D
dougalovich
Hello All,
I have been called to a job where the entire network had ground to a
halt. About 30 Windows 2000 machines, all running AVG Antivirus that is
up-to-date.
I narrowed the problem down to 4 PCs that were infected with the Spybot
virus (see link) that were clogging up the network. I started by
unplugging their cables and the remainder of the network is functioning
normally now.
http://www.sarc.com/avcenter/venc/data/w32.spybot.cym.html
I have removed the offending file and corrected the registry entries as
described in the above link and internet connectivity has been restored
on these machines as well as the other PCs on the network.
However, these 4 PCs cannot communicate with others on the network, the
server, shared printer etc.
They can ping the server and other PCs, it just seems that any kind of
communication involving mapped drives etc on the local network is
'broken'.
I would rather not have to rebuild these PCs, but I know I'll probably
have to. I haven't tried reinstalling the network protocols etc. yet,
but I have done a virus scan and also cleared suspect items with
HijackThis and also checked with LSPFix.
I was wondering if there were any other common registry tweaks that the
virus might have employed to 'break' it's networking capabilites. As I
said, the PCs can access the internet and also ping the server
successfully. Any error messages are of the kind that you'd expect if a
network cable was unplugged or if the server was down etc.
DNS information is fine and I also cannot access the server if I just
use the IP address.
Any help would be appreciated.
Thanks in advance,
David.
I have been called to a job where the entire network had ground to a
halt. About 30 Windows 2000 machines, all running AVG Antivirus that is
up-to-date.
I narrowed the problem down to 4 PCs that were infected with the Spybot
virus (see link) that were clogging up the network. I started by
unplugging their cables and the remainder of the network is functioning
normally now.
http://www.sarc.com/avcenter/venc/data/w32.spybot.cym.html
I have removed the offending file and corrected the registry entries as
described in the above link and internet connectivity has been restored
on these machines as well as the other PCs on the network.
However, these 4 PCs cannot communicate with others on the network, the
server, shared printer etc.
They can ping the server and other PCs, it just seems that any kind of
communication involving mapped drives etc on the local network is
'broken'.
I would rather not have to rebuild these PCs, but I know I'll probably
have to. I haven't tried reinstalling the network protocols etc. yet,
but I have done a virus scan and also cleared suspect items with
HijackThis and also checked with LSPFix.
I was wondering if there were any other common registry tweaks that the
virus might have employed to 'break' it's networking capabilites. As I
said, the PCs can access the internet and also ping the server
successfully. Any error messages are of the kind that you'd expect if a
network cable was unplugged or if the server was down etc.
DNS information is fine and I also cannot access the server if I just
use the IP address.
Any help would be appreciated.
Thanks in advance,
David.