Daughters Computer

Discussion in 'Malware Help (A Specialist Will Reply)' started by SpiderWiz, Mar 16, 2007.

  1. SpiderWiz

    SpiderWiz Private E-2

    Hey guys.

    Needed some help with my daughter computer. The router at home is being flooded and I'm thinking it coming for her computer. I wanted to rule out malware before replacing the wireless nic.

    Thanks
     

    Attached Files:

  2. SpiderWiz

    SpiderWiz Private E-2

    rest of the files
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We don't need Spybot logs but we do need logs from CounterSpy and BitDefender as requested in the READ ME.

    And describe what you mean by the router being flooded and how do you know this?
    Also is it incoming or outgoing?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Even without the other logs, it does not look like you have malware problems, but I do have somethings for you to do.

    Uninstall the below software:
    Java 2 Runtime Environment, SE v1.4.2
    Viewpoint Media Player (Remove Only) <-- should have been uninstalled in step 0 of the READ ME

    Now Run this Disable/Remove Windows Messenger to remove Windows Messenger.

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
    O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [DXM6Patch_981116] C:\WINDOWS\p_981116.exe /Q:A
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
    O4 - Startup: PowerReg Scheduler V3.exe
    O4 - Global Startup: KODAK Software Updater.lnk = C:\Program Files\Kodak\KODAK Software Updater\7288971\Program\backWeb-7288971.exe
    O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZSzed012ITUS_ZNxdm41464US

    After clicking Fix, exit HJT


    Now what is your status?
     
  5. SpiderWiz

    SpiderWiz Private E-2

    sorry i thought i attached the couterspy report. I will need to rerun that now. But I will follow you repy first then attach everything then. Attached bitdefender.txt
     

    Attached Files:

  6. SpiderWiz

    SpiderWiz Private E-2

    The probelm I'm having at home is the all computer (wired or wireless) loss internet connection. By power cycling the router every one is able to reconnect to the internet. I replace the router with a new router. I went the malware process with my computer. Contacted Roadrunner. They suggest testing leaving individual computers off to determine if it happens with certian computers. When my daughter computer is on, we see to lose the internet connection. Roadrunner tech suggest that somehting on one of the computer are flooding the ports thus causing the above problem.

    I did have a roadrunner tech come out and check all the line coming into the house. He claims no problems found.

    I followed you reply above. What files would you like to see now. Or any ideal what the connection might be.

    I really apprieciate all the help.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can attach a new HJT log just so I can verify the fixes I gave you but this has nothing to do with your problem. Your problems sound more like a network configuration issue.

    Are you sure that you setup all of the PCs to use DHCP? This is referred to as Obtain an IP address automatically in your Internet Protocal (TCP/IP) Properties.

    If you disconnect ALL other PCs from the router and only connect your daughters PC, do you have any kind of problem? Does her PC work okay? Like can you surf and perform all normal functions? Are you using file sharing on any of your PCs including your daughters?


    However run the below just for the heck of it!

    Please download Blacklight Beta
    • Download blbeta.exe and save it to the Desktop.
    • Once saved... double click blbeta.exe to install the program.
    • Click accept agreement and Click scan
      This app too may fire off a warning from antivirus. Let the driver load.
      Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.
     
  8. SpiderWiz

    SpiderWiz Private E-2

    I have attached the two log files for you.

    Her computer works normally. But after a period of time everyone loses internet connection, this is true even if her computer is the only one connected. She connects via a D-Link DWL-520 wireless nic.

    All devies are set to Obtain an IP address automatically. I also tried assign IPs to each device, but the result has been the same. I do use the WEP secutirty setting. I do have file sharing turn on and print sharing also.

    Thanks
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You logs are clean as suspected.

    At this point I have to refer you to the Networking Forum or to the Hardware Forum if you suspect that the wireless card is bad, but that seems unlikely if it only occurs after a length of time (....unless it is a heat issue that is causing it to take awhile to occur).

    Provide the above info to provide in the other forums. Also indicate what happens to your network if her PC is never turn on. Does everything run fine? Even for a long enough time??? Do you have a hardwired connection you can test from her PC to see how it works? Make sure you disable the wireless interface while doing this or else it will prove nothing.
     
  10. SpiderWiz

    SpiderWiz Private E-2

    Thanks.

    I left her computer disconnected from the network all weekend(well since Saturday) but it was running. The computer would run all the application find. Last night when I went to bed all the computer were turn off but this morning I had to power cycle the router. I will take all this to the network forums, just want to post a update to you guys.

    Thanks for all you input.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome and good luck. Sounds like it was not your daughter's computer then.
     
  12. SpiderWiz

    SpiderWiz Private E-2

    Yeah, she will be glad to hear. But doesn't help me solve this mystery.
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    True! And I doubt it is your router! Didn't you say that you tried a new router? Was it the exact same model router?? Perhaps there is an issue with how it talks to your DSL or Cable modem. Maybe it requires a firmware update.
     
  14. SpiderWiz

    SpiderWiz Private E-2

    I purposely bought a different brand of router. I had a Linksys before got a Netgear this time. I can't remember if I update the firmware on the new router but I know I update on the Linksys prior to replacing it.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it really sounds like it is not a router problem and that resetting the router is making the problem disappear but it may not be the cause of the problem. Perhaps you have issues with your DSL or Cable hardware or ISP service. Or perhaps one of your other PCs is causing problems on the network. Are any of the other PCs using P2P or other Torrent downloading applications? You ISP may not like you trying to act like a server.

    Note: I'm just throwing ideas out at you to look into. This was not a malware problem based on your daughters PC, but you do have other PC that could have problems. Did you start checking them for malware?
     
  16. SpiderWiz

    SpiderWiz Private E-2

    3 Computers. 2 we have went thru the malware removal process here. third one was built at the end of January. No, I'm not doing torrent or p2p downloads. No, I'm not acting as a server. Time Warner has already been to my house to check the modem, the cable lines and connections. They check the modem history (at least that what the guy told me) and doesn't see any issues with the modem losing connection from their node.

    I do have a laptop connecting wireless. I will go through the malware process with the laptop. But I highly doubt there is any issues with the laptop.
     
    Last edited: Mar 19, 2007
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Next time the problem happens, don't power cycle the router. Try power cycling the Cable modem and see what happens.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds