Strange Connection Problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by HaloJedi20, May 27, 2005.

  1. HaloJedi20

    HaloJedi20 Private E-2

    I encountered this problem on Tuesday. It seems that whenever I browse the internet, every minute or so, my connection resets and I must refresh the page I am on. Now this might not seem like a big deal, but when I am constantly browsing, it gets really annoying. I've ran HijackThis and really didn't see anything out of the ordinary, but I'm no expert. If anybody has any recommendations, it would be appriciated.
     
  2. HaloJedi20

    HaloJedi20 Private E-2

    It also seems that right before the connection cuts on me, my webpage changes to a random page.
     

    Attached Files:

  3. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the following items:

    L2MeFix Tool

    Generic Detection Tool - NT/2000/XP

    VX2.BetterInternet Finder XP/2k - Version Msg126

    Pocket KillBox

    NOW!
    Please move the L2MeFix Tool to your Desktop and DoubleClick l2mfix.exe. Click the Install button to extract the files and follow the prompts, then open the newly added l2mfix Folder on your Desktop. DoubleClick l2mfix.bat and type 2 and ENTER to select option #2 for Run Fix. Then, press any key to Reboot your machine.
    Your computer will go crazy for a bit, but just let it run. It should eventually spit out a log in Notepad. Please attach that log.

    Please don't run any other files in the L2MFix folder.
     
  4. HaloJedi20

    HaloJedi20 Private E-2

    I downloaded every thing exept the L2MEFIX Tool because it was a dead link.
     
  5. HaloJedi20

    HaloJedi20 Private E-2

    Nevermind, I found it. Here is the log.
     

    Attached Files:

    • log.txt
      File size:
      12.1 KB
      Views:
      2
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Unzip the Generic Detection Tool to a safe folder of your choice and run "find.bat" - Allow it as much time as it needs to run. You may get an error message of "File Not Found," but just let it go.

    The tool should generate a long text file. Attach this log as an attachment to your post along with a fresh HJT log.
     
  7. HaloJedi20

    HaloJedi20 Private E-2

    Since I ran L2MEFIX, my connection hasn't been interrupted. Here are the things requested.
     

    Attached Files:

    • GDT.txt
      File size:
      10.3 KB
      Views:
      1
    • HJT.txt
      File size:
      8.7 KB
      Views:
      1
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=AdSubtract:4445
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

    R3 - Default URLSearchHook is missing

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    After you complete the above REBOOT, Scan with HijackThis and attach the new log.
     
  9. HaloJedi20

    HaloJedi20 Private E-2

    Did all of the steps. Here is the requested log.
     

    Attached Files:

    • HJT.txt
      File size:
      8.4 KB
      Views:
      1
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled

    Now scan with HijackThis and Check the Boxes for the following:

    O4 - HKCU\..\Run: [Towfygh] C:\WINDOWS\System32\??crosoft.NET\tracert.exe

    Make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Navigate to and DELETE the following if they should remain:

    C:\WINDOWS\System32\??crosoft.NET ←–– Delete this whole folder if it exist!

    NEXT:
    Run CCleaner

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds