unknown laptop problem

Discussion in 'Malware Help (A Specialist Will Reply)' started by SpecialFNK, Jul 13, 2005.

  1. SpecialFNK

    SpecialFNK Private First Class

    i have a laptop, Toshiba Techra 8000.
    i run windows 98.
    i have a dial up connection.
    i use Zone Alarm free firewall
    i was using avast! anti virus, but recently switched to AntiVir

    i have been having a problem with my lap top tonight.
    earlier today i was online with no problems, and shut down without any problems. then tonight i turned on my lap top and it wouldnt go past the first screen where it says microsoft windows 98, it was just frozen there. the only thing i could do was hit the power off.
    then when i started it back up it came to the same screen again, except this time after that screen it went to the black screen which gave me options of which mode to start in. i clicked to start in regular mode and it came to the microsoft windows 98 screen again and again this time it went to the black screen with mode options.
    this time i started in safe mode and it was able to start that way. i then did all of the normal virus/spyware checks and everything came up clean.
    i was able to finally get it to start up in regular mode.
    i then would dial up and log online.
    i noticed then the log file in my firewall at something it said.. normally everything is blocked incoming but this time the first log was a block outgoing. i rebooted a couple times, and had everything load properly, but after connecting online every first log in the firewall was a block outgoing.

    i did all the steps in the read me first and ran all of those in safe mode and everything was clean. i was using an older version of CCleaner, and tonight downloaded the newest version. in doing the cleaning with the newer version it listed alot of cookies from websites that were removed. i dont know if any of those had anything to do with the problem. after dialing up and connectiong, i again had the first log file as a block outgoing.

    any ideas what the problem would be?
    is there anything else i can download/run?
    should i run hijackthis?
     
  2. SpecialFNK

    SpecialFNK Private First Class

    i need some help here please
     
  3. SpecialFNK

    SpecialFNK Private First Class

    i think i have something bad on my laptop.
    everytime i dial up online the first log in the firewall is a block outgoing. would that be something trying to send a signal to someone that im online?
    is there anything i can download/run to check for this?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    First some words of wisdom. You are not doing youself a favor by bumping your thread. You should just be patient and wait your turn in the queue.

    We work on the oldest unanswered and oldest threads we have in programs first. And then goto newer threads (time permitting) to see if they need attention. Bumping causes your thread to move to newer position in the forum and also makes its post count non-zero. This means it gets less attention.

    What is the name of the out process that is trying to get out? Or what address is it trying to contact? This could just be normal. Some process do have to be given permission to access the internet or your local network.

    Please follow the below steps exactly:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. SpecialFNK

    SpecialFNK Private First Class

    this is what it said in my firewall Entry Detail..
    packet sent from IP# (NetBIOS Name) to IP# (NetBIOS Name) was blocked. Rating-Medium.

    i did a right click and more info and a website came up giving this information..
    ZoneAlarm has successfully stopped Internet traffic from leaving your computer. No breach in your security has occurred. Your computer is safe.
    Your computer attempted to connect to 137 on another computer, located at address 149.99.255.255.
    One possible explanation for the alert is your computer is attempting to renew an IP address from a DHCP server. It is common for this to occur in both the Trusted Zone and Internet Zone. Both DHCP and NetBIOS are common on most local area networks using Windows platform domains. The address could also belong to a DNS server or another LAN-specific server.

    the only time i get traffic blocked outgoing is right after i connect online through my dial up. all other traffic that is blocked is incoming.

    im also attaching my hijackthis log.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I would guess that it because your trying to connect to your ISP. Notice who the address belongs to:

    Code:
    [url="http://samspade.org/t/whois?a=149.99.255.255;server=auto"][color=#0000ff]149.99.255.255[/color][/url] = [  ] 
     
      OrgName:	Sprint Canada Inc. 
      OrgID:	  SPCA 
      Address:	2550 Victoria Park Ave. 
      Address:	Suite 200 
      City:	   Toronto 
      StateProv:  ON 
      PostalCode: M2J-5E6 
      Country:	CA 
     
     
  7. SpecialFNK

    SpecialFNK Private First Class

    i dont think i understand, what does that mean?
    thats not my address.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Jul 14, 2005
  9. SpecialFNK

    SpecialFNK Private First Class

    i downloaded that virus cleaner tool and nothing was found.

    i live 2 hours south of Toronto. i use Sprint for my connection and i think it connects through Toronto server.
    up until this week ive never seen it block anything outgoing after every time i log online.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well then I would expect that this is not a problem and as long as eveything is working okay, just let it remain blocked.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds