Need help w/ shellexp.exe & comctl_32.exe

Discussion in 'malware problems & news' started by blender, Sep 15, 2003.

Thread Status:
Not open for further replies.
  1. blender

    blender Guest

    Okay, this is my dad's computer, so I don't know what the hell is going on with it. It's Win98, and every time it boots up apparently Explorer gets "hijacked" (I guess that's the term, I'm new to all this) and the only thing that appears on the screen is the wallpaper & cursor. No icons, no taskbar, and when you hit ctrl-alt-del there's _nothing_ running. So you can't do anything except shut down. The same thing happens in safe mode. However, if I choose command prompt only and then run win.com for the C:/windows directory everything loads (I don't know how I figured that out).

    So, I can get into everything now. I've read the two other threads here, and both shellexp.exe & comctl_32.exe are in the /system folder. I've run hijackthis and deleted the references to them, and also deleted the files, and disabled them in msconfig and all that, and got cwshredder too. They keep coming back though (apparently), and it still won't boot normally. I can't get his computer on-line at my house so I'm going back and forth here between his and mine. Anyway, here's the log from hijack this (and yes I am up at 4AM working on this stupid thing), thanks:

    ogfile of HijackThis v1.97.2
    Scan saved at 4:20:37 AM, on 9/15/03
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\NIKON\NKVIEW4\NKVWMON.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearcher.net/
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.catlist.com/
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {00000580-C637-11D5-831C-00105AD6ACF0} - C:\WINDOWS\MSVIEW.DLL
    O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\WINDOWS\TEMP\RESIINH.DLL (file missing)
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKCU\..\Run: [Explorer] C:\WINDOWS\SYSTEM\shellexp.exe en
    O4 - Startup: NkVwMon.exe.lnk = C:\Program Files\Nikon\NkView4\NkVwMon.exe
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {01110A81-3E00-11D2-8470-0060089874ED} (Support.com - Control Command Class) - http://www.comcastsupport.com/sdcCommon/download/tgcmd.cab
    O16 - DPF: {86698251-D2C0-4D0F-A3E4-95CEF12F9F18} - http://64.156.188.99/iwasher/internetwasherpro.cab
    O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.1800thetrop.com/CFIDE/classes/CFJava.cab
     
  2. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    Hi blender,

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.coolsearcher.net/
    O2 - BHO: (no name) - {00000580-C637-11D5-831C-00105AD6ACF0} - C:\WINDOWS\MSVIEW.DLL
    O2 - BHO: (no name) - {1F48AA48-C53A-4E21-85E7-AC7CC6B5FFAF} - C:\WINDOWS\TEMP\RESIINH.DLL (file missing)
    O4 - HKCU\..\Run: [Explorer] C:\WINDOWS\SYSTEM\shellexp.exe en
    O16 - DPF: {86698251-D2C0-4D0F-A3E4-95CEF12F9F18} - http://64.156.188.99/iwasher/internetwasherpro.cab

    Then reboot, recheck everything you disabled in msconfig and make a new HijackThis log. Do NOT reboot in between using msconfig and following any advise given.

    Regards,

    Pieter
     
  3. blender

    blender Guest

    Thanks. Here's the new log:

    Logfile of HijackThis v1.97.2
    Scan saved at 5:02:49 AM, on 9/15/03
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\NIKON\NKVIEW4\NKVWMON.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.catlist.com/
    F1 - win.ini: run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSINFO\msinfo.exe C:\WINDOWS\SYSTEM\cmmpu.exe
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
    O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
    O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\Run: [infwin] c:\windows\system\infwin.exe /noconnect
    O4 - HKLM\..\Run: [OD] C:\WINDOWS\SYSTEM\ShellExt\SYSCNTR.EXE -n
    O4 - HKLM\..\Run: [SysPnP] rundll32 setupapi,InstallHinfSection DefaultInstall 128 oemsyspnp.inf
    O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\WINUPDATE.EXE
    O4 - HKLM\..\Run: [VB_run] C:\WINDOWS\comctl_32.exe
    O4 - HKLM\..\Run: [keymgrldr] rundll32 setupapi,InstallHinfSection Oemkeymgr9x 128 keymgr3.inf
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
    O4 - HKCU\..\Run: [ATI Launchpad] "C:\PROGRAM FILES\ATI MULTIMEDIA\MAIN\LAUNCHPD.EXE"
    O4 - HKCU\..\Run: [Windows Update] C:\WINDOWS\WINUPDATE.EXE
    O4 - HKCU\..\Run: [Explorer] C:\WINDOWS\SYSTEM\shellexp.exe en
    O4 - Startup: NkVwMon.exe.lnk = C:\Program Files\Nikon\NkView4\NkVwMon.exe
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {01110A81-3E00-11D2-8470-0060089874ED} (Support.com - Control Command Class) - http://www.comcastsupport.com/sdcCommon/download/tgcmd.cab
    O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.1800thetrop.com/CFIDE/classes/CFJava.cab
     
  4. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    Hi blender,

    Check the items listed below in HijackThis, close all windows except HijackThis and click Fix checked:

    O4 - HKLM\..\Run: [ComcastSUPPORT] C:\Program Files\Support.com\bin\tgkill.exe /cleaneahtioga /start
    O4 - HKLM\..\Run: [infwin] c:\windows\system\infwin.exe /noconnect
    O4 - HKLM\..\Run: [OD] C:\WINDOWS\SYSTEM\ShellExt\SYSCNTR.EXE -n
    O4 - HKLM\..\Run: [SysPnP] rundll32 setupapi,InstallHinfSection DefaultInstall 128 oemsyspnp.inf
    O4 - HKLM\..\Run: [Windows Update] C:\WINDOWS\WINUPDATE.EXE
    O4 - HKLM\..\Run: [VB_run] C:\WINDOWS\comctl_32.exe
    O4 - HKLM\..\Run: [keymgrldr] rundll32 setupapi,InstallHinfSection Oemkeymgr9x 128 keymgr3.inf
    O4 - HKCU\..\Run: [Windows Update] C:\WINDOWS\WINUPDATE.EXE
    O4 - HKCU\..\Run: [Explorer] C:\WINDOWS\SYSTEM\shellexp.exe en

    Then reboot and let us know if everything is back as it is supposed to be.

    Regards,

    Pieter
     
  5. blender

    blender Guest

    Thanks. But no, same problem. Nothing will load on startup, have to go through safe mode>command prompt. And shellexp.exe is still there, (comctl_43 is gone I think). Here's what the log looks like now, thanks for your help.



    Logfile of HijackThis v1.97.2
    Scan saved at 5:20:20 AM, on 9/15/03
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\DIGSTREAM\DIGSTREAM.EXE
    C:\WINDOWS\SYSTEM\SHELLEXP.EXE
    C:\PROGRAM FILES\NIKON\NKVIEW4\NKVWMON.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.catlist.com/
    F1 - win.ini: run=C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSINFO\msinfo.exe C:\WINDOWS\SYSTEM\cmmpu.exe
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
    O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
    O4 - HKCU\..\Run: [ATI Launchpad] "C:\PROGRAM FILES\ATI MULTIMEDIA\MAIN\LAUNCHPD.EXE"
    O4 - HKCU\..\Run: [Explorer] C:\WINDOWS\SYSTEM\shellexp.exe en
    O4 - Startup: NkVwMon.exe.lnk = C:\Program Files\Nikon\NkView4\NkVwMon.exe
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {01110A81-3E00-11D2-8470-0060089874ED} (Support.com - Control Command Class) - http://www.comcastsupport.com/sdcCommon/download/tgcmd.cab
    O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.1800thetrop.com/CFIDE/classes/CFJava.cab
     
  6. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    OK. Two more things to do.
    Hit Ctr-Alt-Del and stop shellexp.exe then delete the file and have hijackThis fix:
    O4 - HKCU\..\Run: [Explorer] C:\WINDOWS\SYSTEM\shellexp.exe en

    Then click Start > Run > type or cop&paste win.ini > ok

    Your win.ini will appear.
    Remove the line pointing to C:\WINDOWS\..\PROGRA~1\COMMON~1\MICROS~1\MSINFO\msinfo.exe in run=
    The rest has to stay, then save that file.

    Then reboot again. Keep us posted.

    Regards,

    Pieter
     
  7. blender

    blender Guest

    Nope, exact same thing. :(

    I'm going to bed now but I'll check back tomorrow. Thanks again. :)
     
  8. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    That may be best.I know how frustrating it can be.

    When you return all fresh and rested, let us know what else you have disabled and how. I'm afraid you threw something out that was needed.

    And post a new HijackThis log so we have the latest standings.

    Regards,

    Pieter
     
  9. blender

    blender Guest

    The only thing I disabled were the startup programs in msconfig, the two lines in hijackthis that had the filenames shellexp & comctl in them, and then I deleted the files.

    ogfile of HijackThis v1.97.2
    Scan saved at 12:03:39 PM, on 9/15/03
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v5.51 SP2 (5.51.4807.2300)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\WINDOWS\TASKMON.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\DIGSTREAM\DIGSTREAM.EXE
    C:\WINDOWS\SYSTEM\SHELLEXP.EXE
    C:\PROGRAM FILES\NIKON\NKVIEW4\NKVWMON.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\WINDOWS\DESKTOP\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = http://www.catlist.com/
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
    O4 - HKLM\..\Run: [AtiCwd32] Aticwd32.exe
    O4 - HKLM\..\Run: [AtiQiPcl] AtiQiPcl.exe
    O4 - HKLM\..\Run: [C-Media Mixer] C:\Program Files\PCI Audio Applications\Bin\AudioRack.exe /MixerStartup
    O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE
    O4 - HKLM\..\Run: [DIGStream] C:\Program Files\DIGStream\digstream.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [ATIPOLAB] ati2evxx.exe
    O4 - HKCU\..\Run: [ATI Launchpad] "C:\PROGRAM FILES\ATI MULTIMEDIA\MAIN\LAUNCHPD.EXE"
    O4 - HKCU\..\Run: [Explorer] C:\WINDOWS\SYSTEM\shellexp.exe en
    O4 - Startup: NkVwMon.exe.lnk = C:\Program Files\Nikon\NkView4\NkVwMon.exe
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {01110A81-3E00-11D2-8470-0060089874ED} (Support.com - Control Command Class) - http://www.comcastsupport.com/sdcCommon/download/tgcmd.cab
    O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://www.1800thetrop.com/CFIDE/classes/CFJava.cab
     
  10. blender

    blender Guest

    This is really odd. If I start windows using the win.com command it works fine every time and shellexp is nowhere to be found. But as soon as I let it load normally shellexp is back and nothing works. What's the difference between running win.com from a C: prompt and just letting the computer load on its own? Everything is 100% operational under win.com
     
  11. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    Hi blender,

    I think we need to see some more startuplocations.
    Could you please download and run asviewer from: http://www.diamondcs.com.au/index.php?page=asviewer

    After running it click Main > Save and post the content of that log.

    Regards,

    Pieter
     
  12. marcus

    marcus Registered Member

    Joined:
    Sep 15, 2003
    Posts:
    1
    I had the same problem as Blender and I wasn't able to fix the problem until I did a search for explorer.exe which found a version on C:\ that was not the same as the explorer.exe on C:\windows. I deleted the file and the PC was able to boot normally.
     
  13. blender

    blender Guest

    I got it! :D I think so anyway. There was a "fake" explorer file in the C:\ directory. It was dated a couple days ago and had no icon. I tried to delete it but it said it was being used. So I deleted it in DOS, and then I replaced the one in /windows with a working explorer.exe from another computer.

    Everything appears to be perfect now. It stars normally, everything works, and when I press ctrl-alt-del the only things running are systray and explorer. Is there anyway to make 100% sure that it's gone?

    Also, what can I do to prevent this in the future? Like I said this is my dad's computer so I don't know what he's doing with it. He's got cable though and no firewall, is that the problem? Or was it just a worm through e-mail or something? Thanks for your help.
     
  14. blender

    blender Guest

    lol, I just read Marcus' post. I could've used that info 10 hours ago. ;) Thanks though!
     
  15. Pieter_Arntz

    Pieter_Arntz Spyware Veteran

    Joined:
    Apr 27, 2002
    Posts:
    13,331
    Location:
    Netherlands
    That is good to hear.

    To prevent infection:
    For starters read: http://boards.cexx.org/viewtopic.php?t=957

    Then advance to www.wilders.org
    and read around on this forum. ;)

    Regards,

    Pieter
     
Loading...
Thread Status:
Not open for further replies.