Hello and welcome to CertForums.co.uk, here we host free active certification forums with links to the best free resources for Microsoft's MCSA MCSE MCDBA Cisco's CCNA CCDA and CCNP, and CompTIA's A+ Network+ i-NET+ and Security+ certifications in the UK. If you wish to post or use other advanced features you will need to register first. Registration is absolutely free and takes only a few minutes to complete so sign up today!

If you have any problems with the registration process or your account login, please contact support

Go Back   CertForums > Computing Support Forums > Security & Viruses
Home Forums Register Search Today's Posts Mark Forums Read

After getting rid of trojans, can't connect with wireless

Post New ThreadReply
 
Thread Tools Display Modes
  #1  
Old 14-Sep-2008, 06:45 PM
tripwire45's Avatar
tripwire45 tripwire45 is offline
Administrator
Posts: 14,011
Points: 4638 tripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 points
Power: 197
None
Join Date: 29 Jun 2003
Location: Boise, ID, USA
Certifications: A+ and Network+
After getting rid of trojans, can't connect with wireless

I get the feeling this is more of a virus/malware issue than a networking issue, but it's hard to be sure. Let me explain.

My son (he's 22, so you'd think he'd know better) was playing some sort of free online game. He'd played it for awhile so figured it was harmless. Then suddenly, various popups started happening on his computer. He's running Windows XP Pro on an HP laptop. He had both an expired version of Norton running and AVG Free 7.5. He couldn't even open them to try a scan. The processes would die when he tried. He asked me to take a look.

Whatever he had, it had really hosed his laptop. I tried going back to a Restore Point before all this occurred, but that failed, regardless of the date I tried.

I tried doing an online scan but although I could connect to the internet and surf, I couldn't open up any websites related to virus scans or security at all. I copied AVG Free 8.0 from one of my other computers onto a thumb drive and used that to put the installer onto his laptop and install the program.

It installed successfully and updated the antivirus defs, but when I started the scan, the program suddenly had no active components. I closed the program but was unable to reopen it.

Finally, I rebooted into Safe Mode and was able to successfully start a scan with AVG. It ran on the command line and a long list of trojans started being located and being placed in the virus vault. I went to bed before the scan was complete.

When I woke up the next morning, the laptop was gone from my office, so I figured my son took it and all was well. I asked him about it later, and he told me it seemed fine except that it had "no or limited connectivity to the network".

I spent a good deal of time yesterday trying to get him connected wirelessly but to no avail. I turned off the Windows firewall of course, tried repairing the connection and every other troubleshooting trick I could think of. I can connect to the wireless access point (which is my wee little home server), but can't get an IP address via DHCP.

I tried again this morning. I turned off AVG, thinking it might have something to do with it, but that didn't change anything. I rebooted the server to see if the wireless service itself had died, but nada tostada. I hardcoded the wireless connection to give it an IP address, subnet mask and DNS server address. It said it had a full connection and initially could ping the server and another node on the network. It *couldn't* ping the DSL modem or the internet. Subsequently, it couldn't even ping the server or another network node, even though the systray icon said it was connected.

I suspect that there are still "critters" onboard that are causing a problem, so I'm running another AVG scan to start with. Can you think of anything else (and I know my troubleshooting description isn't complete) that I could do?

Thanks.


You know, I wish my parents played Mozart when I slept because half the time I don't even know what the heck anyone's talking about!

 
Reply With Quote
  #2  
Old 14-Sep-2008, 06:58 PM
NightWalker's Avatar
NightWalker NightWalker is offline
Lifetime Member
Posts: 1,124
Points: 1088 NightWalker has over 1000 pointsNightWalker has over 1000 pointsNightWalker has over 1000 pointsNightWalker has over 1000 pointsNightWalker has over 1000 pointsNightWalker has over 1000 pointsNightWalker has over 1000 pointsNightWalker has over 1000 points
Power: 28
None
Join Date: 04 Apr 2005
Location: Devon, UK
Age: 30
Certifications: A+, Network+, MCP, MCSA:M 2003
WIP: Active Directory 70-294
More AV scans is a must, sounds like it got some backdoor app that downloaded more stuff on to it. I would also try resetting the TCP/IP stack it you are having problems networking it.

http://support.microsoft.com/kb/299357

Make sure the Wireless Zero Configuration service is running afterwards, before you try and connect to your WLAN (and the firewall is off while you troubleshoot like you did earlier).


A+, N+, MCP, MCSA:Messaging 2003 (70-270, 284, 290, 291, 293).
Microsoft Course 2576 - IIS 6.
Blackberry Course - Administering BES 4.1.5 (Part 1 & 2).

CPU: C2D E6600 @ 3.3 Ghz
HSF: Zalman CNPS9500A-LED
Mobo: Asus P5K Premium-Black Pearl
Ram: Corsair Dominator DDR2 2x1GB 1066MHz
GPU: Asus EN8600GT DX10
HD: OS = 1xWD1600YS
HD: Data = 3xWD1600JS RAID5
PSU: Hiper Type-R 530W
Case: Thermaltake VC3000BWS
Display: Samsung 2232BW


 
Reply With Quote
  #3  
Old 14-Sep-2008, 07:02 PM
MLP's Avatar
MLP MLP is offline
Registered Member
Posts: 75
Points: 128 MLP has over 100 pointsMLP has over 100 points
Power: 4
None
Join Date: 02 Oct 2007
Location: Northants, England
Age: 28
Certifications: HND Computing
WIP: Not Decided
Hi

Apologies if this is stuff you have already tried, but have you considered taking the HDD out and placing it in a caddy? Then you can connect it via USB to another machine (Ensuring that the machine i fully patched, has valid AV, and as an extra precaution, has been booted into safe mode.). Then perform a full scan on the drive. As an extra measure, if you have a Mac or a linux machine, plug it into that. Clam AV works on Linux, and I'm sure I once used a version of Clam AV on a Mac before.

If this isn't possible, try going into msconfig, and seeing what items are set to run on boot. Also, try services.msc, and see if there is anything suspicious looking going on in there.

I've had some success with Windows Defender lately for getting rid of some nasty spyware lately.

Hope this helps somehow.

Maria

 
Reply With Quote
  #4  
Old 14-Sep-2008, 08:59 PM
Sparky's Avatar
Sparky Sparky is offline
Beer monster :)
Posts: 6,019
Points: 3533 Sparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 pointsSparky has over 3000 points
Power: 101
None
Join Date: 15 Dec 2005
Location: Scotland
Age: 29
Certifications: MSc MCSE MCSA:M MCTS:Vista N+ A+
WIP: Server 2008 upgrade
Had a similar issue with a customers laptop a while back, removed the spyware but could not get a reliable connection to the network.

Ended up doing a repair install of the OS and it fixed the problem.


RIP UCM

 
Reply With Quote
  #5  
Old 14-Sep-2008, 10:27 PM
Bluerinse's Avatar
Bluerinse Bluerinse is offline
Senior Moderator
Posts: 7,722
Points: 2747 Bluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 points
Power: 115
None
Join Date: 29 Jun 2003
Location: The Gold Coast, QLD Australia
Certifications: C&G Electronics - MCSA (W2K) MCSE (W2K)
WIP: None but considering SBS
James, can you get Internet connectivity using a *wired* connection?

If not, i suspect your Winsock has been messed up.

You can use one of these programs to fix it..

http://www.snapfiles.com/get/winsockxpfix.html

http://www.cexx.org/lspfix.htm

Quote:
LSP-Fix is a free Windows utility to repair a loss of Internet access associated with certain types of software. This type of software, known as a Layered Service Provider or LSP, typically handles low-level Internet-related tasks, and data is passed through a chain of these programs on its way to and from the Internet. However, due to bugs in the LSP software or deletion of the software, this chain can get broken, causing the Internet connection to become inaccessible.
Unfortunately, problematic LSP software, including malware/spyware, is sometimes quietly installed by unrelated products such as file-sharing programs, sneaking onto a system unannounced. In fact, in many cases, the user does not know of its existence until something goes wrong, and he/she can no longer access Web sites. Historically, New.net* (NEWDOTNET) and WebHancer* (often bundled with file-sharing utilities, DVD player software, and other free downloads) have been the worst offenders, but the problem can be caused by any improperly-written Layered Service Provider software, or the deletion of any LSP program's files. LSP-Fix repairs the LSP chain by removing the entries left behind when LSP software is removed by hand (or when errors in the software itself break the LSP chain), and removing any gaps in the chain.


RIP UCM

Last edited by Bluerinse : 14-Sep-2008 at 10:30 PM.
 
Reply With Quote
  #6  
Old 15-Sep-2008, 02:26 AM
tripwire45's Avatar
tripwire45 tripwire45 is offline
Administrator
Posts: 14,011
Points: 4638 tripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 points
Power: 197
None
Join Date: 29 Jun 2003
Location: Boise, ID, USA
Certifications: A+ and Network+
Thought you had something, Pete. I tried to connect the laptop using a wired connection and got the same problem. Downloaded and installed the recommended winsock repair utility. The wired connection came up like a dream. So did several pop ups of the malware persuasion. Disabled the wired nic and enabled the wireless. Alas...same problem.


You know, I wish my parents played Mozart when I slept because half the time I don't even know what the heck anyone's talking about!

 
Reply With Quote
  #7  
Old 15-Sep-2008, 02:40 AM
Bluerinse's Avatar
Bluerinse Bluerinse is offline
Senior Moderator
Posts: 7,722
Points: 2747 Bluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 pointsBluerinse has over 2500 points
Power: 115
None
Join Date: 29 Jun 2003
Location: The Gold Coast, QLD Australia
Certifications: C&G Electronics - MCSA (W2K) MCSE (W2K)
WIP: None but considering SBS
try re-installing the wireless adapter drivers and software maybe.. then i would do a repair as Sparky suggested.


RIP UCM
 
Reply With Quote
  #8  
Old 15-Sep-2008, 02:54 AM
Mr.Cheeks's Avatar
Mr.Cheeks Mr.Cheeks is offline CertForums News Posting Member
Soz Hun I have a headache
Posts: 4,817
Points: 2647 Mr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 pointsMr.Cheeks has over 2500 points
Power: 80
None
Join Date: 23 Feb 2006
Back vital data
Format and reinstall
Better safe than sorry


RIP Dave - You will never be forgotten!
Another good post?
If so, tell a friend, if not, f*ck off then!


 
Reply With Quote
  #9  
Old 15-Sep-2008, 02:57 AM
tripwire45's Avatar
tripwire45 tripwire45 is offline
Administrator
Posts: 14,011
Points: 4638 tripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 points
Power: 197
None
Join Date: 29 Jun 2003
Location: Boise, ID, USA
Certifications: A+ and Network+
Thanks, Sparky, Pete, and Mr. C. That's the plan at this point, but not tonight. Between rebuilding a website for a non-profit (I volunteered) and my son's laptop, I've been sitting in front of a computer all afternoon (I did yard work this morning). Time to unwind before bed by watching the Bourne Ultimatum.


You know, I wish my parents played Mozart when I slept because half the time I don't even know what the heck anyone's talking about!

 
Reply With Quote
  #10  
Old 15-Sep-2008, 03:53 AM
neutralhills's Avatar
neutralhills neutralhills is offline
Valued Member
Posts: 336
Points: 1814 neutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 points
Power: 23
None
Join Date: 23 Feb 2008
Location: Kirriemuir AB Canada
Age: 40
Certifications: Lots.
WIP: Upgrading MS certs
Trip, I had this exact problem two weeks ago. What worked for me was:

1. Install and run UnHackMe 4.8. Let it remove what it finds that isn't an obvious false positive. There are probably some leftover rootkit bits to knock out.

2. Run the latest version of Combofix from bleepingcomputer.com

3. Reset the TCIP/IP stack if connectivity problem has not corrected:
http://support.microsoft.com/kb/299357

If all this doesn't work, you can try the Winsock XP Fix util:

http://www.watchingthenet.com/repair...x-utility.html

Hope this helps

 
Reply With Quote
  #11  
Old 15-Sep-2008, 05:05 AM
tripwire45's Avatar
tripwire45 tripwire45 is offline
Administrator
Posts: 14,011
Points: 4638 tripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 points
Power: 197
None
Join Date: 29 Jun 2003
Location: Boise, ID, USA
Certifications: A+ and Network+
I tried the Winsock XP Fix app and it had limited results.

Part of the problem after I reconnected to the Internet via a hard wire was that I can no longer boot into Safe Mode. I get a black screen and none of the anti-virus scanners work now in normal mode. I'll give it a shot when I get the time which probably won't be until tomorrow now. Also waiting to see what my job situation is going to turn out like tomorrow, so I'm a little distracted.

Thanks for the tips, Sean.


You know, I wish my parents played Mozart when I slept because half the time I don't even know what the heck anyone's talking about!

 
Reply With Quote
  #12  
Old 15-Sep-2008, 06:18 AM
neutralhills's Avatar
neutralhills neutralhills is offline
Valued Member
Posts: 336
Points: 1814 neutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 pointsneutralhills has over 1500 points
Power: 23
None
Join Date: 23 Feb 2008
Location: Kirriemuir AB Canada
Age: 40
Certifications: Lots.
WIP: Upgrading MS certs
Dude. What you're describing is just ugly.

Thoughts...

UnHackMe is still worth a try. I'd consider following it up with a Windows Repair from the install CD and not a rebuild from scratch, if only because I know how limited your time is and how much of a pain in the arse it will be to reconfigure the system to your preferences.

That and having to blow away and reinstall from scratch feels like losing to me. :-(

 
Reply With Quote
  #13  
Old 15-Sep-2008, 01:11 PM
tripwire45's Avatar
tripwire45 tripwire45 is offline
Administrator
Posts: 14,011
Points: 4638 tripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 pointstripwire45 has over 4000 points
Power: 197
None
Join Date: 29 Jun 2003
Location: Boise, ID, USA
Certifications: A+ and Network+
Me too. Actually, I don't think full install CDs come with Windows computers anymore. I think all you get is a Repair CD, so doing a full (legal) install isn't an option (alas). I told my son last night that the repair CD (assuming he can find it) is the option of last resort and that's pretty much where we are at this point.

I also told him it's times like these that make me really love being a Linux user.


You know, I wish my parents played Mozart when I slept because half the time I don't even know what the heck anyone's talking about!

 
Reply With Quote
  #14  
Old 15-Sep-2008, 04:53 PM
BosonMichael's Avatar
BosonMichael BosonMichael is offline
Certification Guru
Posts: 12,462
Points: 6508 BosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 pointsBosonMichael has over 4000 points
Power: 193
None
Join Date: 02 Nov 2006
Location: near Nashville, TN
Age: 39
Certifications: MCSE+I, MCSE: Securi.. huh? out of room?
WIP: Just about everything!
Quote:
Originally Posted by neutralhills View Post
That and having to blow away and reinstall from scratch feels like losing to me. :-(
Yeah, I feel the same way. But that's really the only way to be sure, these days. It ain't like the old days where we could doctor the registry and pry out the virus by hand...


BosonMichael
MCSE+I, MCSE: Security, MCDST, MCDBA, OCP, CCNP, CCDP, CNE, SCSA, Security+, Linux+, Server+, Network+, A+
Served proudly, US Army, 98C Intelligence Analyst, '89-'92
 
Reply With Quote
  #15  
Old 15-Sep-2008, 04:54 PM
BosonMichael's Avatar
BosonMichael BosonMichael is offline
Certification Guru
Posts: 12,462
Points: 6508 BosonMichael has over 4000 pointsBosonMichael has over 4000 points