Missing Network Shares - Compromised Network?
Posted on 2006-05-01
Saturday I installed a NetGear router. It's attached between my main computer and my cable modem.
The setup program told me to turn off all programs, including firewalls and AV, before installing. I did. And then I got sidetracked by a neighbor. I was open to the Internet for several hours without AV or firewall.
Sunday, all four of my computers on the network started behaving strangely. I first notiiced them being sluggish, taking a long time to load things. Then my main computer started just hourglassing forever at bootup. I'd start a Windows Explorer window, and it would just churn without evre opening it.
I lost connectivity to my router's web interface.
The administrative shares on the two XP machines are gone. If I re-enable them in the registry, they are gone again next time I reboot.
I pulled the plug on the Internet last night after reading a Microsoft help page that indicated that these symtoms--especially the missing admin shares--were likely a sign of a compromised system.
My plan is to wipe the machines and start from scratch. But I sooooo don't want to do that if I'm missing another cause/solution.