I had Kazza and got tons of popups so I reinstalled XP (cause KAZZA wouldn't go away). Now I can connect to the internet fine and everything appears ok, but after maybe five minute connected the modem starts sending and recieving data that I have no controll over. I talked to my IPNS and they said there's no problems with the line at all. If you have any ideas at all or know of any software that would be usefull... PLEASE!

Dani AI

Generated

Persistent, unexplained outbound traffic after an OS reinstall usually means one of three things: the infection was reintroduced from backups or transferred files, the reinstall was a repair/non-formatted install that left infected files in place, or a benign program or scheduled task is making connections. The posts from , and point to the right areas (firewall, Task Manager, anti‑spyware), but a few low‑level checks and an isolation workflow close the gap.

Isolation and identification (quick checklist)

  • Physically disconnect the machine from the network/modem to stop data leaving.

  • From an elevated command prompt, list active connections and note PIDs:

    netstat -ano
    netstat -b    (requires admin rights)
    tasklist /svc

    Enable the PID column in Task Manager (View → Select Columns → PID) and match PIDs to executables. Use a more detailed tool (Process Explorer / AutoRuns) to see full paths, loaded modules and startup entries.

Cleanup and remediation

  • Boot to Safe Mode, disable unknown startup items (msconfig) and scheduled tasks, then run up‑to‑date anti‑malware and anti‑virus scans. Scan any backed‑up files before restoring them.
  • Inspect Run keys in the registry (HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and HKCU...\Run) and remove unfamiliar entries only after confirming their role.
  • If the infection persists or a rootkit is suspected, use an offline rescue scanner or perform a full format and clean install from known‑good media.

Router/modem and final hardening

  • Check the modem/router for altered DNS, unfamiliar port forwards or a changed admin password; reset firmware to factory defaults and update if available. Once clean, apply all OS service packs and security updates and run a firewall in “monitor” mode to log outbound connections. This expands on ’s and ’s suggestions with a focused detection path so the exact process generating the traffic can be found and removed.

Recommended Answers

All 2 Replies

I had Kazza and got tons of popups so I reinstalled XP (cause KAZZA wouldn't go away). Now I can connect to the internet fine and everything appears OK, but after maybe five minute connected the modem starts sending and recieving data that I have no control over. I talked to my IPNS and they said there's no problems with the line at all. If you have any ideas at all or know of any software that would be useful.

One way to find out would be to download and install the free version of the ZoneAlarm firewall software from http://www.ZoneLabs.com. Running ZA would force programs to "ask permission" before going online, and you could find the culprit. The Task Manager can also help, by seeing what's running in the TaskList.

You also need to make sure that you have all your XP patches up-to-date and that you have UPnP and the Messenger service turned off. See http://www.GRC.com for more on these.

no need to reload windows to get rid of kazaa ,just use ad-aware or spybot to remove the Clint.dill and all the other spyware ,and then replace the clint .dll with the one on this site .Or look for Kazaa begone and then install Kazaa lite .

Kazaa lite

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.