Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Small Business Networking

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Six Minutes With ... Perry Wu, CEO of BitGravity. Listen now!

DEMO: Six minutes with...

Six Minutes With ... Scott Ryan, CEO of Asankya. Listen now!

DEMO: Six minutes with...

Additional Resources

RSS

FEATURED WHITEPAPERS

Core PCI Requirements for Windows and Active Directory NetPro

The Payment Card Industry Data Security Standard (PCI DSS) is a set of industry regulations imposed by the major credit card companies to ensure the safety, security, and integrity of cardholder data. Any business that processes, stores, and transmits cardholder account data must comply with this complex new standard, and must be able to demonstrate that compliance through automated and manual audits of their systems. This white paper looks at the key challenges and requirements of PCI DSS as it relates to Microsoft Windows and Active Directory, and shows you how a third-party software solution can help with PCI compliance.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Reduce Complexity and Cost - Windows Server Consolidation with Virtualization from Novell Novell

There are many compelling reasons for virtualizing Windows and Linux applications. Virtualization improves server utilization by allowing you to run multiple workloads on a single physical server. It reduces the number of physical servers you have to maintain, while allowing you to use less physical space and power while still improving scalability. All of these capabilities translate directly into lower costs, less complexity, and greater flexibility in your mixed IT environment. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

Its not hard to keep on eye on how much bandwidth that you are using, check out this page for more info: http://technicianspot.blogspot.com/2008/05/monitor-bandwidth.html- Anonymous

Join the Discussion

Partner Content

Company Description

Emerson Network Power and its Liebert power and cooling technologies increase IT system flexibility and availability, while lowering the total cost of ownership.

Data Center Efficiency

Discover how to optimize your data center efficiency through virtualization, digital system controls and emerging monitoring capabilities.

Download this white paper

Maui Computing Center

Learn how Liebert technology ensures availability for U.S. DoD facility while providing the flexibility to add a new supercomputer.

Download this case study

Cutting Energy Costs

Reduce cooling system energy costs by 30 to 45 percent through five data center efficiency strategies.

Download this white paper

Disinfecting a spyware-riddled PC

Nutter's Help Desk By Ron Nutter , Network World , 03/31/2008
  • Social Web 
  • Email 
  • Feedback 
  • Close

What do I do if I suspect someone is controlling my PC? When my IP address has been changed without my knowledge? My boot-up process is getting harder unless I unplug the Ethernet cable and the CPU is at 100% every time I open any program. There is also a new connection to the Internet that is between my connection and the net I know was not there a month ago. When I try to register my e-mail address the programs say it's invalid and does not match whatever it has to compare it to.
-- Teresa Hurst.

It sounds like some spyware or other unwelcome software has gotten installed on your computer. You need to do some process of elimination to see where the problem is. I would recommend that you start the computer without the Ethernet cable being connected and to start up the operating system on your computer in "safe" mode to minimize what is getting automatically started.

If you are comfortable with using a network sniffer such as Wireshark or one of the commercially available packages, try putting a hub (not switch) between the infected computer and your internet connection and let Wireshark tell you what it is finding. This could help in identifying the exact cause of the problem and serve as a good learning experience in terms of doing some detective work on finding the cause of a problem.

On a different computer, download several different anti-spyware utilities such as Spybot and Ad-Aware. There are several very good packages out there to choose from. The main thing is to run at least two different packages, preferably three, because no single app will remove all the spyware in the wild these days.

Burn these apps onto a CD and then install them onto the computer you have booted into safe mode. Since you are running without a network connection for the time being, you will also need a way to download any signature or other updates and install those before running the software for the first time. After you have run each of the spyware detection programs once, run them at least one more time apiece until you have a clean report from each. This may sound like extra work, but I have seen where one spyware removal program will remove a particular package allowing the same or different spyware removal package to see another piece of spyware/adware that went previously undetected.

1 | 2 |  Next >
Comments (6)
Login
Forgot your account info?

Return to known good but analyzeBy Anonymous on April 9, 2008, 7:26 pmIf you suspect that your system has been compromised, regardless of the INITIAL or APPARENT vector, you should be starting from a known good state. You need to...

Reply | Read entire comment

An Even Better Idea...By AWTroxell on April 8, 2008, 9:40 amFor corporate environments, create a Norton Ghost (or open-source alternative) image of a clean system. Update it periodically with patches and new apps. Once...

Reply | Read entire comment

I disagree with the necessity of flatten & rebuild until effortsBy Scunnerous on April 5, 2008, 5:59 amI disagree with the necessity of flatten & rebuild until efforts to clean have been tried. There are plenty of tools to help out there, like IceSword & RootKitRevealer. One...

Reply | Read entire comment

Sometimes that's just quickerBy Fred Evil on April 4, 2008, 3:12 pmNot to mention at least then you're SURE there is nothing left from an infestation. From a corporate standpoint, once the system is compromised, it's hard to trust,...

Reply | Read entire comment

check running services also........By mayur on April 3, 2008, 1:18 amrun msconfig and check the currently active services. Any suspicious item seen go to that source and remove it.also keep ur Temp Files clean.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code