1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

virus/security problems

Discussion in 'Legacy Windows' started by shenanigins, 2003/06/16.

Thread Status:
Not open for further replies.
  1. 2003/06/19
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    Great we crossed in the mail!

    I feel now comfortable that this is a false positive.

    Go for it!

    mike
     
  2. 2003/06/19
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    Okay.... The router is installed and the dsl modem is connected directly to the router as instructed in the setup directions. As you can see, I have internet access... so apparently THIS part was a success! :)

    I'm going to call it quits for tonight, but will need to return in the a.m. to finish connecting the other computers... providing you think it's safe to proceed?

    I can't begin to thank you all enough for your help and patience! I would have been in a deep mess without your help! :D

    BTW... I've been told I'm very determined before... sometimes it pays off! ;)
     

  3. to hide this advert.

  4. 2003/06/19
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    Pay off yes!

    Yes plug them in tomorrow!

    You have done a fantactic job.

    Tomorrow I will check in from work as I will be in the office all day.

    I will help you connect the others to the Hi spped connection.

    Let me know then how the performance is.


    Mike

    ZZZZZZZZZZZZZZzzzzzzzzzzzzzzzzzzzzzzz
     
    Last edited: 2003/06/19
  5. 2003/06/19
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    Back up to the ipconfig information. Problems there. Any address in the 169.254.x.x range indicates a NIC that can't find the network properly. Take a read thru Automatic Private IP Addressing (APIPA).
     
  6. 2003/06/20
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    Yeah I noticed that also but didn't mention it, as it was not an issue as everything was working and you had enough to do at the time with the primary problem.

    What is best here is to just blank any manual setting on the NIC that now is not being used and disable it in this profile.

    OK Shannon as I see it we have the following things to do.

    Handle this extra NIC; reconfirm the settings of the NIC you have connected to the Router.

    Take a few more steps to assure you are not back in here in a few days to do some of this again.

    Please send the ipconfig again since you now have the Router connected. Then after I see it later today I will tell you how to handle unused NIC.

    Personally I would physically remove it and store it since it should never be needed again. This would free some resources.

    Additionally this would be a good time to blow the dust and lint out the computer case with Air Spray. If you do remove it then also do in device manager.

    So some smaller downloads these should be run on all computers.

    HiJackThis: http://www.tomcoyote.org/hjt/
    Run HiJackThis and go to config then Misc tools then click generate startup list. Paste this list back so we can advise on any problems. Do this on each computer but be sure to identify each computer with each list. This should allow us to advise on possible problems but also fine tune the performance.

    BTW: after all is over with do a scandisk and defrag last on all.

    These are well documented at the site so d/l and run
    NSClean cleanups and exploit fixes

    http://nsclean.com/dsostop.html
    http://nsclean.com/htastop.html
    http://nsclean.com/0click.html
    http://nsclean.com/socklock.html
    http://nsclean.com/sclean.html

    Firewall. Download and install on at least the 2K machine.
    http://www.kerio.com/kpf_download.html
    This firewall will complement the Router further and block uninvited guests from the outside word. Additionally it will prevent something bad that does get on the computer somehow from being able to get back out onto the www to invite friends and relatives and other gang members in for a party. Your POP should then purchase this later after it shows what it can do. SPECIAL NOTE: after you install this it will be in learn mode so every time you run a program that tries to get on the www it will warn you. Of course give Internet Explorer and Outlook permission and tell it to remember this. You should go ahead and give this permission yourself. Now what you need to impress on POP is to call you if something else comes up one day and wants out. Don’t just give it permission unless it is legitimate. Program and windows updates will do this but they are OK You are looking for the unexpected / unexplained here.

    OK so for hi speed Internet access on the other 2 computers

    First send the ipconfigs for these 2. Hopefully the Workgroup is the same on all 3 computers. General network access was working for them before since you mentioned no problems here. In Network Neighborhood / My Network Places (2K). All computers should see all the rest. So any problems sharing drives and printers let us know.

    Suggestion add Netbeui protocol on all three computers and on the two 98 machines go to advanced and make it the default protocol. Problems just ask.

    Ok today should be simpler and more straight forward, and should not take as long.

    Post me the results and let me know how the system is performing.

    Another thought for later. After you get hi speed on all, you should do a windows update I am sure they are all out of date.

    Mike

    PS I just noticed the links to NSCLEAN are not working. They were a few days ago. They may be down temp. If they are not up when you read this let me know and I will get alternative source.
     
  7. 2003/06/20
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    Ok Shannon

    At the office now. Will try to keep a check, but sometimes not easy if very busy.

    An additional note on firewall. After installed if there was somehow a worm or trojan left on the computer the firewall will catch it if it tries to get out. Watch for this. If so it will allow us not only to know but perhaps to pinpoint it.

    Also one more small d/l we will use it to cleanup your startup list.

    Startup control
    http://www.mlin.net/StartupCPL.shtml

    This gives simple and full control of what starts at boot up. After install there will be a Startup icon in control panel. Why this over Msconfig? Msconfig only allows unchecking/disabling of items. Startup Control panel allows deleting items or moving from startup to run as a service etc.

    Put on all computers.

    Mike
     
  8. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    Good morning, guys... looks like I should have checked back here this morning before proceeding with the router connection to the other computers, huh?

    I got here early this morning and started connecting the other slaves. Everything was working fine on the administrator computer. I connected the first computer... using the connection wizard disk... all went fine. I connected slave 2 the same way... in the process somehow I lost the internet connection. However the router connection to the computer appeared to set up properly. I connected the 3rd slave and it is communicating with the network correctly, as well. But now I have no internet connection on any of the computers.

    The dsl modem has a "restore" option that basically troubleshoots the connection. The modem appears to be okay, but is not connecting. I'm at a loss now.

    I haven't done any of the other things you listed in the last couple of posts, because I didn't check here this morning before proceeding. I'm wondering what my next step should be now?

    *help*

    ~Shannon
     
  9. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    Here's the ipconfig info from today:



    Windows 2000 IP Configuration



    Host Name . . . . . . . . . . . . : administrater
    Primary DNS Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Hybrid

    IP Routing Enabled. . . . . . . . : No

    WINS Proxy Enabled. . . . . . . . : No


    Ethernet adapter Local Area Connection 3:



    Media State . . . . . . . . . . . : Cable Disconnected

    Description . . . . . . . . . . . : Efficient Networks Enternet P.P.P.o.E Adapter
    Physical Address. . . . . . . . . : 44-45-53-54-77-77


    Ethernet adapter Local Area Connection 2:



    Media State . . . . . . . . . . . : Cable Disconnected

    Description . . . . . . . . . . . : D-Link DFE-530TX+ PCI Adapter
    Physical Address. . . . . . . . . : 00-05-5D-43-B9-C4


    Ethernet adapter Local Area Connection:



    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network Connection
    Physical Address. . . . . . . . . : 00-10-DC-58-D6-4F

    DHCP Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    IP Address. . . . . . . . . . . . : 192.168.1.100

    Subnet Mask . . . . . . . . . . . : 255.255.255.0

    Default Gateway . . . . . . . . . : 192.168.1.1

    DHCP Server . . . . . . . . . . . : 192.168.1.1

    DNS Servers . . . . . . . . . . . : 192.168.1.1
    Lease Obtained. . . . . . . . . . : Friday, June 20, 2003 10:15:49 AM

    Lease Expires . . . . . . . . . . : Friday, June 20, 2003 10:20:49 AM
     
  10. 2003/06/20
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    Shannon

    Only a moment but can get back to you in about 1.5 hrs.

    For now do not do a restore. Disconnect all other computers. Turn off dsl modem and router. Shut down (not reboot) 2K. While it is off turn modem back on then the router. Wait 30 or so seconds and then bring up the 2k. Confirm internet is avail. If so get the d/ls I sent this morn and install and do on all until I can get back.


    Mike
     
  11. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    BTW... I ran all the NSCLEAN utilities yesterday on all the computers. Do I need to run them again today?
     
  12. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    I shut everything off as instructed... gave it 5 minutes... then turned back on in the order listed above... still no internet connection. However, all the computers are communicating with each other so the business end of things are operational for now. That's the big thing for the moment.

    Will wait to hear back from you again on how to proceed.

    Shannon
     
  13. 2003/06/20
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    On the NSClean. No, I forgot that I had already sent them then.

    Are you saying even the 2K machine is not connecting anymore?

    Did you remove the unused Network card?

    And one very important question? The ipconfig on the 2K was it after or before all stoped working.

    Send me a fresh one so that I can see what changed.

    Mike
     
  14. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    Correct on the 2k machine not connecting either. I didn't remove anything... I actually ran into this problem first thing this morning before I checked back on here. I didn't know anything about the unused NIC.

    The ipconfig I sent is AFTER the connections stopped working.
     
  15. 2003/06/20
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    It says in the ipconfig that the cable is disconnected. Did you do this ipconfig with the cable disconnected?

    Do you have a confirmation light on the network card in the computer and the port light for that cable on the hub.

    If you have lights do this and report back.

    command prompt

    ping 192.168.1.1

    then

    ping yahoo.com

    Who is the ISP?

    What is your ISP Domain name like bellsouth.net or what is the name to the right of the @ in the email address.

    Mike
     
  16. 2003/06/20
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    Oops we were writing at the same time.

    Shannon that is what I needed. While it was working as last night.

    Shut down. Pop case remove unused NIC (Network interface Card). Get it out of the way.

    Try this on the 2K machine. Network properties - Local area network properties - Dbl click Internet protcol (Tcp).

    Key these values

    leave IP

    gateway 192.168.1.1

    dns 151.164.17.201 and 151.164.11.201


    Then reboot and recheck internet.

    Mike
     
  17. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    Mike,

    The only unused card I am finding inside the computer is the dsl network card, which I didn't unplug until I connected the router last night. I can remove it, but this doesn't explain the card that showed unused yesterday before I added the router? I'm confused at this point... suggestions?
     
  18. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    There is no IP address assigned in the tcp/ip properties.
     
  19. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    One other thing.... the computers are all connected to the router and all the computers have access to the network, but not all of the lights are on for each of the connections on the router. The LED light is on for all of them, but the last 2 lines I connected don't light up any other lights (other than the LED) even though they are communicating with each other.
     
  20. 2003/06/20
    shenanigins

    shenanigins Inactive Thread Starter

    Joined:
    2002/08/02
    Messages:
    104
    Likes Received:
    0
    Most recent ipconfig info:



    Windows 2000 IP Configuration



    Host Name . . . . . . . . . . . . : administrater
    Primary DNS Suffix . . . . . . . :
    Node Type . . . . . . . . . . . . : Hybrid

    IP Routing Enabled. . . . . . . . : No

    WINS Proxy Enabled. . . . . . . . : No


    Ethernet adapter Local Area Connection 3:



    Media State . . . . . . . . . . . : Cable Disconnected

    Description . . . . . . . . . . . : Efficient Networks Enternet P.P.P.o.E Adapter
    Physical Address. . . . . . . . . : 44-45-53-54-77-77


    Ethernet adapter Local Area Connection:



    Connection-specific DNS Suffix . :
    Description . . . . . . . . . . . : Intel(R) PRO/100 VE Network Connection
    Physical Address. . . . . . . . . : 00-10-DC-58-D6-4F

    DHCP Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    IP Address. . . . . . . . . . . . : 192.168.1.102

    Subnet Mask . . . . . . . . . . . : 255.255.255.0

    Default Gateway . . . . . . . . . : 192.168.1.1

    DHCP Server . . . . . . . . . . . : 192.168.1.1

    DNS Servers . . . . . . . . . . . : 151.164.17.201
    151.164.11.201
    Lease Obtained. . . . . . . . . . : Friday, June 20, 2003 1:00:24 PM

    Lease Expires . . . . . . . . . . : Friday, June 20, 2003 1:05:24 PM
     
  21. 2003/06/20
    mflynn

    mflynn Inactive

    Joined:
    2002/08/14
    Messages:
    4,141
    Likes Received:
    9
    Shannon

    Ok don't get bogged down on this now.

    1. send me the ISP info.

    2. before the router you needed 2 network cards, one for the hub and one for the dsl modem.

    3. so now you have the dsl modem into the router. There is a network card in the computer that has no cable plugged into it. Remove it!

    ISP info

    mike
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.