G
Guest
How do you TURN ON the Acer Notebook OEM Windows XP SP2 Home Edition FIREWALL
when it has been TURNED OFF by a *digital criminal* who used GROUP POLICY?
What happens is when I try and chance the firewall or Windows Security
settings it says it is being controlled by Group Policy. Windows XP SP2 Home
Edition does not have gpedit.msc. You can try Administrative Tools >>
Computer Management >> Services and I Clicked Startup *Automatic - it was
*Disabled, then Start. That still is ON but no Firewall.
**windows messages***
********************************************
Windows Firewall -General
For your security, some settings are controlled by Group policy
"Windows Firewall"
'Windows Firewall is turned off. Your network administrator is using Group
Policy to control these settings.'
********************************************
Happened as a result of new unknown virus/malware that includes::::
In C:\ these files.. (Delete)
sw.bat
is.bat
tb.exe
xe.exe
low.exe
mmxateam.exe
IELower.exe
In C:\Windows.. (Delete)
lsass.exe
(Real one is in C:\WINDOWS\SYSTEM32\lsass.exe)
Turn off system restore.
Delete all Browser Cache files
Delete all temp files
Use CCleaner if possible
**There may be other unknown files.
It turned off my Auto-updates and Windows Firewall. WinXP SP2 Home
Appears to be Reg Enteries.... (Picked up by Spybot S&D)
Windows Security Center.SP2Update: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0
Windows Security Center.AntiVirusOverride: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusOverride!=dword:0
Windows Security Center.FirewallOverride: Settings (Registry change, nothing
done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallOverride!=dword:0
Windows Security Center.FirewallDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallDisableNotify!=dword:0
Windows Security Center.AntiVirusDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusDisableNotify!=dword:0
Windows Security Center.UpdateDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\UpdatesDisableNotify!=dword:0
IELower.exe is the compressed file silent installer - it appears as a
diferent NAME in each case. sw.bat fires the other files..
What happens is when I try and chance the firewall or Windows Security
settings it says it is being controlled by Group Policy. I go into gpedit.msc
and I found the specific settings but Windows says it is unconfigured.
**WHAT DOES IT APPEAR TO DO?***
SLOWS YOUR INTERNET CONNECTION TO A CRAWL, SAY A FEW BYTES, WHILE UPLOADING
FROM YOUR COMPUTER.
when it has been TURNED OFF by a *digital criminal* who used GROUP POLICY?
What happens is when I try and chance the firewall or Windows Security
settings it says it is being controlled by Group Policy. Windows XP SP2 Home
Edition does not have gpedit.msc. You can try Administrative Tools >>
Computer Management >> Services and I Clicked Startup *Automatic - it was
*Disabled, then Start. That still is ON but no Firewall.
**windows messages***
********************************************
Windows Firewall -General
For your security, some settings are controlled by Group policy
"Windows Firewall"
'Windows Firewall is turned off. Your network administrator is using Group
Policy to control these settings.'
********************************************
Happened as a result of new unknown virus/malware that includes::::
In C:\ these files.. (Delete)
sw.bat
is.bat
tb.exe
xe.exe
low.exe
mmxateam.exe
IELower.exe
In C:\Windows.. (Delete)
lsass.exe
(Real one is in C:\WINDOWS\SYSTEM32\lsass.exe)
Turn off system restore.
Delete all Browser Cache files
Delete all temp files
Use CCleaner if possible
**There may be other unknown files.
It turned off my Auto-updates and Windows Firewall. WinXP SP2 Home
Appears to be Reg Enteries.... (Picked up by Spybot S&D)
Windows Security Center.SP2Update: Settings (Registry change, nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\DoNotAllowXPSP2!=dword:0
Windows Security Center.AntiVirusOverride: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusOverride!=dword:0
Windows Security Center.FirewallOverride: Settings (Registry change, nothing
done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallOverride!=dword:0
Windows Security Center.FirewallDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\FirewallDisableNotify!=dword:0
Windows Security Center.AntiVirusDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\AntiVirusDisableNotify!=dword:0
Windows Security Center.UpdateDisableNotify: Settings (Registry change,
nothing done)
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security
Center\UpdatesDisableNotify!=dword:0
IELower.exe is the compressed file silent installer - it appears as a
diferent NAME in each case. sw.bat fires the other files..
What happens is when I try and chance the firewall or Windows Security
settings it says it is being controlled by Group Policy. I go into gpedit.msc
and I found the specific settings but Windows says it is unconfigured.
**WHAT DOES IT APPEAR TO DO?***
SLOWS YOUR INTERNET CONNECTION TO A CRAWL, SAY A FEW BYTES, WHILE UPLOADING
FROM YOUR COMPUTER.