|
Answer» Windows XP home SP2 (had SP3 but installed because of problems) on a home wireless network
Well, Its infected with spyware etc, spybot S&D and adaware couldnt remove it, I tried restarting in safe mode and manually deleting some of the files to no avail. Only get popups when I am surfing the web. The thing that got me is that I think it is preventing me from PERFORMING windows update, updating windows defender, and preventing me from TURNING the windows firewall on. It says its controlled by group policy and I havent set up a group policy. Tried to find solutions and went run/services.msc and there wasnt anything there about the group policy. Tried turning updates, firewall and security center on from services and WOULD automatically stop them after I started them.
After running the steps, I havent had a pop up.... yet, but am still not able to run windowns firewall
[attachment deleted by admin]Download ComboFix by sUBs from one of the below links. Be sure to save it to the Desktop.
http://download.bleepingcomputer.com/sUBs/ComboFix.exe http://subs.geekstogo.com/ComboFix.exe
Close any open web browsers (Firefox, Internet Explorer, etc) before starting ComboFix.
Temporarily disable your anti-virus, and any anti-spyware real-time protection before performing a scan. Click this LINK to see a list of security programs that should be disabled and how to disable them.
Double-click combofix.exe and follow the prompts. When finished, ComboFix will produce a log for you. Post the ComboFix log and a new HijackThis log in your next reply.
NOTE: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.
Remember to re-enable your anti-virus and anti-spyware protection when ComboFix is complete.here are the new logs, btw thanks for ur help!
[attachment deleted by admin]Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system
Delete these files/folders, as follows:
1. Go to Start > Run > type Notepad.exe and click OK to open Notepad. It must be Notepad, not Wordpad. 2. Copy the text in the below code box by highlighting all the text and pressing Ctrl+C
Code: [Select]KillAll::
File:: c:\windows\system32\g35.exe c:\windows\system32\nigoyeje.exe c:\windows\system32\kxrpviwu.ini c:\windows\system32\sfhayogk.ini
3. Go to the Notepad window and click Edit > Paste 4. Then click File > Save 5. NAME the file CFScript.txt - Save the file to your Desktop 6. Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!
ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it will produce a log for you. Post that log (Combofix.txt) in your next reply.
Note: Do not click ComboFix's window while it is running. That may cause your system to freezethe newest logs
[attachment deleted by admin]Well, I don't see a firewall, which needs to be corrected. Unless you have a suite package of Avast (not just anti-virus), then you need to get a good firewall on your computer. I suggest Comodo, ZoneAlarm, or Kerio Sunbelt. Download one, disconnect from the internet, disable Windows Firewall, install your new one, and restart.
Other than that, things appear to be okay. How is everything running now? Are you still experiencing problems?Things are running much much smoother now.... thanks for you help man, and Ill get that firewall downloadedGreat, and while you're at it, go ahead and uninstall ComboFix. To this, simply go to Start > Run and type in combofix /u (note the space) and click OK.
You should also clear out your System Restore points by turning it off and then turning it back on... http://support.microsoft.com/kb/310405
|