.)

And also ...

(From a JohnWill post)

TCP/IP stack repair options for use with Windows XP with SP2 or SP3.

Start, Run, CMD, OK to open a command prompt.

Reset WINSOCK entries to installation defaults: netsh winsock reset catalog

Reset TCP/IP stack to installation defaults. netsh int ip reset reset.log

Reboot the machine.
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 11:09 AM #7
Quote:
Originally Posted by Phantom010 View Post
Are you the one who has edited your HOSTS file?

O1 - Hosts: 66.98.148.65 auto.search.msn.es
My what? (Maybe? I don't know.)

Quote:
Originally Posted by TerryNet View Post
Try with a direct connection to the modem (if your router and modem are separate devices); remember to power cycle the modem when switching devices.

Make sure you have the latest ethernet driver--from your PC manufacturer if possible. Second choice is motherboard manufacturer, with 3rd choice being the NIC manufacturer. If you already have the latest use Device Manager to uninstall it; reboot and let Windows discover the adapter and reinstall the driver. (This procedure in case the installed driver is corrupted.)

And also ...

(From a JohnWill post)

TCP/IP stack repair options for use with Windows XP with SP2 or SP3.

Start, Run, CMD, OK to open a command prompt.

Reset WINSOCK entries to installation defaults: netsh winsock reset catalog

Reset TCP/IP stack to installation defaults. netsh int ip reset reset.log

Reboot the machine.
I was using the most recent driver provided by the PC manufacturer untill after I took these tests.. I went with the most recent by the NIC manufacturer, should I rollback?

I'll repair the TCP/IP stack while I wait for someone to get off the phone to direct connect to the modem..

(We use VoIP)
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
16-Nov-2009, 11:28 AM #8
Quote:
Originally Posted by MBows View Post
My what? (Maybe? I don't know.)



I was using the most recent driver provided by the PC manufacturer untill after I took these tests.. I went with the most recent by the NIC manufacturer, should I rollback?

I'll repair the TCP/IP stack while I wait for someone to get off the phone to direct connect to the modem..

(We use VoIP)
If you don't know what is a HOSTS file, chances are you never touched it. I think your computer is infected and that is most likely the cause for your issue. I don't know what TerryNet thinks about it but you might need to be moved to the Malware Removal forum.
__________________

• Our help is free 'cause we like what we do, so at least, please reply in a timely manner... Thank you.
• If we've solved your problem, please click on Mark Solved in the upper left corner of your thread.
How to Mark Your Own Thread as "Solved".
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 11:31 AM #9
Quote:
Originally Posted by Phantom010 View Post
If you don't know what is a HOSTS file, chances are you never touched it. I think your computer is infected and that is most likely the cause for your issue. I don't know what Terrynet thinks about it but you might need to be moved to the Malware Removal forum.
Alright. Also, I just finished directly connecting to the modem, and the speeds are still the same.

I wouldn't doubt I have malware.. I use to run it pretty unprotected. Perhaps the reason HJT didn't pick as many things up is because I have startup processes disabled?

Though, to my defense, I've run Spybot S&D and SUPER Anti Spyware in safe mode and both never returned anything but a couple hard to remove trackers, if that.
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 11:35 AM #10
Update: I simply googled "Hosts: 66.98.148.65 auto.search.msn.es"

There is a storm of complaints of unusually high memory and cpu usage...

It would seem you hit the nail on the head. Thanks.. Now what to do about it..


and reading over some of these, I can't remember times where firefox would lock up sometimes.


But could the speeds be malware-related too? If not, I guess it's good to address those too..


Last edited by MBows; 16-Nov-2009 at 11:42 AM..
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
16-Nov-2009, 11:47 AM #11
You HOSTS file issue IS malware related.

Please click on the Report button and kindly ask to be moved to the Malware Removal forum.
TerryNet's Avatar
Computer Specs
Moderator with 48,403 posts.
 
Join Date: Mar 2005
Location: Ottawa, IL
Experience: Intermediate to Advanced
16-Nov-2009, 11:51 AM #12
Let's see how much garbage is in the hosts file, and delete that line and see if it comes back.

Use Notepad to edit c:\windows\system32\drivers\etc\hosts

Any lines that begin with # are just comments. Are there many or few non-# lines?

Delete (or put a # in front of) the 66.98.148.65 auto.search.msn.es line. See if the problem goes away, and see if that line gets put back there soon.

Given the name I wonder if it is somebody's (maybe ISP's!) idea of directing searches? If it's malware putting it there we'll have to go to the Malware Removal forum, but I don't rush to move anybody there because the experts are so darn busy.

Good catch, Phantom010.
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 11:58 AM #13
I deleted it, It didn't come back.

I then checked the hosts file and there was nothing without a # besides a "local host"

I'll restart the comp now.
MBows's Avatar
Member with 45 posts.
 
Join Date: Nov 2009
16-Nov-2009, 12:17 PM #14
restarted, still gone, but the speeds remain..

I don't have anyone available to webcam, but i'm going on my game in a bit.

The download speeds are still broken, however. Even when I just tested them in safe mode..
Phantom010's Avatar
Computer Specs
Trusted Advisor with 25,017 posts.
 
Join Date: Mar 2009
Location: Cyberspace
Experience: Advanced
16-Nov-2009, 12:21 PM #15
If malware modified your HOSTS file, it's quite possible that it's still on your computer affecting it in other ways, even if you deleted the offending HOSTS file entry.
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 02:51 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.