DID A VIRUS CAUSE THIS PROBLEM?

  • Thread starter Thread starter XING
  • Start date Start date
X

XING

Problem: The system was connected to the Internet with a
LAN network card. The browser did not work due to failure
to find server or have a DNS error while the local
connection was shown working successfully (receiving 0 but
sending 156 data package).

System info: windows 2000 sp2 updated with all critical
patches from Microsoft websites.
Application: McAfee antivirus package and Sygate personal
firewall software (sharefree).
Hardware: Dell Dimension L800 r and Gateway GP 2000

Records in the System part of Event Log Viewer:

1. Event logger service started. (Info, source: Eventlog,
EvnetID:6005)

2. Microsoft (R) Windows 2000 (R) 5.0 2195 Service Pack 4
Uniprocessor Free.(Info, source: Eventlog, EventID: 6009)

3. The server failed to register the information found by
Management Tools. The server might not be visible to
Management Tools. Data error. (Error, Source: msftpsvc,
Event ID: 105)

4. The server failed to register the information searched
by Management Tools. The server was invisible to
Management Tools. Data is error code. (Error, Source:
smtpsvc, Event ID: 105)

5. The server failed to register the information found by
Management Tools. The server might not be visible to
Management Tools. Data error. (Error, Source: msftpsvc,
Event ID: 105)

6. SMTP service started successfully. (info, source: SNMP,
EventID:1004)

7. The computer has automatically assigned an IP address
to the network card at address 00A024C9F44D. The IP
address being used is 169.254.30.159. (caution, source:
Dhcp, Event ID: 1007)

8. Because of the primary browser has been terminated, the
browser conducted a compellent selection at the
\Device\NetBT_Tcpip_{F97FFB85-4345-482B-90E7-
FDD889EC6124}. (Info, source: Browser, Event ID:8033)
 
What is/are the problem(s) you are experiencing now?

Even with a misconnected NIC, if you were running a current
antivirus and personal firewall it is very unlikely -- but certainly not
inconceivable -- that there was a successful hack into your system.

Steve Duff, MCSE
Ergodic Systems, Inc.
 
The real trouble is I cannot get access to the internet
right now because the browser cannot find the DNS server.
I tried to ping some internet website and got no response.
The problem took place in a sudden when I was surfing on
the Internet. Same problem occured on another computer
with similar configuration in my office. I tried to
exchange network card and it did not help.
 
Hi Xing,

use netmon and take a trace from you client going to the internet. Welchia
and the latest virus usally send tons of ICMP packets and they will be
onafter another. Then you will now for sure.
 
Hello,

From your entry #7, it looks like DHCP requests are not getting through.
Hence, you're not getting a valid IP address, DNS, etc...
Perhaps check the personal firewall settings?

regards,

SteveC
======
If at first you don't succeed, forget skydiving
 
Back
Top