This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Spyware and possible virus on my pc

21 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hi Yes, the laptop can be plugged in directly. Now, I believe this an HP pc. Did you create a Recovery CD/DVD when you purchased it? If not, there should be a Recovery Partition. Before you do that, you may want to back up your data, such as photographs etc. Do not back up any programs. I take it Norton came pre-installed?
I don't remember if I did a recovery cd - however I did pull out all the cd and software that came with it. I tried backing up some of my data, but it seems my cd's are not big enough or the virus is preventing me from doing so? Its only publisher files, so I can't understand why it won't copy. Now the infected pc has a blank screen, nothing is showing. I rebooted and it showed me options to start up in safe or normal mode, but when I chose normal nothing came on the screeen. I'm staring at a gray screen. what's next - i can't wait to get this off my machine. did you say it was malware or virus? thanks n
Try it in Safe Mode. Only essential windows drivers and processes are loaded so malware is dormant. If you can get into Safe Mode with Networking, try this.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location.
  • The log can also be found here:
    C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\mbam-log-date (time).txt
  • Post that log back here.
Here is the maleware log. thanks n Malwarebytes' Anti-Malware 1.19 Database version: 929 Windows 5.1.2600 Service Pack 2 10:55:35 AM 7/7/2008 mbam-log-7-7-2008 (10-55-34).txt Scan type: Full Scan (C:\|) Objects scanned: 169286 Time elapsed: 1 hour(s), 46 minute(s), 3 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 2 Registry Values Infected: 7 Registry Data Items Infected: 7 Folders Infected: 0 Files Infected: 22 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CLASSES_ROOT\CLSID\e405.e405mgr (Trojan.Zlob) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\tdidrv32.sys (Trojan.Zlob) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Trojan.Zlob) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL (Trojan.Zlob) -> Delete on reboot. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Trojan.Zlob) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchURL (Trojan.Zlob) -> Delete on reboot. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchUrl\w\ (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q=%s) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchURL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Default_Search_URL (Hijack.Search) -> Bad: (http://internetsearchservice.com) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Bar (Hijack.Search) -> Bad: (http://internetsearchservice.com/ie6.html) Good: (http://www.google.com/) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\SearchMigratedDefaultURL (Hijack.Search) -> Bad: (http://internetsearchservice.com/search?q={searchTerms}) Good: (http://www.google.com/) -> Quarantined and deleted successfully. Folders Infected: (No malicious items detected) Files Infected: C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\packet.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\wpcap.dll.vir (Spyware.Agent) -> Quarantined and deleted successfully. C:\QooBox\Quarantine\C\WINDOWS\SYSTEM32\162123\162123.dll.vir (Trojan.BHO) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050690.dll (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050691.dll (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050692.exe (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050693.dll (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050694.dll (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050695.exe (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050696.dll (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050698.dll (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050700.exe (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050701.dll (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050702.exe (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050703.dll (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050704.exe (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050705.dll (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050706.dll (Adware.Zango) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP336\A0050713.dll (Adware.Seekmo) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP399\A0067062.dll (Trojan.BHO) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP399\A0067063.dll (Spyware.Agent) -> Quarantined and deleted successfully. C:\System Volume Information\_restore{8513C62E-889D-4878-A5C3-816F635D0F0E}\RP399\A0067065.dll (Spyware.Agent) -> Quarantined and deleted successfully.
my system is a dell, so I'm using the recovery cd, but its asking me if I want to delete the partition or add another one. what should I do?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI