IPv4 settings changed spontaneously on all PCs and server

molly_dog

Honorable
Oct 17, 2013
58
0
10,540
First off, my apologies for the very long post. Trying to include as much detail as possible. I’m having issues with a small network at a municipality.

Hardware consists of

  • 1 Windows Server 2016 Essentials (Dell T130)
    3 Windows 10 Pro x64 PCs (OptiPlex 3040)
    3 shared printers
    1 Networked copy machine
    TP-LINK AC1200 WiFi router
    DLink 16 port unmanaged switch
For clarity, I’m using the following naming convention:

  • SERVER
    STATION-3 — Computer I was originally called about
    STATION-4
    STATION-5
I deployed the server, PCs, switch and router last summer and, up until now, have had no issues.

All devices have (had) static IP addresses and DHCP on the router was disabled.

THE ISSUE
Last week I got a call from a user who was having problems with a couple of specialized apps which run on the SERVER. She told me that it started after a Dell System Agent upgrade occurred on STATION-3. She also complained that the computer was running slow.

Whenever she tried to launch either app, she received a prompt to enter her credentials for the server. Once she did that the app would launch but would afterwards pop up errors when she attempted to use the app. My first thought was that the targets for the apps’ shortcuts somehow got changed but that wasn’t the case.

The more I dug into it the stranger things became.

Upon arrival, I logged into her user account. Windows File Explorer crashes when launched and no other computers besides STATION-3 appear under Network. Also, the antivirus had been disabled. We’re using Panda Adaptive Defense 360.

Additionally, I had Internet connectivity.

I logged out of her account and in on my account. Explorer worked fine but still no other machines, including the SERVER, showed up under Network. Only STATION-3.

Digging deeper, I tried pinging the other machines. All attempts were unsuccessful. Then I found that the IPv4 settings had been changed to DHCP.

Further investigation revealed that not only had all the other computers’ settings changed but even the router, which I’d originally set to 192.168.1.1, was also changed back to the factory default 192.168.0.1. WTF?

I logged back into her account on STATION-3 and ran an ESET online scan. It found nothing. I’ve run ESET scans on her new account and on mine. All clear. Ran the scan on STATION-4 & -5 with the same result. BTW, the installed AV is fine on STATION-4 & -5.

Because the AV is also missing on the SERVER, I’m currently running the ESET scan on it, as well. By "missing" I mean that when I try to launch Panda from the Start menu or the Taskbar, an update download tries to run but generates a download error. So I cannot initiate a scan on the SERVER.

The SERVER also only shows STATION-3 under Network. I can, however, Ping all the other three PCs from SERVER and from STATION-3, -4, -5.

Thinking the user account on STATION-3 was corrupt, I created a new account both on STATION-3 and SERVER. I then copied all her data hoping she could at least get some work done while I figured out the rest of the SNAFU.

Unfortunately, on the new account, I am unable to map network drives unless I enter the complete path because no other networked machines show up in Explorer. Even if I manually enter the complete path, I get an error that the "resource is no longer available".

Also, I created new shortcuts for the two specialty apps but receive the same errors as originally reported. Could the fact that I have not yet deleted her original account from STATION-3 or SERVER be causing a problem?

What I’ve done in the interim:

  • Factory reset on the router and reconfigured it to my original settings
    Reconfigured the IPv4 settings on the SERVER and all 3 PCs. They’ve all been restarted.
    Verified that STATION-4 and STATION-5 both show all 4 computers under Network
I think that’s everything. I’m really stymied at this point.

Thanks for any help y'all can share!

 

mwryder55

Distinguished
Two things come to mind. The first is that the user, or someone that was remoting into the computer, made a change to the network settings. The second is to make sure that there is no proxy server now set up on the computer. I know that the second option can create problems with things like Windows Update as I just fixed a computer that would not update because of a proxy server set up on the computer. The second option does not explain how all of your network gear got changed unless someone did an update that included changing everything back to default. They may have reset the router at some point when it wasn't connecting and reset it to default at the same time.
 

molly_dog

Honorable
Oct 17, 2013
58
0
10,540


I knew I forgot something!!

Thanks, first, for the fast response! I forgot to mention the human equation.

There are only two employees who use the computers. They are the only full-time employees in the building. One of them is my wife, who still hasn't mastered the TV remote at home LOL. Neither has any clue how to even navigate to the network settings. I get a blank look when I ask either of them to open Windows Explorer via the Taskbar. I always have to tell them to click on "the little folder icon" or explain to them where the Windows key is, press and hold it, then press "e". :pt1cable:

The mayor and the 4 other board members have accounts but, after 11 months, none of them have ever logged in. Also, no one besides me has remote access and I haven't logged into here for a while. So I had ruled them out. Just forgot to mention that. (Sorry)

All is not lost, though. I'm beginning to suspect the router's bad. I went home for dinner (a five minute walk from here). When I left Village Hall I left my laptop and tablet here. Both were connected to the router via wireless. Upon my return, both connections were down and my phone could not connect either. Even restarting the router has not remedied the problem.

Oh, yeah. Also when I got back here, the ESET scan on the server had completed. It had found 13 "coupon ad malware" files in the directories where all the old data was stored. Nothing was infecting the current data, however.

Still don't know for sure if that's the whole problem but, given the overall oddity of the situation, I'm thinking it could be the culprit. Router is still under warranty so I'm going to open a ticket with the manufacturer.

Strangely enough, I had also originally considered a possible failed NIC in STATION-3 even though I figured that was unlikely.

Thanks again for the quick response!! I'll update this thread as things progress.

 

molly_dog

Honorable
Oct 17, 2013
58
0
10,540
I was able to determine that an ethernet cable apparently failed. I've reset everything but the server still does not appear under Network.

First, I used a cable tester to check every cable in the network. After STATION-5's cable would not read I disconnected it at both ends.

I also tried a different router and switch. Still only STATION-3 & -4 appear under Network.

Now, STATION-4, which was the only machine to show the SERVER and STATION-3 under Network, isn't showing the SERVER either after I restarted STATION-4.

After I reset the original router, WiFi is again working.

If I type \\SERVERNAME in the search box, however, all the files on the SERVER are displayed, however.

I'm really tired and more confused than ever.
 

molly_dog

Honorable
Oct 17, 2013
58
0
10,540
After all I've gone through over the past few days, the problem is resolved although I'm not 100% sure what resolved it. The only glaring thing was the bad Ethernet cable.

After reconfiguring all the IPv4 settings, rolling the router back to factory defaults, and shutting everything down for about 30 minutes before rebooting, things still weren't right. But I had a doctor appointment so I had to leave.

When I got back, I sat down at STATION-3 to try to get the two apps to work. I was able to map the drives using "Browse" instead of entering the entire path. Was also able to recreate the related shortcuts.

The only issue that remains is that the SERVER does not show under Network on STATION-4.

At least they're up and running for the Board meeting tomorrow and I've got some breathing room to figure that out.