Need help on home network with recovery from rbot.gen virus

Need help on home network with recovery from rbot.gen virus

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
Need help on home network with recovery from rbot.gen virus denzel 01-15-2008
Posted by denzel on January 15, 2008, 1:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I've tried this question on
miscrosoft.public.windows.vista.networking_sharing and haven't gotten any
help. Hopefully someone here will have more experience with this.

Skipping the stupid part of having the virus in the first place, I need help
in fixing my home network. Virus (rbot.gen) was removed and the file that
was containing the virus was deleted. I've run a couple of anti-virus
programs (and spyware programs) and it is definitely gone.

One of the things this did was kept my two computers (one XP and one Vista -
the one with the virus) from seeing each other on the home network. A
couple of the clues were that Windows Update kept being turned off and I
could no longer print from the XP computer to the printer attached to the
Vista computer. So I know that the bot would turn off the Windows Update
service, but I don't know what it did to the home networking.

Can anyone give me some directions to help?

Both computers (wired) and 2 TIVOs (1 wired, 1 wireless) can access the
internet just fine through my Linksys WRT54G router and could do this even
with the bot running. XP computer has also been scanned for any viruses
(and spyware) and is clean. I've deleted and re-established home networking
on both computers with the same workgroup name on both computers. Windows
firewall is not running on either computer (no other firewall for anti-virus
programs are running to interfere with the network). I've changed all the
network settings on the Vista computer to one way, then back. Hey, it's
worked before just fine but stopped working when the Vista computer was
infected. I've looked through the Services to reset back to automatic those
services that looked network related that were set to disabled.

I'm guessing that the bot turned off a service that I need or changed a
registry value that isn't resetting by removing and re-establishing a home
network (I've tried changing workgroup names also). Does anyone know
exactly what this bot did to me? Or can you point me to specific directions
I need to walk through? (I've looked through and followed what I could from
http://nitecruzr.blogspot.com/2005/05/troubleshooting-network-neighborhood.html#AskingForHelp
but maybe someone could point me directly to what I need to follow here.
Cabling, pinging the internet, etc. works, but no seeing the other computers
on the network.).

I've seen that an anonymoususer setting in the registry can get changed by
this virus, but I haven't seen anything that tells me what the setting
should be changed back to. Has anyone got any experience in recovering from
this virus?

Thanks for taking the time to help.




Posted by David H. Lipman on January 15, 2008, 4:11 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| I've tried this question on
| miscrosoft.public.windows.vista.networking_sharing and haven't gotten any
| help. Hopefully someone here will have more experience with this.
|
| Skipping the stupid part of having the virus in the first place, I need help
| in fixing my home network. Virus (rbot.gen) was removed and the file that
| was containing the virus was deleted. I've run a couple of anti-virus
| programs (and spyware programs) and it is definitely gone.
|
| One of the things this did was kept my two computers (one XP and one Vista -
| the one with the virus) from seeing each other on the home network. A
| couple of the clues were that Windows Update kept being turned off and I
| could no longer print from the XP computer to the printer attached to the
| Vista computer. So I know that the bot would turn off the Windows Update
| service, but I don't know what it did to the home networking.
|
| Can anyone give me some directions to help?
|
| Both computers (wired) and 2 TIVOs (1 wired, 1 wireless) can access the
| internet just fine through my Linksys WRT54G router and could do this even
| with the bot running. XP computer has also been scanned for any viruses
| (and spyware) and is clean. I've deleted and re-established home networking
| on both computers with the same workgroup name on both computers. Windows
| firewall is not running on either computer (no other firewall for anti-virus
| programs are running to interfere with the network). I've changed all the
| network settings on the Vista computer to one way, then back. Hey, it's
| worked before just fine but stopped working when the Vista computer was
| infected. I've looked through the Services to reset back to automatic those
| services that looked network related that were set to disabled.
|
| I'm guessing that the bot turned off a service that I need or changed a
| registry value that isn't resetting by removing and re-establishing a home
| network (I've tried changing workgroup names also). Does anyone know
| exactly what this bot did to me? Or can you point me to specific directions
| I need to walk through? (I've looked through and followed what I could from
|
http://nitecruzr.blogspot.com/2005/05/troubleshooting-network-neighborhood.html#AskingForHelp
| but maybe someone could point me directly to what I need to follow here.
| Cabling, pinging the internet, etc. works, but no seeing the other computers
| on the network.).
|
| I've seen that an anonymoususer setting in the registry can get changed by
| this virus, but I haven't seen anything that tells me what the setting
| should be changed back to. Has anyone got any experience in recovering from
| this virus?
|
| Thanks for taking the time to help.
|


Download MULTI_AV.EXE from the URL --
http://www.pctipp.ch/downloads/dl/35905.asp

To use this utility, perform the following...
Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
Choose; Unzip
Choose; Close

Execute; C:\AV-CLS\StartMenu.BAT
{ or Double-click on 'Start Menu' in C:\AV-CLS }

NOTE: You may have to disable your software FireWall or allow WGET.EXE to go
through your
FireWall to allow it to download the needed AV vendor related files.

C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
This will bring up the initial menu of choices and should be executed in Normal
Mode.
This way all the components can be downloaded from each AV vendor's web site.
The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and Reboot the
PC.

You can choose to go to each menu item and just download the needed files or you
can
download the files and perform a scan in Normal Mode. Once you have downloaded
the files
needed for each scanner you want to use, you should reboot the PC into Safe Mode
[F8 key
during boot] and re-run the menu again and choose which scanner you want to run
in Safe
Mode. It is suggested to run the scanners in both Safe Mode and Normal Mode.

When the menu is displayed hitting 'H' or 'h' will bring up a more comprehensive
PDF help
file.

Additional Instructions:
http://pcdid.com/Multi_AV.htm


* * * Please report back your results * * *


--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by denzel on January 15, 2008, 5:50 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
Thanks....but, this is just a method of scanning for viruses with multiple
av programs, right?

I don't have the virus any more, so they won't find any and can't fix any.
I've cleaned the system from viruses, but what I need is help in fixing
whatever settings were changed for my home network.

So even if these programs could fix the changed settings if they found the
virus, they can't fix it now because I don't have the virus any longer. I
guess I could re-install the virus and see if these programs would do a
better job of recovery, but I don't like that method.

I guess I'm looking for a little higher level of expertise help from someone
that actually knows what this virus changed in my registry or services and
what I need to do to fix it back.

>
> | I've tried this question on
> | miscrosoft.public.windows.vista.networking_sharing and haven't gotten
> any
> | help. Hopefully someone here will have more experience with this.
> |
> | Skipping the stupid part of having the virus in the first place, I need
> help
> | in fixing my home network. Virus (rbot.gen) was removed and the file
> that
> | was containing the virus was deleted. I've run a couple of anti-virus
> | programs (and spyware programs) and it is definitely gone.
> |
> | One of the things this did was kept my two computers (one XP and one
> Vista -
> | the one with the virus) from seeing each other on the home network. A
> | couple of the clues were that Windows Update kept being turned off and I
> | could no longer print from the XP computer to the printer attached to
> the
> | Vista computer. So I know that the bot would turn off the Windows
> Update
> | service, but I don't know what it did to the home networking.
> |
> | Can anyone give me some directions to help?
> |
> | Both computers (wired) and 2 TIVOs (1 wired, 1 wireless) can access the
> | internet just fine through my Linksys WRT54G router and could do this
> even
> | with the bot running. XP computer has also been scanned for any viruses
> | (and spyware) and is clean. I've deleted and re-established home
> networking
> | on both computers with the same workgroup name on both computers.
> Windows
> | firewall is not running on either computer (no other firewall for
> anti-virus
> | programs are running to interfere with the network). I've changed all
> the
> | network settings on the Vista computer to one way, then back. Hey, it's
> | worked before just fine but stopped working when the Vista computer was
> | infected. I've looked through the Services to reset back to automatic
> those
> | services that looked network related that were set to disabled.
> |
> | I'm guessing that the bot turned off a service that I need or changed a
> | registry value that isn't resetting by removing and re-establishing a
> home
> | network (I've tried changing workgroup names also). Does anyone know
> | exactly what this bot did to me? Or can you point me to specific
> directions
> | I need to walk through? (I've looked through and followed what I could
> from
> |
>
http://nitecruzr.blogspot.com/2005/05/troubleshooting-network-neighborhood.html#AskingForHelp
> | but maybe someone could point me directly to what I need to follow here.
> | Cabling, pinging the internet, etc. works, but no seeing the other
> computers
> | on the network.).
> |
> | I've seen that an anonymoususer setting in the registry can get changed
> by
> | this virus, but I haven't seen anything that tells me what the setting
> | should be changed back to. Has anyone got any experience in recovering
> from
> | this virus?
> |
> | Thanks for taking the time to help.
> |
>
>
> Download MULTI_AV.EXE from the URL --
> http://www.pctipp.ch/downloads/dl/35905.asp
>
> To use this utility, perform the following...
> Execute; Multi_AV.exe { Note: You must use the default folder C:\AV-CLS }
> Choose; Unzip
> Choose; Close
>
> Execute; C:\AV-CLS\StartMenu.BAT
> { or Double-click on 'Start Menu' in C:\AV-CLS }
>
> NOTE: You may have to disable your software FireWall or allow WGET.EXE to
> go through your
> FireWall to allow it to download the needed AV vendor related files.
>
> C:\AV-CLS\StartMenu.BAT -- { or Double-click on 'Start Menu' in C:\AV-CLS}
> This will bring up the initial menu of choices and should be executed in
> Normal Mode.
> This way all the components can be downloaded from each AV vendor's web
> site.
> The choices are; Sophos, Trend, McAfee, Kaspersky, Exit this menu and
> Reboot the PC.
>
> You can choose to go to each menu item and just download the needed files
> or you can
> download the files and perform a scan in Normal Mode. Once you have
> downloaded the files
> needed for each scanner you want to use, you should reboot the PC into
> Safe Mode [F8 key
> during boot] and re-run the menu again and choose which scanner you want
> to run in Safe
> Mode. It is suggested to run the scanners in both Safe Mode and Normal
> Mode.
>
> When the menu is displayed hitting 'H' or 'h' will bring up a more
> comprehensive PDF help
> file.
>
> Additional Instructions:
> http://pcdid.com/Multi_AV.htm
>
>
> * * * Please report back your results * * *
>
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Posted by David H. Lipman on January 15, 2008, 6:02 pm
If you were  Registered and logged in, you could reply and use other advanced thread options

| Thanks....but, this is just a method of scanning for viruses with multiple
| av programs, right?
|
| I don't have the virus any more, so they won't find any and can't fix any.
| I've cleaned the system from viruses, but what I need is help in fixing
| whatever settings were changed for my home network.
|
| So even if these programs could fix the changed settings if they found the
| virus, they can't fix it now because I don't have the virus any longer. I
| guess I could re-install the virus and see if these programs would do a
| better job of recovery, but I don't like that method.
|
| I guess I'm looking for a little higher level of expertise help from someone
| that actually knows what this virus changed in my registry or services and
| what I need to do to fix it back.
|

Unfortunately all we have is the name, RBot.Gen. Not even the AV application
that declared
it.

By this name all we know is this is a Generic RBot worm. Specifics can NOT be
provided.

There are two options if substantial alterations of the OS have been made...

Restore the OS to point prior to the RBot infection.

Wipe, reformat and re-install the OS from scratch.

--
Dave
http://www.claymania.com/removal-trojan-adware.html
Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp



Posted by denzel on January 16, 2008, 1:22 pm
If you were  Registered and logged in, you could reply and use other advanced thread options
I never quite know how to respond to replies like this. I don't really like
to argue in forums; for some reason it never seems to help and it certainly
won't change your mind. But maybe if I keep this thread open with one more
entry, the right person will see it. But I also know that if you don't get
an answer in the first 12 hours, you're likely not going to get it.

I'm sure there are hundreds of people with the question like "My computer is
going slow; I must have a virus; What do I do???" And your answer is great
for them. But my original post clearly states that I've removed the virus I
had, but I need help in fixing my network. Now we can argue about whether
you think I removed it or not, but I'm not asking you to weigh in on this.
You gave me your stock answer on virus scanning. Thanks, but I don't need
that.

So I responded because I don't want anyone reading this thread to think that
you've solved my problem and I don't need any more help. But of course you
have to justify your first response. You can't help me because I didn't
give you the specific anti-virus program and specific name that the scan
found. You even yelled! ("Specifics can NOT be provided.") No soup for
you!

Obviously, there's a lot more information I can provide, down to the serial
number of my motherboard. But the original post didn't justify all that
detail. Do you know anything about this family of viruses and what setting
changes it could make to my network? Do you have information that could
help me but you are holding out because I didn't give you a specific av
scanner name? I'd be glad to provide whatever details the right
knowledgeable person would need to help me. In fact, I just need to be
pointed in the right general direction from somebody that knows something.
But you don't sound like the one. Especially since you didn't fully read
the original post and gave me a canned answer that didn't apply to me. And
you gave me such useful information. Only two options? You left out

Buy a new computer.

Do without any computers.

Spread the virus to as many other computers as you can in hopes that someone
will have the same problem and post a solution.

Do without home networking.

Track down the original virus author and get his help.

Get a degree in computer programming with a minor in viruses and fix it
yourself.

Ask someone smarter than David H. Lipman.

Yeah, I apologize now. I'm kind of bored and thought I'd just type for a
while. Really, no hard feelings. You're not required to help me and you
probably do help a lot of people. Hopefully, I haven't pissed you off. I'm
just another ranter without anything useful to say. Just trying to be funny
today. Rant back at me if you wish and I'll read it and not take it
personal and won't post a reply. Or of course you can take the higher
ground and just ignore me. Probably be the best if I had done the same. I
really appreciate all the help I do find on public boards and the internet.
Like I said at the top of this reply, I just wanted to keep this thread
alive for one more post in case someone really could help a fellow out.
Have a good day.

Dennis



>
> | Thanks....but, this is just a method of scanning for viruses with
> multiple
> | av programs, right?
> |
> | I don't have the virus any more, so they won't find any and can't fix
> any.
> | I've cleaned the system from viruses, but what I need is help in fixing
> | whatever settings were changed for my home network.
> |
> | So even if these programs could fix the changed settings if they found
> the
> | virus, they can't fix it now because I don't have the virus any longer.
> I
> | guess I could re-install the virus and see if these programs would do a
> | better job of recovery, but I don't like that method.
> |
> | I guess I'm looking for a little higher level of expertise help from
> someone
> | that actually knows what this virus changed in my registry or services
> and
> | what I need to do to fix it back.
> |
>
> Unfortunately all we have is the name, RBot.Gen. Not even the AV
> application that declared
> it.
>
> By this name all we know is this is a Generic RBot worm. Specifics can
> NOT be provided.
>
> There are two options if substantial alterations of the OS have been
> made...
>
> Restore the OS to point prior to the RBot infection.
>
> Wipe, reformat and re-install the OS from scratch.
>
> --
> Dave
> http://www.claymania.com/removal-trojan-adware.html
> Multi-AV - http://www.pctipp.ch/downloads/dl/35905.asp
>
>



Similar ThreadsPosted
Norton and home network October 4, 2006, 4:05 pm
my network server has a virus and i can not conect to the network. November 1, 2008, 6:19 pm
Windows XP "RBOT" virus infection? February 18, 2006, 7:20 pm
spyware recovery July 26, 2005, 12:58 am
URL of home in IE has been replaced!! Which Virus? July 18, 2005, 1:17 pm
Virus, rootkit or something else ??? Strange network behavior... January 6, 2006, 5:59 pm
Virus on yahoo.com home page February 6, 2006, 2:04 pm
How to find virus/worm/trojan on network client September 21, 2005, 11:29 pm
MS05-39 Plug and Play Network virus and Trend Micro July 5, 2006, 11:28 pm
Anti-Virus program: Free avast! 4 Home Edition April 9, 2006, 9:10 pm

The site map in XML format XML site map

Contact Us | Privacy Policy