WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Sad tearing

Okay, lets try this, see if it finds any leftovers we might have missed.
If it comes back clean, we know it's not a virus causing this.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log with a fresh copy of HijackThis log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Hi,

I had to download MBAM on another computer, as I can't dnload anything like that as it always comes up with "Page cannot be displayed".
I a rying o run the setup, but when I click on it nothing happens. It appears under 'Processes' on the Task maager, but nothing appears on screen.

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
I guess you won't be able to access this either. Evil or enraged

Please run a free online scan with Kaspersky AntiVirus (works only with MS Internet Explorer 5.0 or higher).
Go to http://www.kaspersky.com/virusscanner and click the "Kaspersky Online Scanner" button (NOT "Kaspersky File Scanner").

  • In the new window that opens, click the "Accept" button to accept the user agreement, install the ActiveX control, and download the program.
  • When you get the Windows dialog asking if you want to install this software, click the "Install" button.
  • When the "Update progress" line changes to "Ready" and the "NEXT ->" button lights up with a green arrow, click it.
  • Click on the "Scan Settings" button, and in the next window select the "extended" database, and click Ok.
  • Under "Please select a target to scan:", click My Computer to start the scan.
When the scan is finished, click the "Save as Text" button, and save the file as kavscan.txt to your Desktop, close the Kaspersky On-line Scanner window, and post the text in kavscan.txt in your next reply.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Nope, can't access this either I'm afraid, I just get redirected to a search engine or I get the message: "Intrnet Explorer cannot display the webpage".

😢

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
This is actually quite annoying now.

Close MBAM in Task Manager.
Download combofix from here

Once downloaded, rename it to combo-fix.exe.
Double click it to run it, follow the prompts and post the resulting log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Hi,

Here is the log:

ComboFix 08-10-08.02 - Toshiba 2008-10-12 20:00:09.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.277 [GMT 1:00]

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\RECYCLER\ADAPT_Installer.exe
C:\WINDOWS\system32\oembios.exe
C:\WINDOWS\system32\tdssadw.dll
C:\WINDOWS\system32\TDSSerrors.log
C:\WINDOWS\system32\tdssinit.dll
C:\WINDOWS\system32\tdssl.dll
C:\WINDOWS\system32\TDSSlog.dll
C:\WINDOWS\system32\tdssmain.dll
C:\WINDOWS\system32\TDSSserf.dll
C:\WINDOWS\system32\tdssservers.dat

.
((((((((((((((((((((((((( Files Created from 2008-09-12 to 2008-10-12 )))))))))))))))))))))))))))))))
.

2008-10-12 19:30 . 2008-10-12 19:30 268 --ah----- C:\sqmdata07.sqm
2008-10-12 19:30 . 2008-10-12 19:30 244 --ah----- C:\sqmnoopt07.sqm
2008-10-12 18:03 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-12 18:02 . 2008-10-12 18:02 d-------- C:\Program Files\Common Files\Java
2008-10-12 17:59 . 2008-10-12 17:59 268 --ah----- C:\sqmdata06.sqm
2008-10-12 17:59 . 2008-10-12 17:59 244 --ah----- C:\sqmnoopt06.sqm
2008-10-12 17:01 . 2008-10-12 17:01 268 --ah----- C:\sqmdata05.sqm
2008-10-12 17:01 . 2008-10-12 17:01 244 --ah----- C:\sqmnoopt05.sqm
2008-10-12 16:52 . 2008-10-12 16:52 d-------- C:\WINDOWS\system32\bits
2008-10-12 16:47 . 2008-04-13 22:06 144,384 --------- C:\WINDOWS\system32\drivers\hdaudbus.sys
2008-10-12 16:47 . 2008-04-14 00:10 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-10-12 16:46 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\004917_.tmp
2008-10-12 16:46 . 2008-10-12 17:00 2,711 --a------ C:\WINDOWS\imsins.BAK
2008-10-11 18:15 . 2008-10-11 18:15 d-------- C:\Program Files\Lavasoft
2008-10-11 18:15 . 2008-10-11 18:15 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-11 18:14 . 2008-10-11 18:14 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-11 18:04 . 2008-10-11 18:04 260 --a------ C:\WINDOWS\system32\ikhcore.cfg
2008-10-11 13:08 . 2008-10-11 13:08 244 --ah----- C:\sqmnoopt04.sqm
2008-10-11 13:08 . 2008-10-11 13:08 232 --ah----- C:\sqmdata04.sqm
2008-10-11 13:06 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-10-11 13:06 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-10-11 13:06 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2008-10-11 13:00 . 2008-10-11 13:00 244 --ah----- C:\sqmnoopt03.sqm
2008-10-11 13:00 . 2008-10-11 13:00 232 --ah----- C:\sqmdata03.sqm
2008-10-11 12:49 . 2008-10-12 19:13 d-------- C:\Program Files\Sophos
2008-10-11 09:25 . 2008-10-11 09:25 268 --ah----- C:\sqmdata02.sqm
2008-10-11 09:25 . 2008-10-11 09:25 244 --ah----- C:\sqmnoopt02.sqm
2008-10-10 12:37 . 2008-10-10 12:37 268 --ah----- C:\sqmdata01.sqm
2008-10-10 12:37 . 2008-10-10 12:37 244 --ah----- C:\sqmnoopt01.sqm
2008-10-10 12:36 . 2008-10-10 12:36 d-------- C:\Program Files\Alwil Software
2008-10-10 12:36 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-10-09 23:00 . 2008-10-09 23:00 268 --ah----- C:\sqmdata00.sqm
2008-10-09 23:00 . 2008-10-09 23:00 244 --ah----- C:\sqmnoopt00.sqm
2008-10-09 22:55 . 2008-10-09 23:00 d-------- C:\Program Files\ChrisTV PVR
2008-10-09 22:55 . 2004-08-04 00:56 1,376 --a------ C:\WINDOWS\system32\wstcode16a.dll
2008-10-09 22:17 . 2008-10-11 18:07 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-09 22:16 . 2008-10-09 22:16 d-------- C:\Program Files\Nsasoft
2008-10-09 22:07 . 2008-10-09 22:07 d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-10-09 20:42 . 2008-10-09 22:19 d-------- C:\Documents and Settings\Toshiba\Application Data\Download Manager
2008-10-09 20:31 . 2008-04-14 05:42 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-10-03 00:12 . 2008-10-03 00:12 d-------- C:\Program Files\Windows Media Connect 2
2008-10-03 00:07 . 2008-10-03 00:07 d-------- C:\WINDOWS\system32\LogFiles
2008-10-03 00:07 . 2008-10-03 00:10 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-10-02 23:58 . 2008-10-02 23:58 d-------- C:\Program Files\Kontiki
2008-10-02 23:58 . 2008-10-02 23:58 d-------- C:\Program Files\Channel4
2008-10-02 23:58 . 2008-10-12 20:02 d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2008-10-02 23:57 . 2008-10-02 23:57 d-------- C:\Documents and Settings\All Users\Application Data\Channel4
2008-09-25 14:42 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-09-25 14:42 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-09-25 14:42 . 2008-04-14 00:15 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-09-18 21:43 . 2008-09-18 21:43 d-------- C:\Documents and Settings\All Users\Application Data\SWiSHMax2WorkFolder
2008-09-18 21:16 . 2008-09-18 21:16 d-------- C:\Program Files\Common Files\SWiSHzone.com
2008-09-18 21:16 . 2004-03-29 15:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-09-18 21:15 . 2008-09-18 21:16 d-------- C:\Program Files\SWiSH miniMax2
2008-09-16 23:19 . 2008-09-16 23:19 d-------- C:\Program Files\QuickTime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-12 17:05 --------- d-----w C:\Program Files\Java
2008-10-10 14:25 90,112 ----a-w C:\WINDOWS\DUMP2059.tmp
2008-10-10 12:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-09 19:30 283,648 ----a-w C:\WINDOWS\system32\drivers\AF15BDA.sys
2008-09-05 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-09-05 08:56 34,488 ----a-w C:\Documents and Settings\Toshiba\Application Data\GDIPFONTCACHEV1.DAT
2008-09-03 21:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-26 15:35 --------- d-----w C:\Program Files\Windows Live
2008-08-26 15:34 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-26 15:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-24 17:27 --------- d-----w C:\Program Files\Norton PC Checkup
2008-08-13 13:55 --------- d-----w C:\Program Files\Google
2008-08-13 13:18 20,747 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-08-13 13:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-13 13:18 --------- d-----w C:\Program Files\BLUENEXT
2008-08-06 14:29 348,160 ----a-w C:\WINDOWS\system32\msvcr71.dll
2008-08-06 14:27 499,712 ----a-w C:\WINDOWS\system32\msvcp71.dll
2008-07-18 21:10 94,920 ----a-w C:\WINDOWS\system32\cdm.dll
2008-07-18 21:10 53,448 ----a-w C:\WINDOWS\system32\wuauclt.exe
2008-07-18 21:10 45,768 ----a-w C:\WINDOWS\system32\wups2.dll
2008-07-18 21:10 36,552 ----a-w C:\WINDOWS\system32\wups.dll
2008-07-18 21:09 563,912 ----a-w C:\WINDOWS\system32\wuapi.dll
2008-07-18 21:09 325,832 ----a-w C:\WINDOWS\system32\wucltui.dll
2008-07-18 21:09 205,000 ----a-w C:\WINDOWS\system32\wuweb.dll
2008-07-18 21:09 1,811,656 ----a-w C:\WINDOWS\system32\wuaueng.dll
2008-07-18 21:07 270,880 ----a-w C:\WINDOWS\system32\mucltui.dll
2008-07-18 21:07 210,976 ----a-w C:\WINDOWS\system32\muweb.dll
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2003-03-11 122880]
"PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [2003-11-24 1019904]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - C:\Program Files\Sophos\AutoUpdate\ALMon.exe [10/11/2008 1:13:19 PM 245760]
BN-WD54G Wireless Client Utility.lnk - C:\Program Files\BLUENEXT\BN-WD54G\Installer\WINXP\BCU.exe [8/13/2008 2:18:17 PM 593920]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]
--a------ 2003-05-23 15:15 253952 C:\WINDOWS\system32\00THotkey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
--a------ 2007-04-23 11:23 1032640 C:\Program Files\Kontiki\KHost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
-ra------ 2003-07-17 18:38 159744 C:\Program Files\Apoint2K\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 05:42 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2003-04-07 01:07 114688 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2003-04-07 01:19 155648 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
--a------ 2007-04-23 11:23 1032640 C:\Program Files\Kontiki\KHost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-16 23:19 413696 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-08-13 14:55 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
--a------ 2003-09-05 04:24 65536 C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\000StTHK]
--a------ 2001-06-23 21:28 24576 C:\WINDOWS\system32\000StTHK.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTSMMSG]
--a------ 2003-04-18 11:06 32768 C:\WINDOWS\ltsmmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFNF5]
-ra------ 2003-10-15 17:03 73728 C:\WINDOWS\system32\TFNF5.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
--a------ 2003-11-27 17:53 266240 C:\WINDOWS\system32\TPSMain.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Toshiba\\ConfigFree\\CFSServW.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [ ]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [ ]
S3 AF15BDA;AF9015 BDA Filter;C:\WINDOWS\system32\Drivers\AF15BDA.sys [2008-10-09 283648]

*Newly Created Service* - CATCHME
.
Contents of the 'Scheduled Tasks' folder

2008-09-17 C:\WINDOWS\Tasks\At1.job
- c:\program files\norton pc checkup\pc_checkup.exe [2008-06-29 22:50]
.
- - - - ORPHANS REMOVED - - - -

MSConfigStartUp-TFncKy - TFncKy.exe


.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.google.co.uk/
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
O8 -: E&xport to Microsoft Excel - C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O16 -: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} - hxxp://dlm.tools.akamai.com/dlmanager/versions/activex/dlm-activex-2.2.4.3.cab
C:\WINDOWS\Downloaded Program Files\DownloadManagerV2.inf
C:\WINDOWS\Downloaded Program Files\Manager.exe
C:\WINDOWS\Downloaded Program Files\DownloadManagerV2.ocx
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-12 20:02:41
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv]
"imagepath"="\systemroot\system32\drivers\TDSSserv.sys"
.
Completion time: 2008-10-12 20:03:52
ComboFix-quarantined-files.txt 2008-10-12 19:03:47

Pre-Run: 50,150,449,152 bytes free
Post-Run: 50,252,124,160 bytes free

208 --- E O F --- 2008-10-03 18:03:33


.

Since running this I can now access antivirus websites, but Sophos Antivirus has disappeared completely from my system!!! ??

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Don't worry about Sophos for now.
We have bigger issues, just do not surf the internet until we are done.


Your system is serverly compromised. Combofix took down a horrible rootkit, it has backdoor functions and steals passwords/personal information. If you do any online banking (Ebay, Paypal, etc) you need to get to a clean machine and change any passwords.
====

Now open a new notepad file.
Input this into the notepad file:

KILLALL::

File::
C:\sqmdata07.sqm
C:\sqmnoopt07.sqm
C:\sqmdata06.sqm
C:\sqmnoopt06.sqm
C:\sqmdata05.sqm
C:\sqmnoopt05.sqm
C:\sqmdata04.sqm
C:\sqmnoopt04.sqm
C:\sqmdata03.sqm
C:\sqmnoopt03.sqm
C:\sqmnoopt02.sqm
C:\sqmdata02.sqm
C:\sqmnoopt02.sqm
C:\sqmdata01.sqm
C:\sqmnoopt01.sqm
C:\sqmdata00.sqm
C:\sqmnoopt00.sqm
C:\WINDOWS\Tasks\At1.job
C:\WINDOWS\system32\drivers\TDSSserv.sys

Registry::
[-HKEY_LOCAL_MACHINE\system\ControlSet001\Services\TDSSserv]


Save this as CFScript.txt, save it to your desktop also.
Then drag and drop CFScript.txt into combofix as seen below:
Can't access antivirus update, etc. - Page 1 Sfxdaw

This will open combofix.exe again, agree to it's terms and allow it to run, it may want to reboot after it's done. Post the resulting log back here.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
So will I need to wipe my system?

Here is the new log:

ComboFix 08-10-11.04 - Toshiba 2008-10-12 20:23:51.2 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.3.1252.1.1033.18.253 [GMT 1:00]
Running from: C:\Documents and Settings\Toshiba\Desktop\combo-fix.exe.exe
Command switches used :: C:\Documents and Settings\Toshiba\Desktop\CFscript.txt
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!

FILE ::
C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\sqmnoopt07.sqm
C:\WINDOWS\system32\drivers\TDSSserv.sys
C:\WINDOWS\Tasks\At1.job
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\sqmdata00.sqm
C:\sqmdata01.sqm
C:\sqmdata02.sqm
C:\sqmdata03.sqm
C:\sqmdata04.sqm
C:\sqmdata05.sqm
C:\sqmdata06.sqm
C:\sqmdata07.sqm
C:\sqmnoopt00.sqm
C:\sqmnoopt01.sqm
C:\sqmnoopt02.sqm
C:\sqmnoopt04.sqm
C:\sqmnoopt05.sqm
C:\sqmnoopt06.sqm
C:\sqmnoopt07.sqm
C:\WINDOWS\Tasks\At1.job

.
((((((((((((((((((((((((( Files Created from 2008-09-12 to 2008-10-12 )))))))))))))))))))))))))))))))
.

2008-10-12 18:03 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-10-12 18:02 . 2008-10-12 18:02 d-------- C:\Program Files\Common Files\Java
2008-10-12 16:52 . 2008-10-12 16:52 d-------- C:\WINDOWS\system32\bits
2008-10-12 16:47 . 2008-04-13 22:06 144,384 --------- C:\WINDOWS\system32\drivers\hdaudbus.sys
2008-10-12 16:47 . 2008-04-14 00:10 10,240 --------- C:\WINDOWS\system32\drivers\sffp_mmc.sys
2008-10-12 16:46 . 2006-12-29 00:31 19,569 --a------ C:\WINDOWS\004917_.tmp
2008-10-12 16:46 . 2008-10-12 17:00 2,711 --a------ C:\WINDOWS\imsins.BAK
2008-10-11 18:15 . 2008-10-11 18:15 d-------- C:\Program Files\Lavasoft
2008-10-11 18:15 . 2008-10-11 18:15 d-------- C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-10-11 18:14 . 2008-10-11 18:14 d-------- C:\Program Files\Common Files\Wise Installation Wizard
2008-10-11 18:04 . 2008-10-11 18:04 260 --a------ C:\WINDOWS\system32\ikhcore.cfg
2008-10-11 13:06 . 2004-05-14 16:53 462,848 --a------ C:\WINDOWS\system32\ltkrn13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 450,560 --a------ C:\WINDOWS\system32\ltimg13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 401,408 --a------ C:\WINDOWS\system32\lfcmp13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 299,008 --a------ C:\WINDOWS\system32\ltdis13n.dll
2008-10-11 13:06 . 2004-01-12 02:09 206,336 --a------ C:\WINDOWS\system32\ltefx13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 163,840 --a------ C:\WINDOWS\system32\ltfil13n.dll
2008-10-11 13:06 . 2003-11-04 15:10 69,632 --a------ C:\WINDOWS\system32\lfgif13n.dll
2008-10-11 13:06 . 2004-05-14 16:53 57,344 --a------ C:\WINDOWS\system32\lfbmp13n.dll
2008-10-11 13:00 . 2008-10-11 13:00 244 --ah----- C:\sqmnoopt03.sqm
2008-10-11 12:49 . 2008-10-12 19:13 d-------- C:\Program Files\Sophos
2008-10-10 12:36 . 2008-10-10 12:36 d-------- C:\Program Files\Alwil Software
2008-10-10 12:36 . 2003-03-18 21:20 1,060,864 --a------ C:\WINDOWS\system32\MFC71.dll
2008-10-09 22:55 . 2008-10-09 23:00 d-------- C:\Program Files\ChrisTV PVR
2008-10-09 22:55 . 2004-08-04 00:56 1,376 --a------ C:\WINDOWS\system32\wstcode16a.dll
2008-10-09 22:17 . 2008-10-11 18:07 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP
2008-10-09 22:16 . 2008-10-09 22:16 d-------- C:\Program Files\Nsasoft
2008-10-09 22:07 . 2008-10-09 22:07 d-------- C:\Documents and Settings\All Users\Application Data\Pinnacle
2008-10-09 20:42 . 2008-10-09 22:19 d-------- C:\Documents and Settings\Toshiba\Application Data\Download Manager
2008-10-09 20:31 . 2008-04-14 05:42 53,760 --a------ C:\WINDOWS\system32\vfwwdm32.dll
2008-10-03 00:12 . 2008-10-03 00:12 d-------- C:\Program Files\Windows Media Connect 2
2008-10-03 00:07 . 2008-10-03 00:07 d-------- C:\WINDOWS\system32\LogFiles
2008-10-03 00:07 . 2008-10-03 00:10 d-------- C:\WINDOWS\system32\drivers\UMDF
2008-10-02 23:58 . 2008-10-02 23:58 d-------- C:\Program Files\Kontiki
2008-10-02 23:58 . 2008-10-02 23:58 d-------- C:\Program Files\Channel4
2008-10-02 23:58 . 2008-10-12 20:23 d-------- C:\Documents and Settings\All Users\Application Data\Kontiki
2008-10-02 23:57 . 2008-10-02 23:57 d-------- C:\Documents and Settings\All Users\Application Data\Channel4
2008-09-25 14:42 . 2001-08-17 13:48 12,160 --a------ C:\WINDOWS\system32\drivers\mouhid.sys
2008-09-25 14:42 . 2001-08-17 13:48 12,160 --a--c--- C:\WINDOWS\system32\dllcache\mouhid.sys
2008-09-25 14:42 . 2008-04-14 00:15 10,368 --a------ C:\WINDOWS\system32\drivers\hidusb.sys
2008-09-18 21:43 . 2008-09-18 21:43 d-------- C:\Documents and Settings\All Users\Application Data\SWiSHMax2WorkFolder
2008-09-18 21:16 . 2008-09-18 21:16 d-------- C:\Program Files\Common Files\SWiSHzone.com
2008-09-18 21:16 . 2004-03-29 15:23 90,112 --a------ C:\WINDOWS\unvise32.exe
2008-09-18 21:15 . 2008-09-18 21:16 d-------- C:\Program Files\SWiSH miniMax2
2008-09-16 23:19 . 2008-09-16 23:19 d-------- C:\Program Files\QuickTime

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-10-12 17:05 --------- d-----w C:\Program Files\Java
2008-10-10 14:25 90,112 ----a-w C:\WINDOWS\DUMP2059.tmp
2008-10-10 12:04 --------- d-----w C:\Documents and Settings\All Users\Application Data\avg8
2008-10-09 19:30 283,648 ----a-w C:\WINDOWS\system32\drivers\AF15BDA.sys
2008-09-05 11:35 --------- d-----w C:\Documents and Settings\All Users\Application Data\MailFrontier
2008-09-05 08:56 34,488 ----a-w C:\Documents and Settings\Toshiba\Application Data\GDIPFONTCACHEV1.DAT
2008-09-03 21:32 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2008-08-26 15:35 --------- d-----w C:\Program Files\Windows Live
2008-08-26 15:34 --------- dcsh--w C:\Program Files\Common Files\WindowsLiveInstaller
2008-08-26 15:30 --------- d-----w C:\Documents and Settings\All Users\Application Data\WLInstaller
2008-08-24 17:27 --------- d-----w C:\Program Files\Norton PC Checkup
2008-08-13 13:55 --------- d-----w C:\Program Files\Google
2008-08-13 13:18 20,747 ----a-w C:\WINDOWS\system32\drivers\AegisP.sys
2008-08-13 13:18 --------- d--h--w C:\Program Files\InstallShield Installation Information
2008-08-13 13:18 --------- d-----w C:\Program Files\BLUENEXT
.

((((((((((((((((((((((((((((( snapshot@2008-10-12_20.03.24.54 )))))))))))))))))))))))))))))))))))))))))
.
+ 2008-10-12 19:26:32 16,384 ----atw C:\WINDOWS\temp\Perflib_Perfdata_6c8.dat
+ 2008-10-11 12:11:17 655,360 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\ALUpdate.exe
+ 2008-10-11 12:13:33 172,032 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\ChannelUpdater.dll
+ 2008-10-11 12:13:15 20,480 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\crypto.dll
+ 2006-08-25 11:14:34 159,744 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\libcurl.dll
+ 2008-10-11 12:11:58 745,472 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\libeay32.dll
+ 2005-07-11 15:18:55 499,712 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\MSVCP71.DLL
+ 2005-07-11 15:18:56 348,160 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\MSVCR71.DLL
+ 2008-10-11 12:11:49 208,896 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\retailer.dll
+ 2008-10-11 12:13:09 18,432 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\SharedRes.dll
+ 2008-10-11 12:13:20 14,336 ----a-w C:\WINDOWS\temp\sophos_autoupdate1.dir\xmlcpp.dll
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2008-04-14 15360]
"msnmsgr"="C:\Program Files\Windows Live\Messenger\msnmsgr.exe" [2007-10-18 5724184]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TouchED"="C:\Program Files\TOSHIBA\TouchED\TouchED.Exe" [2003-03-11 122880]
"PadTouch"="C:\Program Files\TOSHIBA\PadTouch\PadExe.exe" [2003-11-24 1019904]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 144784]

C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
AutoUpdate Monitor.lnk - C:\Program Files\Sophos\AutoUpdate\ALMon.exe [10/11/2008 1:13:19 PM 245760]
BN-WD54G Wireless Client Utility.lnk - C:\Program Files\BLUENEXT\BN-WD54G\Installer\WINXP\BCU.exe [8/13/2008 2:18:17 PM 593920]

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Microsoft Office.lnk]
path=C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Microsoft Office.lnk
backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck]
C:\WINDOWS\system32\dumprep 0 -k [X]

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]
--a------ 2003-05-23 15:15 253952 C:\WINDOWS\system32\00THotkey.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\4oD]
--a------ 2007-04-23 11:23 1032640 C:\Program Files\Kontiki\KHost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Apoint]
-ra------ 2003-07-17 18:38 159744 C:\Program Files\Apoint2K\Apoint.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
--a------ 2008-04-14 05:42 15360 C:\WINDOWS\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
--a------ 2003-04-07 01:07 114688 C:\WINDOWS\system32\hkcmd.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
--a------ 2003-04-07 01:19 155648 C:\WINDOWS\system32\igfxtray.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\kdx]
--a------ 2007-04-23 11:23 1032640 C:\Program Files\Kontiki\KHost.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MsnMsgr]
--a------ 2007-10-18 11:34 5724184 C:\Program Files\Windows Live\Messenger\msnmsgr.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck]
--a------ 2001-07-09 10:50 155648 C:\WINDOWS\system32\NeroCheck.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
--a------ 2008-09-16 23:19 413696 C:\Program Files\QuickTime\qttask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\swg]
--a------ 2008-08-13 14:55 171448 C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD]
--a------ 2003-09-05 04:24 65536 C:\Program Files\Toshiba\TOSCDSPD\TOSCDSPD.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\000StTHK]
--a------ 2001-06-23 21:28 24576 C:\WINDOWS\system32\000StTHK.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LTSMMSG]
--a------ 2003-04-18 11:06 32768 C:\WINDOWS\ltsmmsg.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TFNF5]
-ra------ 2003-10-15 17:03 73728 C:\WINDOWS\system32\TFNF5.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TPSMain]
--a------ 2003-11-27 17:53 266240 C:\WINDOWS\system32\TPSMain.exe

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\Program Files\\Toshiba\\ConfigFree\\CFSServW.exe"=
"C:\\Program Files\\Kontiki\\KService.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"C:\\Program Files\\Windows Live\\Messenger\\livecall.exe"=

S1 AvgLdx86;AVG Free AVI Loader Driver x86;C:\WINDOWS\system32\Drivers\avgldx86.sys [ ]
S2 AvgTdiX;AVG Free8 Network Redirector;C:\WINDOWS\system32\Drivers\avgtdix.sys [ ]
S3 AF15BDA;AF9015 BDA Filter;C:\WINDOWS\system32\Drivers\AF15BDA.sys [2008-10-09 283648]
.

**************************************************************************

catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-10-12 20:26:58
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...


C:\WINDOWS\TEMP\eu28dmak.TMP

scan completed successfully
hidden files: 1

**************************************************************************
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\Program Files\Toshiba\ConfigFree\CFSvcs.exe
C:\Program Files\Kontiki\KService.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Sophos\AutoUpdate\ALsvc.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\system32\wscntfy.exe
.
**************************************************************************
.
Completion time: 2008-10-12 20:29:28 - machine was rebooted
ComboFix-quarantined-files.txt 2008-10-12 19:29:21
ComboFix2.txt 2008-10-12 19:03:53

Pre-Run: 50,206,830,592 bytes free
Post-Run: 50,225,643,520 bytes free

216 --- E O F --- 2008-10-03 18:03:33

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
You can do if you want, but you don't have to.
====

To Unhide Files and folders:

  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.

    Under the Hidden files and folders heading deselect "Show hidden files and folders".
  • Check the "Show hidden files and folders" option.
  • Hit the "Apply To All Folders" option.
  • Click Yes to confirm. Click OK.


Delete this file in bold:
C:\sqmnoopt03.sqm
===

Download ATF Cleaner

  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
  • Close ATF-Cleaner.exe.

====

Lastly, do this.
Start > Run
Type in: ComboFix /u then press enter.
This will uninstall Combofix.
====

How's the machine now? Is Sophos still on your machine?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Hi there,

First of all, thank you very much for your help - I took my laptop to PC World and they thought it was a motherboard problem!?!?!?

I can't uninstall combofix - a message pops up saying it cannot be found is it ok to just delete the combo fix files and folder?

Machine seems to be ok, and Sophos is back and working (doing a scan now).

Is there anything else I need to do? Is it all fine?

Oh btw, when I boot it up an error message appears that reads 'Cant find HotKey' or something like that.

Dan

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
The combofix error - Probably my bad spelling. LMBO or ROFL
You can delete these.
C:\Combofix
C:\Quarantine
And the combo-fix.exe on the desktop.
And any logs it made.

Thank you for staying with me, I wouldn't let tdssserv beat me this time.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
And the hotkey problem.

Now open a new notepad file.
Input this into the notepad file:
QUOTE

REGEDIT4

[-HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\00THotkey]


Save this as fix.reg, save it to your desktop.
Double click fix.reg and select yes to the merge with registry prompt.

That should fix that problem.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Thank again for your help, I don't know what I would have done otherwise (probably would have given PC World £200 - for a motherboard or something!!)

Dan Hooray!

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
Everything looks great --- your HijackThis log appears to be clean. Smile...
Below I have included a number of recommendations for how to protect your computer in order to prevent future malware infections. Please take these recommendations seriously; these few simple steps can stave off the vast majority of spyware problems. As happy as we are to help you, for your sake we would rather not have repeat customers. Goofy

1) Please navigate to http://windowsupdate.microsoft.com and download all the "critical updates" for Windows. This can patch many of the security holes through which attackers can gain access to your computer.

Please either enable Automatic Updates under Start -> Control Panel -> Automatic Updates , or get into the habit of checking for Windows updates regularly. I cannot stress enough how important this is.

2) In order to protect yourself against spyware, you should consider installing and running the following free programs:

Ad-Aware SE
A tutorial on using Ad-Aware to remove spyware from your computer may be found here.

Spybot-Search & Destroy
A tutorial on using Spybot to remove spyware from your computer may be found here. Please also remember to enable Spybot's "Immunize" and "TeaTimer" features.

SpywareBlaster
A tutorial on using SpywareBlaster to prevent spyware from ever installing on your computer may be found here.

SpywareGuard
A tutorial on using SpywareGuard for realtime protection against spyware and hijackers may be found here.

Make sure to keep these programs up-to-date and to run them regularly, as this can prevent a great deal of spyware hassle.

3) Please consider using an alternate browser. Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added benefit!) that I have ever seen. If you are interested, Firefox may be downloaded from here:
http://www.mozilla.org/products/firefox/

4) Also make sure to run your antivirus software regularly, and to keep it up-to-date.

5) Finally, consider maintaining a firewall. Some good free firewalls are ZoneAlarm, Kerio, or
Outpost
A tutorial on understanding and using firewalls may be found here.

Please also read Tony Klein's excellent article: How I got Infected in the First Place

Hopefully this should take care of your problems! Good luck. Big Grin

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Can't access antivirus update, etc. - Page 1 DXwU4
Can't access antivirus update, etc. - Page 1 VvYDg

descriptionCan't access antivirus update, etc. - Page 1 EmptyRe: Can't access antivirus update, etc.

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum