Network not Found error

Discussion in 'Malware Help (A Specialist Will Reply)' started by amandalee76, Jan 25, 2006.

  1. amandalee76

    amandalee76 Private E-2

    Hey here I am yet again!!! Love you guys!

    Ok heres the low down:

    My computer is fine, we are still dealing with the BF's comp...New issues now though...

    He is XP Pro with SP2..Up until last week, the updates were done automatically...

    We have been on this network since May of 2005, never had the following issue b4: (Keep in mind he had a lot of spyware on his comp - through using the various suggestions you all have, I beleive I finally got rid of those....)

    When you open IE, you get an error message that says "network slow or not found"..We have a Dlink modem and a Realtek router (hub is it called?)...I ran the auto network settings, nothings changed...

    I opened CMD and tried to ping and I get an error message:""Command Prompt Ping 127.0.0.1
    The NTVDM Cpu has encountered illegal instuction"

    We have run: Smit, CWShredder, Ad-Aware, Microsoft Anti Spyware, winsokfix (no it didnt fix), Free AVG, and Spybot S& D...

    I no longer have the hijacked homepage for IE and the comp is running much much faster...

    Does anyone out there know why we could be getting these errors?

    (and yes, I tried to unplug and re plug in all parts: Modem & router etc..)


    Again,

    I owe you all big time!! Hugs, Amanda
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems may not be malware related.

    First just try the below (choice the one that is correct for your OS):

    For Windows XP Pro: download and run XPproFix
    For Windows XP Home: download and run XPHomeFix

    Now see if you can ping. Are you sure the router is working okay? Can you login to it using the PC?
     
  3. amandalee76

    amandalee76 Private E-2

    His comp is XP pro...so I will go and run that fix in jsut a min...

    I wanted to let you know that i am not sure if the router is working, but it was working great up until about a week ago, and all its green lights are on...


    Ok brb with ping results, ty for assistance so far!
     
  4. amandalee76

    amandalee76 Private E-2

    ok I burned the XP Pro fix that you recommended and uploaded to BF's comp, it unzipped itself to System 32 file...Is this normal?


    I tried to ping, but still got same error message..
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes that is normal. It is trying to fix/replace files that below in the system32 folder. These type of messages are normally fixed by running what I gave you to run. Have you rebooted since installing that fix? If not, try again after reboot.

    If ping still does not work continue reading for more info on this type of problem.
    See the following link for some info on that error message: http://support.microsoft.com/kb/156687/

    You can also look at the info provided in the following link which may help: http://support.microsoft.com/kb/314106

    Do other DOS type commands run OK? Try the procedure in the below and attach the log if it works:

    Using GetRunKey
     
    Last edited: Jan 26, 2006
  6. amandalee76

    amandalee76 Private E-2

    Hi Chaz, sorry busy day here...

    Yes after the program unzipped itself, I rebotted prior to trying the ping again...

    I am about to try your last suggestions and will get back to you in a few, Thanks !!!
     
  7. amandalee76

    amandalee76 Private E-2

    I read through the links you provided, neither really applies because I can get the CMD prompt open, I just get error messages trying to ping..

    You asked if it will show any other cmd prompts, but I know no other ones to test (I am only aware of the ping test)

    I got the runkeys loaded and ran, but I dont think its gonna be much help...I got about 10 error messages while it was attempting to run...

    Thanks for everything so far,

    Amanda

    runkey.txt file is attached!
     

    Attached Files:

  8. amandalee76

    amandalee76 Private E-2

    For some reason I just remmebered that way back when I used to be able to type DIR into a cmd...

    I went onto bf's comp and typed dir, and I get no errors
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What error messages did you get? Give the exact word for word message. This is part of what I was trying to test.

    Also run Windows Explorer and make sure viewing of hidden files, system files, and file extensions are enabled per the READ ME. The navigate to c:\windows\system32

    Look for ping.exe but also look for ping.com. Tell me what you find and what the filesizes are.
     
  10. amandalee76

    amandalee76 Private E-2

    All the error message I received were the same:

    "The operation failed. as no adapter is in the state permissable for this operation"

    Then it had 2 buttons to pick from, one was ignore, I cant recall what the name on the other button was (sorry)

    Ok opened all files as requested (they were in fact open already :)

    in C:windows\system32 I found the following:

    ping6.exe
    ping.com
    ping.exe

    I didnt click on any of them..should I?
     
  11. amandalee76

    amandalee76 Private E-2

    Sorry Chas,

    file sizes:

    ping6.exe - 32.5 kb
    ping.com - 2 bytes
    ping.exe - 17.5 kb
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Rename ping.com to ping.ccc
    Rename ping6.exe to ping6.xxx

    Now try your ping.

    You may have other issues and really should do the below.

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis

    .
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Also look in system32 for any files starting with regedit and tell me what you find. You may have one named regedit.com which should not be there either.
     
  14. amandalee76

    amandalee76 Private E-2

    for regedit I found the following:

    reg.exe - 49 kb
    regedit.com - 2 bytes
    regedt32.exe - 3.5 kb...

    working on redoing all scans again.. will attach files in next message...:)
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    regedit.com should be deleted. The other two are okay. regedit.com is what cause the getrunkey.bat program to fail.

    Was there also a regedit.exe ? There should be!

    Does ping work now without an error message?
     
  16. amandalee76

    amandalee76 Private E-2

    I have deleted regedit.com..

    double checked and no there isnt a regedit.exe...(Performing scans now)
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still did not answer...... DOES PING WORK?

    Look in c:\windows for regedit.exe . There should be a copy there. If not, we will have to get one from an i386 folder on the PC or from a CD.
     
  18. amandalee76

    amandalee76 Private E-2

    and yes ping now works with no errors, but I still get the Limited or no COnnectivity warning when trying to connect to internet..

    I went and looked in help files, and it said the icon thats beside my LAN means that driver is diabled...I have no idea what that means!

    (Please keep in mind that its gonna be hard for me to udate the programs since I cant get his comp online...)
     
  19. amandalee76

    amandalee76 Private E-2

    checked c:\windows and there is a regedit.exe (icon looks like a blue rubix cube)
     
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    By the way rename ping6.xxx back to ping6.exe. I forgot that Win XP SP2 included this for IPv6 standards. You can delete the ping.ccc file we renamed from ping.com.

    There are probably a few more .com file we need to remove. Do not do this on your own because there are some that are valid. There may be some of the below:
    tasklist.com
    taskkill.com
    taskman.com
    taskmgr.com

    Just tell me what you find also indicate if the EXE form of the file exist. All of these should be in system32.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You will have to look in Device Manager (under My Computer) for your network interface card and see what is going on. There may be a yellow exclaimation point to indicate a problem with the drivers and the may need to be reloaded. It Windows cannot find them on your system you may need the disk for you network card or you may have to download them.

    Updates can also be downloaded and manually installed for programs like Ad-Aware and Spybot. They are in the Spyware Tools file directory on the main page of Majorgeeks.

    Re try this now too: Using GetRunKey
     
  22. amandalee76

    amandalee76 Private E-2

    Thanks so much about the info for updates chas! I had no idea!

    I will go and look @ device mgr now, will let you know in one sec..

    re updates:

    Will the install automatically when opened? If not where do I install them to?
     
  23. amandalee76

    amandalee76 Private E-2

    dont worry about the updates, i figured it out!
     
  24. amandalee76

    amandalee76 Private E-2

    RE: GetrunKey : ran great, log attached

    CCleaner - ran and removed 11.4 mb
    Microsoft WIndows Malicious SOftware Removal Tool - ran & found zero
    Ad Aware SE - found 4 and removed
    Spybot - ran and found zero
    Microsoft Antispyware - ran and found zero
    Kill2me - ran found zero
    CWShredder - ran found zero

    (I have run CCleaner, Ad aware, Microsoft removal tool, Spybot, Antispyware...before I came to you all with my issues...which is why a few found nothing, because before they found a lot - and no sorry i didnt keep a record of what they found.)

    I wasnt able to do either online scan, since I am not yet able to access the internet (Bitdefender and Panda)

    Hijack, Getrunkeys and Ad Aware logs are attached

    Cant wait to see what to do next!

    I cant tell you how much I appreciate this!!!

    Amanda
     

    Attached Files:

  25. amandalee76

    amandalee76 Private E-2

    By the way I did read the full tutorial for hijack, have not deleted R03, was waiting for you to let me know what to do...
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please read the instructions in the below link again and disable the use of msconfig.

    Downloading, Installing, and Running HijackThis


    The get a new HJT log and attach it.

    [EDIT: Also you did not install HJT properly. You are running it directly from the ZIP file.]
     
  27. amandalee76

    amandalee76 Private E-2

    I did read it and thats where I put it, in its own file on c: drive and thats where it was run from
     
  28. amandalee76

    amandalee76 Private E-2

    Ok I did it again, in Hijack instead of HJ folder BUT

    It wont let me attach it again, saying I already attached it to this thread
     
  29. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to extract the hijackthis.exe file from the HijackThis.zip file. You did not do that. What you did was double click on the ZIP file and then you selected the hijackthis.exe file that was still in the ZIP and you ran it. That creates a temporary copy (as seen in your log) while running. If you do this, you will not get backups.

    If you cannot upload, it means you did not put hijackthis.exe in the properly folder yet and you also did not disable msconfig.
     
  30. amandalee76

    amandalee76 Private E-2

    Where does it say anything about msconfig in the Hijack instructions? am I missing something?
     
  31. amandalee76

    amandalee76 Private E-2

    never mind, found it
     
  32. amandalee76

    amandalee76 Private E-2

    Ok here we go again...sorry for all the trouble chas

    Hi jack log attached...
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay that looks better Amanda! Hang on for a few minutes while I work up a fix!
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure viewing of hidden files is enabled (per the tutorial).

    Copy the contents of the below Quote Box to Notepad. Then click File and then Save As. Change the Save as Type to All Files. Name the file fixme.reg and then click save. (make sure you save it somewhere you can find it. Saving it to your Desktop may make that easy.) Then double-click on the fixme.reg file on your desktop (or locate it with Windows Explorer and double click on it if not saved to the Desktop) and when it prompts to Add in to the registry, say yes.
    Now Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {d262e70a-7841-4a85-9aa1-8d66aa593c89} - (no file)
    O4 - HKLM\..\Run: [] C:\WINDOWS\Options\OEMReset.exe /Audit
    O4 - HKLM\..\Run: [SysService32] C:\WINDOWS\systask32l.exe
    O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} - https://components.viewpoint.com/MTSInstallers/MetaStream3.cab?url=http://www.viewpoint.com/cgi-bin/installer.v4/vet_install_popup.pl?1&6&04.00.09.13&unknown&unknown&http://www.toyota.com/vehicles/2006/tacoma/key_features/ext360.html
    O18 - Filter: text/html - (no CLSID) - (no file)
    O18 - Filter: text/plain - (no CLSID) - (no file)

    After clicking Fix, exit HJT.
    Boot into safe mode and use Windows Explorer to delete:
    C:\WINDOWS\systask32l.exe

    If you get an error when deleting a file. Right click on the file and check to see if the read only attribute is checked. If it is, uncheck it and try again. Other wise open Task Manager and kill the process if running then delete the file.

    Now if running Win XP goto c:\windows\Prefetch and delete all files in this folder.
    Now run Ccleaner (installed while running the READ ME FIRST).

    Now we need to Reset Web Settings:
    1) If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2) Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3) If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.

    Reminder Note: Once we have determined you are malware free you will need to disable System Restore, reboot, and re-enable system restore per step 1 of the READ & RUN ME. This only applies to if using WinXP or WinMe.
     
  35. amandalee76

    amandalee76 Private E-2

    fixme.reg installed great

    Ran Hijack and removed requested items

    Went and looked for - C;\WINDOWS\systask32l.exe, but couldnt find it in the specified location

    Emptied Prefetch of 90 items (what is prefetch for?)

    I reset web settings, set home page to majorgeeks,deleted cookies, delete files (offline too)

    rebooted in normal, ran Hicjack, new log attached
     

    Attached Files:

  36. amandalee76

    amandalee76 Private E-2

    Oh and I know view hidden files was defanitly on because I could see the system32 file
     
  37. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Prefetch is a folder for Windows XP to help speed up loading of frequently used processes.

    How are things working? Can you get online?
     
  38. amandalee76

    amandalee76 Private E-2

    No im sorry to say I cant chas :(...still showing the network error...
     
  39. amandalee76

    amandalee76 Private E-2

    Im so sorry for the choppy messages but i meant to ask you this:


    Under the driver for the Realtek...it said no network address specified..whats that mean?
     
  40. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Is RealTek your NIC (Network Interface Card) in your PC?

    Earlier you said you had a Dlink modem and a Realtek router. This does not seem correct.
    Did you mean you have a Dlink router and a Realtek NIC?

    How do you access the internet (cable or dsl)? There should be a cable modem or a dsl modem for these.

    Do you have your PC's TCP/IP protocal set for DHCP?
     
  41. amandalee76

    amandalee76 Private E-2

    OK yes im sorry Chas,

    It is realtek in PC,

    then to SMC Barricade router

    then to D Link modem


    We are on DSL

    The last question has thrown me for a loop! LOL...but I went to IP properties and it says IP addy is DHCP enabled...;)
     
  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    So the Dlink modem is your conversion from DSL to Ethernet....right?

    If you have enabled DHCP, I don't understand what you meant by the below:

    Where are you looking exactly?
     
  43. amandalee76

    amandalee76 Private E-2

    Yes I think so..connection looks like this:

    Phone line to Dlink
    Dlink has blue network (?) cable to SMC Barricade
    I have grey cord to my computer from SMC Barricade &
    BF has grey wire from computer to another spot in SMC BArricade

    I clicked on Start, Control Panel, Network COnnections
    Clicked on Local Area Network 2
    Clicked on Change Settings of this connection
    clicked on configure realtek
    click advanced tab
    click on network address

    there are two spots here
    1. Value (its blank)
    2. a circle to pick and the choice is Not Present....
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Colors of cables do not matter. It's what's in them that matters. There are straight thru cables and crossover cables. But for the moment, I would assume there are no cabling problems because I also assume this configuration worked at some point. And is it safe to assume no one was playing around phyiscally with the cables.

    Why are you on Local Area Connection 2? What's on LAN 1?

    Are you sure about these last steps being exactly correct?
     
    Last edited: Jan 27, 2006
  45. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you are sure that you should be using Local Area Connection 2 and not Local Area Connection 1, then use 2 in the below. Otherwise maybe you need to be operating on Local Area Connection 1.

    Clicked on Start, Control Panel, Network Connections
    Double clicked on Local Area Network 2
    On the General Tab click on the Properties button
    In the little window box with the title: This connection uses the following items
    find the item labeled something like: Internet Protocol (TCP/IP) and double click on it.
    On this Internet Protocol (TCP/IP) Properties form select the below:
    Obtain an IP address automatically.
    Obtain DNS server address automatically

    Click OK and Ok or Apply your way back out of all of these windows.

    Any change to status.

    If not, you should start checking the LED status LEDs on the router and on your PC to make sure they show connectivity. Normally connectivity is shown by a green LED. Activity (mean data flowing) may be show by a flashing green LED or sometime certain interfaces have a second LED that could be amber (or yellow) in color.
     
  46. amandalee76

    amandalee76 Private E-2

    HI chas, I will try changing the LAN to 1 in just a sec here,

    Just wanted you to know I totally tested the spots on the router with my comp (also tested his grey wire) and all lit up and worked great..

    And yes you are correct, we have been on this connection since may 2005. This new issues just started about a week ago.

    I am not positive he needs to be on LAN 1 or 2, but his spot in the SMC Barricade is spot two (im in one)

    OK will try to change it and see what happens!!!! Be back soon!

    And yes I am sure the steps I wrote are correct :) I had to write them all down so i didnt mess them up , lol

    Ok gonna try to change LAN now, be right back :)
     
  47. amandalee76

    amandalee76 Private E-2

    Went and looked chas, comp is already set up to auto IP and auto DNS...:(


    any other ideas?
     
  48. amandalee76

    amandalee76 Private E-2

    Should there be a LAN1 beside the LAN 2? in network connection?
     
  49. amandalee76

    amandalee76 Private E-2

    Also, am I malware free? Should I complete this step now?
     
  50. amandalee76

    amandalee76 Private E-2

    Chas,

    Been googling the error message I keep getting for the network... found this...I am not sure exactly what the 2nd paragraph means. Although I try to pretend to be a computer guru - I am not lol...Thanks again

    "This connection has limited or no connectivity. You might not be able to access the Internet or some network resources. "

    It appears this is a bug in Service Pack 2 of Windows XP dealing with a loss of network connectivity for workstations that use Microsoft’s L2TP-based virtual private networking (VPN) client to connect to servers that are connected to NAT-based networks. However, this bug seems to appear in situations that are not associated with VPNs either.

    Solutions to the problem are varied, however most of the solutions found on the web just mask the problem by simply guiding the user through turning off this notification. Now this solution may work great for systems that are showing a false positive error, but what if the system genuinely has lost its local area connection or the connection is unstable, what then?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds