1.

Solve : Strange Internet problem?

Answer»

ok now i'm a first time poster. (never needed any tech SUPPORT ever) so i'll try to be as descriptive as possible.

Basic problem: Recently had problems with my phone line (no internet either but i could still access my modem page), had my ISP/Teleco fix them, and when they did i had no access to my internet or modem page. (i'm not the only admin on this computer so i'll assume the other admin messed up with it somewhere)

TroubleShooting done so FAR:

  • tested with a friends laptop and everything worked without a problem.
  • replaced my network card (installed and working fine, same as the old one)
  • gone through all the settings and everything is on default.
  • when attempting to ping my modem it times out
  • when attempting to view my modem homepage it times out
  • windows firewall is disabled
  • sygate firewall is disabled
  • all windows services are started
  • i'm 99% sure my brother hasn't messed around with the registry at all
  • its using an ethernet connection, also tried it with the usb cord too

now something strange
internet and everthing works in safe mode.

sorry if this did not make alot of sense, but in my ... opinion it is not sometihng hardware related, since internet works in safe mode (with networking).
so it must be sometihng windows related...

any ideas?

feel free to ask more questions.In safe mode some kinds of enamelware can not function.
Otherwise you have something that is messing with you LAN card, but does not run in safe mode.
Try this:
Create a new user account with admin level.
Log on as that user.
Set up the network Wizard again.
Now try the internet, both modes.
Does it do the same thing?tried and done, works in safe more but not normal mode for the new log inThat is not so good. I was thinking profile corruption.
Safe mode lets you do less things, not more things.

So we now think you have a virus. Here on this forum there are people that can do a Hijack log, but I am not one of them. My first recommendation is to download the new version of malwarebytes and do a scan in both safe mode and normal. They recommend normal, but IME that real bad stuff you only find in safe mode.
http://www.malwarebytes.org/
It is a great site, but please come back here and LET us know what you find.
Logfile of HijackThis v1.99.0
Scan saved at 6:16:15 PM, on 5/04/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Documents and Settings\Mitchell\Desktop\old desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [DVD43] "C:\Program Files\DVD Region+CSS Free\DVDRegionFree.exe" /hidden
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [winlogon] C:\WINDOWS\winlogon.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - http://dl8-cdn-01.sun.com/s/ESD5/JSCDL/jre/6u11-b90/jinstall-6u11-windows-i586-jc.cab?e=1231332228960&h=ce89ad66b6c354ff754da703f12d1e33/&filename=jinstall-6u11-windows-i586-jc.cab
O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL
O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: AVG Free8 WatchDog - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: Java Quick Starter - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Sygate Personal Firewall - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

trying the other WEBSITE now anywayBAM FIXED!!!

TY very much. done a quick scan with malware bites and it popped up with over 350 infected things... only a couple from the registry.

what had me really stumped was that it happened jsut after my ISP/Telco messed up then fixed it up so i was sure that had sometihng to do with it.

a virus didnt even occur to me.


Discussion

No Comment Found