Solved Fixing Ethernet After BIS 2013 Encroachment

Status
Not open for further replies.

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
I installed BIS 2013. Within a few days I was sending packets but not receiving them. Status was "connected". I could ping 127.0.0.1, ping localhost, ping 192.168.1.1, etc., and get a response, but I could not receive packets, so I could not access the internet. I read of several other people that had this problem, though not all scenarios were after BIS installation. They tried everything under the sun and could not get their ethernet connection (via cable from tower to wireless router) to receive packets, yet, like my LAN, the satellite PC's were connecting. That is the first time I had ever seen my ethernet connection fail without and ISP service issue being the cause, so I knew it would be a bear (pain in the arse).

I tried a few tricks and kept utilizing restore points to backtrack and start over in the event my changes failed. TCP/IP automatic address acquisition would not work after resetting TCP/IP. It would kill the connection altogether. WinSock Fix would not work either. I shut down all BIS functions that I could. NO change. I then uninstalled BIS and then dove in head first without seeking any more similar scenarios via the internet. It was time to fly blind, which works really well sometimes, esp. in wireless and router hardwire connection ethernet issues, which there seems to be much ignorance out there pertinent to. (I am one of the ignorant ones, lol)

After BIS uninstall, no change. I brought Process Explorer in via my USB toolbox stick. I clicked the "services" tab and began to scroll like mad man until I saw "ethernet" in any given line item. The first item like that I came across was: KLSIENET; DRIVER FOR USB ETHERNET ADAPTOR--Status: stopped----Start Type: demand start;
I started that service, and then I stopped it. I got a BSOD immediately. I rebooted via the power supply, fired it back up, and WALLAH, I was online via my ethernet cable. I had to rename the wireless network, set a new password, redo MAC filtering, and reselect the wireless channel I needed to use. Then I was back in business, just like that.

I had to wrestle with one of the satellite PC's a little to get it reconnected, but that is typical on this network, though not all that common.

The only thing I can figure is that somehow BIS caused a MAC address discrepancy via some security protocol, which, as a result, would not let my hardwired PC receive packets. When I stopped and started that service spoken of above, it must have reset a service/function pertinent to the hardwired tower's MAC address. (basically, the router's MAC filtering rules were not able to--read/detect/confirm/deny--the hardwired PC's MAC address. imho)
(I have MAC's entered as to only allow certain devices to attach to this LAN)

Ok. It is time to poke fun at me now, so GO AHEAD. :)

Router is an outdated Linksys
 

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
Left over boot drivers from uninstalled security products can cause more problems then an infection.
You may have to Google to find the names of the drivers for your uninstalled security products.

Excellent advice.
Especially when considering most users overlook such things due to relying on REVO, AV uninstallers, etc.

I keep Comodo Killswitch on one PC and Process Hacker on the other; MAN, are they handy!!
PCHunter (XueTr) could be used very effectively as well.
 
Upvote 0

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
Left over boot drivers from uninstalled security products can cause more problems then an infection. BitDefender is not the only vendor to do this, but their removal tool should have deleted this gzflt.sys driver. I have had problems in the past with Norton, McAfee, Comodo, Avira, Outpost, PC Tools and others that left behind boot drivers.

I took that to heart, and ran Process Hacker II "services" and checked every running driver, via Google, on my other PC. I have had several different AV's installed on that one, so I wanted to make sure nothing was hanging around. Pun intended.
 
Upvote 0
D

Deleted member 178

my advice:

Do a clean image backup of your system (that contain just your OS, 3rd party drivers, optimizations, prefered softs) but without security softs; then when you want install a new solution , restore your backup first.

you will lost 30mn, but you will never have issue because drivers.
 
Upvote 0

Gnosis

Level 5
Thread author
Apr 26, 2011
2,779
That system is kinda trippy anyway.
Getting rid of that left over BIS 2013 driver took care of most of the quirkiness though.
 
Upvote 0
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top