Page 2 of 2 FirstFirst 12
Results 11 to 18 of 18

Thread: Please help

  1. #11
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 10:10:38 AM, on 10/14/2007
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Boot mode: Normal

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\Explorer.EXE
    C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe
    C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
    C:\Program Files\QuickTime\qttask.exe
    C:\WINNT\system32\winsock4.exe
    C:\WINNT\system32\svohst.exe
    c:\program files\internet explorer\iexplore.exe
    C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    C:\Program Files\NetAssistant\bin\mpbtn.exe
    C:\WINNT\system32\notepad.exe
    C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.ca/
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\windows\system32\blank.htm
    R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
    O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe
    O4 - HKLM\..\Run: [Keyboard Driver (do not remove)] ESOLVER.EXE
    O4 - HKLM\..\Run: [REGRUN] C:\WINNT\system32\iexplorer\a.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [winsockdriver] winsock4.exe
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [svchst] C:\WINNT\system32\svohst.exe
    O4 - HKLM\..\RunServices: [sys33] Sys33.exe
    O4 - HKCU\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO
    O4 - HKCU\..\RunServices: [HTML Help System] hhs.pif
    O4 - HKCU\..\RunServices: [Browser Help Svc] BHSV.EXE
    O4 - HKCU\..\RunServices: [Updt Service] updt.pif
    O4 - HKCU\..\RunOnce: [winsockdriver] winsock4.exe
    O4 - HKUS\S-1-5-21-1214440339-2111687655-854245398-500\..\Run: [ccleaner] "C:\Program Files\CCleaner\CCleaner.exe" /AUTO (User '?')
    O4 - HKUS\S-1-5-21-1214440339-2111687655-854245398-500\..\RunOnce: [winsockdriver] winsock4.exe (User '?')
    O4 - HKUS\S-1-5-21-1214440339-2111687655-854245398-500\..\RunServices: [HTML Help System] hhs.pif (User '?')
    O4 - HKUS\.DEFAULT\..\Run: [Win32 Info] windowsnfo.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [CU1] C:\Program Files\Common Files\VCClient\VCClient.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [CU2] C:\Program Files\Common Files\VCClient\VCMain.exe (User 'Default user')
    O4 - HKUS\.DEFAULT\..\Run: [Aupw] "C:\Program Files\mssa\ostn.exe" -vt yazr (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
    O4 - HKUS\.DEFAULT\..\RunServices: [Win32 Info] windowsnfo.exe (User 'Default user')
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: NetAssistant.lnk = C:\Program Files\NetAssistant\bin\matcli.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
    O16 - DPF: {02ECD07A-22D0-4AF0-BA0A-3F6B06086D08} (GamesCampus Control) - http://www.gamescampus.com/xiah/luncher/GamesCampus.cab
    O16 - DPF: {56393399-041A-4650-94C7-13DFCB1F4665} (PSFormX Control) - http://www.pestpatrol.com/pestscan/pestscan.cab
    O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} - http://advnt01.com/dialer/int_ver34.CAB
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O19 - User stylesheet: (file missing)
    O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
    O23 - Service: DNS Clientt (Dnscachee) - Unknown owner - C:\WINNT\system32\DNS.exe
    O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
    O23 - Service: PPPoE Service (PPPoEService) - Unknown owner - C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe
    O23 - Service: SBHookSvc - Motive Communications, Inc. - C:\PROGRA~1\NETASS~1\SMARTB~1\SBHookSvc.exe

    --
    End of file - 5420 bytes

  2. #12
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    ComboFix 07-10-12.4 - Administrator 10/14/2007 9:53:59.1 - NTFSx86
    Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.31 [GMT -4:00]
    Running from: C:\Documents and Settings\Administrator\Desktop\ComboFix.exe
    .

    ((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
    .

    C:\b.exe
    C:\Documents and Settings\Administrator\Application Data\Microsoft\25319.dat
    C:\Program Files\Common Files\misc001
    C:\Program Files\WinBudget
    C:\Program Files\WinBudget\bin\crap.1166048051.old
    C:\Program Files\WinBudget\bin\crap.1166566298.old
    C:\Program Files\WinBudget\bin\crap.1166817217.old
    C:\Program Files\WinBudget\bin\crap.1167079181.old
    C:\Program Files\WinBudget\bin\crap.1167321020.old
    C:\Program Files\WinBudget\bin\crap.1167840550.old
    C:\Program Files\WinBudget\bin\crap.1168107582.old
    C:\Program Files\WinBudget\bin\crap.1168391203.old
    C:\Program Files\WinBudget\bin\crap.1187224927.old
    C:\Program Files\WinBudget\bin\matrix.dll.1166566297.old
    C:\Program Files\WinBudget\bin\matrix.dll.1166817217.old
    C:\Program Files\WinBudget\bin\matrix.dll.1167079181.old
    C:\Program Files\WinBudget\bin\matrix.dll.1167321019.old
    C:\Program Files\WinBudget\bin\matrix.dll.1167840549.old
    C:\Program Files\WinBudget\bin\matrix.dll.1168107582.old
    C:\Program Files\WinBudget\bin\matrix.dll.1168391202.old
    C:\Program Files\WinBudget\bin\matrix.dll.1187224925.old
    C:\Program Files\WinBudget\bin\matrix.dll.1189295359.old
    C:\WINNT\Downloaded Program Files\Quarantine
    C:\WINNT\rund1132.exe
    C:\WINNT\sysc00.exe
    C:\WINNT\SYSC00.exe
    C:\WINNT\system32\KB09869277.exe
    C:\WINNT\system32\KB51695342.exe
    C:\WINNT\system32\KB83647438.exe

    .
    ((((((((((((((((((((((((( Files Created from 2007-09-14 to 2007-10-14 )))))))))))))))))))))))))))))))
    .

    2007-10-14 09:46 51,200 --a------ C:\WINNT\NirCmd.exe
    2007-10-13 15:17 2,368 --a------ C:\WINNT\system32\SVKP.sys
    2007-10-13 15:16 210,944 --a------ C:\ad.exe
    2007-10-13 12:00 451,584 --a------ C:\WINNT\system32\svohst.exe
    2007-10-12 16:39 <DIR> d-------- C:\WINNT\ERUNT
    2007-10-11 18:16 102,664 --a------ C:\WINNT\system32\drivers\tmcomm.sys
    2007-10-11 18:07 <DIR> d-------- C:\Documents and Settings\Administrator\.housecall6.6
    2007-10-05 09:39 <DIR> d-------- C:\Program Files\Trend Micro
    2007-10-01 15:11 <DIR> d-------- C:\Program Files\CCleaner
    2007-09-29 20:33 235,280 --a------ C:\WINNT\system32\GDI32.DLL
    2007-09-29 14:54 1,119,232 --a------ C:\WINNT\system32\msxml3.dll

    .
    (((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    2007-10-06 14:02 34 ----a-w C:\YFX6MTMP.BAT
    2007-10-04 13:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
    2007-10-01 19:15 --------- d-----w C:\Program Files\Common Files\PestPatrol
    2007-09-28 22:15 --------- d-----w C:\Program Files\PokerStars.NET
    2007-09-28 22:15 --------- d-----w C:\Program Files\PacificPoker
    2007-09-28 22:13 --------- d--h--w C:\Program Files\InstallShield Installation Information
    2007-08-15 15:16 23,600 ----a-w C:\WINNT\system32\drivers\TVICHW32.SYS
    2007-07-22 18:27 15,360 ----a-w C:\WINNT\twain_32.exe
    2007-05-17 02:58 60,480 -c----w C:\Documents and Settings\Administrator\Application Data\GDIPFONTCACHEV1.DAT
    2007-02-04 19:53 32 ------r C:\Documents and Settings\All Users\hash.dat
    2006-04-05 20:13 268,178 -c----w C:\Documents and Settings\Administrator\msninfo.exe
    2006-02-14 23:56 2,208 -c----w C:\Program Files\setuplog.txt
    2005-12-26 19:14 283,154 -c----w C:\Documents and Settings\Administrator\wanxguard.exe
    2005-09-09 03:35 51,318 -c----w C:\Documents and Settings\Administrator\payload.dat
    2005-03-24 20:34 271 ---h--w C:\Program Files\desktop.ini
    2005-03-24 20:34 21,952 ---h--w C:\Program Files\folder.htt
    2006-02-24 20:42:37 122,368 --sh--r C:\WINNT\iexpress.exe
    2006-01-17 00:24:46 121,856 --sh--r C:\WINNT\msinm.exe
    2003-06-19 19:05:04 286,141 --sha-r C:\WINNT\msnchecke0.exe
    2003-06-19 19:05:04 286,141 --sha-r C:\WINNT\msnchecke1.exe
    2003-06-19 19:05:04 286,141 --sha-r C:\WINNT\msnchecke3.exe
    2003-06-19 19:05:04 286,141 --sha-r C:\WINNT\msnchecke4.exe
    2003-06-19 19:05:04 286,141 --sha-r C:\WINNT\msnchecke7.exe
    2003-06-19 19:05:04 286,141 --sha-r C:\WINNT\msnchecke8.exe
    2003-06-19 19:05:04 286,141 --sha-r C:\WINNT\msnchecker.exe
    2006-02-08 00:38:04 122,368 --sha-r C:\WINNT\nav32.exe
    2006-02-02 01:09:39 122,368 --sh--r C:\WINNT\nvcr32.exe
    2006-01-18 12:21:07 122,368 --sh--r C:\WINNT\svbhost.exe
    2006-03-02 12:09:27 122,368 --sh--r C:\WINNT\wscntify.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke0.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke1.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke2.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke3.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke4.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke5.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke6.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke7.exe
    2003-06-19 12:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke8.exe
    2003-06-19 19:05:04 286,141 -csh--r C:\WINNT\system32\msnchecke9.exe
    .

    ((((((((((((((((((((((((((((((((((((((((((((( AWF ))))))))))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    ------w 393,216 2004-10-22 19:13:54 C:\Program Files\NetAssistant\SmartBridge\bak\MotiveSB.exe
    ------w 69,632 2006-12-13 01:03:00 C:\Program Files\NetAssistant\SmartBridge\MotiveSB.exe

    -c----w 4,284,416 2005-04-02 19:10:30 C:\Program Files\RegistryFix\bak\registryfix.exe

    -c-h--w 244,311 2005-11-30 20:51:16 C:\WINNT\bak\DLLLOADRS.EXE

    -c----w 141,312 2005-12-08 08:13:40 C:\WINNT\system32\iexplorer\bak\a.exe
    ------w 69,632 2006-12-13 01:03:00 C:\WINNT\system32\iexplorer\a.exe

    .
    ((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
    .
    .
    *Note* empty entries & legit default entries are not shown

    [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "Motive SmartBridge"="C:\PROGRA~1\NETASS~1\SMARTB~1\MotiveSB.exe" [06-12-12 21:03 ]
    "Keyboard Driver (do not remove)"="ESOLVER.EXE" []
    "REGRUN"="C:\WINNT\system32\iexplorer\a.exe" [06-12-12 21:03 ]
    "QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [06-09-29 16:05 ]
    "winsockdriver"="winsock4.exe" [03-06-19 13:05 C:\WINNT\system32\winsock4.exe]
    "Synchronization Manager"="mobsync.exe" [03-06-19 13:05 C:\WINNT\system32\mobsync.exe]
    "svchst"="C:\WINNT\system32\svohst.exe" [07-10-13 12:00 ]

    [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
    "ccleaner"="C:\Program Files\CCleaner\CCleaner.exe" [07-09-28 04:05 ]

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runonce]
    "winsockdriver"=winsock4.exe

    [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\runservices]
    "HTML Help System"=hhs.pif
    "Browser Help Svc"=BHSV.EXE
    "Updt Service"=updt.pif

    [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
    "sys33"=Sys33.exe

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\runonce]
    "^SetupICWDesktop"=C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop
    "Keyboard Driver (do not remove)"=ESOLVER.EXE
    "winsockdriver"=winsock4.exe

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\runservices]
    "Win32 Info"=windowsnfo.exe
    "OS Security"=mswind32.pif
    "Browser Help Svc"=BHSV.EXE

    [HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
    "Win32 Info"=windowsnfo.exe
    "OS Security"=mswind32.pif
    "Browser Help Svc"=BHSV.EXE
    "Configuration Loader"=msgfix.exe
    "CU1"=C:\Program Files\Common Files\VCClient\VCClient.exe
    "CU2"=C:\Program Files\Common Files\VCClient\VCMain.exe
    "Aupw"="C:\Program Files\mssa\ostn.exe" -vt yazr

    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon]
    "Shell"="explorer.exe winsock4.exe"

    R0 idebd;idebd;C:\WINNT\system32\DRIVERS\idebd.sys
    R0 IntelATA;Intel Ultra ATA Controller;C:\WINNT\system32\DRIVERS\intelata.sys
    R2 Dnscachee;DNS Clientt;C:\WINNT\system32\DNS.exe
    R2 PPPoEService;PPPoE Service;C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\pppoeservice.exe
    R2 SVKP;SVKP;\??\C:\WINNT\system32\SVKP.sys
    R3 NTSPPPOE;Efficient Networks Enternet P.P.P.o.E LAN Miniport Driver;C:\WINNT\system32\DRIVERS\ntspppoe.sys
    R3 NTSTAP1;NTSTAP1;\??\C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\NTSTAP1.SYS
    R3 TAPBIND;TAPBIND;\??\C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\TAPBIND1.SYS
    S3 RAWESR;RAWESR;\??\C:\PROGRA~1\SYMPAT~1\ACCESS~1\app\RAWESR.SYS

    .
    Contents of the 'Scheduled Tasks' folder
    "2007-08-21 11:18:03 C:\WINNT\Tasks\AppleSoftwareUpdate.job"
    - C:\Program Files\Apple Software Update\SoftwareUpdate.exe
    .
    **************************************************************************

    catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
    Rootkit scan 2007-10-14 10:05:29
    Windows 5.0.2195 Service Pack 4 NTFS

    scanning hidden processes ...

    scanning hidden autostart entries ...

    HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
    winsockdriver = winsock4.exe?280102?winsockdriver?spybot?iroffer v1.2b13 [November 10th, 2001] By PMG, http://iroffer.org/ - CYGWIN_NT-5.0 1.3.

    scanning hidden files ...

    scan completed successfully
    hidden files: 0

    **************************************************************************
    .
    Completion time: 2007-10-14 10:07:12 - machine was rebooted
    .
    --- E O F ---

  3. #13
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    I still highly recommend reformatting as I see now what your computer has "eaten".

    So you still want to continue with cleaning?
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  4. #14
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    ok that's fine. I'll reformat.

  5. #15
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    If you need help with that, see here

    I also give you some tips how to stay clean in the future:

    Looking over your log, it seems you don't have any evidence of an anti-virus software.

    Anti-virus software are programs that detect, cleanse, and erase harmful virus files on a computer, Web server, or network. Unchecked, virus files can unintentionally be forwarded to others, including trading partners and thereby spreading infection. Because new viruses regularly emerge, anti-virus software should be updated frequently. Anti-virus software can scan the computer memory and disk drives for malicious code. They can alert the user if a virus is present, and will clean, delete (or quarantine) infected files or directories. Please download a free anti-virus software from one these excellent vendors NOW:

    1) Antivir PersonalEdition Classic - Free anti-virus software for Windows. Detects and removes more than 50,000 viruses. Free support.
    2) avast! 4 Home Edition - Anti-virus program for Windows. The home edition is freeware for noncommercial users.
    3) AVG Anti-Virus Free Edition - Free edition of the AVG anti-virus program for Windows.

    It is strongly recommended that you run only one antivirus program at a time. Having more than one antivirus program active in memory uses additional resources and can result in program conflicts and false virus alerts. If you choose to install more than one antivirus program on your computer, then only one of them should be active in memory at a time.

    Looking over your log, it seems you don't have any evidence of a third party firewall.

    As the term conveys, a firewall is an extra layer of security installed onto computers, which restricts access to systems from the outside world. Firewalls protect against hackers and malicious intruders. I want you to download a free firewall NOW from one of these excellent vendors:

    1) Comodo
    2) Sunbelt/Kerio
    3) Agnitum
    4) ZoneAlarm

    If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.

    Re-enable system restore with instructions from tutorial above

    • Make your Internet Explorer more secure - This can be done by following these simple instructions:
    • From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    • Next press the Apply button and then the OK to exit the Internet Properties page.

    • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.


    See this link for a listing of some online & their stand-alone antivirus programs:

    Virus, Spyware, and Malware Protection and Removal Resources


    • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

    • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

      For a tutorial on Firewalls and a listing of some available ones see the link below:

      Understanding and Using Firewalls

    • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

    • Install Ad-Aware - Install and download Ad-Aware. You should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

      A tutorial on installing & using this product can be found here:

      Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

    • Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option.

      This will provide real-time spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an anti virus software. A tutorial on installing & using this product can be found here:

      Instructions for - Spybot S & D and Ad-aware

    • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

      A tutorial on installing & using this product can be found here:

      Using SpywareBlaster to protect your computer from Spyware and Malware

    • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
    Follow this list and your potential for being infected again will reduce dramatically.

    Here are some additional utilities that will enhance your safety

    • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
    • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your computer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
    • Google Toolbar <= Get the free google toolbar to help stop pop up windows.
    • Comodo BOCLEAN <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
    • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
      Using Winpatrol to protect your computer from malicious software


    Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

    The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

    Also, please read this great article by Tony Klein So How Did I Get Infected In First Place
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  6. #16
    Junior Member
    Join Date
    Oct 2007
    Posts
    10

    Default

    Hi, I have a question. I have the cd for reinstalling windows 2000 professional inc. service pack 1, but the link you gave asks for an XP cd. Is it the same? I just need to make sure. thanks.

  7. #17
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Hi

    Yes as you have Windows 2000 installed.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

  8. #18
    Security Expert: Emeritus
    Join Date
    Oct 2006
    Location
    Finland
    Posts
    29,374

    Default

    Since this issue appears resolved ... this Topic is closed.

    If you need this topic reopened, please request this by sending the moderating team
    a PM with the address of the thread. This applies only to the original topic starter.

    Everyone else please begin a New Topic.
    Microsoft MVP Consumer Security 2008-2011

    Member of ASAP and UNITE since 2006

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •