[Resolved] infected
18 min read
Hello 111mike,
Welcome to What the Tech.
My name is OCD, I will be helping you today.
Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advise.
This may cause a delay, but I will do my best to keep it as short as possible.
If you are unable to download HijackThis to the infected computer please use another computer and download HJT
to a thumb drive or a CD, transfer it to the infected computer and generate a log for review.
- - - - - Next - - - - -
Download HijackThis from http://www.trendsecure.com/portal/en-US/_download/HJTInstall.exe .
- Choose the default location of C:\Program Files\Trend Micro\HijackThis as the destination. HJT needs to be in its own folder so that the program itself isn't deleted by accident. Having the backups could be VITAL to restoring your system if something went wrong in the FIX process!
- Click the Install button.
- Accept the license agreement .
- The progam will place a shortcut on your desktop. This will make it easier for you to access the tool when required.
- Click Do a system scan and save a log file. A Notepad file will open.
- To post the text, first you must highlight the entire text and then press the (Ctrl+C) keys which copies it to your clipboard.
- Now paste the log into this thread using the (Ctrl + V) buttons.
- - - - - Next - - - - -
Reboot, on your next post please provide the following:
- HijackThis log
- Tell me how your computer is running at the moment.
Heres the log
thanks
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:54:52 PM, on 6/2/2009
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16764)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Napster\napster.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch…P&M=GT5453E
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch…P&M=GT5453E
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch…P&M=GT5453E
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\..\Run: [Messenger (Yahoo!)] "C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe" -quiet
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OneNote 2007 Screen Clipper and Launcher.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra button: PokerStars.net - {FA9B9510-9FCB-4ca0-818C-5D0987B47C4D} - C:\Program Files\PokerStars.NET\PokerStarsUpdate.exe
O13 - Gopher Prefix:
O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL,avgrsstx.dll
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\Gateway Games\Gateway Game Console\GameConsoleService.exe
O23 - Service: Google Desktop Manager 5.7.806.10245 (GoogleDesktopManager-061008-081103) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
O23 - Service: PrismXL - New Boundary Technologies, Inc. - C:\Program Files\Common Files\New Boundary\PrismXL\PRISMXL.SYS
O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot - Search & Destroy\SDWinSec.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
–
End of file - 8732 bytes
Hello 111mike,
- You may want to print out these instructions for reference prior to proceeding.
- This solution is specifically tailored for this particular problem, please do not attempt to use this solution on another computer.
- If you have any questions, or are uncertain about any steps please ask 'before' proceeding.
Please tell me what Firewall you currently have installed and are using for protection.
- - - - - Next - - - - -
Disable SpyBot's Tea Timer
- Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
- On the left hand side, click on Tools, then click on the Resident Icon in the list.
- Uncheck the "Resident TeaTimer" (Protection of overall system settings) active." box.
- Click on the "System Startup" icon in the List
- Uncheck the "TeaTimer" box and "OK" any prompts.
- If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
- Exit Spybot S&D when done.
Please download ATF Cleaner by Atribune.
Download - http://www.nutnworks.com/downloads/ATF_Cleaner.exe
- Right Click ATF-Cleaner.exe and select "Run As Administrator" to run the program.
- Under Main choose: Select All
- Click the Empty Selected button.
- Click Firefox at the top and choose: Select All
- Click the Empty Selected button.
- NOTE: If you would like to keep your saved passwords, please click No at the prompt.
- Click Opera at the top and choose: Select All
- Click the Empty Selected button.
- NOTE: If you would like to keep your saved passwords, please click No at the prompt.
- - - - - Next - - - - -
You stated in your opening that you ran Malwarebytes and it removed some entries.
Please open MBAM, go to the Logs tab and locate your previous scan's log and post it.
(The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.)
If you no longer have the log, please re-run Malwarebytes by following the steps below.
Right Click mbam-setup.exe and select "Run As Administrator" to install the application.
- Make sure a check mark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
- If an update is found, it will download and install the latest version.
- Once the program has loaded, select "Perform Quick Scan", then click Scan.
- The scan may take some time to finish,so please be patient.
- When the scan is complete, click OK, then Show Results to view the results.
- Make sure that everything is checked, and click Remove Selected.< < Don't forget this!
- When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.
(The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.)
- Copy and Paste the entire report in your next reply.
Please download DDS by sUBs from one of the following links and save it to your desktop.
- DDS.scr
- DDS.pif
- Disable any script blocking protection (How to Disable your Security Programs)
- Right Click DDS icon and select "Run As Administrator" to run the tool (may take up to 3 minutes to run)
- When done, DDS.txt will open.
- After a few moments, attach.txt will open in a second window.
- Save both reports to your desktop.
Reboot, on your next post please provide the following:
- MBAM log
- Post the contents of the DDS.txt report in your next reply
- Attach the Attach.txt report to your post by scroling down to the Attachments area and then clicking Browse. Browse to where you saved the file, and click Open and the click UPLOAD.
- Answer firewall question from above
111mike,
You have/had Limewire, a P2P/file sharing program installed on your computer. P2P applications like it are the largest source of malware we see. You'll be doing yourself a favor by removing it.
References for the risk of these programs can be found in these links:
http://www.microsoft.com/windows/ie/commun…protection.mspx
http://www.techweb.com/wire/160500554
http://www.internetworldstats.com/articles/art053.htm
If you wish to keep it, please do not use it until your computer is cleaned.
I would recommend that you uninstall Limewire, however that choice is up to you.
- - - - - Next - - - - -
You log shows signs of Norton or Symantec Products on your computer. Do you use these anymore?
If not please follow these instructions:
Remove Norton or Symantec Products
Note : You should first attempt to remove your Norton/Symantec product using Add/Remove Programs in the Windows Control Panel (Programs and Features, in Windows Vista). This is the best method.
Uninstall anything with Norton or Symantec in the name
After uninstalling using Windows Add/Remove Programs, run the Norton Removal Tool to ensure successful removal of all Norton references.
If no entries are present in the Windows Add/Remove Programs you still need to run Norton Removal Tool below.
Please go to http://service1.symantec.com/Support/tsgen…005033108162039 and select the product you have
- Download the Norton Removal Tool.
- Save the file to the Windows desktop.
- On the Windows desktop, double-click the Norton Removal Tool icon.
- Follow the on-screen instructions.
Your computer may be restarted more than once, and you may be asked to repeat some steps after the computer restarts.
Please go to Start Menu > Control Panel > Add/ Remove Programs
Scroll Down and locate the following programs:
- Norton or Symantec (any product with Norton or Symantec in the name)
- LimeWire
- Java™ SE Runtime Environment 6
(if the program is not listed don't be alarmed, just continue with the list)
Exit the Control Panel when finished.
- - - - - Next - - - - -
Please locate the file in red and delete it. Please be sure to only delete the file that is designated.
(Not the folder they are contained in)
- c:\users\sister\appdata\roaming\wklnhst.dat
I need you to run the following scan: Eset Online Scanner
You will need Internet Explorer to run this scan.
- Place a check mark in the box YES, I accept the Terms Of Use
- Click the Start button.
- Now click the Install button.
- Click Start. The scanner engine will initialize and update.
- Place a check mark in the box beside Remove found threats.
- Click the Scan button. The scan will now run, please be patient.
- When the scan finishes click the Details tab.
- Copy and paste the contents of the C:\ProgramFiles\EsetOnlineScanner\log.txt into your next reply.
Reboot, on your next post please provide the following:
- ESET log.txt
- Tell me how your computer is running at the moment.
111mike,
OK, but please refrain from using Limewire until after we are finished.1. Can't do anything about Limewire, it's a friend's computer. I will explain to them though the risk of getting further infections.
I should have been clearer with my instructions. The path is most likely:3. There is no c:\users\sister\appdata\roaming\wklnhst.dat. In fact, there is no appdata folder at all.
c:\users\sister\application data\roaming\wklnhst.dta
Please navigate the following path to locate the ESET log.4. Also, I ran ESET. There was no details tab. I ran it again just to make sure. Maybe I missed it. At any rate, no infections were found either time.
C:\ProgramFiles\EsetOnlineScanner\log.txt
- - - - - Next - - - - -
So please continue with these steps:
Enable the Viewing of Hidden files, please follow these steps:
- Open Folder Options by clicking the Start button,
- Clicking Control Panel > Appearance and Personalization, and then > Folder Options
- Click the View Tab > Under Advanced Settings, click Show hidden files and folders, and then click OK.
Please locate the file in red and delete it. Please be sure to only delete the file that is designated.
(Not the folder they are contained in)
- c:\users\sister\application data\roaming\wklnhst.dta
Please navigate the following path to locate the ESET log.
C:\ProgramFiles\EsetOnlineScanner\log.txt
- - - - - Next - - - - -
Reboot, on your next post please provide the following:
- ESET log.txt
- Tell me how your computer is running at the moment.
111mike,
Please try this scanner by Kaspersky.
The below scan can take up to an hour or longer, please be patient.
*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so no conflicts and to speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once scan is finished remember to re-enable resident antivirus protection along with whatever antispyware app you use.
Please do a scan with Kaspersky Online Scanner or from here
http://www.kaspersky.com/virusscanner
Note: If you are using Windows Vista, open your browser by right-clicking on its icon and select 'Run as administrator' to perform this scan.
- Click on the Accept button and install any components it needs.
- The program will install and then begin downloading the latest definition files.
- After the files have been downloaded on the left side of the page in the Scan section select My Computer.
- This will start the program and scan your system.
- The scan will take a while, so be patient and let it run. (At times it may appear to stall)
- Once the update is complete, click on My Computer under the green Scan bar to the left to start the scan.
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Do NOT be alarmed by what you see in the report. Many of the finds have likely been quarantined.
- Once the scan is complete, click on View scan report To obtain the report:
- Click on: Save Report As
- Next, in the Save as prompt, Save in area, select: Desktop
- In the File name area, use KScan, or something similar In Save as type, click the drop arrow and select: Text file [*.txt]
- Then, click: Save
- Please post the Kaspersky Online Scanner Report in your reply.
Animated tutorial
http://i275.photobucket.com/albums/jj285/B…ng/KAS/KAS9.gif
(Note.. for Internet Explorer 7 users:
If at any time you have trouble with the "Accept" button of the license, click on the "Zoom" tool located at the bottom right of the IE window and set the zoom to 75 %. Once the license has been accepted, reset to 100%.)
Or use Firefox with IE-Tab plugin
https://addons.mozilla.org/en-US/firefox/addon/1419
- - - - - Next - - - - -
Reboot, on your next post please provide the following:
- Kaspersky log
- Tell me how your computer is running at the moment.
111mike,
Congratulations, your computer is clean.
We have a few items to take care of before we get to my "All Clean Speech"
Enable SpyBot's Tea Timer
- Launch Spybot S&D, go to the Mode menu and make sure "Advanced Mode" is selected.
- On the left hand side, click on Tools, then click on the Resident Icon in the list.
- Check the "Resident TeaTimer" (Protection of overall system settings) active." box.
- Click on the "System Startup" icon in the List
- Check the "TeaTimer" box and "OK" any prompts.
- If Teatimer gives you a warning that changes were made, click the "Allow Change" box when prompted.
- Exit Spybot S&D when done.
Consider changing your Firewall to one that provides better protection than the Windows Firewall you are currently using.
Here are a few FREE ones:
- Please download one (1) of the firewalls below, but do not install it just yet.
- After you have downloaded the new firewall, disable the Windows firewall.
- Then install the newly selected firewall.
- Comodo - http://www.personalfirewall.comodo.com/
- Outpost Firewall FREE - http://www.agnitum.com/products/outpostfree/
Your Adobe Reader is out of date.
Please go to http://get.adobe.com/reader/ and download Adobe Reader 9
follow the instructions to install Adobe Reader.
- - - - - Next - - - - -
Your Java is outdated.
Please follow these steps to remove any older version Java components we may have missed.
- Close any programs you may have running, ESPECIALLY your web browser
- Click Start > Control Panel.
- Click Add/Remove Programs.
- Check any item with Java Runtime Environment (JRE or J2SE) in the name.
- Click the Remove or Change/Remove button.
- Repeat as many times as necessary to remove all versions of Java.
- Reboot your computer once all Java components are removed.
There is no need to download the Sun Dowload manager but it is optional.
- - - - - Next - - - - -
Here comes the "All Clean Speech":
Now that your log is clean, you need to set a new clean System Restore Point
Create a new Restore Point
- Click on the Start button to open your Start Menu.
- Click on the Control Panel menu option.
- Click on the System and Maintenance menu option.
- Click on the System menu option.
- Click on System Protection in the left-hand task list.
- Create the manual restore point you should click on the Create button. When you press this button a prompt will appear asking you to provide a title for this manual restore point.
- Type in a title for the manual restore point and press the Create button.
- Close the System window after you have been advised that the procedure has been successfully completed.
Clear your existing system restore points except for the new clean restore point you just created:
- Go to Start > Run and type in cleanmgr
- Select the More options tab
- Next to System Restore click Clean up
- This will remove all restore points except the new one you just created.
Delete the Contents of the Temporary Internet Files Folder:
- Quit Internet Explorer and quit any instances of Windows Explorer.
- Click Start, click Control Panel, and then double-click Internet Options.
- On the General tab, click Delete Files under Temporary Internet Files.
- In the Delete Files dialog box, click to select the Delete all offline content check box , and then click OK.
- Click OK
Automatic Updates:
The easiest way to ensure you don't miss any of the critical Windows Updates is to set your computer up to receive Automatic Updates.
To set your computer up for Automatic Updates please do the following:
- Click Start, and then click Control Panel.
- Depending on which Control Panel view you use, Classic or Category, do one of the following:
- Click System, and then click the Automatic Updates tab.
- Click Performance and Maintenance, click System, and then click the Automatic Updates tab.
- Select Automatic and choose a frequency and time that's convenient for you to get the updates.
- Click Apply, then OK
- Close the Control Panel.
Here are some tips to reduce the potential for spyware infection in the future:
Make your Internet Explorer more secure - This can be done by following these simple instructions:
- From within Internet Explorer click on the Tools menu and then click on Options.
- Click once on the Security tab.
- Click once on the Internet icon so it becomes highlighted.
- Click once on the Custom Level button.
- Change the Download signed ActiveX controls to Prompt
- Change the Download unsigned ActiveX controls to Disable
- Change the Initialize and script ActiveX controls not marked as safe to Disable
- Change the Installation of desktop items to Prompt
- Change the Launching programs and files in an IFRAME to Prompt
- Change the Navigate sub-frames across different domains to Prompt
- When all these settings have been made, click on the OK button.
- If it prompts you as to whether or not you want to save the settings, press the Yes button.
Simple and easy ways to keep your computer safe and secure on the Internet
Alternate Browsers - If you are currently using Internet Explorer you might want to consider changing over to Firefox.
Firefox is one of the most popular alternate browsers. - Mozilla Firefox
Update your AntiVirus Software - You are using AVG8 as your anti virus software. It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Use a Firewall - You are using Windows Firewall (unless you changed to one of the suggested ones above) I cannot stress how important it is that you keep the Firewall on your computer active at all times. Without a firewall your computer is susceptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly. For a tutorial on Firewalls and a listing of some available ones see the link below:
Understanding and Using Firewalls
Install SpywareBlaster - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs. A tutorial on installing & using this product can be found here:
Using SpywareBlaster to protect your computer from Spyware and Malware
IE-SPYAD puts over 5000 sites in your restricted zone so you'll be protected when you visit innocent-looking sites that
aren't actually innocent at all. Using IE-SPYAD to help block unwanted sites and activities
Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly.
This will ensure your computer always has the latest security updates available installed on your computer.
If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Update all security programs regularly - Make sure you update all the programs regularly.
Without regular updates you WILL NOT be protected when new malicious programs are released.
Remember to have only one (1) Firewall and one (1) Anti-Virus program running at any one time.
I would also suggest you read "So how did I get infected in the first place"?: by Tony Klein
Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
111mike,
I'm glad everything is working well for you. It has been my pleasure to help. ![]()
Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI