Wierd networking problem (Could be a virus of sorts)

mic_y

Expert Member
Joined
Dec 23, 2004
Messages
1,645
Hi guys,

I am experiencing the following problem. On Friday, a client calls me, and says that the internet on one machine is not working. I go out to their office to check up on what the issue is, and see that the machine is connected to the wireless network, but the connection is just at the physical level. To explain this, if I right-click on the wireless connection, and click status, it gives me the following:

IPv4: Not Connected
IPv6: Not Connected
Media state: Enabled
Duration: ...
Speed: 54mbps

And so on and so forth.

If I click on the details button (where all the IP's and so on would normally be listed), I was greeted with a completely blank form. By blank, I mean that even the property column contained absolutely no values what so ever.

Now, I tried reinstalling driver, etc, etc, but no luck.

Eventually, I gave up and decided to take the machine in to just back it up, reinstall Windows (Win 7 Pro - 64 Bit) and go from there.

Got it home, tried with another wireless card (just to make sure that it wasn't the hardware) and still the same result. Took my removable drive, backed up all the data from the clients machine, and started reinstalling windows.

While this was happening, I needed something off the removable, so I plugged it into my machine. Then shut it down, to reinsert the WiFi card that I had taken out.

Upon rebooting, I was greeted with the same problem as I had been experiencing on the client machine, except this time, with my Wired network connection.

Any ideas on what this could be?
 

mic_y

Expert Member
Joined
Dec 23, 2004
Messages
1,645
@Drake: Eset Smart Security 4.0, fully updated...

@ponder: that is what I had suspected when it was the clients machine, but, when it happened on my personal machine, I started doubting it. And get it right: PEBCAK ;)

On a separate note, the files that I had backed up, were all absolutly clean (only 1 exe - and that was a skype installer), and the rest were PDF, DOCX and XLSX files, so couldnt have been anything dodgy there (at least not without opening them, which I didnt do)...

After a full format and reinstall, everything is working fine on both machines, so I am still completely clueless on what the issue was.
 

Drake2007

Expert Member
Joined
Oct 23, 2008
Messages
4,413
pebcak :)

Oh well, can safely assume it was a virus which your AV didn't detect, there's quite a few that propogate through external drives.
Here's a crude method to lock your drive

mkdir autorun.inf
attrib +a +s +r +h autorun.inf

As a precaution, if it is network propogated you'll never know, make sure the client's PC is locked down before plugging back onto their LAN.
 

mic_y

Expert Member
Joined
Dec 23, 2004
Messages
1,645
hehe, well there were no autorun.inf files on the removable (checked for that). Also, have had multiple flash drives come into contact with infected machines, and the autorun.inf files always get detected and deleted before doing any harm. Also always use total commander, set to show hidden and system files, so if there were something suspicious, I would have seen it... still perplexed as to what i could have been :(

Not too worried any more tho, after a clean format on the mahcines, everything seems to be working fine :) just praying to god that it doesnt happen again.
 

mic_y

Expert Member
Joined
Dec 23, 2004
Messages
1,645
chair and keyboard, keyboard and chair, same ****, different day ;)
 
Top