BleepingComputer.com: No Network after XP antivirus 2012 rootkit removal

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

No Network after XP antivirus 2012 rootkit removal TCPIP protocol service failed to start

#1 User is offline   arau 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 11-January 12

Posted 11 January 2012 - 05:21 PM

hi all,
my pc recently got infected with a rootkit (zerolevel I believe) while surfing web. It was the "XP antivirus 2012" rootkit. I took the PC offline and removed the rootkit manually (with Google's help). Then I ran TDSSKiller, SuperAntiSpyware, ZeroAccessRemovalTool & ComboFix to make sure that the PC was clean. ComboFix did find an infection and cleaned it (I ran it thrice to make sure everything is good).
After all was done I tried to hookup the ethernet wire but couldn't get connected to internet. I quickly looked into network connection properties and found there were no values displayed under "support" tab (I use a static IP). Trying repair under 'Support' tab threw an error message saying "Failed to query TCP/IP". I knew that my TCP/IP stack was corrupt. No matter what I did, I couldn't get it to work again. This is what I've tried so far:

- reset tcp/ip stack using "netsh int ip reset resetlog.txt"
- reset winsock using "netsh winsock reset"
- removed and re-installed tcp/ip protocol
- tried reseting tcp/ip using built-in feature of 'SuperAntiSpyware'

all of this didn't work and i'm still sitting where i was before. I'd really appreciate if anyone here could help me with this as i need to have this pc online very soon.


Edit: sorry I forgot to add that I also get event:7000 in my system logs with error message - "tcp/ip protocol service failed to start becuase the specified proceedure couldn't be found". I also checked the tcpip.sys file and found that it was corrupt. so, i restored a correct copy from the cache.
I also want to add that I ran ComboFix, TDSSKiller & other tools before joining the forums here.

This post has been edited by arau: 11 January 2012 - 05:57 PM


#2 User is offline   arau 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 2
  • Joined: 11-January 12

Posted 11 January 2012 - 07:44 PM

Scratch this ^. I resolved my own issue. I looked into device manager (show hidden devices) and found out that the tcpip device driver had an "!" mark on it. Checked the file version and it was a windows 7 version tcpip.sys file. replaced it with an xp tpcip.sys file from another desktop and voila. i could not get ip address and ping my network devices.

just a quick one. i believe that one of the rootkit remover has also removed my bookmarks for both IE and firefox. is there a way i can get it back? I'd like to get back those bookmarks if possible.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users