Network Status reversed; connected but shows not connected

Discussion in 'Malware Help (A Specialist Will Reply)' started by lov-n-life, Apr 25, 2012.

  1. lov-n-life

    lov-n-life Private E-2

    Vista 32-bit, SP2 on Compaq Presario SR5710Y
    AMD Athlon X2 4450e
    Onboard 10/100
    PCI Modem card

    Quick turn-around if at all possible please!

    I am baffled by a connection issue on a client's computer. System was brought to me about 3 weeks ago for bizarre internet behavior and sluggish performance. I found a trojan and a couple other minor malware infections that were very easily cleaned (SAS, Malwarebytes), but I also noticed the network status indicator was showing opposite of the actual status. I.e., when connected to my network (ethernet) I could surf the internet with any browser, but Windows Update and all other programs attempting to download updates said there was no connection.

    When opening up the network and sharing options, it also shows not connected and no networks available, despite actually being able to surf the web.

    When the ethernet cable is disconnected, it then shows it has a connection, but obviously nothing works.

    Client needed the system back ASAP, so I finished the cleaning, but Windows Update reports last check for updates was February 9, 2011. The network status indication seems to be more than just a display bug, but is affecting the update capability of Windows and other installed software.

    Client dropped the system back off today for me to finish up and again, needs it back ASAP. 96 year old WWII veteran and I would really like to resolve quickly as it is his primary form of entertainment.

    I started by running malware scans again. SAS found the usual assortment of tracking cookings (total of only 5!), MBAM came back clean. So I continued with attempting to fix the network status. After much fruitless search, trial and error attempts, I managed to get Java, SAS, and MBAM to connect and download updates... but it still comes back clean and Windows Update still cannot update.

    When using built-in diagnostics, I get a Windows did not find any problems with your internet connection, regardless of where I run the diagnostics from (N&S or LAN Connection\Status\Diagnose).

    I thought I would redownload SP2 and reinstall it, hoping that might fix the issue, however after agreeing to the terms of service, the installation halts with an error stating Access Denied.

    Although I'm not very familiar with RootRepeal, I ran a scan on the drivers and it found some suspicious items. Log file attached. I DID NOT clean anything yet with RootRepeal as it is a bit beyond my knowledge.

    I currently have it running RootReal on Files and will post a log once it is completed (has been running for 3 hours now... seems long to me, but like I said, I'm not really familiar with it).

    I've done some other work on it that currently escapes my memory, but any suggestions offered that I recall already attempting, I'll let you know. What I know for sure I've done:

    Just about everything through an elevated command prompt I can think of, including: common netsh commands to reset everything, ipconfig /renew, etc... (current ipconfig /all attached)

    Disabled IPv6
    Uninstall/reinstalled NIC drivers
    restored IE8 to default settings
    MS firewall restored to default
    System had Norton 360 installed. Uninstalled with Norton removal tool
    Clean boot (safe mode w/networking) and duplicated other attempted repairs
    disabled UAC
    restarted all network services
    set all network services that are default manual to automatic
    reset all network services to default values
    Attempted to uninstall IPv4 and 6 by editing nettcpip.inf [MS_TCPIP.PrimaryInstall] Characteristic = 0xA0 to 0x80, however access denied when trying to save.

    Any help or suggestions would be greatly appreciated!
     

    Attached Files:

  2. lov-n-life

    lov-n-life Private E-2

    *Can a moderator please move this thread to the malware forums - I'm beginning to believe there is still hidden malware as the root cause to the problem and not just a networking issue*

    RootRepeal ran all night searching files, but the computer was locked up this morning and still showing 9:39pm on the clock. No log was generated and I had to power off to get it unlocked and restarted.

    Despite SAS and MBAM showing the system clean, I downloaded MS Security Essentials to put some protection back on the system until the owner decides if they want to continue with Norton or not. Ran a full scan, and MSSE found a Java exploit. So, after MSSE did it's cleaning, I uninstalled Java completely (using Revo Uninstaller), then rebooted. The network status monitor still indates "backwards". I went to the Oracle website and reinstalled the latest Java release.

    The system is now running significantly better than it has been since it was brought over, in fact there appears on the surface to be absolutely nothing wrong with it... except the network status still shows not connected when it is. However, there has been a change.... When the network cable is unplugged, the indicator remains showing disconnected! At this point, I call that progress.

    In addition, I created and ran a batch file as indicated here:

    http://answers.microsoft.com/en-us/...80070005/3b00bcc8-f44a-4134-af68-e727605ad647

    After reboot, the network status indicator actually showed it was attempting to connect, network sharing said it was indentifying the network. However, once it finally connected, it is back to the usuall trickery... showing not connected and no networks available as before, even though it is connected. Still baffled, but if anyone has any suggestions I would appreciate it!
     
  3. handygal

    handygal First Sergeant

    i asked the same thing earlier today, let me see if I can "report" you again. It does sound like an issue i had last year with incomplete removal of malware.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In order for use to provide proper support, we need you to work thru our cleaning process given below and then you need to attach the logs we request in the procedure.

    Please read ALL of this message including the notes before doing anything.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:
    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds