Home > Hijackthis Log > Hijackthis Log (need To Remove Ad.yieldmanager And Atmdt Trojans)

Hijackthis Log (need To Remove Ad.yieldmanager And Atmdt Trojans)

This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread. Messenger (HKLM)O9 - Extra 'Tools' menuitem: Yahoo! Dropper Posted: 01-Dec-2008 | 4:23PM • Permalink It's nice of you to help him out, Quads.  Another guy, also disappeared the other day, without coming back, after you helped him... O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe

Run HijackThis and post a fresh log and the vundofix.txt file from the vundofix folder into as well. We keep you safe and we keep it simple. Well done Quads. Please help!

Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O9 - Extra button: (no Messenger (HKLM)O9 - Extra button: Messenger (HKLM)O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)O10 - Unknown file in Winsock LSP: c:\program files\common files\pc tools\lsp\pctlsp.dllO10 - Unknown file in Winsock LSP: c:\program The selected area was scanned. thank you for your help.

However, this method will restore Internet Explorer to the state it was in when it was first installedRegards,RoJaGo Back to top Back to Resolved/Inactive HijackThis Logs 1 user(s) are reading this Also, when I go to my IE browser and click on Tools-->Internet Options and try to change the homepage (to anysite) it always comes back to http://go.microsoft.com/fwlink/?linkid=677 all the time. Dropper Posted: 01-Dec-2008 | 4:52PM • Permalink TrDo wrote:It's nice of you to help him out, Quads.  Another guy, also disappeared the other day, without coming back, after you helped him... There are currently no users on-line.

Quads Norton Fighter25 Reg: 21-Jul-2008 Posts: 16,481 Solutions: 182 Kudos: 3,388 Kudos1 Stats Re: Downloader, Spyshredder, Trojan. Dropper Posted: 02-Dec-2008 | 7:53AM • Permalink Quads, here are the results of the scan I did last night with Malawarebites: Malwarebytes' Anti-Malware 1.30Database version: 1441Windows 5.1.2600 Service Pack 3 12/2/2008 The forum is run by volunteers who donate their time and expertise. Me Too0 Last Comment Replies Quads Norton Fighter25 Reg: 21-Jul-2008 Posts: 16,481 Solutions: 182 Kudos: 3,388 Kudos0 Re: Downloader, Spyshredder, Trojan.

In the last 3 days there were 1 new threads and 7 reply posts. Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\COMPAN~1\Installs\cpn\ycomp5_3_12_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file) O2 - BHO: Norton Please do restart now.After Windows restarts open the file C:\Windows\ntbtlog.txt with NotepadFrom the Edit menu choose Select All then Edit, COPY and post that back on your next reply.Note: Vista users Did Norton not remove these for you after detection?? 2.

Locations: C:\Documents and Settings\Stephen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-120354e8-22b19301.zip C:\Documents and Settings\Stephen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-15638f2b-6841df29.zip C:\Documents and Settings\Stephen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-2697d909-204a0413.zip C:\Documents and Settings\Stephen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-3493963f-6a652234.zip C:\Documents and Settings\Stephen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-3daa24a3-5139929e.zip] C:\Documents and Settings\Stephen\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\archive.jar-5d530a84-2b58449a.zip Restart the computer. navigate here Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn1\yt.dllO2 - BHO: &Yahoo! HijackThis log included. Because it could be possible that files in use will be moved/deleted during reboot.[*]After reboot, post the contents of the log from Dr.Web you saved previously to your Desktop in your

How old is your AV Program?? Dropper Posted: 04-Dec-2008 | 8:51AM • Permalink Hey Quads, it appears that my computer is all normal again, thanks to you.  I'm deeply grateful for your help.  Can I offer you You enjoy a clean, safe computer. Error Type: MyBB Error (40) Error Message: Your board has not yet been installed and configured.

During the scan it will prompt you to clean files, click OK. Paste the following locations into KILL BOX one at a time. Here is the malawarebites log: Malwarebytes' Anti-Malware 1.30Database version: 1441Windows 5.1.2600 Service Pack 3 12/1/2008 10:30:34 AMmbam-log-2008-12-01 (10-30-34).txt Scan type: Full Scan (C:\|)Objects scanned: 170308Time elapsed: 1 hour(s), 12 minute(s), 32 Next you will see: Please type in the second filepath as instructed by the forum staff then press enter: At this point please type the following file path (make sure to

Besides being fast, there is also a good chance that this method will be the one to resolve the problem. Show Ignored Content As Seen On Welcome to Tech Support Guy! Post a new HijackThis log and the results of the Ewido ad ActiveScan reports.

The memory could not be read".

When the scan is finished, look at the bottom of the screen and click the Save report button. Dropper Posted: 30-Nov-2008 | 10:05PM • Permalink Hi 1. Dropper Posted: 01-Dec-2008 | 3:27PM • Permalink I suggest running a Panda ActiveScan. I have to tell you, the little bit that you had me do, has increased performance on my PC.  Thanks!

Over the Net I am a little bit more conservative as well as I'm not there to check signatures of files.   RickRojas Contributor4 Reg: 30-Nov-2008 Posts: 13 Solutions: 0 Kudos: Quote Report Back to top Posted 12/2/2005 12:53 AM #24242 kingspade96 Valued member Date Joined Nov 2016 Total Posts: 12 hijackthis Logfile of HijackThis v1.99.1 Scan saved at 4:53:06 Jump to content Sign In Create Account Search Advanced Search section: This topic Forums Members Help Files Calendar View New Content Forum Rules BleepingComputer.com Forums Members Tutorials Startup List http://magicnewspaper.com/hijackthis-log/hijackthis-log-trojans-viruses-bump.html Sign Up This Topic All Content This Topic This Forum Advanced Search Browse Forums Guidelines Staff Online Users Members More Activity All Activity My Activity Streams Unread Content Content I Started

But do not get demotivated, Quads, please....Beacause, your help is really invaluable.... Fixing Registry -------------------------------------------------------------------------------------- Quote Report Back to top Posted 12/1/2005 11:12 PM #24235 JSntgvr Advanced member Date Joined Nov 2016 Total Posts: 526 Download the trial version of Ewido Wait about 15 seconds and then restart the computer into regular windows. If you need this topic reopened, please send a Private Message to any one of the moderating team members.

Will try and spot the startup entries to fix to give the PC more resouces.  3. But do not get demotivated, Quads, please....Beacause, your help is really invaluable.... Quads  RickRojas Contributor4 Reg: 30-Nov-2008 Posts: 13 Solutions: 0 Kudos: 0 Kudos0 Re: Downloader, Spyshredder, Trojan. thanks Quote Report Back to top Post a reply Unread posts or replies No unread posts or replies Unread Posts (Read Only Forum) No Unread Posts (Read Only Forum)

Please welcome our newest member, Eddieb. Dropper Posted: 01-Dec-2008 | 4:00PM • Permalink Hi The poster starter already has Panda Active scan in the Hijackthis.log.   The person has just disappeared after my last set of major Lionlady23 replied Feb 10, 2017 at 5:32 PM Email list TonyB25 replied Feb 10, 2017 at 5:30 PM Windows 10 update damaged my... Similar Threads - Hijackthis (need remove Solved HELP! 11b1 and bafa issues.

Please start a New Thread if you're having a similar issue.View our Welcome Guide to learn how to use this site. Sign In Sign Up Browse Back Browse Forums Guidelines Staff Online Users Members Activity Back Activity All Activity My Activity Streams Unread Content Content I Started Search Malwarebytes.com Back Malwarebytes.com Malwarebytes Your cache administrator is webmaster. Use your up arrow key to highlight Safe Mode then hit enter.

Did SuperAntiSpyware remove them all??    Quads  Stu Guru Norton Fighter25 Reg: 08-Apr-2008 Posts: 4,672 Solutions: 18 Kudos: 297 Kudos0 Re: Downloader, Spyshredder, Trojan. Thread Status: Not open for further replies. Please include a link to this thread with your request. I am so afraid of loosing all of my Quickbooks accounts or running the risk of them being corrupted.Do I go onto Step 03?