<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>
<channel>
	<title>Comments for Web Trac</title>
	<atom:link href="http://www.web-trac.com/comments/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.web-trac.com</link>
	<description>Computer, Internet, Web, Mobile ...</description>
	<pubDate>Sun, 07 Sep 2008 17:52:26 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.5.1</generator>
		<item>
		<title>Comment on Update: Removing JS/Downloader.Agent virus by Dhiru</title>
		<link>http://www.web-trac.com/update-removing-jsdownloaderagent-virus-02-02/#comment-64</link>
		<dc:creator>Dhiru</dc:creator>
		<pubDate>Wed, 06 Aug 2008 02:11:04 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/update-removing-jsdownloaderagent-virus-02-02/#comment-64</guid>
		<description>Well, i had the same problem with my Network, but luckily my ISP provides a good antivirus as a compulsion. I had 3 infected PC's in my Network. Whenever these PC's were ON, i used to have this problem.

My Solution that worked for me:
1. Whenever you get this problem, Ping to your Gateway and check Latency
2. Scan for all the PC's in the network using some third party software to determine their MAC address. Once done, note down the infected IP's MAC Address and also note down the MAC Address of your .
2. Change your IP address 
3. Disable your LAN Adapter
4. Reenable your LAN Adapter
5. In the Command Prompt, type "arp -s  
EX: ARP -S 10.21.207.1 00-11-11-b9-57-66
6.Similarly use "ARP -S  
7. Once done, type "ARP -A" to see the changes.
8. Change back your IP address and look for the Gateway Ping Latency. You can observer Relatively lower latency because all your data packets are directly reaching the Gateway instead of the Infected Computer.
9. In this way, i do it everytime i start my PC. I know the list of Infected PC's so i just assign a Static ARP Entry so that they can spoof my ARP.

Hope this Helps!</description>
		<content:encoded><![CDATA[<p>Well, i had the same problem with my Network, but luckily my ISP provides a good antivirus as a compulsion. I had 3 infected PC&#8217;s in my Network. Whenever these PC&#8217;s were ON, i used to have this problem.</p>
<p>My Solution that worked for me:<br />
1. Whenever you get this problem, Ping to your Gateway and check Latency<br />
2. Scan for all the PC&#8217;s in the network using some third party software to determine their MAC address. Once done, note down the infected IP&#8217;s MAC Address and also note down the MAC Address of your .<br />
2. Change your IP address<br />
3. Disable your LAN Adapter<br />
4. Reenable your LAN Adapter<br />
5. In the Command Prompt, type &#8220;arp -s<br />
EX: ARP -S 10.21.207.1 00-11-11-b9-57-66<br />
6.Similarly use &#8220;ARP -S<br />
7. Once done, type &#8220;ARP -A&#8221; to see the changes.<br />
8. Change back your IP address and look for the Gateway Ping Latency. You can observer Relatively lower latency because all your data packets are directly reaching the Gateway instead of the Infected Computer.<br />
9. In this way, i do it everytime i start my PC. I know the list of Infected PC&#8217;s so i just assign a Static ARP Entry so that they can spoof my ARP.</p>
<p>Hope this Helps!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by islam</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-62</link>
		<dc:creator>islam</dc:creator>
		<pubDate>Fri, 04 Jul 2008 05:22:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-62</guid>
		<description>virus changed its code to http:// mx.content-type.cn: 443 / f / index.htm

DONT OPEN IT
be aware from this trojan</description>
		<content:encoded><![CDATA[<p>virus changed its code to <a href="http://" rel="nofollow">http://</a> mx.content-type.cn: 443 / f / index.htm</p>
<p>DONT OPEN IT<br />
be aware from this trojan</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by Dhiru</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-61</link>
		<dc:creator>Dhiru</dc:creator>
		<pubDate>Tue, 01 Jul 2008 07:57:22 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-61</guid>
		<description>Same thing what hamid told...

There will be a computer connected to your LAN with a different IP but it will have the same MAC Address of that of your Gateway. You must talk to your ISP and deal with the PC that is infected. All the Network Traffic Passes through the infected computer and hence the JS Virus is infected in the browser page that is requested!</description>
		<content:encoded><![CDATA[<p>Same thing what hamid told&#8230;</p>
<p>There will be a computer connected to your LAN with a different IP but it will have the same MAC Address of that of your Gateway. You must talk to your ISP and deal with the PC that is infected. All the Network Traffic Passes through the infected computer and hence the JS Virus is infected in the browser page that is requested!</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on Answers to win 26&#8243; LCD TV by Rose</title>
		<link>http://www.web-trac.com/answers-to-win-26-lcd-tv-19-11/#comment-58</link>
		<dc:creator>Rose</dc:creator>
		<pubDate>Tue, 24 Jun 2008 11:03:16 +0000</pubDate>
		<guid isPermaLink="false">http://web-trac.com/index.php/answers-to-win-26-lcd-tv-19-11/#comment-58</guid>
		<description>Thank you for posting, but it's seem too late for me as I just found your post here. :-)</description>
		<content:encoded><![CDATA[<p>Thank you for posting, but it&#8217;s seem too late for me as I just found your post here. <img src='http://www.web-trac.com/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' /></p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by Fachia</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-55</link>
		<dc:creator>Fachia</dc:creator>
		<pubDate>Mon, 16 Jun 2008 17:15:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-55</guid>
		<description>@ hamid reza, please tell me clearly how to identify if a computer in a network is infected by this virus. Tell me how to use ARPprotect mentioned above</description>
		<content:encoded><![CDATA[<p>@ hamid reza, please tell me clearly how to identify if a computer in a network is infected by this virus. Tell me how to use ARPprotect mentioned above</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by how can kill this virus</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-52</link>
		<dc:creator>how can kill this virus</dc:creator>
		<pubDate>Sun, 15 Jun 2008 00:36:46 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-52</guid>
		<description>how i can kill or stop this virus</description>
		<content:encoded><![CDATA[<p>how i can kill or stop this virus</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by hamid reza</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-51</link>
		<dc:creator>hamid reza</dc:creator>
		<pubDate>Sat, 14 Jun 2008 04:36:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-51</guid>
		<description>Salam
This virus is in LAN no in ISP. This virus use ARP Spoofing Tec for redirect LAN Treffic from this path LAN &#62; LAN Gateway &#62; Internet to    LAN &#62; Infected PC &#62; LAN Gateway &#62; Internet.
For virus identification you should use "arp -a" command in cmd.
If there is(or are) MAC address same with "gateway MAC address" this computer(s)infected with this virus.</description>
		<content:encoded><![CDATA[<p>Salam<br />
This virus is in LAN no in ISP. This virus use ARP Spoofing Tec for redirect LAN Treffic from this path LAN &gt; LAN Gateway &gt; Internet to    LAN &gt; Infected PC &gt; LAN Gateway &gt; Internet.<br />
For virus identification you should use &#8220;arp -a&#8221; command in cmd.<br />
If there is(or are) MAC address same with &#8220;gateway MAC address&#8221; this computer(s)infected with this virus.</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by panchitoman</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-50</link>
		<dc:creator>panchitoman</dc:creator>
		<pubDate>Sat, 07 Jun 2008 23:58:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-50</guid>
		<description>well.. now my pc is clean.. and I didn't have to change my ISP</description>
		<content:encoded><![CDATA[<p>well.. now my pc is clean.. and I didn&#8217;t have to change my ISP</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by Vinu</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-49</link>
		<dc:creator>Vinu</dc:creator>
		<pubDate>Fri, 06 Jun 2008 23:09:52 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-49</guid>
		<description>I Found my system/network to be infected with this Trojan ... Then i thought if this spreads via ARP then clearing your arp cache and protecting your would be a good option and it works for me 

and  btw I use Comodo FW Pro 3</description>
		<content:encoded><![CDATA[<p>I Found my system/network to be infected with this Trojan &#8230; Then i thought if this spreads via ARP then clearing your arp cache and protecting your would be a good option and it works for me </p>
<p>and  btw I use Comodo FW Pro 3</p>
]]></content:encoded>
	</item>
	<item>
		<title>Comment on hk.www404.cn:53/ads.js by panchitoman</title>
		<link>http://www.web-trac.com/hkwww404cn53adsjs-10-05/#comment-46</link>
		<dc:creator>panchitoman</dc:creator>
		<pubDate>Sun, 01 Jun 2008 00:47:32 +0000</pubDate>
		<guid isPermaLink="false">http://www.web-trac.com/index.php/hkwww404cn53adsjs-10-05/#comment-46</guid>
		<description>well...I used a program "ARProtect" , this program help you to detect which PCs in your red is infected really, so I found that my computer did not have the virus if not that another PC in my network was infected and it have the real virus (this PC infects to all PCs in my network) ....so the only thing to do is disconnect the real infected computer from the network ....so if you want to know which computer is infecting your Internet..download the program "ARProtec"..in the coming days I will tell you that happened...</description>
		<content:encoded><![CDATA[<p>well&#8230;I used a program &#8220;ARProtect&#8221; , this program help you to detect which PCs in your red is infected really, so I found that my computer did not have the virus if not that another PC in my network was infected and it have the real virus (this PC infects to all PCs in my network) &#8230;.so the only thing to do is disconnect the real infected computer from the network &#8230;.so if you want to know which computer is infecting your Internet..download the program &#8220;ARProtec&#8221;..in the coming days I will tell you that happened&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
