This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Slow, sometimes no Connectivity to the internet

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am having connectivity issues that started about 3 days ago.
My problem is slow or no loading Empty pages, timing out. Inability to post in forums-sporadic-if I get to post here from my computer, Haloscan and mozilla forums.
I have tried everything-First the reboot trick, unplugging the modem, then system restore, calling the cable people, turning off my security.
Last night I went to GRC and did the leak test, and for the first time it said my Firewall had been penatrable. Also my Messenger was on, which is something I turned off ages ago. I turned it off again.
My browser is Firefox 2.0.0.1 I have Free AVG 7.5, Free Kerio Firewall, Spybot, AdAware, Spyware Blaster. I ran scans with AVG and Adaware, all updated, in regular and safe mode. Also did a Spybot scan in regular and safe mode, but when I had tried to update it (to 1.4), there was an error message (! With red cicle slashed over it-no details), so I couldn’t do that.
I have Winduhs XP Pro, SP1. I have over half the memory free. I have not installed or removed any new programs in the period before this started up.
My email seems to come through fine (Thunderbird). My cable provider says my signal is very strong, that the ping is 4-9 ms going each way.
And FF which usually runs around 21-25,000 has been spiking to 50-51,000. As usual, IE is sucking up a storm too :rofl: , so I’ve been thinking it’s not the browser. Also, I seem not to be running as many processes as I usually do.

So here’s my log. Does it look funky?

Logfile of HijackThis v1.99.1
Scan saved at 11:13:17 AM, on 1/10/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\NMSSvc.exe
C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\taskmgr.exe
C:\Documents and Settings\User\Desktop\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.crooksandliars.com/
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O8 - Extra context menu item: &AOL Toolbar search - res://C:\Program Files\AOL Toolbar\toolbar.dll/SEARCH.HTML
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {4E888414-DB8F-11D1-9CD9-00C04F98436A} (Microsoft.WinRep) - https://webresponse.one.microsoft.com/oas/ActiveX/winrep.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1138863458203
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} - http://www.pandasoftware.com/activescan/as5free/asinst.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/ac…ta/SymAData.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/ac…/ActiveData.cab
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Intel® NMS (NMSSvc) - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PictureTaker - LANovation - C:\WINDOWS\System32\PCTKRNT.SYS
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: PrismXL - Lanovation - C:\Program Files\Common Files\Lanovation\PrismXL\PRISMXL.SYS
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe (file missing)
This is in no way meant to bump my post-but I found out I could not send email through Thunderbird. Receiving was ok. I could get it out through my provider's webpage, however, and so I called them to find out if they had any ideas (that, and a little tech roulette. Third time's a charm :D) Well, we changed the port and it made all the diff. I still don't know how haloscan posting will work-either my computer is messed up, or their server is down. My ISP is checking to see if I've been turn into a bot-I'll still need help if it is possible to determine where the application is and how to remove it. BTW, it took nearly 3 minutes for my original post here to post. :( And I forgot to thank you for your attention in advance! :wavey:
Ok again not trying to bump. I have posted my latest discovery over at the Mozilla forum. I scanned with Panda and came up with 2 bits of spyware. one was: Documents and Settings\User\Application Data\Thunderbird\Profiles\49xwn2ol.default\cookies.txt[.atdmt.com] the text in the cookie file was: # HTTP Cookie File # http: //www.netscape.com/newsref/std/cookie_spec.html # This is a generated file! Do not edit. # To delete cookies, use the Cookie Manager. .ncmail.netscape.com TRUE / FALSE 1163453093 Version 21462 .evite.com TRUE / FALSE 1469154265 evuserid 67.168.180.88.1153794261660762 ads.as4x.tmcs.net FALSE / FALSE 2145801610 NGUserID c0a83e47-20629-1154110356-5 .atdmt.com TRUE / FALSE 1311811210 AA002 1154110356-1831943281/1155342874 .nytimes.com TRUE / FALSE 1165102567 RMID 2cd39e6614584390da648184 (I stuck a space in the second line to disable the link) The other one is WINDOWS\System32\cd-clint.dll So I apologise for posting and bumping, but I keep figuring out new things and thought it might help in trying to figure out what's going on-save some steps… :huh:
Sorry for the delay :oops:
If you still need help and haven't posted at another forum.

Download and install AVG Anti-Spyware (ewido). Then scan and save the log from the scan.
Instructions and download link can be found here.

Then run this online scan. Save the report.

Rescan with HJT and post a new log with the results from AVG .
Also please describe how your computer behaves at the moment.
This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Also follow the recommendations in Tony Klein's article
So how did I get infected in the first place?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI