Hi, I'm trying to clean a friends computer. I have followed the preliminary removal instructions and here are the logs. He is getting the popups saying his computer is infected directing him to AntiSpyware Gold, WinAnonymous, AntiSpyware Golden etc.
They belong to Regcure (Registry Cleaner) found HERE.
Did you install this?
Regards Jason
This thread is for the use ofvinnie05ONLY. Please do NOT post your own virus/spyware problems into this thread. Instead, open a new thread in our security and the web forum.
No i didn't, but pehaps my friend whos computer it is might have, I will remove anyway as i don't trust it.
I'll wait to see what Evilfantasy says about the combofix log but i think that the preliminary instructions may have worked to remove AntiSpyware Gold, WinAnonymous, AntiSpyware Golden popups.
I do advise you to remove Regcure - as registry cleaners are dangerous if not used properly.
Apart from that I think everything is Ok.
Regards Jason
This thread is for the use ofvinnie05ONLY. Please do NOT post your own virus/spyware problems into this thread. Instead, open a new thread in our security and the web forum.
Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!
ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.
Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang
Thereafter, please post freshHJT and ComboFix logs from normal mode as attachments into this thread.
Regards,
momok =)
This thread is for the use of vinnie05 only. Please don't post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.