Jump to content

Recommended Posts

Posted

a couple of people have talked about using safe mode - this is a good idea but do you know that "safe mode" isn't always safe? Basically, safe mode starts the processes listed at HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot (there are two keys under there; minimal and network which should be obvious ...)

 

If a virus, trojan etc has added something to the lists here then that can interfere with normal operation.

 

I would try and boot from BartPE etc disc and then use regedit to load the hive from c:\windows\system32\config\system - you can then be reasonably sure that what you're looking at is the genuine thing and not interfered with by rootkits etc. If you do see anything you don't recognise then you can delete it (you will have taken a backup copy, won't you? :-)) and then see if the machine starts OK

 

I understand the desire to learn how to fix obscure problems but given that this machine has been virus infected you could be fighting a losing battle. It really comes down to deciding do you want to beat the virus writers or do you want a working machine?

 

Good luck :-)

Posted
I understand the desire to learn how to fix obscure problems but given that this machine has been virus infected you could be fighting a losing battle.

 

Hmmmmm, I've been fixing PCs with Viruses / Worms for over 15 years - never ONCE have I re-built a PC because of it.

All the traces of the recent virus / trojan have gone and I can say hand on my heart it's virus free - unless there is something on the EISA partition......

I'll get to the bottom of it - may even take a copy so I can see how it works as a VM.

Posted
The EISA partition may just be an area used for the factory restore. A lot of pre-installed machines seem to have them, the fujitsu siemens laptop I was looking at the other day for instance.
Posted
Have you removed the trend micro stuff? Might be worth running some sort of cleaning tool to get all of it off. I don't know of one offhand, but cleanwipe does the job for Symantec. Also "AOE4A4.EXE" isn't one I recognise, maybe disable it it from starting as well as removing trend before doing a reboot. (Age of Empires 4??)
Posted

One thing, are you sure your hijack entry:

O20 - AppInit_DLLs: karna.dat_

Is valid? that smells of malware. Also try a LSPstack viewer and see if it all checks out by checking another pc with its results.

Posted

Also check out:

C:\WINDOWS\TEMP\AOE4A4.EXE

 

And notice your lsp stack could be borked:

O10 - Broken Internet access because of LSP provider 'lsp32.dll' missing

Which will break the internet probably. Try getting that file and dropping it in from a similar sp'ed pc.

Posted

Does it have AVG 8 on?

 

In last 2 weeks i have had 2 people i know have this same issue, and for some reason AVG 8 was the cause. Uninstall AVG and internet worked again, re-install AVG 8 and all is still fine. :confused:

Posted

I've had a smilar problem with a friends pc recently. Tried everything mentioned above and it still did it.

 

I could browse the net using the ip address in the address bar but it got very tiring having to remember them!!

 

Have you tried Malware Bytes Anti Malware? I found the problem with the PC I had was done to AVG being uninstalled and leaving some files behind. There was also a whole host of other problems on this PC so i just rebuilt it and it turned out a lot quicker than ever!!

Posted

Had a similar issue to this last week teachers laptop would not connect to the internet at all.

 

Didn't check to see if it was able to browse via ip addresses but it could ping domain names.

 

Colleague here resolved the issue by replacing the tcpip file in system32\drivers to resolve the issue.

 

He isn't around today so I can't ask him how he managed to find out that resolution or what else he tried but it may be of some use to you.

Posted
3rd vote for Malware Bytes Anti Malware software it does what it says on the tin absolutely brill!! :)

 

It is the best I have used. I tried all the normal ones on my last problematic machine and this is the only one that detected the problem and shifted it!

Posted
It is the best I have used. I tried all the normal ones on my last problematic machine and this is the only one that detected the problem and shifted it!

 

Yet software such as Adaware still gets rave reviews in the I.T press. The mind boggles. Malwarebytes saved my bacon recently. I salute it.

  • 2 weeks later...
Posted

Long shot, but I carry a USB network adapter with me, if it's based on an ADM8511 chip it don't need any drivers for XP - stick it in, plug your cable in and see what happens.

 

Also had something similar due to remnants of Norton Internet Security hanging around.

Guest blacksheep
Posted
@Quackers - There is a fix for that on Grisoft website

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...