Tech Support Guy banner
  • IMPORTANT: Only authorized members may reply to threads in this forum due to the complexity of the malware removal process. Authorized members include Malware Specialists and Trainees, Administrators, Moderators, and Trusted Advisors. Regular members are not permitted to reply, and any such posts will be deleted without notice or further explanation. Notice

wierd "disconnections" every now and then

1104 Views 4 Replies 3 Participants Last post by  Sephiroth11
every now and then i get a type of disconnection from my dsl... aim will all of a sudden say everyone has signed on again.. as if my connection went out. i have pinned down the purpose of this as a ip address connecting to my computer only for a few seconds... i got a trace route on it but have no clue what to do with it. i went to the above.net service to see if there was a way to contact them about possible attacks on my computer. my main problem is that i think i could be hacked. so much bad crap happens to this computer. its horrible. (other threads i've started)

heres the traceroute in case anyone can interpret it.

Traceroute from US


traceroute to 69.44.114.30 (69.44.114.30), 30 hops max, 40 byte packets
1 inside.fw1.sjc2.mfnx.net (208.184.213.129) 0.300 ms 0.419 ms 0.259 ms
2 99.ge-5-1-1.er10b.sjc2.us.above.net (64.124.216.11) 0.574 ms 0.855 ms 0.630 ms
3 so-2-0-0.mpr4.sjc2.us.above.net (64.125.30.101) 0.534 ms 0.605 ms 0.596 ms
4 so-3-3-0.cr1.dfw2.us.above.net (64.125.29.58) 45.159 ms 45.099 ms 45.069 ms
5 so-0-0-0.cr2.dfw2.us.above.net (64.125.28.210) 45.214 ms 45.090 ms 45.110 ms
6 so-2-0-0.cr2.dca2.us.above.net (64.125.29.10) 73.462 ms 73.795 ms 73.444 ms
7 so-6-0-0.cr2.iad1.us.above.net (64.125.28.130) 73.620 ms 73.627 ms 73.593 ms
8 so-3-0-0.mpr2.iad2.us.above.net (64.125.29.134) 73.798 ms 73.949 ms 73.818 ms
9 so-3-0-0.mpr1.iad10.us.above.net (64.125.30.117) 74.216 ms 74.057 ms 74.012 ms
10 above-oc3.iad.wcg.net (64.125.12.94) 73.854 ms 74.542 ms 74.284 ms
11 hrndva1wcx2-pos6-0.wcg.net (64.200.240.193) 74.710 ms 74.658 ms 75.520 ms
12 nycmny2wcx2-oc48.wcg.net (64.200.240.45) 80.870 ms 80.850 ms 81.159 ms
13 nycmny2wcx3-pos11-3.wcg.net (64.200.68.98) 81.155 ms 81.200 ms 81.037 ms
14 nycmnyhlce1-oc48.wcg.net (64.200.87.110) 80.755 ms 80.819 ms 80.665 ms
15 nycmnyhlce1-akamai-gige.wcg.net (64.200.60.94) 79.748 ms 79.884 ms 79.903 ms
16 69-44-114-30.wcg.net (69.44.114.30) 80.079 ms 80.292 ms 80.459 ms

this was done from a free online smart tracer
also if in germany heres what it would look like.

Traceroute from Europe(Germany)


traceroute to 69.44.114.30 (69.44.114.30), 30 hops max, 40 byte packets
1 fe0-0r0.ffm1.de.carpe.net (212.96.130.129) 1.724 ms 0.815 ms 0.774 ms
2 w1-0r0.ffm0.de.carpe.net (212.96.129.5) 2.794 ms 2.879 ms 2.782 ms
3 ge-3-1-0-4.fra20.ip.tiscali.net (213.200.64.37) 3.046 ms 3.45 ms 2.966 ms
4 so-3-0-0.nyc10.ip.tiscali.net (213.200.81.82) 84.23 ms 84.304 ms 84.227 ms
5 nyiix.akamai.net (198.32.160.47) 84.47 ms 84.439 ms 84.413 ms
6 69-44-114-30.wcg.net (69.44.114.30) 84.853 ms 84.621 ms 85.171 ms
See less See more
Status
Not open for further replies.
1 - 3 of 5 Posts
Logfile of HijackThis v1.97.7
Scan saved at 4:55:09 PM, on 3/31/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINNT\system32\drivers\KodakCCS.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\System32\ScsiAccess.EXE
C:\WINNT\Explorer.EXE
C:\WINNT\System32\devldr32.exe
C:\PROGRA~1\NORTON~1\navapw32.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE
C:\Cole's Stuff\AIM\aim.exe
C:\Program Files\Winamp3\Studio.exe
C:\Cole's Stuff\Ad Aware\Ad-aware 6\Ad-aware.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Cole's Stuff\Hijack This\Hijack This and Stinger\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - C:\Program Files\Microsoft Money\System\mnyviewer.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [GWMDMpi] C:\WINNT\GWMDMpi.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Program Files\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [WorksFUD] C:\Program Files\Microsoft Works\wkfud.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKCU\..\Run: [EPSON Stylus C80 Series] C:\WINNT\System32\spool\DRIVERS\W32X86\3\E_A10IC2.EXE /P23 "EPSON Stylus C80 Series" /O5 "LPT1:" /M "Stylus C80"
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: MoneySide (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (sys Class) - http://support.gateway.com/support/contact/formassist.CAB
O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) - http://office.microsoft.com/officeupdate/content/opuc.cab
O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productupdates/content/opuc.cab
O16 - DPF: {70BA88C8-DAE8-4CE9-92BB-979C4A75F53B} (GSDACtl Class) - http://launch.gamespyarcade.com/software/launch/alaunch.cab
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2003120501/housecall.antivirus.com/housecall/xscan53.cab
O16 - DPF: {9A57B18E-2F5D-11D5-8997-00104BD12D94} (compid Class) - http://support.gateway.com/support/serialharvest/gwCID.CAB
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37581.7223842593
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/techsupp/activedata/SymAData.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {E77C0D62-882A-456F-AD8F-7C6C9569B8C7} (ActiveDataObj Class) - https://www-secure.symantec.com/techsupp/activedata/ActiveData.cab
O16 - DPF: {F5C90925-ABBF-4475-88F5-8622B452BA9E} (Compaq System Data Class) - http://www29.compaq.com/falco/SysQuery.cab

i'm pretty sure that this is pretty clean.... it could just be my ISP switching servers i'm connected to.. i really don't know if thats what happens or not.
See less See more
i also have a few things disabled in ms-config...

money express.exe and activation.exe (both Money apps)
C:\WINNT\realtime.exe
C:\Cole's Stuff\quick time\qttask.exe -atboottime
C:\WINNT\UpdReg.EXE
CTHELPER.EXE


i would have restarted the computer for them to show in hijack log...but, i'm kinda lazy and really tired from sleep deprivation.
1 - 3 of 5 Posts
Status
Not open for further replies.
Top