This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

iexplore.exe and other problems

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey, I've been having some problems lately. Mainly there are a few instances of iexplore.exe running at all times which I have had problems with before and cannot get rid of. Here is my HJT Log. Thanks in advance for your help. Logfile of HijackThis v1.99.1 Scan saved at 7:02:03 PM, on 1/3/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe F:\Program Files\Java\jre1.5.0_06\bin\jusched.exe F:\Program Files\Eset\nod32kui.exe F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe F:\WINDOWS\system32\ctfmon.exe f:\progra~1\intern~1\iexplore.exe F:\Program Files\Logitech\SetPoint\SetPoint.exe F:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE F:\WINDOWS\System32\cisvc.exe F:\Program Files\Eset\nod32krn.exe F:\WINDOWS\system32\nvsvc32.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\explorer.exe F:\Program Files\Internet Explorer\IEXPLORE.EXE F:\Program Files\Trillian\trillian.exe F:\Program Files\Mozilla Firefox\firefox.exe F:\WINDOWS\system32\cidaemon.exe F:\Program Files\hijackthis\HijackThis.exe O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O4 - HKLM\..\Run: [NVMixerTray] "F:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [nod32kui] "F:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [nod32upd] rundll32 "F:\Program Files\Eset\fc_upd.dll",NOD32Ioctl O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [RoxWatchTray] "F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe" O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [mfcd cake] F:\DOCUME~1\Matt\APPLIC~1\GRIMKE~1\Bold first real.exe O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe O10 - Unknown file in Winsock LSP: f:\progra~1\netdog\netd.dll O10 - Unknown file in Winsock LSP: f:\progra~1\netdog\netd.dll O11 - Options group: [INTERNATIONAL] International* O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\ O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Autodesk Licensing Service - Autodesk - F:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - F:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe O23 - Service: RoxMediaDB - Sonic Solutions - F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
Hi! :wavey: and welcome to the Malware Removal forums.
My name is John Brouwer - if it helps, you can call me John for short. I'll be glad to help you with your computer problems.

HijackThis logs can take some time to research, so please be patient with me. I know that you need
your computer working as quickly as possible, and I will work hard to help see that happens.
I am currently looking over your log. As I am a trainee, everything that I post to you must be checked by an Admin or Moderator. Thus, there may be a tiny bit of a delay between posts, but it shouldn't be too long. I will post back shortly with a potential fix.

Please be patient and I'd be grateful if you would note the following:
  • I will working be on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for this issue on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
Greets, John.
Hi,

You've got only one infection. The infection is called LOP and a special tool is available to remove it.

Step 1: Download and Run NoLop
Download NoLop.exe to your Desktop.
  • First close any other programs you have running as this will require a reboot
  • Double click NoLop.exe to run it.
  • Now click the button labelled "Search and Destroy"
    <>
  • When scanning is finished you will be prompted to reboot only if infected, Click OK
  • Now click the "REBOOT" Button.
  • A Message should popup from NoLop. If not, double click the program again and it will finish.
  • Please post the contents of C:\NoLop.log later.
NOTE :
  • If you receive an error, "mscomctl.ocx or one of its dependencies are not correctly registered," please download mscomctl.ocx to C:\WINDOWS\system32\ folder then rerun the program.
Step 2: Post C:\NoLop.log + new HijackThis log

Greets, John.
Thanks, here is the NoLOP log followed by the new HJT log. NoLop! Log by Skate_Punk_21 Fix running from: F:\Documents and Settings\[removed]\Desktop [1/5/2007] [7:15:45 AM] —Infection Files Found/Removed— F:\WINDOWS\tasks\B9ADB0FE817A25FA.job Beginning Removal… Rebooting… Removing Lop's Leftover Files/Folders… Editing Registry… **Fix Complete!** —Listing AppData sub directories— F:\Documents and Settings\All Users\Application Data\Adobe F:\Documents and Settings\All Users\Application Data\Adobe Systems F:\Documents and Settings\All Users\Application Data\Ahead F:\Documents and Settings\All Users\Application Data\Apple Computer F:\Documents and Settings\All Users\Application Data\Autodesk F:\Documents and Settings\All Users\Application Data\Avg7 – EMPTY Directory F:\Documents and Settings\All Users\Application Data\Installshield F:\Documents and Settings\All Users\Application Data\Less Deaf Lite Two F:\Documents and Settings\All Users\Application Data\Microsoft F:\Documents and Settings\All Users\Application Data\Nview_profiles – EMPTY Directory F:\Documents and Settings\All Users\Application Data\Office Genuine Advantage F:\Documents and Settings\All Users\Application Data\Pixelstorm F:\Documents and Settings\All Users\Application Data\Quicktime F:\Documents and Settings\All Users\Application Data\Real – EMPTY Directory F:\Documents and Settings\All Users\Application Data\Roxio F:\Documents and Settings\All Users\Application Data\Sonic F:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy F:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage F:\Documents and Settings\Default User\Application Data\Microsoft F:\Documents and Settings\Localservice\Application Data\Adobe F:\Documents and Settings\Localservice\Application Data\Help – EMPTY Directory F:\Documents and Settings\Localservice\Application Data\Microsoft F:\Documents and Settings\Localservice\Application Data\Roxio F:\Documents and Settings\Matt\Application Data\Adobe F:\Documents and Settings\Matt\Application Data\Adobeum F:\Documents and Settings\Matt\Application Data\Ahead F:\Documents and Settings\Matt\Application Data\Aim F:\Documents and Settings\Matt\Application Data\Anvil Studio F:\Documents and Settings\Matt\Application Data\Apple Computer F:\Documents and Settings\Matt\Application Data\Autodesk F:\Documents and Settings\Matt\Application Data\Azureus F:\Documents and Settings\Matt\Application Data\Bitgrabber F:\Documents and Settings\Matt\Application Data\Dmcache – EMPTY Directory F:\Documents and Settings\Matt\Application Data\Executivesoftware F:\Documents and Settings\Matt\Application Data\Fretsonfire F:\Documents and Settings\Matt\Application Data\Grim Keep F:\Documents and Settings\Matt\Application Data\Help F:\Documents and Settings\Matt\Application Data\Identities F:\Documents and Settings\Matt\Application Data\Kana Solution F:\Documents and Settings\Matt\Application Data\Lavasoft F:\Documents and Settings\Matt\Application Data\Leadertech F:\Documents and Settings\Matt\Application Data\Logitech F:\Documents and Settings\Matt\Application Data\Macromedia F:\Documents and Settings\Matt\Application Data\Mechsoft F:\Documents and Settings\Matt\Application Data\Media Player Classic F:\Documents and Settings\Matt\Application Data\Microsoft F:\Documents and Settings\Matt\Application Data\Mozilla F:\Documents and Settings\Matt\Application Data\Opera – EMPTY Directory F:\Documents and Settings\Matt\Application Data\Publish Providers – EMPTY Directory F:\Documents and Settings\Matt\Application Data\Rapidget F:\Documents and Settings\Matt\Application Data\Real F:\Documents and Settings\Matt\Application Data\Roxio F:\Documents and Settings\Matt\Application Data\Smartftp F:\Documents and Settings\Matt\Application Data\Sony F:\Documents and Settings\Matt\Application Data\Ssh F:\Documents and Settings\Matt\Application Data\Sun F:\Documents and Settings\Matt\Application Data\Talkback F:\Documents and Settings\Matt\Application Data\Thunderbird F:\Documents and Settings\Matt\Application Data\Winamp F:\Documents and Settings\Networkservice\Application Data\Microsoft Logfile of HijackThis v1.99.1 Scan saved at 7:22:10 AM, on 1/5/2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.5730.0011) Running processes: F:\WINDOWS\System32\smss.exe F:\WINDOWS\system32\winlogon.exe F:\WINDOWS\system32\services.exe F:\WINDOWS\system32\lsass.exe F:\WINDOWS\system32\svchost.exe F:\WINDOWS\System32\svchost.exe F:\WINDOWS\system32\spoolsv.exe F:\WINDOWS\Explorer.EXE F:\WINDOWS\system32\netdde.exe F:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe F:\Program Files\Java\jre1.5.0_06\bin\jusched.exe F:\Program Files\Eset\nod32kui.exe F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe F:\WINDOWS\system32\ctfmon.exe F:\WINDOWS\System32\cisvc.exe f:\progra~1\intern~1\iexplore.exe F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe F:\Program Files\Logitech\SetPoint\SetPoint.exe F:\Program Files\Eset\nod32krn.exe F:\WINDOWS\system32\nvsvc32.exe F:\Program Files\Internet Explorer\IEXPLORE.EXE F:\WINDOWS\System32\svchost.exe F:\Program Files\Common Files\Logitech\KHAL\KHALMNPR.EXE F:\WINDOWS\system32\wscntfy.exe F:\Program Files\Common Files\Roxio Shared\SharedCOM8\CPSHelpRunner.exe F:\WINDOWS\system32\wuauclt.exe F:\Program Files\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.5.0_06\bin\ssv.dll O4 - HKLM\..\Run: [NVMixerTray] "F:\Program Files\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] F:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE F:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE F:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE O4 - HKLM\..\Run: [nod32kui] "F:\Program Files\Eset\nod32kui.exe" /WAITSERVICE O4 - HKLM\..\Run: [nod32upd] rundll32 "F:\Program Files\Eset\fc_upd.dll",NOD32Ioctl O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [RoxWatchTray] "F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatchTray.exe" O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "F:\Program Files\Common Files\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [mfcd cake] F:\DOCUME~1\Matt\APPLIC~1\GRIMKE~1\Bold first real.exe O4 - Startup: Adobe Gamma.lnk = F:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = F:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe O10 - Unknown file in Winsock LSP: f:\progra~1\netdog\netd.dll O10 - Unknown file in Winsock LSP: f:\progra~1\netdog\netd.dll O11 - Options group: [INTERNATIONAL] International* O20 - Winlogon Notify: WgaLogon - F:\WINDOWS\ O23 - Service: Adobe LM Service - Adobe Systems - F:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Autodesk Licensing Service - Autodesk - F:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - F:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - F:\Program Files\Eset\nod32krn.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - F:\WINDOWS\system32\nvsvc32.exe O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxLiveShare.exe O23 - Service: RoxMediaDB - Sonic Solutions - F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxMediaDB.exe O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - F:\Program Files\Common Files\Roxio Shared\SharedCOM8\RoxWatch.exe
Hi,

Step 1: Remove bad HijackThis entries
  • Run HijackThis
  • Click on the Scan button
  • Put a check beside all of the items listed below (if present):

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [mfcd cake] F:\DOCUME~1\Matt\APPLIC~1\GRIMKE~1\Bold first real.exe

  • Close all open windows and browsers/email, etc…
  • Click on the "Fix Checked" button
  • When completed, close the application.
Step 2: Show your hidden files
To enable the viewing of Hidden files follow these steps:
  • Close all programs so that you are at your desktop.
  • Double-click on the My Computer icon (or click Start, then select My Computer)
  • Select the Tools menu and click Folder Options.
  • After the new window appears select the View tab.
  • Put a checkmark in the checkbox labeled Display the contents of system folders.
  • Under the Hidden files and folders section select the radio button labeled Show hidden files and folders.
  • Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
  • Remove the checkmark from the checkbox labeled Hide protected operating system files.
  • Press the Apply button and then the OK button and shutdown My Computer.
    Now your computer is configured to show all hidden files.
Step 3: Delete bad folders
Use Explorer to navigate to and delete the following folders (if present):

F:\Documents and Settings\All Users\Application Data\Less Deaf Lite Two
F:\Documents and Settings\Matt\Application Data\Grim Keep

Now just close Explorer.

Step 4: Update Java
Older versions have vulnerabilities that malware can use to infect your system. Please follow these steps to remove older version Java components and update.
  • Download the latest version of Java™ SE Runtime Environment 6.
  • Scroll down to where it says "The J2SE Runtime Environment (JRE) allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation with or without Multi-language and save to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Control Panel double-click on Add/Remove programs and remove all older versions of Java.
  • Check any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on the download to install the newest version.
Step 5: Run Kaspersky Online Scan
Please do an online scan with Kaspersky WebScanner

Click on Kaspersky Online Scanner

You will be promted to install an ActiveX component from Kaspersky,
Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
Step 6: Post logs
You may need several replies for this:
* Kaspersky log
* New HijackThis log
* Tell me if you're still experiencing any problems

Greets, John.
While I was in the process of doing the fix my computer hit some major problems. After I was unable to delete the "F:\Documents and Settings\All Users\Application Data\Less Deaf Lite Two" directory because it was in use- iexplore.exe was still not stopped. I attempted to reboot to safemode, which is when my computer failed to restart. I can get my computer to the windows f8 option screen but cannot get it to boot with any of the options. So I need to fix my boot sector, if only I could find my Win XP installation CD. Is there any easy way to repair the boot sector with knoppix if it has not been backed up previously? Also, any guess what got screwed up? No settings other than the folder view options were changed while attempting the fix, and I know that couldn't have done anything serious. Anyway, I'll keep working at it and hopefully have an update on the attempted fix by tomorrow.
Hi, Are you getting any errors or do you hear beeps? You can use the cd of a friend if you don't have one yourself… Greets, John.
Hey, sorry! I got my computer back up and running yesterday and ran the scans last night. Everything seems to be taken care of. Thanks for your help.
Hi,

This is my normal post for when you are clear - which you now are - or seem to be. Please advise of any problems you still have :

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
  • Disable and Enable System Restore. - If you are using Windows ME or XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.
    You can find instructions on how to enable and re enable system restore here:
    Managing Windows Millennium System Restore
    or
    Windows XP System Restore Guide
    re-enable system restore with instructions from tutorial above.
  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialise and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an Anti Virus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future. See this link for a listing of some on line & their stand-alone anti virus programs:
    Computer Safety On line - Anti-Virus
    I recommend AVG Anti-Virus (Free Edition)!
  • Update your Anti Virus Software - It is imperitive that you update your Anti virus software at least once a week (Even more if you wish). If you do not update your anti virus software then it will not be able to catch any of the new variants that may come out.
  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is susceptible to being hacked and taken over. Simply using a Firewall in its default configuration can lower your risk greatly. For an article on Firewalls and a listing of some available ones see the link below:
    Computer Safety On line - Software Firewalls
    I recommend ZoneAlarm (Free Edition)!
  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
  • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.
    This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with the program on a regular basis just as you would an anti virus software in conjunction with Spybot. A tutorial on installing & using this product can be found here:
    Instructions for - Spybot S & D and Ad-aware
  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs. A article on anti-malware products with links for this program and others can be found here:
    Computer Safety on line - Anti-Malware
  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Stand Up and Be Counted!
Please take the time to tell us what you would like to be done about the people who are behind all the problems you have had. We can only get something done about this if the people that we help, like you, are prepared to complain. We have a dedicated forum for collecting these complaints Malware Complaints, you have to be registered to post after registering just find your country room and register your complaint.
The infection you had was LOP

May your God go with you..

John.
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.

Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.

Coyote's Installed programs for prevention:

http://forums.tomcoyote.org/index.php?showtopic=31418

The help you receive here is free. If you wish to show your appreciation, then you may donate to help keep us online.

Visit the CoyoteStore http://TomCoyote.org/coyotestore.php

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI