Smitfraud-c.Tolbar888 Help me too please....

I am Willing to give it a try....would you like me to try that now or wait untill we have finished cleaning the bugs out. Also would you like me to capture a shot of the address bar and send to you so you can see what I mean. I am fairly sure that the Padlock used to come up in the info bar at the bottom of the IE screen and not in the address bar as it does now.

Waiting your directions, Thanks.
 
Hi

I guess that bugs cleaning is over now or do you have any symptoms left?

You can put a screenshot to imageshack and post link here.
 
Hi

"My main concern is that maybe something has changed in the security settings which may allow grabbing of user names and passwords etc"

I don't think so.

Yes, let me know after that :)
 
Back again. I haven't done a re-install of IE7. I went into the setup and checked the settings. The cookie blocker had been set to minimum (accept all cookies) and the security settings for the Internet zone had been set to Medium where it was on Med-High before. I also discovered that the green highlight in the address bar is due to Automatic Website Checking now turned on in the Phishing Filter. If I turn that off the address bar behaves as I remember.

Questions.
1. What setting do you recommend for the Auto Website Checking and if left on does it significantly slow down loading of web pages.

2. Would these changes to security settings have been done by the Viruses/Trojans that I picked up or by the cleaning process that you took me through. (just for my own info and peace of mind if you don't mind me taking up a bit more of your time.)

The changed icon in the Links toolbar has been solved by deleting both shortcuts and re-saving the Sensis link after re-starting IE.

As far as I can tell at this point in time everything is back to normal.

Thanks.
:bigthumb::bigthumb::bigthumb::bigthumb:
 
Hi

That's great :)

1. Default should be good.

2. "Would these changes to security settings have been done by the Viruses/Trojans that I picked up "

Yes, I think so.

Any other problems?
 
Any other problems?

No all appears to be ok now from what I can see.

I did read in another post about some Websites to visit that sets up site blocking etc and recommomended software to install.

What would you recommend I do now to (hopefully) keep it clean.
 
Hi

See my recommendations below :)

Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:

Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system. A malicious site could render Java content under older, vulnerable versions of Sun's software if the user has not removed them. Please follow these steps to remove older version Java components and update:
  • Download the latest version of Java Runtime Environment (JRE) 6 Update 1 and save it to your desktop.
  • Scroll down to where it says "Java Runtime Environment (JRE) 6u1...allows end-users to run Java applications".
  • Click the "Download" button to the right.
  • Read the License Agreement and then check the box that says: "Accept License Agreement".
  • The page will refresh.
  • Click on the link to download Windows Offline Installation and save the file to your desktop.
  • Close any programs you may have running - especially your web browser.
  • Go to Start > Settings > Control Panel, double-click on Add/Remove Programs and remove all older versions of Java.
  • Check (highlight) any item with Java Runtime Environment (JRE or J2SE) in the name.
  • Click the Remove or Change/Remove button.
  • Repeat as many times as necessary to remove each Java versions.
  • Reboot your computer once all Java components are removed.
  • Then from your desktop double-click on jre-6u1-windows-i586-p.exe to install the newest version.

  • Disable and Enable System Restore. - If you are using Windows XP then you should disable and re-enable system restore to make sure there are no infected files found in a restore point.

    You can find instructions on how to enable and reenable system restore here:

    Windows XP System Restore Guide

Reenable system restore with instructions from tutorial above

  • Make your Internet Explorer more secure - This can be done by following these simple instructions:
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
  • Next press the Apply button and then the OK to exit the Internet Properties page.
  • Use an AntiVirus Software - It is very important that your computer has an anti-virus software running on your machine. This alone can save you a lot of trouble with malware in the future.

See this link for a listing of some online & their stand-alone antivirus programs:

Virus, Spyware, and Malware Protection and Removal Resources


  • Update your AntiVirus Software - It is imperitive that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.

  • Use a Firewall - I can not stress how important it is that you use a Firewall on your computer. Without a firewall your computer is succeptible to being hacked and taken over. I am very serious about this and see it happen almost every day with my clients. Simply using a Firewall in its default configuration can lower your risk greatly.

    For a tutorial on Firewalls and a listing of some available ones see the link below:

    Understanding and Using Firewalls

  • Visit Microsoft's Windows Update Site Frequently - It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.

  • Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.

    A tutorial on installing & using this product can be found here:

    Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer

  • Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.

    A tutorial on installing & using this product can be found here:

    Using SpywareBlaster to protect your computer from Spyware and Malware

  • Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Follow this list and your potential for being infected again will reduce dramatically.

Here are some additional utilities that will enhance your safety

  • IE/Spyad <= IE/Spyad places over 4000 websites and domains in the IE Restricted list which will severely impair attempts to infect your system. It basically prevents any downloads (Cookies etc) from the sites listed, although you will still be able to connect to the sites.
  • MVPS Hosts file <= The MVPS Hosts file replaces your current HOSTS file with one containing well know ad sites etc. Basically, this prevents your coputer from connecting to those sites by redirecting them to 127.0.0.1 which is your local computer
  • Comodo BOCLEAN <= Stop identity thieves from getting personal information. Instantly detects well over 1,000,000 unique, variant and repack malware in total. And it's free.
  • Winpatrol <= Download and install the free version of Winpatrol. a tutorial for this product is located here:
    Using Winpatrol to protect your computer from malicious software

Stand Up and Be Counted ---> Malware Complaints <--- where you can make difference!

The site offers people who have been (or are) victims of malware the opportunity to document their story and, in that way, launch a complaint against the malware and the makers of the malware.

Also, please read this great article by Tony Klein So How Did I Get Infected In First Place

Happy surfing and stay clean!
 
A million Thankyou's again for your time and patience in helping me resolve this issue. I owe you a debt of gratitude as my next step would have been a complete format and rebuild. (not a pleasant thought). I am hopefull that what you have so kindly done for me has negated the need for that drastic step. (I guess only time will fully answer that one.)

Thanks for the information on staying clean in your last post. I will now continue on with the steps you suggest but as it appears to be very time consuming, I thought I would send you this post to say thanks again and (don't take this the wrong way) hopefully won't be needing to take up your valuable time any further.

You guys (and gals) are doing a terrific job of saving all of us from the lowlife conponent of the web world.

Keep up the great work and maybe someday we can rid the world of these virus writing SCUM.

I just can't say it enough so Many, Many Thanks again.

:) :D: :bigthumb: :bigthumb: :bigthumb: :bigthumb: :bigthumb:
 
Since this issue appears resolved ... this Topic is closed.

If you need this topic reopened, please request this by sending the moderating team
a PM with the address of the thread. This applies only to the original topic starter.

Everyone else please begin a New Topic.
 
Back
Top