[TriLUG] what is blocking a website in winxp?
    Glenn Starling 
    gjstarling at charter.net
       
    Thu Apr 23 15:15:41 EDT 2009
    
    
  
Two possibilities come to my mind as I think back on recent events with clients.  1)  I have had similar difficulties with browser settings that check Google for possible malware sites and prevents going there.  Is the site possibly infected with something and is therefore blocked and you do not have similar checking on that computer?   2)  I have also had problems with a client who got some spyware that sent out lots of spam messages to everyone in the address book.  As we looked at the IE browser settings for blocked sites, it had a HUGE list that was put there by some "anti-spyware" program or perhaps the trojan itself.  We never determined what put it there, but it blocked access from legitimate update sites, like the AVG virus checker (free edition) installed on the computer.  A quick analysis with the client reading me the list on the phone indicated there was a list of legitimate sites and strange (possibly malware) sites.  A quick Control-A to select all of them and delete them opened the computer back up to the internet and lots of security updates were then downloaded almost automagically.  I don't know if this was a one-of-a-kind instance, or the computer you are working on has the same malware running.
Good luck.
-- Glenn
  ----- Original Message ----- 
  From: Lucas Myers 
  To: Triangle Linux Users Group General Discussion 
  Sent: Thursday, April 23, 2009 9:38 AM
  Subject: Re: [TriLUG] what is blocking a website in winxp?
  Since you can connect using a linux boot it's probably not a problem with the router, modem or ISP.  More likely a driver, config, or program issue. Here's a few ideas:
  -Try booting into "Safe Mode with Networking" and seeing if it can connect. If so, there may be a program installed that is preventing the browser from working. 
  -Install a different browser to see if it can connect (i.e., try installing Chrome if it's not on the box).
  -Check the hosts file (c:\windows\system32\drivers\etc\hosts) and remove any offending entries. 
  -Try is uninstalling and reinstalling TCP/IP from the Network settings in the Control Panel.
  -Check for updated drivers for the NIC. Window Update may have them listed as Optional Updates., or find the NIC in the Control Panel Device manager and check for an updated driver there, or see if the PC or NIC manufacturers have one on either of their websites.
  Good luck!
  James Jones wrote: 
Chris and all,
On the modem router issue, I plan to investigate more thoroughly
today. When you access the modem/router using the default username and
password, there is NO screen or menu item for content filtering.
In the last 30 minutes I found a complete reference manual for the
modem/router. There is another login using superuser and password (
most likely changed by road runner ). If it is at default, I will be
able to inspect the blocking routines within the modem/router's
firewall.
If I am not able to access this area, I will place a call to RR.
What is really weird is the fact that a knoppix operating system is
able to access the site using the same hardware as ubuntu and winxp is
using.
I will report what I find and IF I find a solution.
jcj
On Thu, Apr 23, 2009 at 8:17 AM, Chris Knowles <cknowles2112 at gmail.com> wrote:
  Hmm... reading the manuals for the CG814WG (which appears to be comcast
only??) and the related CG814M, they both claim to have a firewall inside of
them, specifically in the CG814M there's a section on "Filtering" in the web
interface including a "block sites" section.
I can't find any screenshots of the web interface for the CG814WG.
Only two thoughts...
1) re-check to make sure that any filtering options are turned off.  You
might even reset the netgear to factory defaults.  (If the password is still
default, there's a chance you've got someone mucking with teh settings)
2) What is the IP address of the computer when you are in windows, ubuntu,
and knoppix.  Theoretically, with most DHCP servers, they should be the
same, but is the address is shifting, and whatever rules are in the router,
that could explain why it works in one and not the others.
Good luck.  These kind of problems can cause premature graying.
CJK
On Thu, Apr 23, 2009 at 1:15 AM, James Jones <jc.jones at tuftux.com> wrote:
    Patrick and all,
I have used a guest account on the same box. It provides the same results.
Here is my results from today's activities.
1. checked for malware with spybot-S&D .. Plenty of "problems" but
when all problems were removed, the block website still existed as
blocked.
2. Used autoruns, process explorer to find any unusual startups -- none
found
2. The day before I had inserted a knoppix cd in the machine and
booted to it. I could reach the website from konqueror within knoppix.
Based on this, I installed Ubuntu 8.10 on her pc today. THE BLOCKED
WEBSITE WAS STILL BLOCKED when using firefox on ubuntu.
Note: I again inserted the knoppix cd and booted to it and COULD
access the website -- no blocking!!!
The internet service provider is road runner and the cable modem/wifi
router is a Netgear model number cg814wg. I don't see any place in
it's administration for blocking external ip addresses and no firewall
on the router.
I am nearing the point of blowing winxp away and re-installing,
something I don't like to do. It means that I haven't found the
problem.
Perplexed -- jc jones
On 4/22/09, Patrick Brewer <patwbrewer at yahoo.com> wrote:
       While I would first expect malware, I have had heard of issues similar
        that are resolved by blowing away the browser config.  A simple test for
that would be to create a new user or try to connect from a guest account if
one exists on the box.
      
 --
 TriLUG mailing list        :
        http://www.trilug.org/mailman/listinfo/trilug
       TriLUG FAQ  : http://www.trilug.org/wiki/Frequently_Asked_Questions
        --
Jc Jones
Blogs -
http://www.wendellgeek.com/weblog/
http://kixtech.blogspot.com/
webmaster for:
http://www.raleighchurchofchrist.org
http://www.wendellgeek.com
http://classof1955.org
http://www.tuftux.com
http://www.dabeak.com
http://www.therealpatpatterson.com
http://jonesjc.freeshell.org
http://www.trilug.org/~jonesjc <http://www.trilug.org/%7Ejonesjc>
--
TriLUG mailing list        : http://www.trilug.org/mailman/listinfo/trilug
TriLUG FAQ  : http://www.trilug.org/wiki/Frequently_Asked_Questions
      --
TriLUG mailing list        : http://www.trilug.org/mailman/listinfo/trilug
TriLUG FAQ  : http://www.trilug.org/wiki/Frequently_Asked_Questions
    
  
------------------------------------------------------------------------------
  --
  TriLUG mailing list        : http://www.trilug.org/mailman/listinfo/trilug
  TriLUG FAQ  : http://www.trilug.org/wiki/Frequently_Asked_Questions
------------------------------------------------------------------------------
  No virus found in this incoming message.
  Checked by AVG - www.avg.com 
  Version: 8.0.238 / Virus Database: 270.12.3/2076 - Release Date: 04/23/09 06:30:00
    
    
More information about the TriLUG
mailing list