📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Help got virus etc on laptop and no antivirus in place

Options
245

Comments

  • dogmaryxx
    dogmaryxx Posts: 2,446 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    If the problem is more prominant however, use a tool called Combofix which is also free. It's a utility which will only run in safe mode and cleans all low level spyware on registry level.

    News to me.
  • Browntoa
    Browntoa Posts: 49,605 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    an1179 wrote: »
    I did download programmes to laptop in safe mode then the request for payment came up . I need to transfer the files I have downloaded onto my pc ontio a DVDR to put into laptop but having problems with that at the moment. Not sure where I am going wrong tried highlighting and moving to DVDR - not working tried highlights cut/paste not working.

    download this

    http://www.filehippo.com/download_imgburn/

    install and burn the file to the dvd

    you want "write files/folders to disc"

    screenshot_ezmodepicker.png
    Ex forum ambassador

    Long term forum member
  • dogmaryxx
    dogmaryxx Posts: 2,446 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    edited 21 February 2011 at 2:12PM
    Detailed instructions for removal can be found here.

    Scroll down to
    Automated Removal Instructions for System Tool using Malwarebytes' Anti-Malware:

    Try directly on infected computer before worrying about downloading/burning etc.
  • an1179
    an1179 Posts: 1,847 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    I had downloaded ImgBurn and I lthought I had burned malwarebytes and PC Tools securrity followed by Combo
    I have only got shortcuts on the 1st 2 which I thought I had copied from programmes and the complete Combo which i copied from Applications - My Documents
    OMGoodness I am useless at this
  • spakkker
    spakkker Posts: 1,322 Forumite
    Part of the Furniture 1,000 Posts Combo Breaker
    Can you download combofix to the laptop using safe mode with networking ?

    http://www.bleepingcomputer.com/download/anti-virus/combofix

    Save to desktop if you can.
  • Browntoa
    Browntoa Posts: 49,605 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    and attempt to then run it in safe mode
    Ex forum ambassador

    Long term forum member
  • an1179 wrote: »
    I had downloaded ImgBurn and I lthought I had burned malwarebytes and PC Tools securrity followed by Combo
    I have only got shortcuts on the 1st 2 which I thought I had copied from programmes and the complete Combo which i copied from Applications - My Documents
    OMGoodness I am useless at this


    It sounds like you are downloading and then installing the programs on your PC, then copying the shortcuts to DVD.

    Skip the installing part. When you go to the website to download and click on the download link do not select 'run,' select 'save.' This will put the installer file in your default downloads folder on your PC (Documents or Downloads or Desktop or whatever). You then need to browse to your default download folder and find the installer file(s). That's what you need to ImgBurn to DVD.
    604!
  • an1179
    an1179 Posts: 1,847 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    It sounds like you are downloading and then installing the programs on your PC, then copying the shortcuts to DVD.

    Skip the installing part. When you go to the website to download and click on the download link do not select 'run,' select 'save.' This will put the installer file in your default downloads folder on your PC (Documents or Downloads or Desktop or whatever). You then need to browse to your default download folder and find the installer file(s). That's what you need to ImgBurn to DVD.

    Thank you I think I am getting somewhere now. Have got Malwarebytes running scan and downloading pctools - watch this space

    Separate issue
    I think i have duplicated my programmes file I have got
    programme files properties 655MB / 2515 files /475 folders
    programme files (x86) properties 5.54GB / 17022 files/1820 folder
    sbut I will deal with that later I think
    both modified 22/02/2011

    Thank you every one for helping me so far
  • an1179
    an1179 Posts: 1,847 Forumite
    Part of the Furniture 1,000 Posts Photogenic Name Dropper
    Malwarebytes' Anti-Malware 1.50.1.1100
    www.malwarebytes.org
    Database version: 5838
    Windows 6.1.7600 (Safe Mode)
    Internet Explorer 8.0.7600.16385
    22/02/2011 11:01:22
    mbam-log-2011-02-22 (11-01-13).txt
    Scan type: Full scan (C:\|)
    Objects scanned: 256943
    Time elapsed: 21 minute(s), 30 second(s)
    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 0
    Registry Values Infected: 3
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 7
    Memory Processes Infected:
    (No malicious items detected)
    Memory Modules Infected:
    (No malicious items detected)
    Registry Keys Infected:
    (No malicious items detected)
    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\NVIDIA driver monitor (Worm.Rimecud) -> Value: NVIDIA driver monitor -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\MicrosoftWindows (Trojan.Agent) -> Value: MicrosoftWindows -> No action taken.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce\MicrosoftWindows (Trojan.Agent) -> Value: MicrosoftWindows -> No action taken.
    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.StartPage) -> Bad: (http://redirecturls.info/) Good: (http://www.google.com) -> No action taken.
    Folders Infected:
    (No malicious items detected)
    Files Infected:
    c:\Windows\nvsvc32.exe (Worm.Rimecud) -> No action taken.
    c:\Users\nashlaptop\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\2ZVAG8ED\facebook-pic0009206951100-jpeg[1].exe (Worm.Rimecud) -> No action taken.
    c:\Users\nashlaptop\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\XO721CP2\gus[1].exe (Worm.Rimecud) -> No action taken.
    c:\Users\nashlaptop\AppData\Local\microsoft\Windows\temporary internet files\Content.IE5\XO721CP2\gux[1].exe (Worm.Rimecud) -> No action taken.
    c:\Windows\temp31233724419.exe (Worm.Rimecud) -> No action taken.
    c:\Windows\temp3123376123.exe (Worm.Rimecud) -> No action taken.
    c:\Windows\temp31233764419.exe (Worm.Rimecud) -> No action taken.
  • dogmaryxx
    dogmaryxx Posts: 2,446 Forumite
    Part of the Furniture 1,000 Posts Name Dropper
    You need to select and remove/delete above in Malwarebytes else pointless running it.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 351.1K Banking & Borrowing
  • 253.2K Reduce Debt & Boost Income
  • 453.6K Spending & Discounts
  • 244.1K Work, Benefits & Business
  • 599.1K Mortgages, Homes & Bills
  • 177K Life & Family
  • 257.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.1K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.