Monday, November 24, 2008

Windows update takes you to MSN

This seems to be a rare case but here is what was found. First the IP address set to obtain it automatically, would switch between 2 addresses. It is irrelevant which 2 but after about a half an hour one would stay on long enough to be able to do something online. However windows update took you to MSN so updates could not be done. Defender was unable to update as was AVG. When I applied a static IP I noticed the dns filled in with 2 sets of numbers that I had not chosen and could not change.
This led me to the registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Tcpip\Parameters\Interfaces\{c597fac3-1744-4d67-8484-77c8aa503b99}\NameServer
where the dns numbers were found. Data: 85.255.114.41,85.255.112.130
I deleted the key {c597fac3-1744-4d67-8484-77c8aa503b99} and then went back to networking where I changed it back to automatic and repaired the connection.
This fixed it. Since the system was heavily infected it was obviously caused by on of the nasties lurking around.

No comments: