also @ TechSpot: Exploit allows command prompt to launch at Windows 7 login screen

TechSpot

C:\WINDOWS\wml.exe

Discussion in 'Virus and Malware Removal' started by Quazze, Apr 8, 2008.

Thread Status:
Not open for further replies.
  1. Blind Dragon Newcomer, in training

    Just knowing that you appreciate the help is good. Also, making sure to follow the advice I have given to keep yourself safe.

    1 anti-virus
    1 firewall
    and multiple anti-spyware programs
    keep everything up to date and scan regularly.

    If you do have any more issues please let me know.

    Regards,

    BD
  2. Quazze Newcomer, in training

    Just a quick note:

    When using Trend Micro Housecall, it keeps collecting a series of particular cookies in my Cache that it considers Spyware. They are as follows:

    Cache\mediaplex.com, cache\atdmt.com, cache\advertising.com, cache\doubleclick.net, cache\revsci.net and cache\zedo.com

    I do not visit any adult sites or any other malicious websites that would produce something like this. Websites I had visited in the past three hours that might have produced these spyware threats are: www.cnn.com, www.ebay.com, www.weather.com, www.yahoo.com, www.google.com, www.techspot.com, www.hsx.com, www.hotmail.com and www.aol.com

    I am sure these quasi threats are not a big deal and pose no true harm. Trend Micro Housecall was able to successfully remove them. But when I remove Housecall from my computer later on today and reinstall my Trend Micro AV 2007, am I going to be vulerable again?

    I do have my Firewall up
    I do have my Trend AV
    And I still have Malwarebuytes Anti-Malware installed.

    What multiple anti-spyware programs do you suggest?
    _________________

    Edit: After having written the post above, I ran another Trend Micro Housecall and it picked up 5 more spyware programs and safely removed them. However, I had not visited any websites with the exception of this one. Actually, I did nothing except write the post above and walked away from the CPU for 5 minutes; ran a scan out of curiousity and found it picked up most of the same spyware listed above. Any thoughts?
  3. Blind Dragon Newcomer, in training

    you will pick up those very popular cookies even by visiting us here at techspot. Usually you will see Tribalfusion ones from here. My suggestion

    First of all only use internet explorer if you absolutely have to: Here are 2 more secure browsers to choose from
    1)Firefox -> http://www.mozilla.com/en-US/firefox/
    2)Opera -> http://www.opera.com/

    Second if you are going to use internet explorer:
    Make your Internet Explorer more secure - This can be done by following these simple instructions:
    1. From within Internet Explorer click on the Tools menu and then click on Options.
    2. Click once on the Security tab
    3. Click once on the Internet icon so it becomes highlighted.
    4. Click once on the Custom Level button.
      • Change the Download signed ActiveX controls to Prompt
      • Change the Download unsigned ActiveX controls to Disable
      • Change the Initialize and script ActiveX controls not marked as safe to Disable
      • Change the Installation of desktop items to Prompt
      • Change the Launching programs and files in an IFRAME to Prompt
      • Change the Navigate sub-frames across different domains to Prompt
      • When all these settings have been made, click on the OK button.
      • If it prompts you as to whether or not you want to save the settings, press the Yes button.
    5. Next press the Apply button and then the OK to exit the Internet Properties page.
Thread Status:
Not open for further replies.