Computing.Net > Forums > Windows XP > Hidden Firewall

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

Hidden Firewall

Reply to Message Icon

Name: Dred
Date: December 20, 2004 at 11:47:09 Pacific
OS: WinXP
CPU/Ram: 2.4GHZ
Comment:

I seem to have a hidden firewall that is preventing me from getting to the internet. I have turned off the WinXP firewall and uninstalled Norton Internet Security to no avail. My Motorola Surfboard modem is receiving an IP address from roadrunner and passing it to my PC but something is blocking my access. I cannot ping anything either.

Any ideas?

Dred



Sponsored Link
Ads by Google

Response Number 1
Name: trdj
Date: December 20, 2004 at 12:48:27 Pacific
Reply:

yeah... well that could be almost anything, huh? So I have a list of questions that could at least help narrow the suspects if you are still wanting help:

1) At some time did you have successful access? or is this a new connection?

2) Have you had any instance of an installed program/virus/spyware since the loss of connection (assuming it wasn't new)

3) Have you scanned for any virus/spyware that maybe on your system without your knowledge.

4) Have you verified that processes of Norton Internet Security aren't still running even after uninstalling? (which I have seen happen)

5) Assuming that "roadrunner" is the name of a broadband service (which I believe that it is), have you tried power cycling your Modem. Turning it off for about 5 minutes and re-starting it. It may be that you lost a lease on an IP address and your modem is not acquiring a new one correctly preventing you from getting network access (also has happened to me before)

6) Have you tried other ports/protocals/ applications for netowkr access (ie. Telnet, Tracert, Messenger, etc.).

7) Are there any additional details you can provide as to what you may think might have caused the loss of access?


Anyway, well I would love to help, but there is too much that could be the problem without knowing more details which is why I am sure you haven't had any posts on this yet, but let me know and I will do what I can to help.

- Michael


0

Response Number 2
Name: Dred
Date: December 20, 2004 at 13:03:52 Pacific
Reply:

In answer to your questions...

1) At some time did you have successful access? or is this a new connection?

Yes, 3 days ago, everything was working fine. Been working for over a year with no problems.

2) Have you had any instance of an installed program/virus/spyware since the loss of connection (assuming it wasn't new)

Nothing new that I am aware of has been installed. My wife was working on it but does not remember installing anything. My 14 year old son was on it but not on the internet.

3) Have you scanned for any virus/spyware that maybe on your system without your knowledge.

I did complete scans with Nortan Internet Security, SpyBot and Spysweeper. Just the usual adware stuff that was supposedly deleted.

4) Have you verified that processes of Norton Internet Security aren't still running even after uninstalling? (which I have seen happen)

I have checked the services in msconfig and no instances that I can detect.

5) Assuming that "roadrunner" is the name of a broadband service (which I believe that it is), have you tried power cycling your Modem. Turning it off for about 5 minutes and re-starting it. It may be that you lost a lease on an IP address and your modem is not acquiring a new one correctly preventing you from getting network access (also has happened to me before)

I did power down and recycle. I have also hooked it up to a DSL modem on another network with same results.

6) Have you tried other ports/protocals/ applications for netowkr access (ie. Telnet, Tracert, Messenger, etc.).

Yes, I have tried remote terminal services and messenger to no avail.

7) Are there any additional details you can provide as to what you may think might have caused the loss of access?

Can't think of anything else at this time. Been on the horn with both Symantec customer support and Roadrunner, both seem to belive there is another firewall running somewhere but I have not installed one and cannot find any. Does anyone know how to detect another firewall?

Thanks for your time and help.


Dred


0

Response Number 3
Name: trdj
Date: December 20, 2004 at 13:12:27 Pacific
Reply:

there's no Firewall Hunting program that I know of other than some good manual effort of reviewing the processes in task manager and making sure that you verify each one as a valid service.

ALso have you tried booting into Safe Mode w/ Netowrking to see if that enables your network access?


0

Response Number 4
Name: Dred
Date: December 20, 2004 at 13:23:45 Pacific
Reply:

I did try booting in safemode with networking and still received same results.

I did notice that MS updates installed the following hotfixes on 12/16/04...

KB873339
KB885835
KB885836
KB886185

I tried uninstalling these to see if any were the culprit but did not have any change in results.

Dred


0

Response Number 5
Name: trdj
Date: December 20, 2004 at 13:40:12 Pacific
Reply:

did you, or even dare you (should I say) do a system restore back a couple days to when it was working... also could you post a list of your system processes so I can see what you have running currently on your system?

You can use Hijack this program or in XP run Tasklist in the Command window and funnel the results to a log file.

Thanks


0

Related Posts

See More



Response Number 6
Name: Dred
Date: December 20, 2004 at 13:55:22 Pacific
Reply:

The following are the processes currently running:

taskmgr.exe
NotifyAlert.exe
Support.exe
explorer.exe
userinit.exe
svchost.exe
svchost.exe
lsass.exe
services.exe
winlogon.exe
csrss.exe
smss.exe
System
System Idle Process

Thankks again for your help.

Dred


0

Response Number 7
Name: trdj
Date: December 20, 2004 at 14:15:14 Pacific
Reply:

is there a way to view the command thread of the "Support.exe" process? according to this link it *may* be a virus: http://www.liutilities.com/products/wintaskspro/processlibrary/support/

but this link says it may be a Dell Support Pogram as well: http://www.pcpitstop.com/spycheck/SWDetail.asp?fn=SUPPORT.EXE

however "support" is pretty generic and this process may be associated to something else, but it may be worth checking out.

Also speaking of viruses, have you verified that your HOSTS file has not had a lot of extra entries blocking your internet connectivity? (as some viruses do).

I think if all else fails I would attempt to do a re-scan for viruses/spyware in safe mode to ensure proper deletion of any malicious programs.

Then if that doesn't work, maybe go for a system restore as that should remove the Windows Updates that you mentioned more officially and see if that works.

Let me know how it goes.



0

Response Number 8
Name: michlin
Date: December 20, 2004 at 16:19:06 Pacific
Reply:

Dred,

Check your "hosts" file (C:\WINDOWS\system32\drivers\etc) for any incorrectly entered I.P. address which could block your access to the Internet.


0

Response Number 9
Name: J_Squared
Date: December 21, 2004 at 01:55:29 Pacific
Reply:

I had a hidden firewall problem which kept all my ports stealthed and prevented anyone pinging me. It also prevented me using a network based on TCP protocol. After much hunting I eventually found a file called vsdatant.sys in my System32 folder which was left over from a copy of the ZoneAlarm firewall that I had uninstalled long ago. The only way that I found out about it was by checking its properties and version and seeing that it was to the TrueVector device driver. Nowhere was it listed in any running process but it could not be deleted while Windows was running so it was clearly in use. To play safe I simply renamed it in DOS and rebooted. The hidden firewall was gone and everything was working as it should.

If, in the past, you have tried a firewall and then uninstalled it there might be some residue left behind which is running in the background. I do not know of any quick way of find it though. I found mine by checking any DLL or SYS file which I did not recognise - it took ages!

Good luck!


0

Sponsored Link
Ads by Google
Reply to Message Icon

CMOS Setting problem help... Using Partion Magic 8.0 t...



Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Windows XP Forum Home


Sponsored links

Ads by Google


Results for: Hidden Firewall

Hidden Firewalls www.computing.net/answers/windows-xp/hidden-firewalls/53496.html

Firewall/Auto Connection Question www.computing.net/answers/windows-xp/firewallauto-connection-question/128689.html

Fire wall www.computing.net/answers/windows-xp/fire-wall/155361.html