help me! hijacked! analyze this....

Status
Not open for further replies.
still infected.....

Logfile of HijackThis v1.99.1
Scan saved at 7:12:24 PM, on 11/23/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\ewido\security suite\ewidoctrl.exe
C:\Program Files\ewido\security suite\ewidoguard.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe
C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\HP\Digital Imaging\bin\hpqgalry.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O4 - HKLM\..\Run: [IPInSightLAN 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPClient.exe" -l
O4 - HKLM\..\Run: [IPInSightMonitor 02] "C:\Program Files\Visual Networks\Visual IP InSight\SBC\IPMon32.exe"
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\SBCSEL~1\SMARTB~1\MotiveSB.exe
O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Program Files\GE\98056 Keyboard and Mouse\mouse32a.exe
O4 - HKLM\..\Run: [OFFICEKB] C:\Program Files\GE\98056 Keyboard and Mouse\kbdap32a.exe
O4 - HKLM\..\Run: [ccApp] C:\Program Files\Common Files\Symantec Shared\ccApp.exe
O4 - HKLM\..\Run: [ccRegVfy] C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SpySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe" /startintray
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\K-Lite Codec Pack\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: SBC Self Support Tool.lnk = C:\Program Files\SBC Self Support Tool\bin\matcli.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
O4 - Global Startup: Spy Sweeper Fix.lnk = C:\Program Files\Webroot\Spy Sweeper\SpySweeperFix.bat
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O9 - Extra button: ICQ 4 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe
O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\YAHOO!\MESSEN~1\YPAGER.EXE
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://by17fd.bay17.hotmail.msn.com/resources/MsnPUpld.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cab
O19 - User stylesheet: (file missing)
O20 - Winlogon Notify: WRNotifier - C:\WINDOWS\SYSTEM32\WRLogonNTF.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Program Files\ewido\security suite\ewidoguard.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Webroot Spy Sweeper Engine (svcWRSSSDK) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\WRSSSDK.exe




---------------------------------------------------------
ewido security suite - Scan report
---------------------------------------------------------

+ Created on: 6:16:54 PM, 11/23/2005
+ Report-Checksum: 3C02BAA4

+ Scan result:

C:\Documents and Settings\main\Cookies\main@casalemedia[2].txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@citi.bridgetrack[1].txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@fastclick[2].txt -> Spyware.Cookie.Fastclick : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@ad.yieldmanager[2].txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@serving-sys[1].txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@2o7[1].txt -> Spyware.Cookie.2o7 : Cleaned with backup
C:\Documents and Settings\main\Cookies\main@questionmarket[1].txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.25:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.26:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.27:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.28:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.35:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.39:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Tradedoubler : Cleaned with backup
:mozilla.40:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.41:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.42:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.43:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.45:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.57:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.58:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.59:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.60:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.61:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.62:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.63:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.64:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Bridgetrack : Cleaned with backup
:mozilla.65:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.66:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.67:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.68:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.69:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.73:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.74:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Valueclick : Cleaned with backup
:mozilla.78:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.79:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.93:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.94:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.95:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Adserver : Cleaned with backup
:mozilla.96:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.97:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.98:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Hitbox : Cleaned with backup
:mozilla.104:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Googleadservices : Cleaned with backup
:mozilla.106:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.107:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.111:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.112:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.113:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.114:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.115:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.117:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.118:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.119:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Statcounter : Cleaned with backup
:mozilla.125:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.126:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.127:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.128:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.129:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Specificclick : Cleaned with backup
:mozilla.133:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Smartadserver : Cleaned with backup
:mozilla.134:C:\Documents and Settings\main\Application Data\Mozilla\Firefox\Profiles\3tlmdt1u.default\cookies.txt -> Spyware.Cookie.Bfast : Cleaned with backup
C:\System Volume Information\_restore{05670185-0513-41E0-AD7A-F84C30CCE5D4}\RP1\A0001494.exe -> TrojanSpy.Small.dg : Cleaned with backup
C:\System Volume Information\_restore{05670185-0513-41E0-AD7A-F84C30CCE5D4}\RP1\A0001495.exe -> Not-A-Virus.Hoax.Win32.Renos.w : Cleaned with backup
C:\System Volume Information\_restore{05670185-0513-41E0-AD7A-F84C30CCE5D4}\RP1\A0001496.dll -> Spyware.BargainBuddy : Cleaned with backup
C:\System Volume Information\_restore{05670185-0513-41E0-AD7A-F84C30CCE5D4}\RP1\A0001497.dll -> Spyware.WildTangent : Cleaned with backup


::Report End


Incident Status Location

Adware:adware/maxifiles Not disinfected C:\PROGRAM FILES\COMMON FILES\Windows
Adware:adware/cws Not disinfected C:\Documents and Settings\main\Favorites\Technology


i
 
Not really infected...just some cleanup items to deal with. Reboot into safe mode and manually delete these folders..

C:\PROGRAM FILES\COMMON FILES\Windows <--delete that folder

C:\Documents and Settings\main\Favorites\Technology <--delete that folder

Run Ewido and let it clean the PC (no log needed)

Run the Cleanup program again and reboot/logoff when prompted. ONce back to normal mode run another Panda scan and post it's log. Let me know how things are running.
 
good news

nothing detected at all all cleaned up!
thanks for your knowledgeable advice it was all worth it
i had never had an attack of this magnitude before
i always laughed at my computer illiterate friends when they mucked their cpus up with spyware and viruses never knew it would happen to me
can you please make me if you can a list of the programs that work best in your opinion for spyware adware hijack removal and which one you think are bs? or maybe a link to a site that has decent reviews of these programs?
 
Well done. Your logs are clean. Any more issues? If not you should be good to go. We still have a few more items to address so please follow the instructions below.


Reset hidden/system files and folders

Windows XP
===============

  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Deselect the Show hidden files and folders option.
  • Select the Hide file extensions for known types option.
  • Select the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.

Windows 2000
===============

  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Select the Advanced settings box option.
  • Select the Hidden files Folders.
  • Deselect the Show all files option.
  • Click Yes to confirm.
  • Click OK.

Windows ME
===============

  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View tab.
  • Deselect the Show hidden files and folders option.
  • Select the Hide protected operating system files option.
  • Click Yes to confirm.
  • Click OK.

Windows 95/98/98SE
===============

  • Open My Computer.
  • Select the View
  • Select the Folder Options option.
  • Select the View tab. option.
  • Select the Advance Advanced settings box option.
  • Select the Hidden files folder.
  • Deselect the Show all files option
  • Click Apply to confirm.
  • Click OK.



Create a new System Restore point

Windows XP
===============

  • Click Start >> Run - type SYSDM.CPL & press Enter
  • Select the System Restore Tab
  • Tick on the checkbox - "Turn off System Restore on all drives"
  • Click Apply
  • Then untick the same checkbox & click OK
  • This deletes ALL restore points that had the infection and creates a clean one

Windows ME
===============

  • Click the Start tab.
  • Select the Settings option.
  • Select the Control Panel option.
  • Double Click the System icon Performance tab option.
  • Select File System
  • Select the Troubleshooting tab
  • Check the Disable System Restore box
  • Click Apply to confirm.
  • Click OK.

Reboot the PC and repeat the above procedure again
When you get to this option
  • Uncheck the Disable System Restore box

For Windows ME..we MUST create a new restore point now as Windows ME will not create one automatically until the computer has been on for 10 hours or 24 hours has passed. To create a new restore point follow the procedure below.

  • Click the Start button.
  • Point to Programs, point to Accessories, point to System Tools, and then click System Restore.
  • Choose Create a restore point, and then click Next.
  • In the Restore point description box, type a name for your restore point, and then click Next.
    Click OK



Enable Windows Auto Update
  • Go to Start>Run - type wuaucpl.cpl
  • Tick on the checkbox - "Keep my computer up to date"
  • Under settings, choose "Automatically download the updates, and install them on the schedule that I specify".
  • Click on "OK".

Please visit Microsoft's Window's Update Page and install the latest service packs, patchÂ’s and security updates for your system.


Recommended Protection Programs

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programs:
  • SpywareBlaster to help prevent spyware from installing in the first place.
  • SpywareGuard to catch and block spyware before it can execute.
  • IESpy-Ad to block access to malicious websites so you cannot be redirected to them from an infected site or email.
  • WinPatrol to monitor any changes that programs make to the registry.

If you do not have a firewall, here are 4 free ones available for personal use:


In todayÂ’s world you MUST have an Antivirus program. If you do not have one, here are 3 FREE ones available for personal use:




In light of your recent issue, I'm sure you'll like to avoid any future infections. Please take a look at these well written articles
Please stay safe out there and take the helpful advice thatÂ’s been given. The goal here is to prevent the adware/spyware/virus/worms from getting on the system in the first place.
 
Status
Not open for further replies.
Back
Top Bottom