{"id":340,"date":"2021-09-03T19:59:40","date_gmt":"2021-09-03T19:59:40","guid":{"rendered":"https:\/\/lgildv5i97.onrocket.site\/answers\/security-modem-becomes-christmas-tree-39813-html"},"modified":"2021-09-03T19:59:40","modified_gmt":"2021-09-03T19:59:40","slug":"security-modem-becomes-christmas-tree-39813-html","status":"publish","type":"question","link":"https:\/\/computing.net\/answers\/security\/modem-becomes-christmas-tree\/39813.html","title":{"rendered":"Solved Modem becomes christmas tree"},"content":{"rendered":"<p><td>I don&#8217;t really know what I am doing, but when I plug in the laptop (cable or wireless) and the modem lights up like a blinking Christmas tree I know something isn&#8217;t right and it seems I am bleeding data and connecting to a site has about a 1 in 4 chance of success. <br \/>It was suggested to post the HijackThis file here.<br \/>Please help and take it slow, I am a noob at this.<\/p>\n<p>Logfile of Trend Micro HijackThis v2.0.5<br \/>Scan saved at 8:54:38 PM, on 15-Oct-14<br \/>Platform: Unknown Windows (WinNT 6.02.1008)<br \/>MSIE: Internet Explorer v11.0 (11.00.9600.17278)<\/p>\n<p>FIREFOX: 33.0 (x86 nl)<br \/>Boot mode: Normal<\/p>\n<p>Running processes:<br \/>C:Program Files (x86)NVIDIA CorporationUpdate CoreNvBackend.exe<br \/>C:UsersToshAppDataRoaminguTorrentuTorrent.exe<br \/>C:Program Files (x86)TOSHIBAPasswordUtilityreadLM.exe<br \/>C:Program Files (x86)AVGAVG2014avgui.exe<br \/>C:Program Files (x86)Epson SoftwareEvent ManagerEEventManager.exe<br \/>C:WindowsSysWOW64ctfmon.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:UsersToshAppDataLocalGoogleGoogle Talk Plugingoogletalkplugin.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:Program Files (x86)SRWare Ironchrome.exe<br \/>C:UsersToshDownloadsHijackThis.exe<\/p>\n<p>R1 &#8211; HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = <a href=\"http:\/\/toshiba13.msn.com\/?pc=TEJB\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/toshiba13.msn.com\/?pc=TEJB<\/a><br \/>R1 &#8211; HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href=\"http:\/\/go.microsoft.com\/fwlink\/?LinkId=54896\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/?Lin&#8230;<\/a><br \/>R0 &#8211; HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href=\"https:\/\/www.google.nl\/\" target=\"_blank\" rel=\"nofollow noopener\">https:\/\/www.google.nl\/<\/a><br \/>R1 &#8211; HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = <a href=\"http:\/\/go.microsoft.com\/fwlink\/p\/?LinkId=255141\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/p\/?L&#8230;<\/a><br \/>R1 &#8211; HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = <a href=\"http:\/\/go.microsoft.com\/fwlink\/?LinkId=54896\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/?Lin&#8230;<\/a><br \/>R1 &#8211; HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = <a href=\"http:\/\/go.microsoft.com\/fwlink\/?LinkId=54896\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/?Lin&#8230;<\/a><br \/>R0 &#8211; HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = <a href=\"http:\/\/go.microsoft.com\/fwlink\/p\/?LinkId=255141\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/go.microsoft.com\/fwlink\/p\/?L&#8230;<\/a><br \/>R0 &#8211; HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = <br \/>R0 &#8211; HKLMSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = <br \/>R0 &#8211; HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WindowsSysWOW64blank.htm<br \/>R0 &#8211; HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = <br \/>F2 &#8211; REG:system.ini: UserInit=userinit.exe<br \/>O2 &#8211; BHO: (no name) &#8211; {02478D38-C3F9-4efb-9B51-7695ECA05670} &#8211; (no file)<br \/>O2 &#8211; BHO: URLRedirectionBHO &#8211; {B4F3A835-0E21-4959-BA22-42B3008E02FF} &#8211; C:PROGRA~2MICROS~1Office15URLREDIR.DLL<br \/>O2 &#8211; BHO: Microsoft SkyDrive Pro Browser Helper &#8211; {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} &#8211; C:PROGRA~2MICROS~1Office15GROOVEEX.DLL<br \/>O4 &#8211; HKLM..Run: [AmIcoSinglun64] &#8220;C:Program Files (x86)AmIcoSingLunAmIcoSinglun64.exe&#8221;<br \/>O4 &#8211; HKLM..Run: [1.TPUReg] &#8220;C:Program Files (x86)TOSHIBAPasswordUtilityreadLM.exe&#8221;<br \/>O4 &#8211; HKLM..Run: [TSVU] &#8220;c:Program FilesTOSHIBATOSHIBA Smart View UtilityTosSmartViewLauncher.exe&#8221;<br \/>O4 &#8211; HKLM..Run: [AVG_UI] &#8220;C:Program Files (x86)AVGAVG2014avgui.exe&#8221; \/TRAYONLY<br \/>O4 &#8211; HKLM..Run: [EEventManager] &#8220;C:Program Files (x86)Epson SoftwareEvent ManagerEEventManager.exe&#8221;<br \/>O4 &#8211; HKLM..Run: [QuickTime Task] &#8220;C:Program Files (x86)QuickTimeQTTask.exe&#8221; -atboottime<br \/>O4 &#8211; HKLM..Run: [Corel Photo Downloader] &#8220;C:Program Files (x86)Common FilesCorelCorel PhotoDownloaderCorel PhotoDownloader.exe&#8221; -startup<br \/>O4 &#8211; HKLM..Run: [AdobeCS6ServiceManager] &#8220;C:Program Files (x86)Common FilesAdobeCS6ServiceManagerCS6ServiceManager.exe&#8221; -launchedbylogin<br \/>O4 &#8211; HKCU..Run: [Spotify Web Helper] &#8220;C:Program Files (x86)SpotifyDataSpotifyWebHelper.exe&#8221;<br \/>O4 &#8211; HKCU..Run: [Akamai NetSession Interface] &#8220;C:UsersToshAppDataLocalAkamainetsession_win.exe&#8221;<br \/>O4 &#8211; HKCU..Run: [uTorrent] &#8220;C:UsersToshAppDataRoaminguTorrentuTorrent.exe&#8221;  \/MINIMIZED<br \/>O4 &#8211; HKCU..Run: [Epic Privacy Browser Update] &#8220;C:UsersToshAppDataLocalEpic Privacy BrowserUpdateEpicUpdate.exe&#8221; \/c<br \/>O4 &#8211; HKCU..Run: [EPLTargetP0000000000000000] C:Windowssystem32spoolDRIVERSx643E_IATILFE.EXE \/EPT &#8220;EPLTargetP0000000000000000&#8221; \/M &#8220;XP-312 313 315 Series&#8221;<br \/>O4 &#8211; HKCU..Run: [EPLTargetP0000000000000001] C:Windowssystem32spoolDRIVERSx643E_IATILFE.EXE \/EPT &#8220;EPLTargetP0000000000000001&#8221; \/M &#8220;XP-312 313 315 Series&#8221;<br \/>O4 &#8211; HKCU..Run: [EPLTargetP0000000000000002] C:Windowssystem32spoolDRIVERSx643E_IATILFE.EXE \/EPT &#8220;EPLTargetP0000000000000002&#8221; \/M &#8220;XP-312 313 315 Series&#8221;<br \/>O4 &#8211; HKCU..Run: [EPLTargetP0000000000000003] C:Windowssystem32spoolDRIVERSx643E_IATILFE.EXE \/EPT &#8220;EPLTargetP0000000000000003&#8221; \/M &#8220;XP-312 313 315 Series&#8221;<\/p>\n<\/td>\n<td>You are now clean. Am I being hacked, I doubt it, will deal with that soon.<\/p>\n<p>A lot of programs, now give you the choice to install toolbars &#038; other during the install. Either uncheck these items during install, or use <b>Custom<\/b> install. No more click, click during an install, you have to read after each click.<\/p>\n<p>I use Softpedia, down the bottom of the page, they make you aware what Ad-supported programs the author of the program has included.<br \/><font color=\"DarkGreen\" size=\"2\"><b>Sample pages<\/b>                <br \/><a href=\"http:\/\/www.softpedia.com\/get\/CD-DVD-Tools\/Data-CD-DVD-Burning\/ImgBurn.shtml\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/www.softpedia.com\/get\/CD-DVD&#8230;<\/a><br \/><font color=\"black\" size=\"2\">First and foremost, extra attention needs to be paid during installation as ImgBurn offers to create desktop shortcuts to third-party apps, as well as install a browser toolbar onto the host computer, which are not required to ensure the smooth running of the app. <br \/>SS of above.<br \/><a href=\"http:\/\/i.imgur.com\/jgGYNsP.gif\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/i.imgur.com\/jgGYNsP.gif<\/a><br \/>This is what ImgBurn tries to install.<br \/><a href=\"http:\/\/i.imgur.com\/ms4DzE9.gif\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/i.imgur.com\/ms4DzE9.gif<\/a><br \/><a href=\"http:\/\/i.imgur.com\/vVkd39a.gif\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/i.imgur.com\/vVkd39a.gif<\/a><br \/><a href=\"http:\/\/i.imgur.com\/rqFVaHs.gif\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/i.imgur.com\/rqFVaHs.gif<\/a><br \/><a href=\"http:\/\/i.imgur.com\/sm1T7h6.gif\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/i.imgur.com\/sm1T7h6.gif<\/a><br \/><a href=\"http:\/\/i.imgur.com\/vhkKLYo.gif\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/i.imgur.com\/vhkKLYo.gif<\/a><\/p>\n<p>I did not run Debut Video Capture Software, down the bottom of the Sofdtpedia page it says this.<br \/>Users are advised to pay attention while installing this ad-supported application:<br \/>    Offers to change the homepage for web browsers installed in the system<br \/>    Offers to change the default search engine for web browsers installed in the system<br \/>    Offers to download or install software or components (such as browser toolbars) that the program does not require to fully function<br \/><a href=\"http:\/\/www.softpedia.com\/get\/Multimedia\/Video\/Other-VIDEO-Tools\/Debut-Video-Capture.shtml\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/www.softpedia.com\/get\/Multim&#8230;<\/a><\/p>\n<p><font color=\"DarkOrange\" size=\"2\"><b>Use Unchecky to help prevent these third party installs. Nothing is perfect, the badies are always ahead of the goodies, so be vigilant.<\/b><br \/><a href=\"http:\/\/www.softpedia.com\/get\/System\/OS-Enhancements\/Unchecky.shtml\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/www.softpedia.com\/get\/System&#8230;<\/a><br \/><a href=\"http:\/\/unchecky.com\/\" target=\"_blank\" rel=\"nofollow noopener\">http:\/\/unchecky.com\/<\/a><br \/><font color=\"black\" size=\"2\">A reliable application that aims to protect your computer against third-party components often offered during software installations.<br \/><\/font><\/font><\/p>\n<p><\/font><\/font><\/p>\n<\/td>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","template":"","meta":{"inline_featured_image":false,"iawp_total_views":4},"question-category":[],"question_tags":[],"class_list":["post-340","question","type-question","status-publish","hentry"],"jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question\/340","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question"}],"about":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/types\/question"}],"author":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/comments?post=340"}],"wp:attachment":[{"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/media?parent=340"}],"wp:term":[{"taxonomy":"question-category","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question-category?post=340"},{"taxonomy":"question_tags","embeddable":true,"href":"https:\/\/computing.net\/answers\/wp-json\/wp\/v2\/question_tags?post=340"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}