Hi,
Quote:
Thankyou for ALL of your help, it is much appreciated.
System appears to be back to normal -
pinging ip address works, msn signs in, internet working normally, no scvhost.exe running in background.
|
You're welcome.

That's great. You've done a good job.
Quote:
|
also, ewido didnt appear in add/remove progs, so i just deleted the folder and containing files from the hdd.
|
You've done the right thing. You must have already uninstalled it earlier.
Quote:
|
is there anything else on my system that could be causing slow start-up/shut-down, or is it most likely just the limits of my pc/normal (safe) start-up progs? (amd64 3000, 1gb ram, winxp sp2)
|
The following are mostly update entries at the startup which can easily be done manually. You can have them fixed with HijackThis so that they'll not load up at the startup.
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0\bin\jusched.exe"
O14 - IERESET.INF: START_PAGE_URL=http://www.google.com.au
Quote:
|
the version java u spoke of wasnt avail, so i downloaded java (jre) 6 [jre-6-windows-i586.exe]
|
Yes, it just updated again yesterday. Well done.
Quote:
could you please suggest an anti-virus program to use that is free?
also, should i stop using bho demon?
|
Glad you mentioned the antivirus program. I was going to mention that anyway. An up-to-date antivirus and a good firewall other than the windows one, which works against incoming traffic only, are two "must have"s on any system. I'll be giving you some links later in the post. You must make sure though that you install only
one of each as more than one would not give you better protection but, on the contrary, cause more problems.
I have never used bho demon. Here's a quote from BC startup data base:
Quote:
Whether or not you need to run this program on startup must be decided by you. If you feel that you want this program starting automatically so that you have it available as needed, then do not disable it.
BHODemon "protects you from unknown Browser Helper Objects (BHOs), by letting you enable/disable them individually. When running, it also monitors your Registry and alerts you when a BHO is installed. Best of all, BHODemon knows about the most common BHOs - the good ones, and the not-so-good ones!". If you prefer forgoing resident protection, the application can also be run on demand
|
This program also is not required to start automatically as you can run it when you need to.
Detects the "Easy Front-Panel Audio Connectivity Drive Internal Drive Bay" that comes with certain Sound Blaster audio cards.. Can be disabled if you don't use the internal drive bay.
O4 - HKLM\..\Run: [SBDrvDet] C:\Program Files\Creative\SB Drive Det\SBDrvDet.exe /r
You can now delete Hoster from your desktop.
Since AVG Anti Spyware is a trial version, the realtime guard and automatic update will stop functioning after the trial period. That is why we are not installing the guard so it will not interfere with the cleanup or the malware removal process. You can use AVG-AS as an on-demand scanner (recommended) but you will have to manually update the definition file each time you scan.
Ccleaner is also a useful tool to keep. You can use it on a regular basis to clean the cookies and the temp files from your system. I use it almost everyday. Just don't use the "issues" block, unless you know what you're doing. It involves the registry and meant for the professionals.
Remember to hide your system files again.
Start>My Computer>Tools>Folder Options>View
Under the
Hidden files and Folders heading uncheck
Show hidden files and folders.
check the
Hide protected operating system files (recommended) option.
Click
Yes to confirm.
check the
Hide file extensions for known file types.
Click
OK.
Create a new System Restore point to prevent reinfection from old restore points.
Click
Start>Run - type
sysdm.cpl & press Enter
* Select the
System Restore Tab
*
Check "
Turn off System Restore on all drives"
* Click
Apply
* Then
uncheck the same checkbox & click
OK
You can also find instructions on how to disable and re enable system restore here:
Windows XP System Restore Guide
And that's all. But to help protect you against further infections, and also to help prevent criminals using your computer to infect other people's computers on the web, I recommend the following: (You may already have some of the items)
Make your Internet Explorer more secure - This can be done by following these simple instructions:
From within Internet Explorer click on the
Tools menu and then click on
Options.
Click once on the
Security tab
Click once on the
Internet icon so it becomes highlighted.
Click once on the
Custom Level button.
Change the
Download signed ActiveX controls to
Prompt
Change the
Download unsigned ActiveX controls to
Disable
Change the
Initialise and script ActiveX controls not marked as safe to
Disable
Change the
Installation of desktop items to
Prompt
Change the
Launching programs and files in an IFRAME to
Prompt
Change the
Navigate sub-frames across different domains to
Prompt
When all these settings have been made, click on the
OK button.
If it prompts you as to whether or not you want to save the settings, press the
Yes button.
Next press the
Apply button and then the
OK to exit the Internet Properties page.
Avoid illegal sites, because that's where most malware is present.
* Don't click on links inside popups.
* Don't click on links in spam messages claiming to offer anti-spyware software; because most of these so called removers ARE spyware.
* Download free software only from sites you know and trust. Because a lot of free software can bundle other software, including spyware.
Keep your antivirus-program up-to-date and do regular scans with it.
Please make sure that you have only one active antivirus program on your system.
If you haven't got an antivirus, you can download and install one of the following ones wh;ich are free for personal use: Make sure that you have only
ONE antivirus running on your computer as more than one would cause conflict and render the computer vulnerable.
AVG Free
here
AntiVir
here
Avast
here
It is essential to keep the anti-virus program fully updated.
IMPORTANT: You Need to Update Windows and Internet Explorer to protect your computer from the malware that is around on the Internet. Please go to the windows update site <http://windowsupdate.microsoft.com/> to get the critical updates.
If you are running Microsoft Office, or any portion thereof, go to the Microsoft's Office Update site <http://office.microsoft.com/officeupdate/maincatalog.aspx?lc=en-us> and make sure you have at least all the critical updates installed (Free) Microsoft Office Update.
Keep your pestware-scanners up-to-date and do regular scans with them.
To keep your computer free of Spyware, Adware, Hijackers etc., download and install the following free pestware-scanners (if you haven't installed them already):
AdAware here
Spybot here Remember to "immunize" after each update
Windows Defender here
Install realtime pestware-scanners and keep them up-to-date.
The following free realtime pestscanners prevent a number of malware-variants from entering your computer, in the first place:
SpywareBlaster here Remember to "enable all protection" after each update.
SpywareGuard here
If you haven't got one, already, install a firewall and keep it up-to-date.
Please make sure that you have only one active firewall on your system.
A firewall will prevent unauthorized contact between your computer and internet.
If there is no firewall installed on your computer, you can download and install one of the following free firewalls:
ZoneAlarm here
Sygate here
Kerio Personal Firewall here
Outpost here
Important: (Windows XP only) If you install a firewall, be sure to turn off the WinXP-firewall!
Test your firewall
here to make sure that it's working properly
Install these programs, to make surfing with Internet Explorer safer:
A popup-blocker, f.e. Google Toolbar
here: A popup-blocker prevents popup-windows from opening, when you come along a websites that uses them, during internet-surfing.
IE-SPYAD here: This utility adds a long list of known bad sites to Internet Explorer's Restricted Sites zone. This prevents those sites from executing their malicious programs on your computer.
SiteHound by Firetrust
here:
Firetrust introduces the SiteHound Toolbar - the safe way to browse the Internet. With SiteHound, when you browse the Internet, you're shown a warning page every time you go to a site which is a known scam, potentially loads viruses or spyware on to your computer, has questionable content or anything you would not consider reasonable. You are shown a warning page with information about that site. From there you can choose to enter the site or go back. SiteHound is a free add-on to Internet Explorer.
SiteHound will alert you when you enter a site which is known to contain:
· Fraudulent claims or scams
· Offensive material
· Security vulnerabilities
· Spyware or Adware
· Spam related material
· or other content deemed to be unsafe
Specifically, SiteHound blocks these categories:
o Adult o Spyware o Spam Advertising o Phishing o Possible scam or fraud o Misleading or False Advertising
o Pharming o Rogue or Suspect Product o Adware o Malware or Virus
Install and use an alternative browser to surf on the internet.
Because Internet Explorer is the most-used browser on the planet, most of the hijackers, adware and spyware are made to abuse your computer thru Internet Explorer.
Here are some good alternative browsers:
Mozilla Suite
here
Mozilla Firefox
here
Opera
here
Netscape
here
Important: You can not uninstall Internet Explorer.
First of all, it's part of Windows and you'll need it to download and install Windows Updates.
Secondly, There are some sites that are only accessable with Internet Explorer, e.g. most of the Online Malware-scanners.
But above all, keep all your software UP-TO-DATE at all time!!
Also, I would recommend reading the excellent advice by Tony Klein: [url=http://boards.cexx.org/viewtopic.php?t=957]
So how did I get infected in the first place[/u]