PDA

View Full Version : Linksys WRT54G


Lehana
06-13-2009, 12:44 AM
I would appreciate any help. My 19 year old set up a Linksys WRT54G to PC1 and a Linksys adapter to PC2. He did not have the cd so he did it via instructions on the net. It seemed to be fine, but PC1 keeps freezing, so I have to hard boot. Also any searches on google redirect me to another search page. We use Mozilla mostly, but it happens on ie too. Any ideas? I turned the Firewall off on PC1. We have the bundle pack from comcast, maybe there is a setting problem??

Paul Komski
06-13-2009, 02:01 AM
Also any searches on google redirect me to another search page.
Freezing plus search re-direciton is malware till proved otherwise and not likely to be anything relaged to your router.

I'm moving this thread to the Security section. I suggest you read this thread (http://www.pcguide.com/vb/showthread.php?t=60009) and then post the content of a HijackThis log in this thread.

Lehana
06-13-2009, 02:01 PM
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:57:32 PM, on 6/13/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16850)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\System32\DLA\DLACTRLW.EXE
C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe
C:\Program Files\Dell Photo AIO Printer 964\memcard.exe
C:\Program Files\McAfee.com\Agent\mcagent.exe
F:\Winamp\winampa.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dlcjcoms.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\WINDOWS\system32\wuauclt.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\Program Files\Java\jre1.5.0_06\bin\jucheck.exe
C:\Documents and Settings\Laura\Desktop\HiJackThis.exe
C:\Program Files\Internet Explorer\Iexplore.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2061021
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk&channel=us&ibd=2061021
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files\BAE\BAE.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXE
O4 - HKLM\..\Run: [Corel Photo Downloader] C:\Program Files\Corel\Corel Photo Album 6\MediaDetect.exe
O4 - HKLM\..\Run: [DLCJCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCJtim e.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [dlcjmon.exe] "C:\Program Files\Dell Photo AIO Printer 964\dlcjmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 964\memcard.exe"
O4 - HKLM\..\Run: [MSKDetectorExe] C:\Program Files\McAfee\SpamKiller\MSKDetct.exe /uninstall
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [WinampAgent] F:\Winamp\winampa.exe
O4 - HKCU\..\Run: [ModemOnHold] C:\Program Files\NetWaiting\netWaiting.exe
O4 - HKCU\..\Run: [ares] "C:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [AIM] F:\Old drive 4-26-08\Program Files\AIM\aim.exe -cnetwait.odl
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - F:\Old drive 4-26-08\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O23 - Service: dlcj_device - Unknown owner - C:\WINDOWS\system32\dlcjcoms.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe

--
End of file - 7686 bytes

Paul Komski
06-14-2009, 12:17 AM
I don't pretend to be a HJT expert but to me there is nothing glaringly or obviously nasty in the log apart from the Dell/Google BHO Toolbar which could well be responsible for some of the Google redirects you have been getting. If you dont want it then you should be able to uninstall it from Control Panel or from Add/Remove programs.

If that doesn't help with the freezes we might be looking at a hardware issue. I have presumed that PC1 was connected by cable to the router and that being the case a PC freeze due to conversations with the router would seem unusual but easily eliminated by seeing if they still occur when detached from the router and also if the router is by-passed temporarily altogether.

Lehana
06-14-2009, 11:50 PM
I did not find Google toolbar in the add/remove, but it was in the program files. I unhooked the Lynksys and am back using my cable modem only. I will see what happens. I read on another site that lots of people having freeze ups with Linksys. One guy moved his wireless phone away from the router & it stopped happening, but I have the bundle and they both run off the same modem, so I can't move my phone to another room. They are both 2.4ghz, so maybe, but not evveryone had a phone nearby, so.... I will test it without for a week, and maybe re-try again. Thanks for your input. I will keep you posted.

Paul Komski
06-15-2009, 01:35 AM
Does this freezing occur only on PC1 when you are surfing and is it a total freeze of the PC? e.g. CTRL+ALT+DEL does not bring up Task Manager. Mention of curing by a hard boot implies a total freeze.

Or do you mean that you cannot browse any more until you reboot in some manner but could maybe do other things like open notepad or whatever.

I thought (had assumed that) PC1 was using a Wired connection; if so there should be no problems with wifi interference. Interference like that would be most unlikely to be specific to one make of router. Wifi was mentioned for PC2 but not for PC1.

A PC freezing in reaction to its NIC (be it cable or wifi) would be more likely to be due to a driver-related problem than anything else (http://www.daniweb.com/forums/thread43284.html#). In other words a problem with the the way the hardware was installed (or its supporting software - particularly for wifi connections) rather than how the information going out to the LAN or Internet was being affected by hardware outside the PC.

Lehana
06-15-2009, 03:10 AM
Yes it is a total freeze and only on PC1. PC 1 had the Linksys router and PC2 has the Linksys adapter. I will check out the driver info you posted. Also, should PC2 have it's firewall turned off? I didn't do that because I thought it should only be done on PC1. Thanks so much for your help! I so appreciate it. This is driving me Crazy!

Paul Komski
06-15-2009, 03:19 AM
Does disconnecting the cable to the router affect anything when the PC freezes?

I will move this back to networking where others may be more likely to chip in.

When testing things out its wise to disable any firewalls just in case network conflicts or blocks could possibly be affecting things. Unlikely that PC2 is interferring but networks are very strange beasts. You could take the router and other PC out of the question by by-passing the router altoghether; that might also help with identifying the culprit.

Lehana
06-15-2009, 07:11 AM
I didn't try disconecting the router when it froze. I actually did take the router out and went back to just the cable modem and so far it's fine. So I am pretty sure it's the router. I will try it for another day or so. I will also diconnect the firewall on PC2 when I reconnect. Thanks

Paul Komski
06-15-2009, 07:15 AM
I will also diconnect the firewall on PC2 when I reconnect. Thanks
One further step in indentifying where the fault might lie would be to connect PC1 to the router but have PC2 completely turned off and powered down.

Lehana
06-15-2009, 12:17 PM
Will do. Thanks

Lehana
06-26-2009, 12:13 AM
You were correct in your assumption, must have been a malware, and then trojan, which was my original thought, but anyway.. I had tried to post a couple of times but it wiped it out, wouldn't let me do anything anti virus wise or spyware. I ended up reinstalling windows and waited a few days then added the Linksys router back, so far so good! Thanks so much for your help, I really appreciate it & hope that you are not getting as much rain as we have been! You guys are great!!!