Disable Windows DefenderWe need to disable your Windows Defender Real-time Protection as it may interfere with the fixes that we need to make.
- Open Windows Defender
- Click on Tools, General Settings
- Scroll down and uncheck Turn on real-time protection (recommended)
- After you uncheck this, click on the Save button and close Windows Defender.
After all of the fixes are complete it is very important that you enable Real-time Protection again.
----------
Open HijackThis and select
Do a system scan only.
Place a check mark next to the following entries: (if there)
- O2 - BHO: (no name) - {3CBB991F-3696-48D8-AC44-ED511EAEB4BC} - C:\WINDOWS\system32\xxyyaayW.dll
- O2 - BHO: D - {B00E6E6D-C2B1-3A27-BA27-7F01DC55C412} - C:\WINDOWS\kx48657.dll
- O9 - Extra button: (no name) - Cmdmapping - (no file) (HKCU)
- O20 - AppInit_DLLs: uaevax.dll hxnekn.dllImportant: Close all windows except for HijackThis and then click
Fix checked.
Exit HijackThis.
----------
Delete these files/folders, as follows:
1. Go to
Start >
Run > type
Notepad.exe and click
OK to open Notepad.
It
must be Notepad, not Wordpad.
- Click Start , then Run
- Type notepad.exe in the Run Box.
2. Copy the text in the below code box by highlighting all the text and pressing
Ctrl+CKillAll::
File::
C:\WINDOWS\system32\xxyyaayW.dll
C:\WINDOWS\kx48657.dll
Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{3CBB991F-3696-48D8-AC44-ED511EAEB4BC}]
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{B00E6E6D-C2B1-3A27-BA27-7F01DC55C412}]
[-HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
3. Go to the Notepad window and click
Edit >
Paste4. Then click
File >
Save5. Name the file
CFScript.txt - Save the file to your Desktop
6. Then drag the
CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below.
Important: Perform this instruction carefully!
ComboFix will begin to execute, just follow the prompts.
After reboot (in case it asks to reboot), it will produce a log for you.
Post that log (Combofix.txt) in your next reply.
Note:
Do not mouseclick combofix's window while it is running. That may cause your system to freeze