{"id":163,"date":"2004-12-18T17:28:24","date_gmt":"2004-12-18T22:28:24","guid":{"rendered":"http:\/\/192.168.33.66\/wp\/?p=163"},"modified":"2004-12-18T17:28:24","modified_gmt":"2004-12-18T22:28:24","slug":"fix-spyware-infection","status":"publish","type":"post","link":"http:\/\/www.wildow.com\/blog\/?p=163","title":{"rendered":"fix spyware infection"},"content":{"rendered":"<p>The DNS servers (205.152.37.23 and 205.152.132.23) are in Atlanta and New<br \/>\nOrleans. You are in South Carolina or somewhere near there. Both servers are<br \/>\nprobably reasonably close, for dialup anyway, but it would be interesting to see<br \/>\ntraceroutes to both from your friends system.<\/p>\n<p>But that doesn&#8217;t explain the browser problem with accessing www.yahoo.com by IP<br \/>\naddress. I&#8217;m betting you should be checking for spyware, specifically a browser<br \/>\nand \/ or DNS hijack of some type.<\/p>\n<p>DNS resolution is affected by the LSP \/ Winsock subsystem.<br \/>\nhttp:\/\/support.microsoft.com\/?id=318584<br \/>\nhttp:\/\/support.microsoft.com\/?id=811259<\/p>\n<p>Give LSP-Fix and WinsockLSPFix a shot first <http:\/\/www.cexx.org\/lspfix.htm>.<\/p>\n<p>Now check for adware \/ crapware \/ spyware. Start by downloading each of the<br \/>\nfollowing free tools (To your computer then figure a way to copy them to your<br \/>\nfriend&#8217;s computer?):<br \/>\nAdAware <http:\/\/www.lavasoftusa.com\/><br \/>\nCWShredder <http:\/\/www.majorgeeks.com\/download4086.html><br \/>\nHijackThis <http:\/\/www.majorgeeks.com\/download.php?det=3155><\/p>\n<p>Spybot S&#038;D <http:\/\/www.safer-networking.org\/index.php?page=download><\/p>\n<p>Stinger <http:\/\/us.mcafee.com\/virusInfo\/default.asp?id=stinger><\/p>\n<p>Create a separate folder for HijackThis, such as C:\\HijackThis &#8211; copy the<br \/>\ndownloaded file there. AdAware and Spybot S&#038;D have install routines &#8211; run them.<br \/>\nThe other downloaded programs can be copied into, and run from, any convenient<br \/>\nfolder.<\/p>\n<p>First, run Stinger. Have it remove any problems found.<\/p>\n<p>Next, close all Internet Explorer and Outlook windows, and run CWShredder. Have<br \/>\nit fix all problems found.<\/p>\n<p>Next, run AdAware. First update it (&#8220;Check for updates now&#8221;), configure for<br \/>\nfull scan (<http:\/\/www.lavahelp.com\/howto\/fullscan\/>), then scan. When scanning<br \/>\nfinishes, remove all Critical Objects found.<\/p>\n<p>Next, run Spybot S&#038;D. First update it (&#8220;Search for updates&#8221;), then run a scan<br \/>\n(&#8220;Check for problems&#8221;). Trust Spybot, and delete everything (&#8220;Fix Problems&#8221;)<br \/>\nthat is displayed in Red.<\/p>\n<p>Then, run HijackThis (&#8220;Scan&#8221;). Do NOT make any changes immediately. Save the<br \/>\nHJT Log.<br \/>\n<http:\/\/forums.spywareinfo.com\/index.php?showtopic=227><\/p>\n<p>Finally, have your HJT log interpreted by experts at one or more of the<br \/>\nfollowing security forums (and please post a link to your forum posts, here):<br \/>\nAumha: <http:\/\/forum.aumha.org\/index.php><br \/>\nNet-Integration: <http:\/\/forums.net-integration.net\/><br \/>\nSpyware Info: <http:\/\/forums.spywareinfo.com\/><br \/>\nSpyware Warrior: <http:\/\/spywarewarrior.com\/index.php><br \/>\nTom Coyote: <http:\/\/forums.tomcoyote.org\/><\/p>\n<p>If removal of any spyware affects your ability to access the internet (some<br \/>\nspyware builds itself into the network software, and its removal may damage your<br \/>\nnetwork), run LSP-Fix and \/ or WinsockXPFIx again.<\/p>\n<p>Cheers,<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The DNS servers (205.152.37.23 and 205.152.132.23) are in Atlanta and New Orleans. You are in South Carolina or somewhere near there. Both servers are probably reasonably close, for dialup anyway, but it would be interesting to see traceroutes to both &#8230; <a class=\"more-link\" href=\"http:\/\/www.wildow.com\/blog\/?p=163\">Read More &raquo;<\/a><\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-163","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/163","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=163"}],"version-history":[{"count":0,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=\/wp\/v2\/posts\/163\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=163"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=163"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.wildow.com\/blog\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=163"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}