Page 2 of 3 FirstFirst 123 LastLast
Results 11 to 20 of 23

Thread: Hosts Hijack

  1. #11
    Junior Member
    Join Date
    Feb 2012
    Posts
    14

    Default

    THANK YOU!

    A clean hosts file at last

    as for the java thing. Last year I got into programming for a little while and had downloaded JRE and some other stuff for java, html, c++, and c# programming. Could JRE be the problem there?

    I'm no longer interested in java programming so I could uninstall the related programs if needed.

  2. #12
    Junior Member
    Join Date
    Feb 2012
    Posts
    14

    Default

    OTL logfile created on: 4/22/2012 3:11:17 AM - Run 2
    OTL by OldTimer - Version 3.2.40.0 Folder = C:\Users\Roger\Desktop
    64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation
    Internet Explorer (Version = 8.0.7600.16385)
    Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

    2.75 Gb Total Physical Memory | 1.62 Gb Available Physical Memory | 59.14% Memory free
    5.49 Gb Paging File | 4.02 Gb Available in Paging File | 73.23% Paging File free
    Paging file location(s): ?:\pagefile.sys [binary data]

    %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
    Drive C: | 136.95 Gb Total Space | 19.09 Gb Free Space | 13.94% Space Free | Partition Type: NTFS

    Computer Name: ROGER-PC | User Name: Roger | Logged in as Administrator.
    Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
    Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

    ========== Processes (SafeList) ==========

    PRC - C:\Users\Roger\Desktop\OTL.exe (OldTimer Tools)
    PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
    PRC - C:\Program Files (x86)\Palringo\palringo.exe (Palringo Limited)
    PRC - C:\Users\Roger\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
    PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
    PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
    PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
    PRC - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\MWLService.exe (Egis Technology Inc.)
    PRC - C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
    PRC - C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
    PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
    PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)


    ========== Modules (No Company Name) ==========

    MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()
    MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
    MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
    MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
    MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll ()
    MOD - C:\Program Files (x86)\Palringo\libspeex.dll ()


    ========== Win32 Services (SafeList) ==========

    SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe (SUPERAntiSpyware.com)
    SRV:64bit: - (ePowerSvc) -- C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated)
    SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
    SRV:64bit: - (Updater Service) -- C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer)
    SRV - (Akamai) -- c:\program files (x86)\common files\akamai/netsession_win_6c825ce.dll ()
    SRV - (MBAMService) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
    SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
    SRV - (npggsvc) -- C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
    SRV - (MWLService) -- C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\\MWLService.exe ()
    SRV - (Greg_Service) -- C:\Program Files (x86)\Acer\Registration\GregHSRW.exe (Acer Incorporated)
    SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
    SRV - (vpnclient) -- C:\Program Files (x86)\PacketiX VPN Client English\vpnclient.exe (SoftEther Corporation)
    SRV - (ProtexisLicensing) -- C:\Windows\SysWOW64\PSIService.exe ()


    ========== Driver Services (SafeList) ==========

    DRV:64bit: - (MBAMProtector) -- C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
    DRV:64bit: - (SASDIFSV) -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV:64bit: - (Neo_VPN) -- C:\Windows\SysNative\drivers\Neo_0001.sys (SoftEther Corporation)
    DRV:64bit: - (SASKUTIL) -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys (SUPERAdBlocker.com and SUPERAntiSpyware.com)
    DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
    DRV:64bit: - (MotioninJoyXFilter) -- C:\Windows\SysNative\drivers\MijXfilt.sys (MotioninJoy)
    DRV:64bit: - (xusb21) -- C:\Windows\SysNative\drivers\xusb21.sys (Microsoft Corporation)
    DRV:64bit: - (jumi) -- C:\Windows\SysNative\drivers\jumi.sys (Windows (R) Codename Longhorn DDK provider)
    DRV:64bit: - (L1C) -- C:\Windows\SysNative\drivers\L1C62x64.sys (Atheros Communications, Inc.)
    DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.)
    DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
    DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
    DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
    DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
    DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
    DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
    DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
    DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
    DRV:64bit: - (RSUSBSTOR) -- C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
    DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
    DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
    DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
    DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
    DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
    DRV:64bit: - (mwlPSDVDisk) -- C:\Windows\SysNative\drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
    DRV:64bit: - (mwlPSDFilter) -- C:\Windows\SysNative\drivers\mwlPSDFilter.sys (Egis Technology Inc.)
    DRV:64bit: - (mwlPSDNServ) -- C:\Windows\SysNative\drivers\mwlPSDNserv.sys (Egis Technology Inc.)
    DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
    DRV:64bit: - (NTIDrvr) -- C:\Windows\SysNative\drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
    DRV:64bit: - (UBHelper) -- C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
    DRV:64bit: - (AtiPcie) AMD PCI Express (3GIO) -- C:\Windows\SysNative\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)
    DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
    DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
    DRV - (DKbFltr) Dritek Keyboard Filter Driver (64-bit) -- C:\Windows\SysWOW64\drivers\DKbFltr.sys (Dritek System Inc.)
    DRV - (NPPTNT2) -- C:\Windows\SysWOW64\npptNT2.sys (INCA Internet Co., Ltd.)


    ========== Standard Registry (SafeList) ==========


    ========== Internet Explorer ==========

    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=...4z1l5t49j2x232
    IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=...4z1l5t49j2x232
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=...4z1l5t49j2x232
    IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC
    IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7

    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
    IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC
    IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://findgala.com/?&uid=5757&q={searchTerms}
    IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&sourceid=ie7
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
    IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;<local>

    ========== FireFox ==========

    FF - prefs.js..browser.startup.homepage: "http://www.google.com/"
    FF - user.js - File not found

    FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
    FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
    FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
    FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: File not found
    FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
    FF - HKLM\Software\MozillaPlugins\@messenger.yahoo.com/YahooMessengerStatePlugin;version=1.0.0.6: C:\Program Files (x86)\Yahoo!\Shared\npYState.dll (Yahoo! Inc.)
    FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
    FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
    FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
    FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/03/16 23:05:52 | 000,000,000 | ---D | M]
    FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 11.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/02/19 01:19:27 | 000,000,000 | ---D | M]

    [2012/02/15 16:46:27 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Roger\AppData\Roaming\Mozilla\Extensions
    [2012/02/19 01:36:58 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Roger\AppData\Roaming\Mozilla\SeaMonkey\Profiles\3nqb6ujo.default\extensions
    [2012/02/15 16:45:13 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
    [2012/03/16 23:05:52 | 000,097,208 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
    [2011/05/04 04:52:23 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
    [2012/02/08 13:12:58 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
    [2012/02/08 13:12:58 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

    O1 HOSTS File: ([2012/04/21 23:29:59 | 000,000,761 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
    O1 - Hosts: 127.0.0.1 localhost
    O1 - Hosts: ::1 localhost
    O2:64bit: - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
    O2 - BHO: (no name) - {1FD79A59-37B1-459B-9097-09F9FAB8A523} - No CLSID value found.
    O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
    O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4:64bit: - HKLM..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Acer Incorporated)
    O4:64bit: - HKLM..\Run: [mwlDaemon] C:\Program Files (x86)\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Egis Technology Inc.)
    O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
    O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
    O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
    O4 - HKLM..\Run: [LManager] C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
    O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
    O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
    O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
    O4 - HKLM..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" File not found
    O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\Roger\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc)
    O4 - HKCU..\Run: [DS3 Tool] C:\Program Files\MotioninJoy\ds3\DS3_Tool.exe (www.motioninjoy.com)
    O4 - HKCU..\Run: [JumiController] File not found
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: EnableShellExecuteHooks = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
    O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
    O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
    O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
    O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
    O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
    O1364bit: - gopher Prefix: missing
    O13 - gopher Prefix: missing
    O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16:64bit: - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jin...ndows-i586.cab (Reg Error: Key error.)
    O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jin...ndows-i586.cab (Java Plug-in 1.7.0)
    O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_26)
    O16 - DPF: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_26)
    O16 - DPF: {CAFEEFAC-0017-0000-0000-ABCDEFFEDCBA} Reg Error: Value error. (Reg Error: Key error.)
    O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jin...ndows-i586.cab (Java Plug-in 1.6.0_26)
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{194F9A23-5F53-4940-B86D-36EE0947E00B}: DhcpNameServer = 192.168.1.1
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
    O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
    O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
    O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
    O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
    O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
    O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
    O32 - HKLM CDRom: AutoRun - 1
    O34 - HKLM BootExecute: (autocheck autochk *)
    O35:64bit: - HKLM\..comfile [open] -- "%1" %*
    O35:64bit: - HKLM\..exefile [open] -- "%1" %*
    O35 - HKLM\..comfile [open] -- "%1" %*
    O35 - HKLM\..exefile [open] -- "%1" %*
    O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
    O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
    O37 - HKLM\...com [@ = comfile] -- "%1" %*
    O37 - HKLM\...exe [@ = exefile] -- "%1" %*

    ========== Files/Folders - Created Within 30 Days ==========

    [2012/04/21 23:26:38 | 000,000,000 | ---D | C] -- C:\Users\Roger\Desktop\Users
    [2012/04/21 02:06:17 | 000,000,000 | ---D | C] -- C:\_OTL
    [2012/04/19 23:28:59 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Roger\Desktop\aswMBR.exe
    [2012/04/19 22:46:26 | 000,595,968 | ---- | C] (OldTimer Tools) -- C:\Users\Roger\Desktop\OTL.exe
    [2012/04/19 22:34:24 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{FCA1B7BB-444E-4336-8F66-D9A1AF180E04}
    [2012/04/19 22:34:12 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{9AC3B0A0-9580-42D6-A413-B3514CA22868}
    [2012/04/18 22:50:22 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{3C9C9AAA-309E-4C0E-B0C2-337680252A5E}
    [2012/04/18 22:50:09 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{8257B05B-E610-4CDC-A8BC-3FCED0E13F35}
    [2012/04/17 21:12:23 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{B0EE6845-A02F-45F7-AC29-4F3DBC675A2D}
    [2012/04/17 21:12:10 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{561545E0-96A6-4149-8336-3762246030AC}
    [2012/04/16 19:03:41 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{6206CA4F-68A7-454D-806E-CE2781284303}
    [2012/04/16 19:03:28 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{66716546-0958-455A-A91D-632F4C688AA2}
    [2012/04/15 18:39:18 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{98AEA568-EAA0-4AC7-A921-79D13BF32E13}
    [2012/04/15 18:39:05 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{91D62BEE-CCF5-4239-B3AC-0FED25DA986C}
    [2012/04/14 17:18:33 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{1ED158E6-BC20-4AD5-BFE3-595731E23755}
    [2012/04/12 12:16:52 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{060FFCE7-3401-4CF3-B2FA-F6D650FE58AD}
    [2012/04/11 19:40:02 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{D6A9E2E1-9E6E-4F6C-B128-9C0F22274E55}
    [2012/04/10 21:26:13 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{401989FE-1CB8-480C-804C-BE6E7FAA6ABF}
    [2012/04/09 20:18:38 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{9AE3D228-D649-492C-B96C-7D41FF4FD467}
    [2012/04/08 13:50:54 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{FD975B7C-7E4F-4243-8EF3-CA453DA1870A}
    [2012/04/07 17:51:04 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{F22C861F-B887-4CB5-97FB-56A6A76C3F9A}
    [2012/04/07 05:50:39 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{C80C3F3C-1E2A-40DF-90F0-1AA2B156FCE8}
    [2012/04/06 17:50:27 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{688202CF-623B-4812-92BE-7A79F84F6D6B}
    [2012/04/06 17:41:12 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Palringo
    [2012/04/06 17:41:12 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Palringo
    [2012/04/05 15:18:54 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{707319B0-56AC-40EB-8F1A-F3E960F5634F}
    [2012/04/04 20:32:30 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{32D772A4-ECC1-4C9C-B565-B09644245595}
    [2012/04/03 21:07:29 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{A43E1B90-9F55-4D5B-B1E2-8EA3B1C95790}
    [2012/04/03 06:55:48 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{D9FED71C-2DEA-44F2-92B1-E8869AF193B3}
    [2012/04/02 18:55:22 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{1B913A82-19D1-40CB-9274-5EF3E03D9C3B}
    [2012/04/01 21:22:46 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{53A4CD5A-93B3-4091-A8A8-041423BD8322}
    [2012/03/28 21:22:53 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{AFAB569C-D0D0-4894-B989-F75AAF24CD27}
    [2012/03/25 21:05:45 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{C5DA689F-D492-452C-89CB-8614EE8CE5ED}
    [2012/03/25 21:05:30 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{810E81B0-E923-4B4A-AB4F-5DE980B97855}
    [2012/03/25 08:48:35 | 000,000,000 | ---D | C] -- C:\Program Files\HijackThis
    [2012/03/24 22:18:41 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{147A021E-77E2-4406-B2B2-B4A45EEB3F36}
    [2012/03/23 12:23:43 | 000,000,000 | ---D | C] -- C:\Users\Roger\Documents\KOEI
    [2012/03/23 11:31:07 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{ECCBA241-E68D-4073-892D-F67E42398734}
    [2012/03/23 11:30:53 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Local\{3E247D0A-61A4-4315-820A-43A4CFA46EE4}
    [2012/03/23 11:00:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Koei
    [2012/03/23 11:00:11 | 000,000,000 | ---D | C] -- C:\Users\Roger\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Koei
    [2012/03/23 07:20:05 | 000,000,000 | ---D | C] -- C:\Users\Roger\Desktop\SSMOInstaller
    [2012/03/23 07:19:25 | 000,478,312 | ---- | C] (株式会社 コーエーテクモゲームス) -- C:\Users\Roger\Desktop\SSMOStarter.exe

    ========== Files - Modified Within 30 Days ==========

    [2012/04/22 02:53:00 | 000,000,898 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
    [2012/04/22 02:53:00 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
    [2012/04/21 23:30:14 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
    [2012/04/21 23:30:14 | 000,009,696 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
    [2012/04/21 23:29:59 | 000,000,761 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
    [2012/04/21 23:27:31 | 000,869,986 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
    [2012/04/21 23:27:31 | 000,716,960 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
    [2012/04/21 23:27:31 | 000,144,982 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
    [2012/04/21 23:26:03 | 000,000,524 | ---- | M] () -- C:\Users\Roger\Desktop\ownership.zip
    [2012/04/21 23:22:41 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
    [2012/04/21 23:22:34 | 2211,483,648 | -HS- | M] () -- C:\hiberfil.sys
    [2012/04/21 02:20:33 | 000,219,324 | ---- | M] () -- C:\Users\Roger\Desktop\java4.png
    [2012/04/21 02:19:48 | 000,196,621 | ---- | M] () -- C:\Users\Roger\Desktop\java3.png
    [2012/04/21 02:19:09 | 000,201,107 | ---- | M] () -- C:\Users\Roger\Desktop\java2.png
    [2012/04/21 02:18:13 | 000,205,319 | ---- | M] () -- C:\Users\Roger\Desktop\java1.png
    [2012/04/21 00:25:54 | 000,000,744 | ---- | M] () -- C:\Users\Roger\Desktop\ownership.reg
    [2012/04/19 23:46:10 | 000,000,566 | ---- | M] () -- C:\Users\Roger\Desktop\MBR.zip
    [2012/04/19 23:45:00 | 000,000,512 | ---- | M] () -- C:\Users\Roger\Desktop\MBR.dat
    [2012/04/19 23:29:17 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Roger\Desktop\aswMBR.exe
    [2012/04/19 22:46:28 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Roger\Desktop\OTL.exe
    [2012/04/15 19:42:31 | 000,195,388 | ---- | M] () -- C:\Users\Roger\Desktop\Untitled.png
    [2012/04/08 20:40:05 | 000,003,548 | ---- | M] () -- C:\Users\Roger\Documents\Three Faces of Quantrill.rtf
    [2012/03/26 08:03:36 | 000,001,301 | ---- | M] () -- C:\Windows\wininit.ini
    [2012/03/23 11:00:11 | 000,001,888 | ---- | M] () -- C:\Users\Roger\Desktop\真・三國無双 Online.lnk
    [2012/03/23 07:19:29 | 000,478,312 | ---- | M] (株式会社 コーエーテクモゲームス) -- C:\Users\Roger\Desktop\SSMOStarter.exe

    ========== Files Created - No Company Name ==========

    [2012/04/21 23:26:38 | 000,000,744 | ---- | C] () -- C:\Users\Roger\Desktop\ownership.reg
    [2012/04/21 23:26:00 | 000,000,524 | ---- | C] () -- C:\Users\Roger\Desktop\ownership.zip
    [2012/04/21 02:20:33 | 000,219,324 | ---- | C] () -- C:\Users\Roger\Desktop\java4.png
    [2012/04/21 02:19:48 | 000,196,621 | ---- | C] () -- C:\Users\Roger\Desktop\java3.png
    [2012/04/21 02:19:08 | 000,201,107 | ---- | C] () -- C:\Users\Roger\Desktop\java2.png
    [2012/04/21 02:18:13 | 000,205,319 | ---- | C] () -- C:\Users\Roger\Desktop\java1.png
    [2012/04/19 23:46:10 | 000,000,566 | ---- | C] () -- C:\Users\Roger\Desktop\MBR.zip
    [2012/04/19 23:45:00 | 000,000,512 | ---- | C] () -- C:\Users\Roger\Desktop\MBR.dat
    [2012/04/15 19:42:31 | 000,195,388 | ---- | C] () -- C:\Users\Roger\Desktop\Untitled.png
    [2012/04/08 20:20:58 | 000,003,548 | ---- | C] () -- C:\Users\Roger\Documents\Three Faces of Quantrill.rtf
    [2012/03/23 11:00:11 | 000,001,888 | ---- | C] () -- C:\Users\Roger\Desktop\真・三國無双 Online.lnk
    [2012/02/20 22:53:08 | 000,000,017 | ---- | C] () -- C:\Users\Roger\AppData\Local\resmon.resmoncfg
    [2012/02/13 23:47:02 | 000,000,000 | ---- | C] () -- C:\Users\Roger\AppData\Local\{6E8214EB-F050-4AAD-9EA9-586718DD0119}
    [2011/07/21 16:12:37 | 000,001,301 | ---- | C] () -- C:\Windows\wininit.ini
    [2011/07/21 00:39:55 | 000,772,430 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
    [2011/06/21 15:06:26 | 000,155,648 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
    [2010/08/08 11:21:51 | 000,118,784 | ---- | C] () -- C:\Windows\dsdxirmv.exe

    ========== LOP Check ==========

    [2011/08/15 20:24:03 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\2XClient
    [2012/02/15 00:35:19 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\30FB9
    [2010/01/31 10:47:27 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\Acer
    [2010/08/08 11:37:28 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\Cakewalk
    [2011/09/26 22:09:51 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\fltk.org
    [2011/07/21 15:13:28 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\GetRightToGo
    [2010/01/31 10:47:27 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\Leadertech
    [2011/10/02 20:19:47 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\MotioninJoy
    [2010/10/16 13:15:21 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\OpenOffice.org
    [2011/08/21 22:45:52 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\SPORE
    [2011/09/12 22:25:53 | 000,000,000 | ---D | M] -- C:\Users\Roger\AppData\Roaming\TS3Client
    [2011/11/17 23:12:18 | 000,032,634 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT

    ========== Purity Check ==========



    ========== Alternate Data Streams ==========

    @Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2

    < End of report >

  3. #13
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi aritus,

    Good job. If you want to remove the Take Ownership option from the right click menu you can use the regfix in the attached zip, undo.zip. Just download it and extract the regfix, undo.reg and merge it like you did with ownership.reg.

    JRE isn't really a problem other than being out of date. The older versions have vulnerabilties that can be exploited.

    There are some websites that may require java so if you want to keep java on your computer they should be updated. If you feel you don't need java you can skip the download part and go right to the uninstall.

    You can get the newest version of Java 32bit and 64bit from HERE
    • in the Java Platform, Standard Edition section click the download button under JRE
    • Accept the Accept License Agreement
    • download Windows x86 (32-bit) Offline and Windows x64 (64-bit)
    • save them to your desktop, do not install them yet


    Click start > Control panel
    • under Programs click Uninstall a program
    • Uninstall
      Java(TM) 7 (64-bit)
      Java(TM) SE Development Kit 7 (64-bit)
      Java(TM) 6 Update 26


    Next

    Install the new java by double clicking the files you downlloaded. Remember to decline the Ask ToolBar.

    Any problems?
    Member of UNITE and ASAP

  4. #14
    Junior Member
    Join Date
    Feb 2012
    Posts
    14

    Default

    Thanks. Before I do the undo, is there any reason NOT to leave the "take control" option?

    And since you're here... does safer-networking have their own site scanner/blacklist? Normally I just google for a website scanner but evidently something slipped through and I'd like that not to happen again.

  5. #15
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi aritus,

    As you can see it was fairly easy to take ownership so I don't think it would be a problem as far as malware goes, malware authors would just write thei own script. It might be something a curious user, other than yourself, might play with though.

    does safer-networking have their own site scanner/blacklist?
    If you mean an on site url scanner, I don't believe so. VirusTotal has one though.

    WOT is an addon you can use.

    Any issues with the computer?
    Member of UNITE and ASAP

  6. #16
    Junior Member
    Join Date
    Feb 2012
    Posts
    14

    Default

    No problems thus far

    thank you soo much for your help

    if I may ask just one more thing... Is Mozilla Firefox still the best browser to use? I read somewhere that it's becoming out-dated but I don't trust Chrome and I especially don't trust IE...

    Again, thank you very much and I apologize for taking up so much of your time.

  7. #17
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi aritus,

    No problem, it was enjoyable. FireFox is vulnerable to some malware specifically targeted at it which won't infect IE. So there isn't a perfect browser. Both IE8 and 9 have pretty good builtin security.

    I don't see an antivirus program installed on this computer. I'll give you some links to some good free ones. You can install one after you remove the tools.

    We'll clean up the tools now.

    From your desktop, please delete, if present
    • any notepads/logs that we created
    • aswMBR.exe
    • mbr.zip
    • mbr.dat
    • DDS.scr
    If you want to keep ownership.reg and undo.reg, that's fine.

    Next

    Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet - allow this. A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.
    Next


    You should reset your System Restore points, you never know what may be lurking in one of the old ones.

    Create new Restore Point
    • Click your Start button
    • In the Search box type [B]create restore[/B
    • click on Create a restore point
    • Click the System Protection tab
    • click Create
    • Give your restore point a name and click Create
    • Wait while Windows creates a system restore point for you


    Remove old Restore Points
    • Click the Start button
    • In the search box, type Disk Cleanup
    • in the list of results, click Disk Cleanup
    • If prompted, select the drive that you want to clean up, and then click OK.
    • In the Disk Cleanup for (usually C dialog box, click Clean up system files. If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
    • If prompted, select the drive that you want to clean up, and then click OK.
    • Click the More Options tab
    • under System Restore and Shadow Copies, click Clean up.
    • In the Disk Cleanup dialog box, click Delete.
    • Click Delete Files, and then click OK.


    I suggest you keep MBAM. Keep it updated and use it regularly.


    Antivirus programs

    Download and install one of these programs.

    Avast
    Help and support can be found here Avast Forum
    Antivir PersonalEditionClassic
    Help and support can be found here Avira Personal Support Forum
    Microsoft Security Essentials
    Support


    Some Recommendations and prevention tips

    Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall. Those you have now provided you are using a firewall and install an antivirus program. Windows 7 has a built in firewall which is pretty good when set up. You can find some very good information HERE .


    You can use Spybot to install a Custom Hosts file.
    1-Left-click the "Spybot - Search & Destroy" shortcut to open the program
    2-Right-click an item in the list of immunizations and click "Deselect All."
    3-Scroll down to the bottom of the list and click the checkbox to the left of "Global (Hosts)" under the "Windows" header.
    4-Click "Immunize" on the Spybot toolbar.


    -Secure your Internet Explorer you will need it to visit some MS sites.

    From within Internet Explorer click on the Tools menu and then click on Options.
    • Click once on the Security tab
    • Click once on the Internet icon so it becomes highlighted.
    • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt
    • Change the Download unsigned ActiveX controls to Disable
    • Change the Initialize and script ActiveX controls not marked as safe to Disable
    • Change the Installation of desktop items to Prompt
    • Change the Launching programs and files in an IFRAME to Prompt
    • Change the Navigate sub-frames across different domains to Prompt
    • When all these settings have been made, click on the OK button.
    • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    Next press the Apply button and then the OK to exit the Internet Properties page.


    - Make sure you have reset Windows Updates to your chosen option. Click your start button > Control Panel > System > Windows updates (lower left) > change settings


    - Keep your antivirus program updated, as well as any other security programs you have.


    -More tips and programs can be found HERE

    Please post back if you have any problems.

    Take care
    Member of UNITE and ASAP

  8. #18
    Junior Member
    Join Date
    Feb 2012
    Posts
    14

    Default

    Thanks a lot for your help.

    I know this sounds kind of dumb but I am actually glad this happened as I have learned a few new things and gained better insight on things that I thought I already knew.

    I have to disagree with you on IE 8/9 though and I'll gladly tell you why. Set IE and FireFox home pages to Google and close both out. Run Spybot S&D and make sure it doesn't detect any thing (cookies included). If you disable your security and bring up Firefox (just to the google homepage, no where else) then close it out and run another scan the results will still be clean. If you disable your security and bring up IE (again just to the google home page) and close it out then do another scan you'll immediately discover AdawareTracking or some derivative of that name. I have cookies disabled on both browsers. In my personal opinion, if IE can't even block a simple cookie on its own, it is not a safe browser. Even if a later version of IE than the one I have fixed this problem it is still the most widely used browser and I'm certain that more malware is written for it than any other on the market, albeit that may change in a few years when everyone switches to Chrome.

    Maybe I'm just paranoid, maybe I'm stubborn, but that's my opinion. I don't even use facebook or myspace because I've proven that it is ridiculously easy to get all sorts of malware from those places and while a good anti-virus might keep them out, why risk the chance of being the first one to catch the latest virus that updates haven't detected yet?

    Thanks again for all your help! I do have another question though, and if you prefer I search another section of this forum for the answer I will understand.

    With Spyboy S&D 2 out is Spybot S&D obsolete?

  9. #19
    Junior Member
    Join Date
    Feb 2012
    Posts
    14

    Default

    sorry to double post but..

    you said you didn't find any antivirus on my system... does Spybot 2 Antispyware Protection not count?

  10. #20
    Senior Member
    Join Date
    Sep 2010
    Posts
    631

    Default

    Hi aritus,

    You're welcome.

    does Spybot 2 Antispyware Protection not count?
    The key is AntiSpyware Spybot is not an antivirus program. They do different things though sometimes overlap. They can be used together to form a layered protection system.

    Too many programs, IMO, use the detection of "Tracking" cookies as sales pitch. Look at what I found and saved you from. If it was really nasty don't you think the tool should either block it or remove it automatically? Cookies are not particularly dangerous, I know I have one set for this forum because I'm too lazy to sign in each time I come here. There's some good cookie information HERE and HERE.

    As for IE8 and 9

    Internet Explorer 8
    Click "Safety" on the Command bar
    Select "Delete Browsing History"
    Select the option for cookies and click Delete
    Alternatively, Internet Explorer 8's new InPrivate browsing feature allows users to browse the internet without recording information from visited sites (including cookies). To use InPrivate mode:

    Click "Safety" on the Command bar
    Select "InPrivate Browsing"
    http://www.aboutcookies.org/Default.aspx?page=2

    There is also information for other browsers in the above link.

    chrome is not invulnerable and is just as easily hijacked as other browsers.

    I agree with you on FaceBook and other social sites. There is far too much unmonitored content. In this day of social engineering it's very easy to get the curious or morbid to click on a link to view the latest disaster or whatever might grab a viewer's attention.

    Security programs will always play catch up. First the malware then the detection. You need to ask yourself is it worth the risk of not being protected against still unwritten malware and known malware or at least being protected against known malware.

    SpyBot is not obsolete but will probably be phased out once SB2 is ready. As far as I know 1.6.2. is the current version and SB2 is still in Beta testing.
    http://www.safer-networking.org/en/home/index.html

    Take care.
    Member of UNITE and ASAP

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •