S,
Can I plug my laptop directly into my router? Will this be okay? Thanks N
Hi
Yes, the laptop can be plugged in directly.
Now, I believe this an HP pc. Did you create a Recovery CD/DVD when you purchased it?
If not, there should be a Recovery Partition.
Before you do that, you may want to back up your data, such as photographs etc. Do not back up any programs.
I take it Norton came pre-installed?
I don't remember if I did a recovery cd - however I did pull out all the cd and software that came with it. I tried backing up some of my data, but it seems my cd's are not big enough or the virus is preventing me from doing so? Its only publisher files, so I can't understand why it won't copy. Now the infected pc has a blank screen, nothing is showing. I rebooted and it showed me options to start up in safe or normal mode, but when I chose normal nothing came on the screeen. I'm staring at a gray screen.
what's next - i can't wait to get this off my machine. did you say it was malware or virus? thanks n
Try it in Safe Mode. Only essential windows drivers and processes are loaded so malware is dormant. If you can get into Safe Mode with Networking, try this.
Please download
Malwarebytes' Anti-Malware to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program. At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware , then click Finish . If an update is found, it will download and install the latest version. Once the program has loaded, select Perform full scan , then click Scan . When the scan is complete, click OK , then Show Results to view the results. Be sure that everything is checked, and click Remove Selected . When completed, a log will open in Notepad. Please save it to a convenient location. The log can also be found here:
C:\Documents and Settings\Username \Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt Post that log back here.
Here is the maleware log. thanks n
Malwarebytes' Anti-Malware 1.19
Database version: 929
Windows 5.1.2600 Service Pack 2
10:55:35 AM 7/7/2008
mbam-log-7-7-2008 (10-55-34).txt
Scan type: Full Scan (C:\|)
Objects scanned: 169286
Time elapsed: 1 hour(s), 46 minute(s), 3 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 2
Registry Values Infected: 7
Registry Data Items Infected: 7
Folders Infected: 0
Files Infected: 22
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdidrv32.sys (Trojan.Zlob) -> Quarantined and deleted successfully.
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Trojan.Zlob) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Trojan.Zlob) -> Delete on reboot.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Trojan.Zlob) -> Delete on reboot.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://internetsearchservice.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\packet.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\wpcap.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully.
C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\162123\162123.dll.vir (Trojan.BHO) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050690.dll (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050691.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050692.exe (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050693.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050694.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050695.exe (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050696.dll (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050698.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050700.exe (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050701.dll (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050702.exe (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050703.dll (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050704.exe (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050705.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050706.dll (Adware.Zango) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050713.dll (Adware.Seekmo) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP399\A0067062.dll (Trojan.BHO) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP399\A0067063.dll (Spyware.Agent) -> Quarantined and deleted successfully.
C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP399\A0067065.dll (Spyware.Agent) -> Quarantined and deleted successfully.
Can you get into Normal Mode now? Do you still wish to format and re-install?
yes I can get into normal mode. and yes I backed up all my files and if need be I'm ready to wipe everything out?
If you have a Windows or Recovery CD, put it in, then reboot. Go for a destructive format.
Do I need to delete anything from my computer first? ie. programs, files etc.?
No. A format completely wipes the hard drive.
Take a look here to see how to format and reinstall Windows on an HP pc. Print out the instructions if you can.
Remember, you need to select Advanced then Destructive Format
http://h10025.www1.hp.com/ewfrf/wc/documen…ocname=bph07145
okay will do. I'll let you know when its complete. thanks n
my system is a dell, so I'm using the recovery cd, but its asking me if I want to delete the partition or add another one. what should I do?
okay its 60% finished. after this what is the next step? will the infection be gone?