Hi moxin,
I'm moving this to our new (or perhaps not-so-new by now) Security forum; that's where we're now concentrating spyware-related troubleshoots.
:)
When you say that you "can't stay on line", what exactly do you mean, and what type of Internet connection do you have?
By the way, this looks a bit odd:
"[rundll32.exe] C:\WINDOWS\System32\rundll32.exe.exe".
Does that entry really have a double ".exe" extension?
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
Tekmaven
Software Architect
1,274 posts since Feb 2002
Reputation Points: 322
Solved Threads: 28
Upon further reasearch, the nameserver line is definatly bad. In fact, its probably the one causing your problems.
Tekmaven
Software Architect
1,274 posts since Feb 2002
Reputation Points: 322
Solved Threads: 28
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Its... really not legit :-P.
Tekmaven
Software Architect
1,274 posts since Feb 2002
Reputation Points: 322
Solved Threads: 28
lsass.exe is a legitimate Windows file. The file dropped by sasser is lsasss.exe
From answers that work:
LSASS is the Local Security Authentication Server. It verifies the validity of user logons to your PC/Server (in technical jargon : it generates the process that is responsible for authenticating users for the Winlogon service).
Recommendation :
An integral part of the operating system, leave alone provided that its full path as shown in The Ultimate Troubleshooter is either C:\WinNT\System32\LSASS.exe (Windows 2000) or C:\Windows\System32\LSASS.exe (Windows XP/2003). If the path is anything else then you may have a virus
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
This looks funny ,note the 2.exe's
O4 - HKLM\..\Run: [rundll32.exe] C:\WINDOWS\System32\rundll32.exe.exe
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
I think that DMR picked that up too. I think we need a fresh log to view.
crunchie
Most Valuable Poster
20,095 posts since Feb 2004
Reputation Points: 1,142
Solved Threads: 985
I think that DMR picked that up too. I think we need a fresh log to view.
you are right ,i need to stop speed reading.:)
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812
Yeah, speed kills man. Remember- friends don't let friends speed and post.
:mrgreen:
DMR
Wombat At Large
7,229 posts since Dec 2003
Reputation Points: 221
Solved Threads: 370
You need to contact you Internet service provider .There is nothing wrong with you log ,so it may be hardware/software ,Or maybe the Aliant stirke!!
Bad modem maybe or bad configuration somewhere .
caperjack
I hate 20 Questions
13,069 posts since Aug 2003
Reputation Points: 1,064
Solved Threads: 812