Router Problems & Startup

Sessional

New Member
Reaction score
5
I have a 2.2Ghz athlon by emachines about 1-2 years old with ZoneAlarm basic firewall installed to run on startup. The ZoneAlarm firewall has been trying to initialize for the past 10 minutes. Every once and awhile it will hide the "Please stand by..." dialog and then it will pop back up within the minute. I'm pretty sure I have the latest patch, but if that is the top suggestion I will go check to see if I do.

Now, onto my router problem, there is around 15-20 sites that I can connect to all the time, but sites like www.runescape.com and www.cnn.com can't load, except for in odd instances where they load for around 20 minutes then die. This has been going on/off for the past few days. At first I thought it was just my ISP, but pinging blackhole.com returns an average ping of 53ms.

Battle.net connections will NOT let me download any maps I do not currently have. At first I thought it would be the wc3 ports I forwarded for hosting, but I removed those and am still having the issue.

Look at that, ZoneAlarm is still going and I didn't start typing this until the first 10 minutes.

Thanks in advance,
~Sessional​
 

enouwee

Non ex transverso sed deorsum
Reaction score
240
First, the basic questions:
  • could you please confirm that your router is indeed acting as router and not modem? If so, is your router set to establish a connection on demand or is it always on?
  • did you check that your PC isn't infected by some kind of malware, that altered your hosts file or modified other funny stuff?
  • did you find any error messages or other suspicious things in the firewall logs?

As for possible causes:

1st guess: it's the firewall
Don't do this if you router is actually a modem: Try accessing the sites without ZoneAlarm running. Only forwarded packets should reach your PC, so you're not really at risk.

2nd guess: it's the maximum packet size
Try sending some ICMP packets to another server (www.google.com or whatever you like).
Code:
ping -n 2 -l [I]<SIZE>[/I] -f <your favorite victim>
where SIZE is one of: 1000, 1400, 1410, 1460, 1500, 1520

Starting at which value does it say: "Packet needs to be fragmented but DF set"?

3rd guess...
Might need a packet capture while you're trying to send a request to one of the sites not working correctly.
 

Sessional

New Member
Reaction score
5
>>could you please confirm that your router is indeed acting as router and not modem? If so, is your router set to establish a connection on demand or is it always on?
>It is always on, because my dad has all 3 of our computers networked together. I thought it was a router.. But who knows! Actiontec: Wireless-Ready DSL Gateway, you determine for yourself.
>>did you check that your PC isn't infected by some kind of malware, that altered your hosts file or modified other funny stuff?
>I just got a message from norton that I have a trojan that couldn't be fixed... If you'd like to help me with that problem too, that would be great. Forgot to get the info from the norton message.. =/

>>did you find any error messages or other suspicious things in the firewall logs?
>How Do I check those?


As for possible causes:

>>1st guess: it's the firewall
Don't do this if you router is actually a modem: Try accessing the sites without ZoneAlarm running. Only forwarded packets should reach your PC, so you're not really at risk.
>Okay, that fixed CNN.com, but now I can't get onto clanieb.2fear.com, a redirection link. The real one doesn't work either.

>>2nd guess: it's the maximum packet size
Try sending some ICMP packets to another server (www.google.com or whatever you like).
Code:
ping -n 2 -l [I]<SIZE>[/I] -f <your favorite victim>
where SIZE is one of: 1000, 1400, 1410, 1460, 1500, 1520
>Do these work in Cygwin? and is the favorite victim www.google.com or something?
At google.com I get the error message thing at 1500.
 

enouwee

Non ex transverso sed deorsum
Reaction score
240
>It is always on, because my dad has all 3 of our computers networked together. I thought it was a router.. But who knows! Actiontec: Wireless-Ready DSL Gateway, you determine for yourself.
Yes, that's a router. All PCs are connected to it or use wireless, right?

>>did you check that your PC isn't infected by some kind of malware, that altered your hosts file or modified other funny stuff?
>I just got a message from norton that I have a trojan that couldn't be fixed... If you'd like to help me with that problem too, that would be great. Forgot to get the info from the norton message.. =/
Yay. I'm not really into Windows malware business anymore. Find more information on it and, if possible, a specialized removal tool. At least one AV vendor should have one. You may delete it yourself, after making sure that the whole system remains usable (the AV description will tell you this).

>>did you find any error messages or other suspicious things in the firewall logs?
>How Do I check those?
I don't know. I have two hardware firewalls protecting me :D Isn't there an obvious "Show Firewall Logs" somewhere?

>Okay, that fixed CNN.com, but now I can't get onto clanieb.2fear.com, a redirection link. The real one doesn't work either.
I have some connection problems myself, but I can't get the other site to work either.


At google.com I get the error message thing at 1500.
Great. It's not an MTU problem then. Might be solved after removing your trojan.
 

Sessional

New Member
Reaction score
5
Okay, trojan data:
Source: C:\WINDOWS\system32\tdrxvdeo.dll
Click for more information about this threat : Trojan Horse
I guess I'll just use there way of removing it? Well, I checked the logs, and for the last week that was the only virus/trojan data showing up.

All computers are connected to my router all the time.
 

enouwee

Non ex transverso sed deorsum
Reaction score
240
Okay, trojan data:
Source: C:\WINDOWS\system32\tdrxvdeo.dll
Click for more information about this threat : Trojan Horse
I guess I'll just use there way of removing it? Well, I checked the logs, and for the last week that was the only virus/trojan data showing up.
Make a backup of your registry before tweaking it!

The Symantec site provides generic instructions, which apply to all malware. Try some real antivirus, rather than that Symantec thing (if you paid for it, get at least one other scanner):
These might tell you exactly which malware you've got installed and provide a removal tool or better instructions.
 
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Ghan Ghan:
    Howdy
  • Ghan Ghan:
    Still lurking
    +3
  • The Helper The Helper:
    I am great and it is fantastic to see you my friend!
    +1
  • The Helper The Helper:
    If you are new to the site please check out the Recipe and Food Forum https://www.thehelper.net/forums/recipes-and-food.220/
  • Monovertex Monovertex:
    How come you're so into recipes lately? Never saw this much interest in this topic in the old days of TH.net
  • Monovertex Monovertex:
    Hmm, how do I change my signature?
  • tom_mai78101 tom_mai78101:
    Signatures can be edit in your account profile. As for the old stuffs, I'm thinking it's because Blizzard is now under Microsoft, and because of Microsoft Xbox going the way it is, it's dreadful.
  • The Helper The Helper:
    I am not big on the recipes I am just promoting them - I use the site as a practice place promoting stuff
    +2
  • Monovertex Monovertex:
    @tom_mai78101 I must be blind. If I go on my profile I don't see any area to edit the signature; If I go to account details (settings) I don't see any signature area either.
  • The Helper The Helper:
    You can get there if you click the bell icon (alerts) and choose preferences from the bottom, signature will be in the menu on the left there https://www.thehelper.net/account/preferences
  • The Helper The Helper:
    I think I need to split the Sci/Tech news forum into 2 one for Science and one for Tech but I am hating all the moving of posts I would have to do
  • The Helper The Helper:
    What is up Old Mountain Shadow?
  • The Helper The Helper:
    Happy Thursday!
    +1
  • Varine Varine:
    Crazy how much 3d printing has come in the last few years. Sad that it's not as easily modifiable though
  • Varine Varine:
    I bought an Ender 3 during the pandemic and tinkered with it all the time. Just bought a Sovol, not as easy. I'm trying to make it use a different nozzle because I have a fuck ton of Volcanos, and they use what is basically a modified volcano that is just a smidge longer, and almost every part on this thing needs to be redone to make it work
  • Varine Varine:
    Luckily I have a 3d printer for that, I guess. But it's ridiculous. The regular volcanos are 21mm, these Sovol versions are about 23.5mm
  • Varine Varine:
    So, 2.5mm longer. But the thing that measures the bed is about 1.5mm above the nozzle, so if I swap it with a volcano then I'm 1mm behind it. So cool, new bracket to swap that, but THEN the fan shroud to direct air at the part is ALSO going to be .5mm to low, and so I need to redo that, but by doing that it is a little bit off where it should be blowing and it's throwing it at the heating block instead of the part, and fuck man
  • Varine Varine:
    I didn't realize they designed this entire thing to NOT be modded. I would have just got a fucking Bambu if I knew that, the whole point was I could fuck with this. And no one else makes shit for Sovol so I have to go through them, and they have... interesting pricing models. So I have a new extruder altogether that I'm taking apart and going to just design a whole new one to use my nozzles. Dumb design.
  • Varine Varine:
    Can't just buy a new heatblock, you need to get a whole hotend - so block, heater cartridge, thermistor, heatbreak, and nozzle. And they put this fucking paste in there so I can't take the thermistor or cartridge out with any ease, that's 30 dollars. Or you can get the whole extrudor with the direct driver AND that heatblock for like 50, but you still can't get any of it to come apart
  • Varine Varine:
    Partsbuilt has individual parts I found but they're expensive. I think I can get bits swapped around and make this work with generic shit though
  • Ghan Ghan:
    Heard Houston got hit pretty bad by storms last night. Hope all is well with TH.
  • The Helper The Helper:
    Power back on finally - all is good here no damage
    +2
  • V-SNES V-SNES:
    Happy Friday!
    +1

      The Helper Discord

      Members online

      No members online now.

      Affiliates

      Hive Workshop NUON Dome World Editor Tutorials

      Network Sponsors

      Apex Steel Pipe - Buys and sells Steel Pipe.
      Top