1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved [Unable to connect to internet, use messenger or AVG, etc]

Discussion in 'Malware and Virus Removal Archive' started by TinyTuba822, 2008/07/25.

  1. 2008/08/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Try pinging 64.233.187.99

    What do you get with the command nslookup ?
     
  2. 2008/08/24
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    That address didnt work. nslookup gives me ekudc1.eku.edu and the IP 157.89.36.108
     

  3. to hide this advert.

  4. 2008/08/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Do you get a response pinging either of the following addresses?

    157.89.36.108
    157.89.36.109
     
  5. 2008/08/24
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    no, it said request timed out 4 times before it quit.
     
  6. 2008/08/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Please run WinsockFixWinAll again if you still have it. Reboot when complete and see if there's any change.
     
  7. 2008/08/24
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    still no reply from the DNS servers after the reboot. I did get a resetlog, and it gave me a lot more info than the last time.

    reset SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{6CB1BA84-C586-4481-AE8D-E9E6960A7F6C}\NameServerList
    old REG_MULTI_SZ =
    <empty>

    added SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{6CB1BA84-C586-4481-AE8D-E9E6960A7F6C}\NetbiosOptions
    deleted SYSTEM\CurrentControlSet\Services\Netbt\Parameters\EnableProxy
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{6CB1BA84-C586-4481-AE8D-E9E6960A7F6C}\NameServer
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D56DA9D9-46FF-45A2-8A0F-D2D44C423BCC}\IpAutoconfigurationAddress
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D56DA9D9-46FF-45A2-8A0F-D2D44C423BCC}\IpAutoconfigurationMask
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{D56DA9D9-46FF-45A2-8A0F-D2D44C423BCC}\IpAutoconfigurationSeed
    <completed>

    reset SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{02C7BE5B-97AB-4595-AC40-AE470AC306B5}\NameServerList
    old REG_MULTI_SZ =
    <empty>

    added SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{02C7BE5B-97AB-4595-AC40-AE470AC306B5}\NetbiosOptions
    deleted SYSTEM\CurrentControlSet\Services\Netbt\Parameters\EnableLmhosts
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{02C7BE5B-97AB-4595-AC40-AE470AC306B5}\NameServer
    added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\DisableDynamicUpdate
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\IpAutoconfigurationAddress
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\IpAutoconfigurationMask
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\IpAutoconfigurationSeed
    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\NameServer
    old REG_SZ = 208.67.222.222,208.67.220.220

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\RawIpAllowedProtocols
    old REG_MULTI_SZ =
    0

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\TcpAllowedPorts
    old REG_MULTI_SZ =
    0

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\UdpAllowedPorts
    old REG_MULTI_SZ =
    0

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{364D3887-9944-488C-B429-A0B6AD0ADF31}\AddressType
    old REG_DWORD = 1

    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{364D3887-9944-488C-B429-A0B6AD0ADF31}\IpAutoconfigurationAddress
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{364D3887-9944-488C-B429-A0B6AD0ADF31}\IpAutoconfigurationMask
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{364D3887-9944-488C-B429-A0B6AD0ADF31}\IpAutoconfigurationSeed
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DontAddDefaultGatewayDefault
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableIcmpRedirect
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableSecurityFilters
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution
    reset Linkage\UpperBind for USB\VID_07B2&PID_7030\ENV-51200000. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for PCI\VEN_11AB&DEV_1FAA&SUBSYS_6B001385&REV_03\4&10416D21&0&00F0. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for PCI\VEN_8086&DEV_1229&SUBSYS_000C8086&REV_08\4&10416D21&0&00F0. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for ROOT\MS_NDISWANIP\0000. bad value was:
    REG_MULTI_SZ =
    PSched

    <completed>

    reset SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{02C7BE5B-97AB-4595-AC40-AE470AC306B5}\NameServerList
    old REG_MULTI_SZ =
    <empty>

    added SYSTEM\CurrentControlSet\Services\Netbt\Parameters\Interfaces\Tcpip_{02C7BE5B-97AB-4595-AC40-AE470AC306B5}\NetbiosOptions
    deleted SYSTEM\CurrentControlSet\Services\Netbt\Parameters\EnableLmhosts
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{02C7BE5B-97AB-4595-AC40-AE470AC306B5}\NameServer
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\IpAutoconfigurationAddress
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\IpAutoconfigurationMask
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{1553B2E8-A076-47ED-909C-9297430D2234}\IpAutoconfigurationSeed
    added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89F4BA47-C5D9-451C-AFB5-ADBA7B5D68D9}\DisableDynamicUpdate
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89F4BA47-C5D9-451C-AFB5-ADBA7B5D68D9}\IpAutoconfigurationAddress
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89F4BA47-C5D9-451C-AFB5-ADBA7B5D68D9}\IpAutoconfigurationMask
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89F4BA47-C5D9-451C-AFB5-ADBA7B5D68D9}\IpAutoconfigurationSeed
    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89F4BA47-C5D9-451C-AFB5-ADBA7B5D68D9}\RawIpAllowedProtocols
    old REG_MULTI_SZ =
    0

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89F4BA47-C5D9-451C-AFB5-ADBA7B5D68D9}\TcpAllowedPorts
    old REG_MULTI_SZ =
    0

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{89F4BA47-C5D9-451C-AFB5-ADBA7B5D68D9}\UdpAllowedPorts
    old REG_MULTI_SZ =
    0

    added SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8A92D973-56C4-4EFC-9C73-E3C86766DF4B}\DisableDynamicUpdate
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8A92D973-56C4-4EFC-9C73-E3C86766DF4B}\IpAutoconfigurationAddress
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8A92D973-56C4-4EFC-9C73-E3C86766DF4B}\IpAutoconfigurationMask
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8A92D973-56C4-4EFC-9C73-E3C86766DF4B}\IpAutoconfigurationSeed
    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8A92D973-56C4-4EFC-9C73-E3C86766DF4B}\RawIpAllowedProtocols
    old REG_MULTI_SZ =
    0

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8A92D973-56C4-4EFC-9C73-E3C86766DF4B}\TcpAllowedPorts
    old REG_MULTI_SZ =
    0

    reset SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{8A92D973-56C4-4EFC-9C73-E3C86766DF4B}\UdpAllowedPorts
    old REG_MULTI_SZ =
    0

    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DontAddDefaultGatewayDefault
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableIcmpRedirect
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\EnableSecurityFilters
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\SearchList
    deleted SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\UseDomainNameDevolution
    reset Linkage\UpperBind for PCI\VEN_14E4&DEV_1677&SUBSYS_01771028&REV_01\4&1D7EFF9E&0&00E0. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for PCI\VEN_11AB&DEV_1FAA&SUBSYS_6B001385&REV_03\4&10416D21&0&10F0. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for USB\VID_07B2&PID_7030\ENV-51200000. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for PCI\VEN_11AB&DEV_1FAA&SUBSYS_6B001385&REV_03\4&10416D21&0&00F0. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for PCI\VEN_8086&DEV_1229&SUBSYS_000C8086&REV_08\4&10416D21&0&00F0. bad value was:
    REG_MULTI_SZ =
    odysseyIM3

    reset Linkage\UpperBind for ROOT\MS_NDISWANIP\0000. bad value was:
    REG_MULTI_SZ =
    PSched

    <completed>
     
  8. 2008/08/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Is ipconfig /all the same as last time?

    Are you connected directly to the modem now?
     
  9. 2008/08/24
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    As direct as I can get with their network.

    Ipconfig:


    Windows IP Configuration



    Host Name . . . . . . . . . . . . : TINY

    Primary Dns Suffix . . . . . . . :

    Node Type . . . . . . . . . . . . : Mixed

    IP Routing Enabled. . . . . . . . : No

    WINS Proxy Enabled. . . . . . . . : No

    DNS Suffix Search List. . . . . . : eku.edu

    eku.edu



    Ethernet adapter Wireless Network Connection 6:



    Connection-specific DNS Suffix . : eku.edu

    Description . . . . . . . . . . . : NETGEAR WG311v3 802.11g Wireless PCI Adapter #2

    Physical Address. . . . . . . . . : 00-1B-2F-C6-D7-35

    Dhcp Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    IP Address. . . . . . . . . . . . : 157.89.250.58

    Subnet Mask . . . . . . . . . . . : 255.255.254.0

    Default Gateway . . . . . . . . . : 157.89.250.128

    DHCP Server . . . . . . . . . . . : 1.1.1.1

    DNS Servers . . . . . . . . . . . : 157.89.36.108

    157.89.36.109

    Primary WINS Server . . . . . . . : 157.89.9.38

    Lease Obtained. . . . . . . . . . : Sunday, August 24, 2008 2:51:02 AM

    Lease Expires . . . . . . . . . . : Sunday, August 24, 2008 3:01:02 AM



    Ethernet adapter Local Area Connection 2:



    Connection-specific DNS Suffix . : eku.edu

    Description . . . . . . . . . . . : Broadcom NetXtreme 57xx Gigabit Controller

    Physical Address. . . . . . . . . : 00-11-11-80-46-E1

    Dhcp Enabled. . . . . . . . . . . : Yes

    Autoconfiguration Enabled . . . . : Yes

    IP Address. . . . . . . . . . . . : 157.89.187.51

    Subnet Mask . . . . . . . . . . . : 255.255.255.0

    Default Gateway . . . . . . . . . : 157.89.187.128

    DHCP Server . . . . . . . . . . . : 157.89.89.15

    DNS Servers . . . . . . . . . . . : 157.89.36.108

    157.89.36.109

    Primary WINS Server . . . . . . . : 157.89.89.17

    Lease Obtained. . . . . . . . . . : Sunday, August 24, 2008 2:22:58 AM

    Lease Expires . . . . . . . . . . : Sunday, August 31, 2008 2:22:58 AM
     
  10. 2008/08/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That computer appears to be connecting properly now. It's possible their server won't respond to pinging. I would suggest you contact campus IT and see if there's something else that needs to be done for throughput to the internet.
     
  11. 2008/08/24
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    Ill give them a call tomorrow, and see what they can do. If they cant fix the problem, I'll probably be right back here though.
     
  12. 2008/08/24
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
  13. 2008/08/26
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    No, I didn't. You don't have to change the name to the email name. It will let you download the software without doing so. I have already contacted them and brought them the computer. Since they are really busy it will at least be another 5 business days. The version of CC Agent was the one from the website. I can't put symantec on the computer without net access. they stopped giving us disks since most people could get to the internet and download the required software.
     
  14. 2008/08/26
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Well, if you say so. I was only going by their instructions in the first link. Hopefully they won't have too much trouble with it and you'll get it back soon. :)
     
  15. 2008/08/27
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    I hope so too. I have a sneaking suspicion in the back of my head that they won't be able to fix it. I really hope I am wrong.
     
  16. 2008/09/01
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    Still haven't gotten the comp back. Did some playing around on my roommate's computer and pinged the network that she's connected to. Since I got a reply, EKU doesn't have anything here that blocks the ping command.
     
  17. 2008/09/03
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    Update: The computer Has been returned to me. ResNet could not fix the problem. A friend of mine tried running an OS that runs from a CD. Internet worked just fine on it. Reinstalled XP Media Center 05, and the computer now works just fine. I am posting this from the computer. :)
     
  18. 2008/09/03
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    I'm happy to hear it's working again. Did you do a repair install or a clean install? A clean install involves formatting the drive, removing everything on it and starting from scratch. If only a repair was done, I recommend you run an online Kaspersky scan to make sure there aren't any leftovers from the infection(s).
     
  19. 2008/09/03
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    I told it to do a new install, but when it boots up I now have 3 XP media center edition 2005's to choose from instead of 2. My guess is it didn't completely remove everything on it that was there before, even though I had to reinstall all of the drivers for my hardware. Kaspersky is running as we speak.
     
    Last edited: 2008/09/03
  20. 2008/09/04
    TinyTuba822

    TinyTuba822 Inactive Thread Starter

    Joined:
    2007/10/05
    Messages:
    102
    Likes Received:
    0
    There are still some infections, but the scan is only 23%. I'll post the log in the morning when I get up.
     
  21. 2008/09/04
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    We'll be here (ok, I won't be till after work ..... lol) :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.