This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Removal of System Security Version 4.51

34 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi
It doesn't show with Add/Remove Programs or Revo Uninstaller, but Task Manager showed that it was stil running in "Processes" so I clicked on "End processes for it again. Here's a new KJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:52:00 AM, on 4/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GS.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [iMeshPersonalization] "C:\Program Files\iMesh Applications\Personalization\iMeshPersonalization.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - http://www.worldwinner.com/games/v42/tilecity/tilecity.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v49/dinerdash/dinerdash.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WUSB54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 10323 bytes
Hi sassybella,

That's fine. Revo Uninstaller may have missed a folder or 2 and the line in msconfig. We'll take care of that now.

Open hijackthis, do a system scan only and checkmark these lines, if present

O4 - HKCU\..\Run: [iMeshPersonalization] "C:\Program Files\iMesh Applications\Personalization\iMeshPersonalization.exe"

Close ALL other windows/browsers and click Fix Checked. Answer Yes if prompted. Close HJT.



We'll use OTMOVEIT3 to remove the folders. Please allow the tool to reboot your machine when prompted.

  • Please double-click OTMoveIt3.exe to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
  • Copy the lines in the codebox below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Do Not copy the word CODE note the fix starts with the :
:Processes
explorer.exe

:Services

:Reg

:Files
C:\Documents and Settings\All Users\Application Data\iMesh Applications 
C:\Documents and Settings\Debra\Application Data\iMesh
C:\Documents and Settings\Debra\Local Settings\Application Data\iMesh Applications
C:\Documents and Settings\Debra\My Documents\My Music\iMesh
C:\Program Files\iMesh Applications 
C:\Program Files\iMesh Applications\iMesh
C:\Program Files\iMesh Applications\iMesh MediaBar 

:Commands
[emptytemp]
[start explorer]
[Reboot]

Please post back with the OTMOVEIT3 log and a new HJT log.

Thanks
Hi,
Okay OTMI File:

========== PROCESSES ==========
Process explorer.exe killed successfully.
========== SERVICES/DRIVERS ==========
========== REGISTRY ==========
========== FILES ==========
C:\Documents and Settings\All Users\Application Data\iMesh Applications\Personalization\Log moved successfully.
C:\Documents and Settings\All Users\Application Data\iMesh Applications\Personalization\DT moved successfully.
C:\Documents and Settings\All Users\Application Data\iMesh Applications\Personalization moved successfully.
C:\Documents and Settings\All Users\Application Data\iMesh Applications moved successfully.
C:\Documents and Settings\Debra\Application Data\iMesh moved successfully.
C:\Documents and Settings\Debra\Local Settings\Application Data\iMesh Applications\Personalization\VH moved successfully.
C:\Documents and Settings\Debra\Local Settings\Application Data\iMesh Applications\Personalization\UFC moved successfully.
C:\Documents and Settings\Debra\Local Settings\Application Data\iMesh Applications\Personalization\SL moved successfully.
C:\Documents and Settings\Debra\Local Settings\Application Data\iMesh Applications\Personalization moved successfully.
C:\Documents and Settings\Debra\Local Settings\Application Data\iMesh Applications moved successfully.
C:\Documents and Settings\Debra\My Documents\My Music\iMesh moved successfully.
C:\Program Files\iMesh Applications\Personalization\FF_v1053\components moved successfully.
C:\Program Files\iMesh Applications\Personalization\FF_v1053\chrome\skin moved successfully.
C:\Program Files\iMesh Applications\Personalization\FF_v1053\chrome\content moved successfully.
C:\Program Files\iMesh Applications\Personalization\FF_v1053\chrome moved successfully.
C:\Program Files\iMesh Applications\Personalization\FF_v1053 moved successfully.
C:\Program Files\iMesh Applications\Personalization moved successfully.
C:\Program Files\iMesh Applications\iMesh MediaBar moved successfully.
C:\Program Files\iMesh Applications\Common moved successfully.
C:\Program Files\iMesh Applications moved successfully.
File/Folder C:\Program Files\iMesh Applications\iMesh not found.
File/Folder C:\Program Files\iMesh Applications\iMesh MediaBar not found.
========== COMMANDS ==========
User's Temp folder emptied.
User's Internet Explorer cache folder emptied.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\P7KNC1OJ\default[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\P7KNC1OJ\InboxLight[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\01[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\iframe[2].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\Removal_System_Security_Version_4_51_t102192[4].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\ToastFull[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\ToastMini[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\8K0GI4Y0\B3249545[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\8K0GI4Y0\im[1].htm scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
File delete failed. C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat scheduled to be deleted on reboot.
User's Temporary Internet Files folder emptied.
Local Service Temp folder emptied.
File delete failed. C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot.
Local Service Temporary Internet Files folder emptied.
Network Service Temp folder emptied.
Network Service Temporary Internet Files folder emptied.
File delete failed. C:\WINDOWS\temp\00b9b389-2a90-41c2-a085-07e29c3fceec.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\09e072a7-b534-4f8b-82ac-f00b70d4e23a.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\11abac69-6682-49b0-9991-be6c3609e874.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\257b2417-a82e-4c3c-9224-a1baed4ef0ae.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\35b4c4dc-e935-4b27-8b84-9fea625cfd60.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\3c901fbe-278f-45e9-badd-e1fd5b9a87b9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\43bb0d17-6cc2-4f4c-ba4f-e071605c0175.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\53228363-6760-4507-ac3e-b3c007dd9048.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\53baa33e-5a6e-4983-8a25-30a76bd5e676.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\59a9c055-3efb-4af9-88b5-cf0de0319552.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\59ea896c-708b-4012-ab0f-0b90845644fb.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\5ab03f09-b92f-4a56-a6ad-e6be1dff47d4.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\5c1a8fd6-f9d7-4ca0-8c0f-62c384c5e87a.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\65e7fe51-4593-4a5d-bd16-0fca556a3d04.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\78454400-d1bd-4c58-baf3-a13ab4ecfe84.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\79ec1e99-eae0-42cc-ba71-35da09536221.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\7def6a33-1ebb-4874-95e4-58854e2f487b.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\7f3e7177-b76a-4bd2-8df8-d12aa8fe35d6.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\85a68419-01c3-4916-b660-34f0413264ae.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\8c0426d1-886d-4feb-80f2-fee5fb8adb9c.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\8de00c4c-b5af-402c-8c04-c43d195cff03.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\8eef63b5-6359-42b8-96ce-a2e3950d2ca9.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\9a7ed734-9202-4631-bddf-9ab91c9f4051.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ba96da31-b6bc-4e0d-b161-6b2f28a083a7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\c6b18cd3-66aa-4791-9426-930d4ac52f11.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\cc61036f-e544-4353-bf63-6d61ffa27343.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\e294acd0-4c8d-4e18-958f-fe8a8efcf142.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\ecae1c21-d36d-40d0-b341-a34c93e899e7.tmp scheduled to be deleted on reboot.
File delete failed. C:\WINDOWS\temp\Perflib_Perfdata_1a0.dat scheduled to be deleted on reboot.
Windows Temp folder emptied.
Java cache emptied.
Temp folders emptied.
Explorer started successfully

OTMoveIt3 by OldTimer - Version 1.0.11.0 log created on 04192009_114051

Files moved on Reboot…
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\P7KNC1OJ\default[1].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\P7KNC1OJ\InboxLight[2].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\01[1].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\iframe[2].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\Removal_System_Security_Version_4_51_t102192[4].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\ToastFull[1].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\E2F62KBO\ToastMini[1].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\8K0GI4Y0\B3249545[1].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\Content.IE5\8K0GI4Y0\im[1].htm moved successfully.
C:\Documents and Settings\Debra\Local Settings\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat moved successfully.
C:\WINDOWS\temp\00b9b389-2a90-41c2-a085-07e29c3fceec.tmp moved successfully.
C:\WINDOWS\temp\09e072a7-b534-4f8b-82ac-f00b70d4e23a.tmp moved successfully.
C:\WINDOWS\temp\11abac69-6682-49b0-9991-be6c3609e874.tmp moved successfully.
C:\WINDOWS\temp\257b2417-a82e-4c3c-9224-a1baed4ef0ae.tmp moved successfully.
C:\WINDOWS\temp\35b4c4dc-e935-4b27-8b84-9fea625cfd60.tmp moved successfully.
C:\WINDOWS\temp\3c901fbe-278f-45e9-badd-e1fd5b9a87b9.tmp moved successfully.
C:\WINDOWS\temp\43bb0d17-6cc2-4f4c-ba4f-e071605c0175.tmp moved successfully.
C:\WINDOWS\temp\53228363-6760-4507-ac3e-b3c007dd9048.tmp moved successfully.
C:\WINDOWS\temp\53baa33e-5a6e-4983-8a25-30a76bd5e676.tmp moved successfully.
C:\WINDOWS\temp\59a9c055-3efb-4af9-88b5-cf0de0319552.tmp moved successfully.
C:\WINDOWS\temp\59ea896c-708b-4012-ab0f-0b90845644fb.tmp moved successfully.
C:\WINDOWS\temp\5ab03f09-b92f-4a56-a6ad-e6be1dff47d4.tmp moved successfully.
C:\WINDOWS\temp\5c1a8fd6-f9d7-4ca0-8c0f-62c384c5e87a.tmp moved successfully.
C:\WINDOWS\temp\65e7fe51-4593-4a5d-bd16-0fca556a3d04.tmp moved successfully.
C:\WINDOWS\temp\78454400-d1bd-4c58-baf3-a13ab4ecfe84.tmp moved successfully.
C:\WINDOWS\temp\79ec1e99-eae0-42cc-ba71-35da09536221.tmp moved successfully.
C:\WINDOWS\temp\7def6a33-1ebb-4874-95e4-58854e2f487b.tmp moved successfully.
C:\WINDOWS\temp\7f3e7177-b76a-4bd2-8df8-d12aa8fe35d6.tmp moved successfully.
C:\WINDOWS\temp\85a68419-01c3-4916-b660-34f0413264ae.tmp moved successfully.
C:\WINDOWS\temp\8c0426d1-886d-4feb-80f2-fee5fb8adb9c.tmp moved successfully.
C:\WINDOWS\temp\8de00c4c-b5af-402c-8c04-c43d195cff03.tmp moved successfully.
C:\WINDOWS\temp\8eef63b5-6359-42b8-96ce-a2e3950d2ca9.tmp moved successfully.
C:\WINDOWS\temp\9a7ed734-9202-4631-bddf-9ab91c9f4051.tmp moved successfully.
C:\WINDOWS\temp\ba96da31-b6bc-4e0d-b161-6b2f28a083a7.tmp moved successfully.
C:\WINDOWS\temp\c6b18cd3-66aa-4791-9426-930d4ac52f11.tmp moved successfully.
C:\WINDOWS\temp\cc61036f-e544-4353-bf63-6d61ffa27343.tmp moved successfully.
C:\WINDOWS\temp\e294acd0-4c8d-4e18-958f-fe8a8efcf142.tmp moved successfully.
C:\WINDOWS\temp\ecae1c21-d36d-40d0-b341-a34c93e899e7.tmp moved successfully.
File C:\WINDOWS\temp\Perflib_Perfdata_1a0.dat not found!

HJT Log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:51:05 AM, on 4/19/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgfws8.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Dell Support Center\bin\sprtsvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe
C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WUSB54GS.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgam.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\WINDOWS\notepad.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\Dell Support Center\bin\sprtcmd.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe
C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Program Files\DellSupport\DSAgnt.exe
C:\Program Files\Windows Media Player\WMPNSCFG.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\AVG\AVG8\aAvgApi.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [dscactivate] "C:\Program Files\Dell Support Center\gs_agent\custom\dsca.exe"
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [DellSupport] "C:\Program Files\DellSupport\DSAgnt.exe" /startup
O4 - HKCU\..\Run: [DellSupportCenter] "C:\Program Files\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\Hp\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm
O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://pccheckup.dellfix.com/sdccommon/download/tgctlcm.cab
O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - http://support.dell.com/systemprofiler/SysPro.CAB
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.1…toUploader5.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/resources/MSNPUpld.cab
O16 - DPF: {54BE6B6F-3056-470B-97E1-BB92E051B6C4} (DeviceEnum Class) - http://h30155.www3.hp.com/ediags/dd/instal…nosticsxp2k.cab
O16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/Facebo…toUploader3.cab
O16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cab
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - http://h20270.www2.hp.com/ediags/gmn2/inst…ctDetection.cab
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) - http://www.worldwinner.com/games/shared/wwlaunch.cab
O16 - DPF: {BA94245D-2AA0-4953-9D9F-B0EE4CC02C43} (Tilecity Control) - http://www.worldwinner.com/games/v42/tilecity/tilecity.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Messe…nt.cab56907.cab
O16 - DPF: {C5326A4D-E9AA-40AD-A09A-E74304D86B47} (DinerDash Control) - http://www.worldwinner.com/games/v49/dinerdash/dinerdash.cab
O16 - DPF: {D6E7CFB5-C074-4D1C-B647-663D1A8D96BF} (Facebook Photo Uploader 4) - http://upload.facebook.com/controls/Facebo…Uploader4_5.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: AVG8 Firewall (avgfws8) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgfws8.exe
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SupportSoft Sprocket Service (dellsupportcenter) (sprtsvc_dellsupportcenter) - SupportSoft, Inc. - C:\Program Files\Dell Support Center\bin\sprtsvc.exe
O23 - Service: WUSB54GSSVC - GEMTEKS - C:\Program Files\Linksys Wireless-G USB Wireless Network Monitor\WLService.exe

–
End of file - 10175 bytes
Hi OT, I checked with Revo Uninstaller and Add/Remove programs and it is still not there. In Task Manager it is gone as well, the only process running that I would question is iexplore.exe. If this isn't suspicious then I hope we can assume that it's gone?
Hi sassybella

It should be gone now. How's the computer?

iexplore= Internet Explorer, so it's OK. :thumbup:

Regarding your other family member's computers, you are more than welcome to post a log here when you get the opportunity. Someone will be more than happy to assist you. :)


We'll clean up the tools now.

From your desktop, please delete
  • any notepads/logs that we created
  • SystemLook.exe
ERUNT, Revo Uninstaller and HostXpert can be kept or removed, your choice.

Erunt can be used to keep a current backup of you registry, just in case you need it.

Revo Uninstaller may be useful if you ever have a similar prroblem with a stubborn uninstall.

HostXpert can be used to install a custom Hosts file.




We'll now remove our tools.

Click the Start button, click Run. Copy and paste the following line into the run box and click OK
Combofix /u

Open OTMoveIt3 then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.


I suggest you keep MBAM. Keep MBAM updated and use it regularly.


Another handy little tool you may be interested in is ATF. It will clean out the temp folders and caches where malware can hide. Just use it from time to time. No need to run it now, but you may like to use it in the future.

It can be downloaded from HEREand is easy to use. Simply download it and save it to a convient location.

Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main menu to close the program.

Note your computer may boot a little slower the first couple of times.




Updates and upgrades

* If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site and make sure you have at least all the cirtical updates installed (Free) Microsoft Office Update

You have an older version of Adobe Reader. You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 8.1.3 first. Be sure to move any PDF documents to another folder first though.



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. With the addition of MBAM,you have those all ready with the exception of a resident antispyware program.

I suggest

Winpatrol
OR
Windows Defender

You should also use Spyware Blaster to help immunize your computer.

- SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.

OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.




-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.



- Ensure that Automatic Update is turned on so you get all the latest patches.
Click start, control panel, click Security Center.


- Keep your antivirus program updated, as well as any other security programs you have.


- You may also want to read this article By Tony Klein
http://www.freedomlist.com/forum/viewtopic.php?t=22879


We will keep this thread open for a couple of days. Please post back if you have any problems or questions. Please post back when you have finished so this thread can be marked "Resolved".

Take care :adios:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI