RANDOM broken internet access.. PLEASE HELP!

Discussion in 'Malware Help (A Specialist Will Reply)' started by keefislegend, Aug 28, 2008.

  1. keefislegend

    keefislegend Private E-2

    I have a stable cable internet connection and have for years. Recently, it started going out at random times quite often. I figured it was my provider, but as it continued for days I grew suspicious. It seems like from 11 PM on I barely ever even get a minute of service, but in the day it isn't as bad. However, my ISP is actually working well and I have great connection.

    A recent HiJackThis log showed a possible cause: I had the Bonjour folder installed by Itunes, and it was missing a file. It recommended LSPfix, which I ran. Nothing changed. After some google searches about similar problems, I also tried WinsockXPFix.

    Still, my internet will work one second and be out the next. HijackThis no longer shows any problems for Bonjour, and LSPfix wont come up with any errors. I don't understand what is wrong, but it must be serious.

    Any ideas? I appreciate it.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Intermittant connection issues are unlikely to be related to malware. Also a broken LSP chain would not be intermittant so you do not need to look at that. Are you using a wireless connection or a hardwired connection? What type of connection ( Is it DSL, Cable, FiOS,...etc. )?

    If you wish to check for malware anyway, please follow the instructions in the below link and attach the requested logs when you finish these instructions
    • If something does not run, write down the info to explain to us later but keep on going.
    • Do not assume that because one step does not work that they all will not.
    Notes:

    1. If you run into problems trying to run theREAD & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. keefislegend

    keefislegend Private E-2

    I finally fixed the program by scanning my PC again with TrendMicro. I hadn't done so in a few days, and it picked up a Trojan Klob virus. Apparently this was the problem. Thanks though!
     
  4. keefislegend

    keefislegend Private E-2

    Actually, the problem is still continuing. However, it seems to be a bit better than before. I tried the Read & Run me, but still no success.

    I am using a hardwired Cable connection
     
    Last edited: Aug 29, 2008
  5. keefislegend

    keefislegend Private E-2

    I also would like to add that the internet only cuts out lately from about midnight through around 4 am when I give up on it. It seems like during the day it runs fine (though maybe not as fast as it used to).
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you do not do what we requested and attach the logs, we cannot help you.

    It is unlikely that your problem has anything to do with a Zlob ( I assume you meant Zlob not Klob) infection.
     
  7. keefislegend

    keefislegend Private E-2

    I still have to gather the rest of the logs because I hadn't saved them originally (I admit I didn't follow instructions very well at first), but here is the long from Malwarebytes


    Memory Processes Infected: 0
    Memory Modules Infected: 1
    Registry Keys Infected: 8
    Registry Values Infected: 0
    Registry Data Items Infected: 0
    Folders Infected: 0
    Files Infected: 5

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll (Trojan.Agent) -> Delete on reboot.

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\jkwslist (Malware.Trace) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CLASSES_ROOT\AppID\poswin.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.

    Registry Values Infected:
    (No malicious items detected)

    Registry Data Items Infected:
    (No malicious items detected)

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    C:\Program Files\Mozilla Firefox\plugins\NPAskSBr.dll (Trojan.Agent) -> Delete on reboot.
    C:\WINDOWS\system32\mcrh.tmp (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\cookies.ini (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\din.ip (Malware.Trace) -> Quarantined and deleted successfully.
    C:\WINDOWS\system32\drivers\detect.htm (Malware.Trace) -> Quarantined and deleted successfully.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please follow the instructions and attach the logs. Do not post them inline like you just did and attach the whole complete unedited logs. The logs from SUPERAntiSpyware and Malwarebytes are automatically saved to their folders under Application Data. The ComboFix and MGtools logs are also automatically saved to the C:\ folder.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds