Pentium with Windows Xp SP2
Hi
Recently, everytime I opened an Explorer window I would get an alert box saying that a program called Netupdate.exe was trying to do something. When this occured any Explorer window I had open at the time would close with a box saying "Windows has encountered an error and had to close the process down". This situation got to the point where I could open nothing and so not really knowing what to do I did a System Restore.
Well that's when the pain started...
Windows seemed to have only half returned to its previous state. My Startup programs hadn't loaded. I couldn't and still can't see hidden files or change folder options an there are lots of other strange behaviours.
I downloaded Malwarebytes on a friends recommendation and tried to run it but it kept on trying to load Microsoft SQL Desktop Engine. And then when MBAM did load it wouldn't scan, saying "Error No Items Selected". Even though they were. So I ran the program in Safe Mode. It discovered something called "Hijack.Shell" which sounded about right. I tried to remove the file but on reboot it still remained active. I tried it again this time it didn't find Hijack.shell so when it finished I ran Combofix (Again on a recommendation) to I believe replace any dodgy or missing files.
Im back in regular Windows XP SP2 and really nothing's changed. Apparently the malware is gone but my program startup's and associations are all gone I have a full .reg file backup of my registry but Windows says "Cannot import regfile backup. Not all Data succesfully written to the registry. Some keys are open by the system or other processes".
Can anyone please help me fix my system?
Have I gone about this the right way?
None of my programs have moved so i'm pretty confident a registry replace would cure it.
Or do you think I might still be infected.
I can upload more info if it's required.
franck