{"id":322,"date":"2011-02-06T11:23:39","date_gmt":"2011-02-06T11:23:39","guid":{"rendered":"http:\/\/simkin.org\/wordpress\/?p=317"},"modified":"2011-02-06T11:23:39","modified_gmt":"2011-02-06T11:23:39","slug":"defender","status":"publish","type":"post","link":"http:\/\/simkin.org\/wordpress\/?p=322","title":{"rendered":"Spyware Infection?"},"content":{"rendered":"<p>I&#8217;m seeing a lot of computers recently with alerts about W32\/Blaster worms, CTHelper.exe infections etc. being reported by the Spyware Defender application. Spyware Defender apparently cannot clear the infection without the registration key. <\/p>\n<p> <!--more--> <\/p>\n<p>If you get the same, the bad news is you are infected. The good news is that there is just one program doing it. It is the one telling you you are infected. <\/p>\n<p>The program is usually called DEFENDER.EXE and can be found in c:\\users\\xxx\\app data\\roaming.\u00a0 Log in as a different user and delete it. There are more thorough removal tips<a href=\"http:\/\/www.virusremovalguru.com\/?p=5706\"> here<\/a>.<\/p>\n<p>There are a few variants. You can sometimes remove it quite effectively by doing the following:<\/p>\n<p>Let the program pop-up and warn you you have lots of infections.<\/p>\n<p>Ctrl &#8211; Alt &#8211; Del and choose Task Manager<\/p>\n<p>In the\u00a0 Applications tab, highlight the rogue program, right-click and choose goto process<\/p>\n<p>Right-click the highlighted process and open file location<\/p>\n<p>Go back to Task Manager and right-click the process and choose End Process Tree<\/p>\n<p>Go back to the Explorer window that popped-up, the files will be hidden so make a note of the path <\/p>\n<p>Run a command prompt and CD to the folder<\/p>\n<p><font face=\"courier new,courier\">ATTRIB -S -H -R<\/font><\/p>\n<p>Make a note of the filename of the executables that just became visible and delete them<\/p>\n<p>Run REGEDIT and search for instances of the filename.<\/p>\n<p>\u00a0\u00a0 You are pretty much guaranteed to find it under <font face=\"courier new,courier\">HKEY_CLASSES_ROOT\\.exe\\shell\\open\\command<\/font> <\/p>\n<p>\u00a0 \u00a0 <font face=\"courier new,courier\"><em>(Default)<\/em><\/font> should be blank<\/p>\n<p>\u00a0 \u00a0<font face=\"courier new,courier\"> IsolatedCommand<\/font> should read <font face=\"courier new,courier\">&#8220;%1&#8221; %*<\/font><\/p>\n<p>Sort the right values out. Run a virus scan. Reboot. <\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>I&#8217;m seeing a lot of computers recently with alerts about W32\/Blaster worms, CTHelper.exe infections etc. being reported by the Spyware &hellip; <a class=\"more-link\" href=\"http:\/\/simkin.org\/wordpress\/?p=322\">More<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"spay_email":""},"categories":[3,287],"tags":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/322"}],"collection":[{"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=322"}],"version-history":[{"count":0,"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=\/wp\/v2\/posts\/322\/revisions"}],"wp:attachment":[{"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=322"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=322"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/simkin.org\/wordpress\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=322"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}