Zlob broke me, need help getting started

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by handygal, Jun 22, 2011.

  1. handygal

    handygal First Sergeant

    I had a user pick up the fake XPAntiVirus. I've had a few users pick it up lately and I got rid of fairly easily and quickly.

    This user was ok for 2 days but now the computer hangs just before the login screen in Safe Mode and standard mode in XP. It did get to the login screen once today after it sat for about 2 hours but after the password it was properly stuck. I can boot from the XP cd to the windows install and view all of the files.

    I don't know where to start. I do have access to other computers and can burn CD's.
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If you cannot boot in any mode ( safe or normal mode ) and you cannot run any of the READ & RUN ME there is not much we can do for you except suggest what is in the below quote box
     
  3. handygal

    handygal First Sergeant

    Ahhh, TimW, my hero.

    I made an image CD of Kaspersky Rescue Disk and I'm on the infected system right now. It has a browser. This is exactly the kind of tool i was looking for. It's amazing! I have some old, dead systems that I'm going to use it on to copy out the files.

    So far it the rescue disk has quarantined a boot file and has identified an infection in Java.

    I'll be back in business in 42% more of this scan
    :)
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds