PDA

View Full Version : Internet Connection Freezes Up



PowerandAwe
2006-08-04, 22:29
I hope that this is the correct place to start this thread. But anyways, here's the deal.

For some reason or another, my internet connection just freezes up rendering my ability to game/surf/download off the internet impossible for about 30-60 seconds. After this freeze up, I can once again surf/download/game until the next time it occurs.

This has never happened until this past week, so I immediately think its something to do with trojans or what not so I then go on to use the spybot tool to search and destroy countless stuff. The only exception being the malware called command service. Using the instructions given in the dlee1964 thread (posted 2006-07-27, 15:27), I was able to eliminate it. So now when I run s&d it finds nothing critical (I forgot the extact phrase it states). However, the problem of my internet connection freezing up still exsists.

At this point, I truely don't know what it may be and hope that someone out there may know what it is, cuz I have run outta ideas.

tashi
2006-08-04, 22:41
Hello, please see our 'sticky' topic:
BEFORE you post and who will advise you. Preliminary Steps (http://forums.spybot.info/showthread.php?t=288)

Copy paste the HJT log here into this thread and a helper will advise you as soon as available to do so.

Cheers.

PowerandAwe
2006-08-05, 00:26
Here is the hjk log

Logfile of HijackThis v1.99.1
Scan saved at 6:24:49 PM, on 04/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\AVWLPSTA.EXE
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Documents and Settings\Happy Lappy\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = \blank.htm
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AVWLPSTA.exe] AVWLPSTA.EXE START
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [defender] C:\\dfndrff_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_7.exe
O4 - HKLM\..\Run: [ktu7bba2] RUNDLL32.EXE wdc0100c.dll,n 0027bba00000000adc0100c
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123934408296
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: Media Center - C:\WINDOWS\system32\cZrds.dll (file missing)
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\cslbact.dll (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Program Files\Common Files\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

PowerandAwe
2006-08-05, 01:12
And the simpilfied end report of the online anti-virus scan of housecall:

(MS06-005) Vulnerability in Windows Media Player Could Allow Remote Code Execution (911565)
(MS06-006) Vulnerability in Windows Media Player Plug-in with Non-Microsoft Internet Browsers Could Allow Remote Code Execution (911564)
(MS06-007) Vulnerability in TCP/IP Could Allow Denial of Service (913446)
(MS06-008) Vulnerability in Web Client Service Could Allow Remote Code Execution (911927)
(MS06-013) Cumulative Security Update for Internet Explorer (912812)
(MS06-014) Vulnerability in the Microsoft Data Access Components (MDAC) Function Could Allow Code Execution (911562)
(MS06-015) Vulnerability in Windows Explorer Could Allow Remote Code Execution (908531)
(MS06-016) Cumulative Security Update for Outlook Express (911567)
(MS06-018) Vulnerability in Microsoft Distributed Transaction Coordinator Could Allow Denial of Service (913580)
(MS06-021) Cumulative Security Update for Internet Explorer (916281)
(MS06-022) Vulnerability in ART Image Rendering Could Allow Remote Code Execution (918439)
(MS06-023) Vulnerability in Microsoft JScript Could Allow Remote Code Execution (917344)
(MS06-025) Vulnerability in Routing and Remote Access Could Allow Remote Execution (911280)
(MS06-030) Vulnerability in Server Message Block Could Allow Elevation of Privilege (914389)
(MS06-032) Vulnerability in TCP/IP Could Allow Remote Code Execution (917953)
(MS06-035) Vulnerability in Server Service Could Allow Remote Code Execution (917159)
(MS06-036) Vulnerability in DHCP Client Service Could Allow Remote Code Execution (914388)

LonnyRJones
2006-08-09, 21:38
Hello

Post a combofix log
1. Download this file - combofix.exe
http://download.bleepingcomputer.com/sUBs/combofix.exe
2. Double click combofix.exe & follow the prompts.
3. When finished, it shall produce a log for you. Post that log in your next reply
Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall
If the log is large You might need to post half in one reply half in another.

PowerandAwe
2006-08-10, 09:33
These are the only 2 lines in the log file...

Start Time= 10/08/2006 2:07:33.31
Running from: C:\Documents and Settings\Happy Lappy\Desktop

LonnyRJones
2006-08-10, 10:08
Start Hijackthis and place a check next to these items If there.
O2 - BHO: VMN Toolbar - {4E7BD74F-2B8D-469E-8DA9-FD60BB9AAE33} - C:\PROGRA~1\VMNTOO~1\VMNTOO~1.DLL (file missing)
O4 - HKLM\..\Run: [defender] C:\\dfndrff_7.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_7.exe
O4 - HKLM\..\Run: [ktu7bba2] RUNDLL32.EXE wdc0100c.dll,n 0027bba00000000adc0100c
====================================
Hit fix checked and close Hijackthis.

Although the infection looks inactive Please download Look2Me-Destroyer.exe to your to the root drive, eg: Local Disk C: or partition where your operating system is installed.
http://www.atribune.org/content/view/28/
Close all windows before continuing.
Double-click Look2Me-Destroyer.exe to run it.
Put a check next to Run this program as a task.
You will receive a message saying Look2Me-Destroyer will close and re-open in approximately 1 to five minute's. Click OK
When Look2Me-Destroyer re-opens, click the Scan for L2M button, your desktop icons will disappear, this is normal.
Once it's done scanning, click the Remove L2M button.
You will receive a Done Scanning message, click OK.
When completed, you will receive this message: Done removing infected files! Look2Me-Destroyer will now shutdown your computer, click OK.
Your computer will then shutdown.
Wait about Four minutes, Turn your computer back on.
Please post the contents of Look2Me-Destroyer.txt

Post a report from this tool if any FILES show
F-Secure Blacklight: https://europe.f-secure.com/blacklight/try.shtml
Click the i accept button near the bottom of that page.
Download and run blacklite click > scan then > next, next again then exit
there will be a new txt near blacklite. post it please.
Important: If any files show Do not rename them YET.....legitimate files can be listed.

PowerandAwe
2006-08-10, 17:10
Look2Me-Destroyer V1.0.12

Scanning for infected files.....
Scan started at 10/08/2006 10:58:02 AM

Infected! C:\WINDOWS\system32\cZrds.dll
Infected! C:\WINDOWS\system32\cslbact.dll
Infected! C:\System Volume Information\_restore{37016AFA-ACD1-41CE-86B6-62862DAA3D27}\RP393\A0029427.dll
Infected! C:\System Volume Information\_restore{37016AFA-ACD1-41CE-86B6-62862DAA3D27}\RP393\A0029428.dll

Attempting to delete infected files...

Attempting to delete: C:\System Volume Information\_restore{37016AFA-ACD1-41CE-86B6-62862DAA3D27}\RP393\A0029427.dll
C:\System Volume Information\_restore{37016AFA-ACD1-41CE-86B6-62862DAA3D27}\RP393\A0029427.dll Deleted successfully!

Attempting to delete: C:\System Volume Information\_restore{37016AFA-ACD1-41CE-86B6-62862DAA3D27}\RP393\A0029428.dll
C:\System Volume Information\_restore{37016AFA-ACD1-41CE-86B6-62862DAA3D27}\RP393\A0029428.dll Deleted successfully!

Making registry repairs.

Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\Media Center
Removing: HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\RunOnceEx

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{A5AC6A4F-CAA4-4452-8213-6C739E0B728A}"
HKCR\Clsid\{A5AC6A4F-CAA4-4452-8213-6C739E0B728A}

Removing: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved "{DBE2D8B1-9A66-4108-870C-AAE5CF7817CC}"
HKCR\Clsid\{DBE2D8B1-9A66-4108-870C-AAE5CF7817CC}

Restoring Windows certificates.

Replaced hosts file with default windows hosts file


Restoring SeDebugPrivilege for Administrators - Succeeded

PowerandAwe
2006-08-10, 17:14
08/10/06 11:10:52 [Info]: BlackLight Engine 1.0.42 initialized
08/10/06 11:10:52 [Info]: OS: 5.1 build 2600 (Service Pack 2)
08/10/06 11:10:52 [Note]: 7019 4
08/10/06 11:10:52 [Note]: 7005 0
08/10/06 11:10:58 [Note]: 7006 0
08/10/06 11:10:58 [Note]: 7011 404
08/10/06 11:10:59 [Note]: 7026 0
08/10/06 11:10:59 [Note]: 7026 0
08/10/06 11:11:05 [Note]: FSRAW library version 1.7.1019
08/10/06 11:13:00 [Note]: 7007 0

LonnyRJones
2006-08-10, 23:52
Hi

Try running combofix again, if you see any error's let us know

LonnyRJones
2006-08-11, 00:53
Yes try combofix again but re-download first please

PowerandAwe
2006-08-11, 05:26
Start Time= 10/08/2006 23:20:50.85
Running from: C:\Documents and Settings\Happy Lappy\Desktop

QuickScan did not find any signs of infected files

(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2006-08-10 09:59:58 40960 ( A.... ) "C:\Look2Me-Destroyer.exe"
2006-08-07 20:58:32 ( .D... ) "C:\Documents and Settings\Happy Lappy\Application Data\3M"
2006-08-07 20:58:08 ( .D... ) "C:\Program Files\3M"
2006-08-04 02:52:14 ( .D... ) "C:\Program Files\SpywareBlaster"
2006-08-04 02:07:54 ( .D... ) "C:\Program Files\NoAdware4"
2006-08-02 16:15:00 ( .D... ) "C:\Program Files\Spybot - Search & Destroy"
2006-08-02 16:07:18 1167 ( A.... ) "C:\WINDOWS\system32\ktu7bba2.sys"
2006-08-02 16:07:18 1167 ( A.... ) "C:\WINDOWS\system32\ktu7bba2.sys"
2006-08-02 15:37:34 61952 ( A.... ) "C:\WINDOWS\system32\ktu7bba2.dll"
2006-06-12 23:18:24 ( .D... ) "C:\Documents and Settings\Happy Lappy\Application Data\vlc"
2006-06-12 20:30:48 ( .D... ) "C:\Program Files\TVU Player"


(((((((((((((((((((((((((((((((((((((( Files Created - Last 30days )))))))))))))))))))))))))))))))))))))))))))


2006-08-10 09:59 40,960 C:\Look2Me-Destroyer.exe
2006-08-02 15:37 61,952 C:\WINDOWS\system32\ktu7bba2.dll
2006-08-02 15:37 1,167 C:\WINDOWS\system32\ktu7bba2.sys


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries are not shown

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"ATIPTA"="C:\\Program Files\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"SoundMan"="SOUNDMAN.EXE"
"SynTPLpr"="C:\\Program Files\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Program Files\\Synaptics\\SynTP\\SynTPEnh.exe"
"AVWLPSTA.exe"="AVWLPSTA.EXE START"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"RemoteControl"="\"C:\\Program Files\\CyberLink\\PowerDVD\\PDVDServ.exe\""
"SunJavaUpdateSched"="C:\\Program Files\\Java\\jre1.5.0_06\\bin\\jusched.exe"
"QuickTime Task"="\"C:\\Program Files\\QuickTime\\qttask.exe\" -atboottime"
"TkBellExe"="\"C:\\Program Files\\Common Files\\Real\\Update_OB\\realsched.exe\" -osboot"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components]
"DeskHtmlVersion"=dword:00000110
"DeskHtmlMinorVersion"=dword:00000005
"Settings"=dword:00000001
"GeneralFlags"=dword:00000005

[HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0]
"Source"="About:Home"
"SubscribedURL"="About:Home"
"FriendlyName"="My Current Home Page"
"Flags"=dword:00000002
"Position"=hex:2c,00,00,00,18,01,00,00,00,00,00,00,60,04,00,00,fe,03,00,00,00,\
00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00
"CurrentState"=hex:04,00,00,40
"OriginalStateInfo"=hex:18,00,00,00,ff,ff,00,00,ff,ff,00,00,ff,ff,ff,ff,ff,ff,\
ff,ff,04,00,00,00
"RestoredStateInfo"=hex:18,00,00,00,6a,02,00,00,23,00,00,00,a4,00,00,00,9a,00,\
00,00,01,00,00,00

[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\CTFMON.EXE"

[HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer]
"NoDriveTypeAutoRun"=dword:00000091

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler]
"{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader"
"{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{AEB6717E-7E19-11d0-97EE-00C04FD91972}"=""




Contents of the 'Scheduled Tasks' folder
C:\WINDOWS\tasks\At1.job
C:\WINDOWS\tasks\At2.job
C:\WINDOWS\tasks\XoftSpy.job

Completion time: 10/08/2006 23:20:59.18
ComboFix ver 06.07.15/30 - This logfile is located at C:\ComboFix.txt

ComboFix.2006-08-10.020213.txt
ComboFix.2006-08-10.020252.txt
ComboFix.2006-08-10.020733.txt
ComboFix.2006-08-10.232050.txt

PowerandAwe
2006-08-11, 05:32
I'm not sure if the above report means that I'm clean or not, or if there are any/no errors, so there it is anyways...

LonnyRJones
2006-08-11, 06:13
Are you still having connection problems ?
If so who is your provider and what type is it ?

go here and submit these files
http://www.virustotal.com/flash/index_en.html
C:\WINDOWS\system32\ktu7bba2.dll
C:\WINDOWS\system32\ktu7bba2.sys
Let us know what if anything is found

It doesnt appear your running either a antiviurs or firewall programs, why is that ?

PowerandAwe
2006-08-11, 08:44
from the ktu7bba2.dll file, the following was found
Fortinet 2.77.0.0 08.11.2006 W32/AXF!tr.dldr
McAfee 4826 08.10.2006 Downloader-AXF

LonnyRJones
2006-08-11, 09:53
Its safe to Delete both then

PowerandAwe
2006-08-13, 01:31
argh...

still having connection problems, btw I'm on broadband cable...

LonnyRJones
2006-08-13, 02:33
Have you tried reseting your modem ?

Turn the PC off unplug your modem's power source and router's if you have one, wait about four minutes plug in the modem wait a few minutes plug in the router (again wait a few moments) then turn the pc on.

PowerandAwe
2006-08-14, 06:19
turning the power off then back on doesn't work... the internet connection still freezes up for a while before coming back to normal...

I guess that I'ma gonna hafta live with this then...

PowerandAwe
2006-08-14, 21:59
Just wondering if you know of any other idea of what this could be attributted to or of another site that may help me fix this up...

at this point it seems to be something else other then malware since I look to be clean of all exsisting problems according to S&D and etc...

thank you for all the help!!

LonnyRJones
2006-08-15, 02:24
Its appears your not running an antivirus program, why is that ?
Install atleast a free av program, update the program, since it's being ran for the first time do a full system scan preferably while the pc is in safe mode.
There are several to choose from mentioned here

http://forums.spybot.info/showthread.php?t=279

Put in place a good hosts file
http://www.mvps.org/winhelp2002/hosts.htm
How To Download and Extract the HOSTS file:
http://www.mvps.org/winhelp2002/hosts2.htm
Repeat that proccess about once or twice a month

tashi
2006-08-20, 09:25
This topic has been closed to prevent others with similar issues posting in it.
If you need it re-opened please send me or your helper a pm and provide a link to the thread.

Applies only to the original topic starter.