BleepingComputer.com: Cannot connect to the internet after rootkit removal

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Cannot connect to the internet after rootkit removal

#1 User is offline   rmorando 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 08-September 11

Posted 08 September 2011 - 09:08 PM

I have a Windows XP Pro SP2 system, I performed a rootkit removal using combofix.

After the removal of the rootkit my tcp/ip stack was damaged, and I have a limited connectivity issue with my internet connection. My LAN works if I set it manually but I cannot connect to the internet. I have tried using different utilities such as XP TCPIP repair, Winsock XP Fix Tool, I have even tried different commands in the command line such as netsh winsock reset, ip flush and others. I am running out of options here, I appreciate all the help.

#2 User is offline   hamluis 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 31,449
  • Joined: 03-September 05
  • Gender:Male
  • Location:Killeen, TX

Posted 09 September 2011 - 06:08 AM

Internet connectivity is the only issue currently apparent?

System manufacturer and model?

Have you tried a repair install of Windows...or running the sfc /scannow command? System files may have become damaged.

Louis

#3 User is offline   GuruLounge 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 21
  • Joined: 05-September 11
  • Gender:Male
  • Location:Los Angeles, CA.

Posted 09 September 2011 - 02:46 PM

Did you also try Microsoft's solution:

http://support.microsoft.com/kb/299357

Jeff

#4 User is offline   rmorando 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 08-September 11

Posted 09 September 2011 - 07:47 PM

View Posthamluis, on 09 September 2011 - 06:08 AM, said:

Internet connectivity is the only issue currently apparent?

System manufacturer and model?

Have you tried a repair install of Windows...or running the sfc /scannow command? System files may have become damaged.

Louis


That's correct internet connectivity is the only issue. It is a Compaq Presario SR1630NX, Athlon 64, 1 GB of RAM. I haven't tried a repair install of Windows XP as I am afraid I may lose my personal information that I am not able to back up at this moment.


View PostGuruLounge, on 09 September 2011 - 02:46 PM, said:

Did you also try Microsoft's solution:

http://support.microsoft.com/kb/299357

Jeff


I tried the manual reset of TCP/IP but it didn't work.

#5 User is offline   GuruLounge 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 21
  • Joined: 05-September 11
  • Gender:Male
  • Location:Los Angeles, CA.

Posted 09 September 2011 - 08:12 PM

If all else fails... try a different network card, a spare one from another computer, a cheap-o from the late-night computer store... :)

Jeff

#6 User is offline   hamluis 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 31,449
  • Joined: 03-September 05
  • Gender:Male
  • Location:Killeen, TX

Posted 10 September 2011 - 08:35 AM

Did you uninstall the network drivers...and then reinstall them?

How do you know that your stack was damaged...what was the exact error message, please?

Louis

#7 User is offline   rmorando 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 3
  • Joined: 08-September 11

Posted 10 September 2011 - 09:08 PM

View Posthamluis, on 10 September 2011 - 08:35 AM, said:

Did you uninstall the network drivers...and then reinstall them?

How do you know that your stack was damaged...what was the exact error message, please?

Louis


I haven't reinstalled the network drivers as the NIC comes integrated with the motherboard.

When I ran combofix it told me that it found a rootkit and that the TCP/IP stack was corrupted, after I ran combofix it removed the rootkit, currently I have LAN access only but no internet access.

I tried the sfc commmand it is asking me for the Windows XP Pro CD, which I have, what i am worried is if it is going to overwrite my documents, photos, and music and if it is going to delete the users of this system?

#8 User is offline   GuruLounge 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 21
  • Joined: 05-September 11
  • Gender:Male
  • Location:Los Angeles, CA.

Posted 10 September 2011 - 11:32 PM

SFC simply scans the windows system for corrupted/damaged system files and replaces them. It doesn't eliminate personal documents or user profiles.

Jeff

#9 User is offline   hamluis 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 31,449
  • Joined: 03-September 05
  • Gender:Male
  • Location:Killeen, TX

Posted 11 September 2011 - 06:42 AM


#10 User is offline   GuruLounge 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 21
  • Joined: 05-September 11
  • Gender:Male
  • Location:Los Angeles, CA.

Posted 11 September 2011 - 01:43 PM

View Posthamluis, on 11 September 2011 - 06:42 AM, said:

References: How To Use Sfc.exe To Repair System Files - http://www.bleepingcomputer.com/forums/topic43051.html AND LEARN how to use SFC.EXE (system file checker) in this article! - http://www.updatexp.com/scannow-sfc.html

Louis


Very good read. I wasn't aware of some of this. Thanks for posting the links.

Jeff

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users