Weird upload issue! help been 2 years with this

Get help and discuss anything related to tweaking your internet connection, as well as the different tools and registry patches on the site. TCP Optimizer settings and Analyzer results should be posted here.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Weird upload issue! help been 2 years with this

Post by PatoZambrano »

my problem is that i got 1mbps/128kbps connection and my upload speed goes from 0 to 5kbps from the 128 kbps i should be getting , my downloads are fine and also i get like 200 ping and i cant navigate fast through sites! plz help im 100% sure i dont have viruses i have scanned reformated and done everything , called my isp and they say everything is ok with the connection i got 2 computers a laptop and other a desktop computer i have been with the laptop on cousins house with same internet and everything is ok on the upload also when i connect my laptop to his internet
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

my problem is that i got 1mbps/128kbps connection and my upload speed goes from 0 to 5kbps from the 128 kbps i should be getting , my downloads are fine and also i get like 200 ping and i cant navigate fast through sites! plz help im 100% sure i dont have viruses i have scanned reformated and done everything , called my isp and they say everything is ok with the connection i got 2 computers a laptop and other a desktop computer i have been with the laptop on cousins house with same internet and everything is ok on the upload also when i connect my laptop to his internet. also i cant upload anything cos the transfer fails. plz help
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

Also i have scanned with everything .. EVERYTHING ,
NOD32
Kaspersky
Zonealarm
Ad-Aware
Spybot S&D
Mcfee
and a lot of other things
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Need the following info in order that members here can offer suggestions:

Which country are you in?

What kind of internet connection? - cable, PPPoE or PPPoA, etc.

What brand and model are your router and modem?

Post your TCP Analyzer report.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

Country mexico , i have been 3 years with this connection and 2 years with the problem kind of connection PPPoE my modem is a 2wire 1701-HG well i have 2 modems and they work same with upload and i cant do tcp analyzer right now maybe tomorrow cos im not on my house right now.
:P
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:Country mexico , i have been 3 years with this connection and 2 years with the problem kind of connection PPPoE my modem is a 2wire 1701-HG well i have 2 modems and they work same with upload and i cant do tcp analyzer right now maybe tomorrow cos im not on my house right now.
:P
The 2wire 1701-HG is a modem with a built-in router. What do you mean that you have 2 modems? Do you mean you have a router connected to the 2wire?

Do a tracert to http://www.yahoo.com and post.

To do a tracert, click 'Start' and then 'Run'. Type "cmd" into the box and click 'ok'.

A DOS black screen will appear. Type after the C:\>

tracert http://www.yahoo.com

and press enter key

When test is completed, move mouse cursor to the DOS black screen, click right and choose 'select all'.

Move mouse cursor to the Quick Reply box of this forum, click right and 'paste'.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

The 2wire 1701-HG is a modem with a built-in router. What do you mean that you have 2 modems? Do you mean you have a router connected to the 2wire?


no i mean i used to have a diferent one it was speedstream but now i have the 2wire one and it is same as the other one.

1 2 ms 3 ms 3 ms home [192.168.1.254]
2 27 ms 25 ms 22 ms dsl-servicio-l200.uninet.net.mx [200.38.193.226]

3 26 ms 25 ms * bb-nvl-mayo-10-POS-9-2.uninet.net.mx [201.125.74
.42]
4 56 ms 56 ms 55 ms vpn-nvl-triara-10-g5-2.uninet.net.mx [200.38.193
.9]
5 94 ms 205 ms 65 ms ge-3-3-0.ar3.LAX1.gblx.net [208.50.86.65]
6 64 ms 64 ms 66 ms yahoo-2.ar2.SJC2.gblx.net [64.208.110.166]
7 103 ms 102 ms 164 ms so-0-0-0.pat1.da3.yahoo.com [216.115.101.137]
8 103 ms 103 ms 101 ms ge-0-1-0-p130.msr2.mud.yahoo.com [216.115.104.85
]
9 100 ms 101 ms 100 ms te-9-1.bas-c1.mud.yahoo.com [68.142.193.9]
10 103 ms 104 ms 104 ms f1.http://www.vip.mud.yahoo.com [209.191.93.52]
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

but as i told you i have done everything like reformatting buying diferent hardrive , buying other computer and it is same :S maybe i should reduce mtu or something? xD
User avatar
mccoffee
Posts: 13365
Joined: Sat Nov 03, 2001 12:00 pm
Location: Cleveland, Ohio, United States

Post by mccoffee »

Reducing the mtu won't help neither would formating scanning for viruses ,and spyware as far as the upload is concearned.

It could be line trouble distance factor from your house to the central office make sure you are allowing icmp traffic/ping to go though on the routers ,and software firewall. Make sure on the router the mtu is enabled.

With a 128 you are only suppose to get 15kbs a second usually with upload trouble thogh it's more of physical promblem wire issues something on pole atleast what I noticed.
Comptia a+ n+
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

With a 128 you are only suppose to get 15kbs a second usually with upload trouble thogh it's more of physical promblem wire issues something on pole atleast what I noticed.
__________________ yeah i only get 0-1 kbs when uploading but how do i check if wires are bad or :S also the central is not so far maybe 1 km or less i got a friend with same connection near my house and he has his connection fine
User avatar
mccoffee
Posts: 13365
Joined: Sat Nov 03, 2001 12:00 pm
Location: Cleveland, Ohio, United States

Post by mccoffee »

You call the phone company ,and isp to sweep the lines outside of the house for any promblems if that comes out nothing. You might want to make sure you have good wirring on the inside.


Move the dsl modem away from any electirical applicanes keep it isolated call the isp ,and have them run some test.
Comptia a+ n+
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

the bad problem is that they dont want to send a guy to check my wires :/ i have called numerous times to my isp we run some tests and but that tests dont work they cant solve my problem they say everything is ok on their part but they cant send a guy to check the wire :@
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

This is the results of TCP analyzer for trogers


« SpeedGuide.net TCP Analyzer Results »
Tested on: 07.26.2007 01:10
IP address: 189.154.xx.xxx

TCP options string: 020405ac0103030001010402
MSS: 1452
MTU: 1492
TCP Window: 30492 (multiple of MSS)
RWIN Scaling: 0
Unscaled RWIN : 30492
Reccomended RWINs: 63888, 127776, 255552, 511104
BDP limit (200ms): 1220kbps (152KBytes/s)
BDP limit (500ms): 488kbps (61KBytes/s)
MTU Discovery: ON
TTL: 114
Timestamps: OFF
SACKs: ON
IP ToS: 00000000 (0)
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

You have not posted your TCP Analyzer report.

Ensure your 2wire is placed a few feet away from any other electrical devices. Do not coil up any excess length of signal cable or phone wire.

Do a speed test at this link using the recommended test server and post your results:

http://speedtest.net/
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

You have not posted your TCP Analyzer report.

Ensure your 2wire is placed a few feet away from any other electrical devices. Do not coil up any excess length of signal cable or phone wire.

Do a speed test at this link using the recommended test server and post your results:


i have already tried that 2 times placing the model without electrical devices close and everything and its still same i get 900 kbps in download and like 0-5 upload if it starts cos sometimes it doesnt
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

:::.. testmy.net test results ..:::
Download Connection is:: 869 Kbps about 0.87 Mbps (tested with 748 kB)
Download Speed is:: 106 kB/s
Upload Connection is:: 13 Kbps about 0 Mbps (tested with 97 kB)
Upload Speed is:: 2 kB/s
Tested From:: http://testmy.net (Main)
Test Time:: 2007/07/26 - 12:29am
D-Validation Link:: http://testmy.net/stats/id-J7HFL2GRI
U-Validation Link:: http://testmy.net/stats/id-WZX1L856B
User Agent:: Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.5) Gecko/20070713 Firefox/2.0.0.4;MEGAUPLOAD 1.0 [!]
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

Try the following with TCP Optimizer:

General Settings tab:
Custom settings - check
Modify All Network Adapters - check
network adapter selection - your NIC
MTU 1492
TTL - 64
TCP Receive Window - 63888
MTU Discovery - Yes
Black Hole Detect - No
Selective Acks - Yes
Max Duplicate ACKs - 2
TCP 1323 Options:
Windows Scaling - uncheck
Timestamps - uncheck

Advanced Settings tab:
Max Connections per Server - 10
Max Connections per 1.0 Server - 20
LocalPriority - 1
Host Priority - 1
DNSPriority - 1
NetbtPriority - 1
Lan Browsing speedup - optimized
QoS: NonBestEffortLimit - 0
ToS: DisableUserTOSSetting - 0
ToS: DefaultTOSValue - 80
MaxNegativeCacheTtl - 0
NetFailureCacheTime - 0
NegativeSOACache Time - 0
LAN Request Buffer Size - 32768
Then select "Apply Changes" and reboot to take effect

Also, scan with these new antispyware:

a-Squared Free
Ad-Aware 2007
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

well i have tried optimal settings in tcp optimizer and its same , also i have already scanned with Ad-Aware 2007 and nothing :/ i got no spywares also i reformated , bought new hard drive and threw the other to the thrash can , bought new computer and the first thing i did was unplug the other one and plug new to check internet but same.. :/
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:well i have tried optimal settings in tcp optimizer and its same , also i have already scanned with Ad-Aware 2007 and nothing :/ i got no spywares also i reformated , bought new hard drive and threw the other to the thrash can , bought new computer and the first thing i did was unplug the other one and plug new to check internet but same.. :/
It could be a line problem as suggested by Mccoffee since the problem is the same with a new comp connected.

Try contacting your ISP again to test the line. Mine charges US$5 for a line check to their switch and US$8 if they have to check the line right to my home.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

yeah but as i said they refuse to send me a guy to check the line
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:yeah but as i said they refuse to send me a guy to check the line
If your have an alternative, change ISP if their service is that poor.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

i dont have other alternative :/ everyone i know with this isp have their connections fine
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

i think im the only one with that problem lol, i have a cousin with his connectioin fine and he has his wires so damaged lol
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

could you tell me how to check my wires if they are ok or something?
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

also other thing i have to say is that i hear no noise in my phone it just sounds fine :S
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:could you tell me how to check my wires if they are ok or something?
Try this NDT test. Post the report under the 'Statistics' button:

http://miranda.ctd.anl.gov:7123/
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

TCP/Web100 Network Diagnostic Tool v5.3.4e
click START to begin
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client to server) . . . . . Server busy: Please wait 30 seconds for previous test to finish

click START to re-test

it always say its busy :S have tried lots of times
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

even i tried at 3:00am xD
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:TCP/Web100 Network Diagnostic Tool v5.3.4e
click START to begin
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client to server) . . . . . Server busy: Please wait 30 seconds for previous test to finish

click START to re-test

it always say its busy :S have tried lots of times
If the test server is busy, all you need to do is leave your computer free and wait 30 seconds. When the test server finished testing the person before you, it will automatically test your line thereafter without you doing anything further. This test is not like a speedtest where you must click and see the test run immediately.

Here are two NDT test servers you can choose from:

http://nitro.ucsc.edu/
http://miranda.ctd.anl.gov:7123/
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

WEB100 Enabled Statistics:
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
checking for firewalls . . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client-to-server [C2S]) . . . . . 14.0kb/s
running 10s inbound test (server-to-client [S2C]) . . . . . . 407.26kb/s

------ Client System Details ------
OS data: Name = Windows XP, Architecture = x86, Version = 5.1
Java data: Vendor = Sun Microsystems Inc., Version = 1.5.0_10

------ Web100 Detailed Analysis ------
Cable modem/DSL/T1 link found.
Link set to Full Duplex mode
No network congestion discovered.
Good network cable(s) found
Normal duplex operation found.

Web100 reports the Round trip time = 541.74 msec; the Packet size = 1452 Bytes; and
No packet loss - but packets arrived out-of-order 2.19% of the time
C2S throughput test: Packet queuing detected: 24.76%
S2C throughput test: Packet queuing detected: 11.46%
This connection is receiver limited 79.82% of the time.
Increasing the the client's receive buffer (29.0 KB) will improve performance
This connection is network limited 20.09% of the time.

Web100 reports TCP negotiated the optional Performance Settings to:
RFC 2018 Selective Acknowledgment: ON
RFC 896 Nagle Algorithm: ON
RFC 3168 Explicit Congestion Notification: OFF
RFC 1323 Time Stamping: OFF
RFC 1323 Window Scaling: OFF

Server 'nitro.ucsc.edu' is not behind a firewall. [Connection to the ephemeral port was successful]
Client is probably behind a firewall. [Connection to the ephemeral port failed]
Information: Network Middlebox is modifying MSS variable
Server IP addresses are preserved End-to-End
Information: Network Address Translation (NAT) box is modifying the Client's IP address
Server says [189.154.70.240] but Client says [192.168.1.65]
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:WEB100 Enabled Statistics:
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
checking for firewalls . . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client-to-server [C2S]) . . . . . 14.0kb/s
running 10s inbound test (server-to-client [S2C]) . . . . . . 407.26kb/s

------ Client System Details ------
OS data: Name = Windows XP, Architecture = x86, Version = 5.1
Java data: Vendor = Sun Microsystems Inc., Version = 1.5.0_10

------ Web100 Detailed Analysis ------
Cable modem/DSL/T1 link found.
Link set to Full Duplex mode
No network congestion discovered.
Good network cable(s) found
Normal duplex operation found.

Web100 reports the Round trip time = 541.74 msec; the Packet size = 1452 Bytes; and
No packet loss - but packets arrived out-of-order 2.19% of the time
C2S throughput test: Packet queuing detected: 24.76%
S2C throughput test: Packet queuing detected: 11.46%
This connection is receiver limited 79.82% of the time.
Increasing the the client's receive buffer (29.0 KB) will improve performance
This connection is network limited 20.09% of the time.

Web100 reports TCP negotiated the optional Performance Settings to:
RFC 2018 Selective Acknowledgment: ON
RFC 896 Nagle Algorithm: ON
RFC 3168 Explicit Congestion Notification: OFF
RFC 1323 Time Stamping: OFF
RFC 1323 Window Scaling: OFF

Server 'nitro.ucsc.edu' is not behind a firewall. [Connection to the ephemeral port was successful]
Client is probably behind a firewall. [Connection to the ephemeral port failed]
Information: Network Middlebox is modifying MSS variable
Server IP addresses are preserved End-to-End
Information: Network Address Translation (NAT) box is modifying the Client's IP address
Server says [189.154.xxx.xxx] but Client says [192.168.1.65]
The test shows your latency (round trip time) at 542ms and your TCP buffer at only 29 KB. If you have done the TCP Optimizer with my settings properly, your TCP buffer would have become 62 KB and thus your line will not have such a high percentage of 'receiver limited'.

Rerun the settings I gave and test again.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

but are will tcp optimizer change settings of my connection or only this comp? cos i got 2 new laptops and this computer and they are same to this on internet
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:but are will tcp optimizer change settings of my connection or only this comp? cos i got 2 new laptops and this computer and they are same to this on internet
TCP Optimizer only make changes in the Windows registry of the comp. So you have to use TCP Optimizer on each and every comp that runs Windows, except those that is using Vista. TCP Optimizer does not tweak Vista.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

always i dont think it will fix the problem :/ could u tell me how to check if the wires are in good state by myself and change them bymyself?
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:always i dont think it will fix the problem :/ could u tell me how to check if the wires are in good state by myself and change them bymyself?
Try posting a new thread in the General Broadband section. Some of our forum moderators have background in this field.
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:WEB100 Enabled Statistics:
Checking for Middleboxes . . . . . . . . . . . . . . . . . . Done
checking for firewalls . . . . . . . . . . . . . . . . . . . Done
running 10s outbound test (client-to-server [C2S]) . . . . . 14.0kb/s
running 10s inbound test (server-to-client [S2C]) . . . . . . 407.26kb/s :thumb:
This test showed your upload speed is not a problem.

It is your download speed that is bad at only 14 kbps. Suggest you increase your TCP buffer by setting TCP Window to 63888.
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

upload is my problem i can just download fine at like 110 kbytes almost all time but i cant even upload a 40kb pic to photobucket or anything
User avatar
trogers
SG VIP
Posts: 12323
Joined: Wed Jan 26, 2005 11:14 pm
Location: Bangkok, Thailand

Post by trogers »

PatoZambrano wrote:upload is my problem i can just download fine at like 110 kbytes almost all time but i cant even upload a 40kb pic to photobucket or anything
What kind of firewall and antivirus are you using?

What is the brand and model of your router and modem?

Download and run HijackThis and post the report:

http://www.majorgeeks.com/download3155.html
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

my antivirus right now is nod32 my router is 2wire 1701-HG
And here is the hijackthis report:


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Archivos de programa\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/c ... poti_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b47946.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 6467 bytes
PatoZambrano
Member
Posts: 57
Joined: Tue Jul 24, 2007 1:34 am

Post by PatoZambrano »

srry i didnt pasted correct

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 02:34:16 a.m., on 30/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Archivos de programa\Eset\nod32kui.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Archivos de programa\Messenger\msmsgs.exe
C:\Archivos de programa\Archivos comunes\Microsoft Shared\VS7Debug\mdm.exe
C:\Archivos de programa\Eset\nod32krn.exe
C:\WINDOWS\system32\pctspk.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wdfmgr.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\WgaTray.exe
C:\WINDOWS\system32\svchost.exe
C:\ARCHIV~1\Mozilla Firefox\firefox.exe
C:\Downloads\setups\HiJackThis.exe
C:\WINDOWS\System32\wbem\wmiprvse.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.es/0SEESES/SAOS01?FORM=TOOLBR
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Vínculos
O2 - BHO: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\ARCHIV~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Archivos de programa\Archivos comunes\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Archivos de programa\Windows Live Toolbar\msntb.dll
O3 - Toolbar: Megaupload Toolbar - {4E7BD74F-2B8D-469E-CCB0-B130EEDBE97C} - C:\ARCHIV~1\MEGAUP~1\MEGAUP~1.DLL
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM\..\Run: [nod32kui] "C:\Archivos de programa\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Archivos de programa\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Archivos de programa\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "C:\Archivos de programa\Ares\Ares.exe" -h
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SERVICIO LOCAL')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Servicio de red')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: &Windows Live Search - res://C:\Archivos de programa\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\ARCHIV~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Consola de Sun Java - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Archivos de programa\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/c ... poti_x.cab
O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/ms ... b56986.cab
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.5) - http://housecall65.trendmicro.com/house ... hcImpl.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://download.bitdefender.com/resourc ... oscan8.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZI ... b47946.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Archivos de programa\Ares\chatServer.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Archivos de programa\Archivos comunes\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Archivos de programa\Eset\nod32krn.exe
O23 - Service: PCTEL Speaker Phone (Pctspk) - PCtel, Inc. - C:\WINDOWS\system32\pctspk.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Archivos de programa\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

--
End of file - 6467 bytes
Post Reply