• Home
  • Reviews
  • Articles
  • News
  • Tools
  • GamingHeaven
  • Forums
  • Network
 

Go Back   DriverHeaven.net > Forums > Hardware and Related Topics > Hardware Discussion & Support

Notices

Reply
 
LinkBack Thread Tools
Old Oct 16, 2005, 12:08 AM   #1
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

a virus maybe?

well, today my sister aproached me earlier today telling me that she can't connect to the internet. I tried setting up her connection like i normally do (through the network setup wizard), but no avail. So, i went to set it up manually. again, nothing. Now, i'm thinking she has a virus on her computer because as i was setting up the network on her end, Norton flashed saying something about attempting to quarantine a file. So, since then, i've been thinking a virus has gotten into her rig. She doesn't want me to reformat, but i'm telling her it's really the only answer at this point. So now she's all like "well, see what you can do". So now, i'm here asking you guys what you think. Here's a pic of her task manager, see what you guys can see that shouldn't be there.

CDsDontBurn is online now   Reply With Quote
Old Oct 16, 2005, 12:43 AM   #2
TJ-
DriverHeaven Extreme Member
 
TJ-'s Avatar
 
Join Date: Oct 2004
Location: Infinity
Posts: 3,682
TJ- is on a distinguished road

why would you have to reformat? Get a real av (symantec) and quarantine or delete the virus.

You just wanted to show your desktop didnt you

edit* goto www.bitdefender.com and do a free online scan, the best scan on the net!
TJ- is offline   Reply With Quote
Old Oct 16, 2005, 12:59 AM   #3
DriverHeaven Extreme Member
 
Necrosis's Avatar
 
Join Date: May 2002
Location: Ohio
Posts: 8,480
Necrosis will become famous soon enough
System Specs

Exactly what Zion said..if you think virus it's always best to get two opinions from anti-virus software.
Necrosis is online now   Reply With Quote
Old Oct 16, 2005, 01:02 AM   #4
DriverHeaven Extreme Member
 
Tipstaff's Avatar
 
Join Date: Jul 2002
Location: Real captial of Canada: Toronto
Posts: 4,742
Tipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of light
System Specs

Quote:
Originally Posted by [zi0n]aXe
why would you have to reformat? Get a real av (symantec) and quarantine or delete the virus.

You just wanted to show your desktop didnt you

edit* goto www.bitdefender.com and do a free online scan, the best scan on the net!
zion, my man, he has Norton AV.. which is from Symantec.

But your right, zion, I would try some of the online scanners to see what they come up with, or even changing it to something like AVG or McAfee to get a second opinion.

CDs, none of the apps running look suspecious to me.

You might want to try running a Winsock repair tool like LSP-Fix, or WinSock XP Fix. After you reboot run a TCP optimizing program like Speedguides TCP Optimizer. Might just be that the TCP protocols need to be reset.

Speaking of which, what type of connection is it? PPPOE, or direct (such as cable)?
Tipstaff is offline   Reply With Quote
Old Oct 16, 2005, 01:13 AM   #5
DriverHeaven Extreme Member
 
Join Date: Jun 2004
Location: Floatin'...
Posts: 4,958
Drakon will become famous soon enough

Actually task manager doesn't really do a good job of showing virii and trojans. I usually use an app called PrcView. Great little app and it works all the time
Drakon is offline   Reply With Quote
Old Oct 16, 2005, 01:32 AM   #6
DriverHeaven Extreme Member
 
Tipstaff's Avatar
 
Join Date: Jul 2002
Location: Real captial of Canada: Toronto
Posts: 4,742
Tipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of lightTipstaff is a glorious beacon of light
System Specs

Quote:
Originally Posted by Drakon
Actually task manager doesn't really do a good job of showing virii and trojans. I usually use an app called PrcView. Great little app and it works all the time
Looks like a good app. I also use HijackThis, but it's not for the squeamish.
Tipstaff is offline   Reply With Quote
Old Oct 16, 2005, 02:19 AM   #7
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

Quote:
Originally Posted by [zi0n]aXe
why would you have to reformat? Get a real av (symantec) and quarantine or delete the virus.

You just wanted to show your desktop didnt you

edit* goto www.bitdefender.com and do a free online scan, the best scan on the net!
but like i said, she can't connect to the internet
CDsDontBurn is online now   Reply With Quote
Old Oct 16, 2005, 02:23 AM   #8
DriverHeaven Granddaddy
 
Dyre Straits's Avatar
 
Join Date: May 2002
Location: Georgia, USA
Posts: 12,115
Dyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to allDyre Straits is a name known to all

CDs,

My mom's rig often gets where it can't connect and I find that either AD-Aware and/or Spybot S&D will take care of it.

I think I finally got her where she uses these consistently on her own.
Dyre Straits is offline   Reply With Quote
Old Oct 16, 2005, 02:40 AM   #9
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

well, i've already d/led all the stuff you've mentioned. one thing i did forget to mention is that she is on wireless and i have my connection on WEP. Now, it's always been able to connect no problem after i enter the password and whatnot, but now whenever i put in the password, it doesn't want to connect. I could test out the connection w/WEP disabled, but i don't want to run it like that 24/7 you know? I haven't yet reset my router, i'll do that next i guess. If that doesn't work, i'll run the tools you guys gave me links to, and if that don't work......dun dun dun.....REFORMAT!!!
CDsDontBurn is online now   Reply With Quote
Old Oct 16, 2005, 08:56 AM   #10
DriverHeaven Addict
 
Join Date: Mar 2005
Posts: 362
soloz2 is on a distinguished road

Sometimes a simple fix when using wireless is to turn off the WEP on your router and see if you can connect like that. While you're into the settings on your router check and see if for some reason the lease expired on your siter's computer. I had a router once that didn't always renew leases for some reason. Try to manually renew it if this is the case then just watch and see what happens.
soloz2 is offline   Reply With Quote
Old Oct 16, 2005, 11:03 AM   #11
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

hmm....well, don't really have all the time in the world ATM. i gotta start getting for work. will have plenty of time to look at this problem when i get back though for sure
CDsDontBurn is online now   Reply With Quote
Old Oct 16, 2005, 12:21 PM   #12
DriverHeaven Extreme Member
 
The_Neon_Cowboy's Avatar
 
Join Date: Dec 2002
Location: U.S.A.
Posts: 16,122
The_Neon_Cowboy is on a distinguished road
System Specs

Psst:
http://www.liutilities.com/products/wintaskspro/
The_Neon_Cowboy is offline   Reply With Quote
Old Oct 16, 2005, 11:33 PM   #13
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

well, i was playing around w/my router just now, and i disabled the WEP encryption. Right after i did that, i went back to my sister's computer and had her computer connect. It connected just fine. But like i said in my one post, i don't want to leave WEP disabled cuz i don't want peeps lagging up on my bandwith and checking out my madness.
CDsDontBurn is online now   Reply With Quote
Old Oct 16, 2005, 11:45 PM   #14
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

update: she's reluctantly agreeing with me to actually just go ahead with the reformat .
CDsDontBurn is online now   Reply With Quote
Old Oct 17, 2005, 12:44 AM   #15
DriverHeaven Senior Member
 
Son_of_Thunder's Avatar
 
Join Date: Jun 2004
Location: Kalamazoo, MI
Posts: 1,426
Son_of_Thunder is on a distinguished road
System Specs

I wouldn't format quite yet. I'd play around with your router a bit more, update it's firmware maybe. Also, you could try deleting all of her connections in the network connections window and letting it set up a fresh one.
Son_of_Thunder is offline   Reply With Quote
Old Oct 17, 2005, 12:00 PM   #16
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

well, i'm looking into this right now. Though the thing about this is that i don't understand why out of nowhere her computer would just stop connecting to the router. It was working fine like 3 days ago .

Also, after i disabled the WEP encryption last night, her computer would be able to connect to the internet, but only for a short period of time. After that, it would cut off again.
CDsDontBurn is online now   Reply With Quote
Old Oct 17, 2005, 12:06 PM   #17
Giggity!
 
niceguyrichy's Avatar
 
Join Date: Apr 2005
Location: ___
Posts: 4,116
niceguyrichy is a name known to allniceguyrichy is a name known to allniceguyrichy is a name known to allniceguyrichy is a name known to allniceguyrichy is a name known to allniceguyrichy is a name known to all
System Specs

winsock fix.


worked wonders for me in the past.
niceguyrichy is offline   Reply With Quote
Old Oct 17, 2005, 12:27 PM   #18
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

i tried using all them tools everybody gave me last night, but still no avail
CDsDontBurn is online now   Reply With Quote
Old Oct 17, 2005, 12:34 PM   #19
DH SuperMod
 
Vikingod's Avatar
 
Join Date: Jul 2004
Location: By the light of lamp I sit and type...
Posts: 15,760
Vikingod is just super!Vikingod is just super!Vikingod is just super!Vikingod is just super!Vikingod is just super!Vikingod is just super!Vikingod is just super!
System Specs

Did she use the latest windows updates? I heard there was some problem with them that was affecting peoples privilages and networking abilities. Read here http://support.microsoft.com/kb/909444

This may not help you out, I haven't looked into it that deeply. Good luck.
Vikingod is offline   Reply With Quote
Old Oct 17, 2005, 01:48 PM   #20
Just an Average Joe...
 
Rasta Monsta's Avatar
 
Join Date: Aug 2002
Location: On my way to live in Haiti or something
Posts: 1,598
Rasta Monsta is a glorious beacon of lightRasta Monsta is a glorious beacon of lightRasta Monsta is a glorious beacon of lightRasta Monsta is a glorious beacon of lightRasta Monsta is a glorious beacon of lightRasta Monsta is a glorious beacon of light

Quote:
Originally Posted by CDsDontBurn
update: she's reluctantly agreeing with me to actually just go ahead with the reformat .
I have one suggestion to help ease her pain. . .I did this on a friend's rig not long ago.

Use Partition Magic to make a nw partition on her HD, then right click "My Documents" and change location to new partition. That way, you can wipe the O/S partition, she can have a clean install AND keep most of her stuff.

rasta
Rasta Monsta is offline   Reply With Quote
Old Oct 17, 2005, 02:17 PM   #21
Allergic to WiFi
 
Yousaif's Avatar
 
Join Date: Jan 2005
Location: Wyoming, MI, USA
Posts: 854
Yousaif is on a distinguished road

Dunno if you've tried this, but an easy way to repair a damaged WINSOCK is to go to start> run and type:

NETSH WINSOCK RESET CATALOG

Hit enter and reboot.

Otherwise, I'm as stumped as you are. Unless Sygate personal firewall is running on the machine. If so then uninstall it and DL it again.
Yousaif is offline   Reply With Quote
Old Oct 17, 2005, 03:56 PM   #22
Driverheaven brewmaster
 
riles9262's Avatar
 
Join Date: Oct 2002
Location: British Columbia, Canada
Posts: 4,835
riles9262 will become famous soon enough

Ya I'd try the command that yousaif mentioned, it works really well if she has sp2...although I think you have to type it in the command prompt, not just the run menu.
riles9262 is offline   Reply With Quote
Old Oct 17, 2005, 04:47 PM   #23
F.U.B.A.R.
 
CDsDontBurn's Avatar
 
Join Date: May 2003
Location: Southern California
Posts: 19,023
CDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura aboutCDsDontBurn has a spectacular aura about
System Specs

thanks guys . i'll try that command line that yousaif mentioned . As for copying over the "my documents" folder, i could just copy the folder over to her secondary HDD, so no worries there . I did d/l the latest available updates on her machine only days before this had happened.

Well, like i said before, i'll give those suggestions a shot, and see if it can get back online. If not, imna go ahead and reformat the machine.
CDsDontBurn is online now   Reply With Quote
Old Oct 17, 2005, 05:29 PM   #24
Allergic to WiFi
 
Yousaif's Avatar
 
Join Date: Jan 2005
Location: Wyoming, MI, USA
Posts: 854
Yousaif is on a distinguished road

Quote:
Originally Posted by riles9262
Ya I'd try the command that yousaif mentioned, it works really well if she has sp2...although I think you have to type it in the command prompt, not just the run menu.
It works in both the run line and the command window.

I probably run that comand 5 times a day on caller's PC's. Seems that the latest spyware/adware/virii are always fubaring the winsock.

Alternately you can go into the registry and under HKEY LOCAL MACHINE> SYSTEM >CONTROL SET 001 > SERVICES delete the winsock and winsock 2 keys, reboot, then go into the local network connection and reinstall TCP/IP.

edit: But you're better off trying the NETSH command first and only going into registry as a last resort, i.e. right before you reformat

Last edited by Yousaif; Oct 17, 2005 at 05:30 PM. Reason: Second thought
Yousaif is offline   Reply With Quote
Old Oct 17, 2005, 05:38 PM   #25