Trojans, worms and viruses oh my

My daughter gets into something called BuddyPic, usually with no problems but today a little dogs head popped up on the toolbar and numerous popup were bombarding the computer...I ran spybot, but it couldn't remove everything..froze up and I had to manually restart.
Ran spybot again, everything looks good, there is nothing unusual in the add/romove programs.
Here is my HiJack in the event I have missed something
Thank you all :o
Logfile of HijackThis v1.99.1
Scan saved at 9:10:31 PM, on 6/8/05
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\SSDPSRV.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\SYSTEM\RPCSS.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\PROGRAM FILES\MCAFEE.COM\SHARED\MCINFO.EXE
C:\HIJACK\HIJACKTHIS.EXE

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL (file missing)
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
O4 - HKLM\..\RunServices: [MSNIA] C:\PROGRA~1\MSN\MSNIA\MSNIASVC.EXE
O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
O16 - DPF: GraphicalChat Application - http://www.onchat.com/ChatWorld/chat-signed-ie.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/games/clients/y/mjst4_x.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab

Comments

  • edited June 2005
    Hi Celestialwave

    The log doen't look all that bad. However, there are a few things you should do.

    Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions.

    Go to My Computer >Tools >Folder Options >View tab and make sure that Show hidden files and folders is enabled. Also make sure that the System Files and Folders are showing / visible. Uncheck the Hide protected operating system files option.

    Download CWShredder here. Run it and instruct it to “fix” anything it finds (most likely nothing).

    Download CleanUp! by going here. Do not run it yet.

    Reboot the PC into safe mode<<< Click Here for instructions

    Open HijackThis and click on Scan. Check the following 4 entries (make sure you do not miss any):

    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O16 - DPF: GraphicalChat Application - http://www.onchat.com/ChatWorld/chat-signed-ie.cab

    O16 - DPF: Yahoo! MahJong Solitaire - http://download.games.yahoo.com/gam...s/y/mjst4_x.cab


    Please remember to close all other windows, including browsers, before clicking ”Fix checked”.

    Reboot your System in normal mode.

    Run CleanUp! and click on CleanUp! button. When it asks you if you want to logoff, click on Yes.

    If you have a fast internet connection (Broadband), run online scans at Panda Activescan and Housecall. Housecall has now been upgraded to beta version 6.0 detect which removes both viruses and spyware that it finds. Make sure they both perform a full system scans and please use the “Autoclean” option when running Housecall.

    Please post a fresh HijackThis log, so that we can check if your system is clean, and let us know how your computer is behaving now.

    MM
  • edited June 2005
    Done everything as instructed, but couldn't download the clenaup program, but used CCleaner did the PandaScan (which requires me to use MSN, won't run on Mozilla)
    This first report is the PandaScan (registry issues it seems)
    Sorry for the length of all of this.
    Incident Status Location

    Adware:Adware/SaveNow No disinfected Windows Registry
    Adware:Adware/SAHAgent No disinfected C:\WINDOWS\unstall.exe
    Adware:Adware/WinTools No disinfected Windows Registry
    Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\conscorr.inf
    Adware:Adware/SideFind No disinfected Windows Registry
    Spyware:Spyware/LocalNRD No disinfected C:\WINDOWS\inf\localNRD.inf
    Adware:Adware/ExactSearch No disinfected C:\WINDOWS\SYSTEM\exdl?.exe
    Adware:Adware/MyWebSearch No disinfected Windows Registry
    Adware:Adware/Adsmart No disinfected C:\WINDOWS\sys????.exe
    Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM\exdl1.exe
    Adware:Adware/Adsmart No disinfected C:\WINDOWS\SYSMON.EXE
    Adware:Adware/PopCapLoader No disinfected C:\WINDOWS\Downloaded Program Files\popcaploader.inf
    Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\INF\TWAINTEC.INF
    Spyware:Spyware/LocalNRD No disinfected C:\WINDOWS\INF\LOCALNRD.INF
    Adware:Adware/IPInsight No disinfected C:\WINDOWS\INF\CONSCORR.INF
    Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\POLALL1R.INF
    Adware:Adware/MyDailyHoroscopeNo disinfected C:\WINDOWS\setup_silent_26223.exe
    Adware:Adware/Adsmart No disinfected C:\WINDOWS\sysim32.exe
    Adware:Adware/SAHAgent No disinfected C:\WINDOWS\unstall.exe
    Adware:Adware/WinTools No disinfected C:\WINDOWS\Key3.txt
    Spyware:Spyware/BargainBuddy No disinfected C:\Temp\bb_click_wider.swf
    Spyware:Spyware/BargainBuddy No disinfected C:\Temp\bb_auto_wider.swf
    Spyware:Spyware/BargainBuddy No disinfected C:\Temp\logo.gif
    Spyware:Spyware/ISTbar No disinfected C:\NULL

    and now the Hijack log

    Logfile of HijackThis v1.99.1
    Scan saved at 11:18:25 AM, on 6/9/05
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\PROGRAM FILES\COMMON FILES\EPSON\EBAPI\SAGENT2.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\SSDPSRV.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSRTE.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\RPCSS.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHLD.EXE
    C:\PROGRAM FILES\MCAFEE.COM\AGENT\MCAGENT.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSESCN.EXE
    C:\WINDOWS\SYSTEM\MSTASK.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\MSN\MSNCOREFILES\MSN.EXE
    C:\WINDOWS\SYSTEM\PSTORES.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\PROGRAM FILES\MSN\MSNIA\MSNIASVC.EXE
    C:\PROGRAM FILES\MSN MESSENGER\MSNMSGR.EXE
    C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSFTSN.EXE
    C:\HIJACK\HIJACKTHIS.EXE

    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL (file missing)
    O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_12_0.DLL
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - C:\PROGRAM FILES\MCAFEE.COM\VSO\MCVSSHL.DLL
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\MCAFEE.COM\VSO\MCMNHDLR.EXE" /checktask
    O4 - HKLM\..\Run: [VirusScan Online] "C:\PROGRA~1\MCAFEE.COM\VSO\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] C:\PROGRA~1\MCAFEE.COM\AGENT\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\MCAFEE.COM\AGENT\MCUPDATE.EXE
    O4 - HKLM\..\RunServices: [SAgent2ExePath] C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    O4 - HKLM\..\RunServices: [SSDPSRV] C:\WINDOWS\SYSTEM\ssdpsrv.exe
    O4 - HKLM\..\RunServices: [MSNIA] C:\PROGRA~1\MSN\MSNIA\MSNIASVC.EXE
    O4 - HKLM\..\RunServices: [McVsRte] C:\PROGRA~1\MCAFEE.COM\VSO\mcvsrte.exe /embedding
    O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm
    O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm
    O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
    O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C:\PROGRAM FILES\YAHOO!\MESSENGER\YHEXBMES0521.DLL
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM\AIM.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
    O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/suite/yautocomplete.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,90/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://download.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,23/mcgdmgr.cab
    O16 - DPF: {FA3662C3-B8E8-11D6-A667-0010B556D978} (IWinAmpActiveX Class) - http://cdn.digitalcity.com/_media/dalaillama/ampx.cab
    O16 - DPF: Yahoo! Freecell Solitaire - http://yog55.games.scd.yahoo.com/yog/y/fs10_x.cab
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v6.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
  • edited June 2005
    The log looks OK to me but you are right on the other items. Registry items indeed.

    Adware:Adware/SaveNow No disinfected Windows Registry

    Ones like this will not be easy to track down. They are leftover registry keys and not causing any problems. Like looking for a needle in a haystack.

    Am I right when I say I don't think your computer is now giving you any trouble? It shouldn't be given what you say here.

    Please let me know.

    If you want to do something about those odd registry left overs here are some things you can try.

    Suggest you print this out so you can follow the advice easier.


    Download Ad-aware SE and install it if you don't have it already. Make sure it's the newest version and check for any updates before running it.

    Go to this site to get the plug-in for fixing VX2 variants. To run this tool go into Ad-aware->Add-ons and select VX2 Cleaner. Then click Run Tool and OK to start it. If it's clean, it will say Status System Clean. Otherwise, you will have to click on the Clean button to remove the VX2 infection. Also make sure to customize the settings in Ad-aware for better scan results by reading this. Run the scan and fix everything that it finds.


    Download CWSShredder, extract the file, and run the program. Click the Fix button to remove any malicious programs found.


    For these................

    Adware:Adware/SAHAgent No disinfected C:\WINDOWS\unstall.exe
    Adware:Adware/IPInsight No disinfected C:\WINDOWS\inf\conscorr.inf
    Spyware:Spyware/LocalNRD No disinfected C:\WINDOWS\inf\localNRD.inf
    Spyware:Spyware/BargainBuddy No disinfected C:\WINDOWS\SYSTEM\exdl1.exe
    Adware:Adware/Adsmart No disinfected C:\WINDOWS\SYSMON.EXE
    Adware:Adware/PopCapLoader No disinfected C:\WINDOWS\Downloaded Program Files\popcaploader.inf
    Adware:Adware/Twain-Tech No disinfected C:\WINDOWS\INF\TWAINTEC.INF
    Spyware:Spyware/LocalNRD No disinfected C:\WINDOWS\INF\LOCALNRD.INF
    Adware:Adware/IPInsight No disinfected C:\WINDOWS\INF\CONSCORR.INF
    Adware:Adware/Transponder No disinfected C:\WINDOWS\INF\POLALL1R.INF
    Adware:Adware/MyDailyHoroscopeNo disinfected C:\WINDOWS\setup_silent_26223.exe
    Adware:Adware/Adsmart No disinfected C:\WINDOWS\sysim32.exe
    Adware:Adware/SAHAgent No disinfected C:\WINDOWS\unstall.exe
    Adware:Adware/WinTools No disinfected C:\WINDOWS\Key3.txt
    Spyware:Spyware/BargainBuddy No disinfected C:\Temp\bb_click_wider.swf
    Spyware:Spyware/BargainBuddy No disinfected C:\Temp\bb_auto_wider.swf
    Spyware:Spyware/BargainBuddy No disinfected C:\Temp\logo.gif
    Spyware:Spyware/ISTbar No disinfected C:\NULL

    Download PocketKillbox and extract it to its own folder somewhere.

    Run Pocket Killbox. Select the option to Replace on Reboot.

    You will need to work through each of these files one at a time then reboot only AFTER the last one.

    Copy and Paste 1st stubborn file name into the box and check the option to Use Dummy. Now, Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No.

    Copy and Paste 2nd stubborn file name into the box and check the option to Use Dummy. Now, Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click No.

    Repeat for each file.

    After the last entry click Yes to the message asking if you want to reboot.

    Allow your system to reboot but boot into safe mode.


    BE VERY CAREFUL

    Adware:Adware/ExactSearch No disinfected C:\WINDOWS\SYSTEM\exdl?.exe
    Adware:Adware/Adsmart No disinfected C:\WINDOWS\sys????.exe

    You would have to try and find these. The ones with a question mark(s) in the filename. Do NOT rely on killbox. It may delete the wrong file. Don't use it for these.


    This file could be legitimate :- C:\WINDOWS\SYSMON.EXE

    http://www.onecomputerguy.com/app_info/sysmon.htm

    Yes, I see it's tagged as Adware:Adware/Adsmart so it might be a good idea to get some more opinions.

    Go here….

    http://virusscan.jotti.org/

    click the "browse" button, Then browse to :-

    C:\WINDOWS\SYSMON.EXE

    ....then click the "submit" button to upload the file.

    Post back the results to this thread.

    You will see what jotti finds. If it’s infected with anything you can boot to safemode again and fix it/them with HijackThis, as you’ve done before.


    Hope all this helps. As I say I don't think they are causing trouble even if you left them. You chose what you want to do of this, if anything.

    Let me know how it all goes after this.

    Best wishes.

    MM
  • edited June 2005
    MM
    My apologies for not saying earlier, yes things are running much smoother now.
    I don't suppose any of you have come up with a program that will teach my husband and daughter to STAY OFF of IE do you? Doesn't seem to matter how often I tell them the risks of IE, they insist on using it instead of Mozilla.

    I will give your recommendations a shot, however I will admit that if things look like something I could really screw up, I will leave them alone (seeing that it isn't causing any problems) and wait until I can afford to take it into the tech shop and have them clean the registry.

    Thank you again for being here for us Non-computer literates. ;D
    CW
  • edited June 2005
    MM
    My apologies for not saying earlier, yes things are running much smoother now.
    Much as I thought. You did well there to keep it as clean as you did. Well done.
    I don't suppose any of you have come up with a program that will teach my husband and daughter to STAY OFF of IE do you? Doesn't seem to matter how often I tell them the risks of IE, they insist on using it instead of Mozilla.
    My family are good learners. They do what I tell them - use Firefox not IE. I'm the only one here that uses IE and only then for updates and online scans.

    What I did was to kill off all IE shortcuts on the desktop, taskbar etc. and hide the program so they couldn't find out HOW to click on IE. I replaced all IE shortcuts with those to firefox. You might like to try that.
    I will give your recommendations a shot, however I will admit that if things look like something I could really screw up, I will leave them alone (seeing that it isn't causing any problems) and wait until I can afford to take it into the tech shop and have them clean the registry.
    The adaware and shredder links are easy to use and great tools. As is Spybot here......

    http://www.safer-networking.org/en/index.html

    (get that too if you don't have it already and activate the "Tea Timer" tool for realtime protection).

    There are registry cleaners on the web. Maybe you should start a new discussion thread as to which ones people find the best. Do this beofre you pay good money to a tech shop.

    Happy surfing.:thumbsup:

    MM
This discussion has been closed.