PC "losing all connections" but AIM still connected (Trillian)

Discussion in 'Malware Help (A Specialist Will Reply)' started by AngelsWilliam, Feb 25, 2009.

  1. AngelsWilliam

    AngelsWilliam Private First Class

    Hi, there. I am a medical transcriptionist, and I was typing along with the necessary apps open: Firefox (Google), Notepad (Job issues), Excel (term list), VPN client, DictaPhone, and Trillian (Employer support).

    I lost connection with the Yahoo IM part of Trillian first, which is my method of communicating with support. No biggee. That happens sometimes. It's Yahoo IM.

    About 15 minutes later, in the middle of typing a report, I lost my VPN and DictaPhone connections and my Yahoo IM connection (this meant I couldn't tell them to assign the job to me so I didn't lose the work I'd put into it) and my ability to bring up pages on Firefox. The AIM part of Trillian, however, remained connected. The little yellow globes were still lit up, and I experimented with sending myself a message, and it went through just fine.

    So...I'm thinking "Something's not quite right, here...."

    So, I went through the "READ AND RUN ME FIRST" routine.

    And, lo and behold, I got that "Webshots has detected another application trying to change your default search page. Do you want to continue with this change?" This, after I have not only uninstalled Webshots, but have also used RegSeeker to remove all entries with the word "webshots" from my system except in the "ZoneMap" part because I know those entries are my blacklist.

    The Webshots message is an issue I brought up once before and was told that my computer was clean...but bizarre things still keep happening on it, so...I'm thinking not. I hope that doesn't across as being unappreciative of this free assistance. It's just my annoyance with the constant shutdown of my ability to work, especially considering the following information, which really fries my fanny.

    --I will make a separate thread for this, but it's relevant to this thread--I should also mention that the Yahoo and VPN disconnect issue came up on my laptop twice last night while I was working on it, too (I specifically asked my workplace to download the work software to it because it had been declared clean and was working fine and I wanted to be able to work when my desktop was down, as that was becoming an issue), except both VPN and Yahoo IM reconnected almost immediately both times and I did not lose either report I had been working on at the time...which never happens. You lose VPN, you lose DictaPhone. It never happens any other way. So, that in itself is...just not right. But, it was a work night and anything that helps with production I take with a smile. Still, after the 2nd time this issue happened, I decided this was the same bug that was getting my desktop and shut down my work software and began the "READ AND RUN ME FIRST" routine after informing support over web GMail. While I was running SSD on the laptop, Avast! popped up 2--count them, 2--trojans for executable files that I didn't recognize at all, nor did I recognize the folder one of them was in.--end relevant laptop info

    So, I don't know if this is coming from my company (I did mention the 2 trojans to them by name and said they might want to check their computers because I'd been working all night with them on my system) or Trillian or what. But, PLEASE don't tell me my computer is clean again before working on it at all...because every time you say that, I think everything's okay, and I start working, and something goes wrong, and...it's just not cool that I'm working with people's medical records with malware on my computer.

    Oh, and my local guy has told me my computer was clean when you guys told me it wasn't, so...I really don't have anywhere else to go. :cry

    Here are the links to my previous threads:
    http://forums.majorgeeks.com/showthread.php?t=179196
    http://forums.majorgeeks.com/showthread.php?t=172826

    First set of logs are attached.
     

    Attached Files:

  2. AngelsWilliam

    AngelsWilliam Private First Class

    Here's the last log. Thanks again! Again, sorry if I come off as snotty. It's just the irritation talking, not animosity toward you.
    :wave
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. You can do some clean up that is not malware related by deleting:
    c:\program files\Webshots
    C:\Documents and Settings\Administrator\Desktop\My Webshots Photos (carolsdesktop)
    c:\documents and settings\Administrator\Application Data\Webshots

    and running C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    I would suggest that this is either an ISP problem or a router/modem issue. You can check that by going to start / run / type "cmd" without quotes ---> once the command prompt opens type:
    ping www.google.com -t

    Let it run and look for time outs. To stop the ping test just hit control + C

    You can let this run while working on line and try to catch the fault when it happens.

    You may also want to remove Keyscrambler to see if that makes a difference.
     
    Last edited: Feb 26, 2009
  4. AngelsWilliam

    AngelsWilliam Private First Class

    I made that post about my laptop before you replied to the desktop thread.

    As far as being told my logs are clean, I didn't imagine what happened on my laptop, and we plan to take it to the Sheriff's office today because they have a special unit to address hacker issues. My work has put me on indefinite leave and is in discussions with their HIPAA department because of this issue.

    So glad you're taking it so seriously.

    I can't address the reply about the desktop until later today because I am currently in bed about to go to sleep for the day and didn't see your response until just now.

    I haven't been posting every other day. I have posted twice the last year about 2 different computers and once in 2007 about one of those computers. And, my mother posted about her computer this year, which also had an actual issue.

    In 2007, my desktop did indeed have an infection and the first time I posted about my laptop, so did it. If a computer exhibits strange behavior and/or slows down, it is often due to malware, yes? And, malware can often be built to hide from malware detecting software, yes?

    I deal with highly confidential material, and it is paramount that my computers remain malware free to protect people's privacy while working with that material. I'm sorry you consider protecting the confidentiality of people's medical records a waste of your time. BJ certainly doesn't.
    :mad
    I don't mean to sound ungrateful, but...you aren't exactly being charitable by telling me "it's a waste of our time," either.
     
    Last edited: Feb 27, 2009
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let me apologize for snapping at you. It was "uncharitable" for me to do that. We all have bad days sometimes, but that was no excuse for me to snap.

    Not necessarily. There are multiple reasons for slow behavior that has nothing to do with malware.

    I, and the rest of the malware team, certainly do not....which is why Chaslang created the How to Protect Yourself......instructions.

    When one of your protection software programs finds something, and removes it, you then run the backup scans to see if they detect something. If they don't, and they are updated, it is more than likely the threat is gone. But you shouldn't assume that any glitch in your system means you are infected.

    One suggestion I will make is that you encrypt your info. Your company should have that in place as a normal routine for safety.

    Again, I apologize for my momentary insanity. I hope you will forgive me.
     
  6. AngelsWilliam

    AngelsWilliam Private First Class

    Thank you for all your help, Tim. Seriously. I think we were both having a bad day--me, a bad week and then some--so it's all cool that there was some tension, there. I thank you very much for your apology. I know that's hard to do.

    The desktop is getting "certified by an authorized computer repair person to be free of spyware, malware, viruses, etc." right now, and the laptop will go in once that comes back. This is mandated by my workplace. *sigh*

    This wouldn't have been required if it hadn't been for the hacker issue...so, because it became a hacker issue, I was "wasting (your) time." I just didn't realize it. My supervisor just e-mailed me around 7a.m. this morning, and I didn't see it until just now.

    Now, it's my turn to apologize. I am very sorry. :-o:-o:-o
     
    Last edited: Feb 28, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds