Hi i can't stay online long when surfing the web.!!!! Why? any help it great! here is hijack this log file

Logfile of HijackThis v1.97.7
Scan saved at 4:14:05 AM, on 6/2/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [rundll32.exe] C:\WINDOWS\System32\rundll32.exe.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{A25B4830-2FC7-47F1-9152-D66BEFBB37E7}: NameServer =

Dani AI

Generated

Interim expert summary and recovery checklist for the reported symptom (IE drops with a DNS error after ~10 minutes): the pattern is classic for a DNS hijack or a compromised/router-pushed DNS value, often installed by malware, or a local network-stack corruption. and correctly flagged abnormal nameserver/startup artifacts and noticed the suspicious double-“.exe” startup entry; those are high‑priority to investigate because they can cause exactly the DNS failures described. (malwarebytes.com)

Immediate, practical steps to try now (run in an Administrator command prompt, then reboot the PC and the router):

ipconfig /flushdns
ipconfig /release
ipconfig /renew
netsh winsock reset
netsh int ip reset c:\resetlog.txt

The netsh commands reset Winsock/TCPIP to a clean state and often repair DNS problems caused by modified networking components; Microsoft documents these reset commands and their use. Reboot after running them. (learn.microsoft.com)

If the problem returns or the fixes above don’t hold, check these next items: inspect the Hosts file (%windir%\System32\drivers\etc\hosts) for injected redirects; verify your NIC’s IPv4 DNS settings (set to obtain automatically, or temporarily point to a trusted public DNS such as 1.1.1.1/8.8.8.8 while troubleshooting); log into the router admin page to confirm the router’s DNS entries and change the router admin password if still default. Also scan with up‑to‑date anti‑malware tools (Malwarebytes, Defender, a full offline AV scan) because DNS‑changer Trojans will reapply registry NameServer changes until the malware is removed. (support.microsoft.com)

Extra cautions: verify system files by path (legitimate lsass.exe runs from C:\Windows\System32 — malware will use lookalike names or different folders); if startup entries show duplicate or oddly named .exe values, remove them with Autoruns or msconfig only after confirming what they are; if an infection is confirmed and persistent, backup essential data, change online passwords from a clean device, factory‑reset the router and update its firmware, and involve the ISP if router/modem behavior looks suspect. For historical context on LSASS exploitation (Sasser) see Microsoft’s advisory. (en.wikipedia.org)

Recommended Answers

All 17 Replies

Hi moxin,

I'm moving this to our new (or perhaps not-so-new by now) Security forum; that's where we're now concentrating spyware-related troubleshoots.

:)

When you say that you "can't stay on line", what exactly do you mean, and what type of Internet connection do you have?


By the way, this looks a bit odd:

"[rundll32.exe] C:\WINDOWS\System32\rundll32.exe.exe".

Does that entry really have a double ".exe" extension?

Get rid of these:

O4 - HKLM..\Run: [rundll32.exe] C:\WINDOWS\System32\rundll32.exe.exe
O4 - HKLM..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) -
"]
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -

I'm not sure about the nameserver line (it probably should be gotten rid of too, but I don't know if you actually have one set).
O17 - HKLM\System\CCS\Services\Tcpip..{A25B4830-2FC7-47F1-9152-D66BEFBB37E7}: NameServer = 142.177.1.2 142.177.129.11

Upon further reasearch, the nameserver line is definatly bad. In fact, its probably the one causing your problems.

Its... really not legit :-P.

I got rid of the one that were there, but I'm still having trouble with being able to surf the web after about 10 min's. It IE says I have a dns error I believe but can't be sure because the error flashes so fast I can't read it all. I have DSL Is that what you needed? Thx for the help so far. Still something is not quite right! :(

I got rid of the one that were there, but I'm still having trouble with being able to surf the web after about 10 min's. It IE says I have a dns error I believe but can't be sure because the error flashes so fast I can't read it all. I have DSL Is that what you needed? Thx for the help so far. Still something is not quite right! :(

you have the sasser worm it infects IE go to symantec and find the removal tool, but I strongly recommend Norton Antivirus to protect you from further issues.

Oh duh forgot to tell you that the file with the isue was C:\WINDOWS\system32\lsass.exe.

hi there

to get rid of the sasser worm virus please click the below link to get the removal tool

CLICK HERE

and i suggest you download AVG 6.0 FREE EDITION to detect further worm/trojan infections and get rid of them!

while downloading you should try WEBROOT SPY SWEEPER to get rid of any spyware that may be causing problems.

I hope you problem is sorted soon!

Lee.

lsass.exe is a legitimate Windows file. The file dropped by sasser is lsasss.exe
From answers that work:
LSASS is the Local Security Authentication Server. It verifies the validity of user logons to your PC/Server (in technical jargon : it generates the process that is responsible for authenticating users for the Winlogon service).

Recommendation :
An integral part of the operating system, leave alone provided that its full path as shown in The Ultimate Troubleshooter is either C:\WinNT\System32\LSASS.exe (Windows 2000) or C:\Windows\System32\LSASS.exe (Windows XP/2003). If the path is anything else then you may have a virus

This looks funny ,note the 2.exe's
O4 - HKLM\..\Run: [rundll32.exe] C:\WINDOWS\System32\rundll32.exe.exe

I think that DMR picked that up too. I think we need a fresh log to view.

I think that DMR picked that up too. I think we need a fresh log to view.

you are right ,i need to stop speed reading.:)

Yeah, speed kills man. Remember- friends don't let friends speed and post.

:mrgreen:

Logfile of HijackThis v1.97.7
Scan saved at 1:33:14 AM, on 6/5/2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Logitech\MouseWare\system\em_exec.exe
C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://download.yahoo.com/dl/installs/yinst0401.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) -
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{A25B4830-2FC7-47F1-9152-D66BEFBB37E7}: NameServer =

I know its not the sasser worm and I have norton

You need to contact you Internet service provider .There is nothing wrong with you log ,so it may be hardware/software ,Or maybe the Aliant stirke!!
Bad modem maybe or bad configuration somewhere .

Thats what my next step was thx for bringing it up though. Now I feel like thats the problem :) thx a bunch guys!!!

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.