BetaONE will rise again!

BetaONE will rise again! (http:\\b1.hcanet.com\forum/index.php)
-   Windows NT/2000/XP (+ Service Packs) (http:\\b1.hcanet.com\forum/forumdisplay.php?f=98)
-   -   Really shocking problem with download (http:\\b1.hcanet.com\forum/showthread.php?t=15550)

Bads 29th Jan 05 06:43 AM

Really shocking problem with download
 
Hello,

I have a strange problem since I format and reinstall windows XP SP2 last week :(

I have always 3 or 4 IE window running at the same time. I surf and work on many forum at the same time.

My problem now: If I download a file and all my windows of IE are openned, my download speed is really slow..........20-25 kbs. But If I minimize my windows, my download speed increase to 400-500 kbs :eek: Same if I try to load a page and I don't minimize my other pages, it will load relly slowly.

I really don't understant why I can't have 4 or 5 IE windows loading at the same times like before my format :huh:

Sometimes my modem is restarting too when I open another window......This is a really new and strange problem.

I need your help again my friends

P.S. I have two monitors in my video card and since one year I had no problem.

robinwilson16 29th Jan 05 08:32 AM

Hello
This is a strange problem
The only thing I can think of is that you have some adware in IE which is doing something strange :unsure:

Have you tried running an ad remover?

Bads 29th Jan 05 06:34 PM

I just run Spybot, and it remove 5 DSO Exploit entries :(

I will search something for downloading now :)

unicorn 29th Jan 05 07:10 PM

Seems as you got it solved Bads.
That's a funny Topic Title though... You are using the Net and there is something really shocking... Ohoh. I see problems coming upfront.
:p

Bads 29th Jan 05 07:34 PM

Not really funny unicorn :(

Spybot found these DSO Exloits entries :

DSO Exploit: Data source object exploit (Modification du registre, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Inter net Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modification du registre, nothing done)
HKEY_USERS\S-1-5-21-776561741-1897051121-682003330-1003\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modification du registre, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Inter net Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modification du registre, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Inter net Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Modification du registre, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\Cur rentVersion\Internet Settings\Zones\0\1004!=W=3


--- Spybot - Search && Destroy version: 1.3 ---
2004-11-29 Includes\Cookies.sbi
2005-01-27 Includes\Dialer.sbi
2005-01-27 Includes\Hijackers.sbi
2005-01-11 Includes\Keyloggers.sbi
2004-05-12 Includes\LSP.sbi
2005-01-27 Includes\Malware.sbi
2004-11-29 Includes\Revision.sbi
2004-11-29 Includes\Security.sbi
2005-01-27 Includes\Spybots.sbi
2004-11-29 Includes\Tracks.uti
2005-01-27 Includes\Trojans.sbi

Spybot clean these entries and when I run another scan, the entries are always there :(

war59312 29th Jan 05 07:50 PM

Easy fix. ;)

Code:


Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"1004"=dword:00000003

Get rid of the spaces in current version. Never have understood why it does that. lol

Bads 29th Jan 05 08:01 PM

What do I have to do with this war ?

Thanks for your help ;)

unicorn 29th Jan 05 09:11 PM

Sorru Bads, I didn't mean to say it was funny you got all those spyware sheizze. To me it seemed as a problem was solved = relief, and then I had a reflection about your topic title.
Calm down, noone is making fun of you.

Bads 29th Jan 05 09:52 PM

There are no problem unicorn ;)


Sometimes I have some trouble with my english :D

Bads 29th Jan 05 11:53 PM

I remove these entrie about 10 times with Spybot and they are still present :(

lickablepig 30th Jan 05 01:39 AM

@bads
war made you a quick reg fix.
All you must do is copy & paste in notepad then save as .reg instead of .txt (stuff between the code tags)

Then you can add it to the registry by double clicking it...

It should squash all those that keep coming back on ya.
ur english is no trouble it's fine... ;)

Code:

Windows Registry Editor Version 5.00
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"1004"=dword:00000003
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"1004"=dword:00000003
[HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\0]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\1]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\2]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\3]
"1004"=dword:00000003
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Lockdown_Zones\4]
"1004"=dword:00000003

lates, jiz

war59312 30th Jan 05 02:09 AM

Yeah what he said. Figured bads you know what i ment.

Srry!

Well it should take care of the problem right after you import the registry file. If not try restarting.

If they still come back then some darn spyware is reopening the whole.

Please report back with results.

cya,
Will

Bads 30th Jan 05 02:52 AM

I have import this fix in my registry before doing another scan with Spybot and the problem is always there :(

I will reboot and scan again just to see.

Bads 30th Jan 05 05:02 PM

After rebooting, the entries are still present :(

freezer121 30th Jan 05 06:16 PM

Spybot has a bug which finds the DSO Exploit when in fact it doesn't exist. There is a fix that you can find at http://majorgeeks.com/download4392.html
:)

Cyberion 30th Jan 05 06:37 PM

personally.. I use Firefox for my browsing.

You might want to cross over out of the dark-side.. /jk

serious though make sure the updates are done/not sp2 and recheck with spybot and adaware. :)

Bads 30th Jan 05 07:11 PM

Thanks,

I will install this update :)

And I will try to use Mozilla more often

tubebuoy 30th Jan 05 08:01 PM

Have you read this?

http://www.betaone.net/forum/thread-15529.html

Unfortunately this has been going on for a few days now and the offending file will be more difficult to find. But odds are you have an exe or dll in one of these folders "windows" "system32" "system" or "internet log" (most likely system32).

A few months ago I was hijacked by "Your Search". My spy removers found it but everytime I rebooted it came back. In the end I found a .dll in system32 that bore no relation to "your search". It was called something like "xcdmilf.dll".

You might also want to try your system restore and go back to a date before you ran into this prob. Good luck!


}---:)

Bads 30th Jan 05 08:42 PM

Hum...........I don't have this file on my system

Bads 30th Jan 05 09:36 PM

I just install the latest versionof Spysweeper :)

Result scan : Cool Web Search (CWS) and Smart tags

Bads 31st Jan 05 07:51 PM

I just reinstall my firewall and all seems to be fast now :)

tubebuoy 1st Feb 05 12:45 AM

Adaware should have found CWS. Oh well, sounds like you got it fixed. Good luck!

}---:)

Bads 1st Feb 05 12:49 AM

Yes tubebuoy,


All is working fine now ;)

But Ad-aware didn't find the CWS :o Only Spysweeper find it.

Bads 2nd Feb 05 05:15 PM

I just found somethings that is new for me.


I'm runnig with two monitors since over one year ;)

I always open IE in my right monitor. But if I open IE in my left monitor, all is really fast :( Why ?

All was running perfectly until I reinstall windows :huh:

I will try to reinstall my video drivers :)

Bads 2nd Feb 05 05:49 PM

Reinstalling the video drivers don't fix my problem :(


All times are GMT +1. The time now is 04:22 PM.

Powered by vBulletin® Version 3.6.5
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.