I had trouble getting to the vundofix download but I finally did. click options > cookies > then keep the cookies you want. Any ideas would be very gratefully received. Under What to scan?

Antimalwaremalpedia Known threats:616,756 Last Update:March 15, 09:27 DownloadPurchaseFAQSupportBlogAbout UsScan Your PC!Testimonials Dear Jean, Thank you for your response. just move on to the next one. Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn1\yt.dllO2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {243B17DE-77C7-46BF-B94B-0B5F309A0E64} - C:\Program Files\Microsoft Money\System\mnyside.dllO2 - BHO: CIEPl Object C:\Documents and Settings\gnoon\Cookies\[email protected][2].txt -> TrackingCookie.Itrack : No action taken.

Use SHUQUTY.DLL Manual Removal Guide How to eliminate PDYCNT.DLL virus? Sorry that's all I can remember. Another information window will open. Ta again Rimbaud 07-06-200605:40 AM #10 Clark76 Member Spyware Fighter Join Date Feb 2006 Location Cleveland, Ohio Posts 1,359 Points 239 Hello To get into safe mode in windows 2000 follow

Select: Delete on Reboot then Click on the All Files button.Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after Looks you have some bad infections on your computer. I have followed the nine step procedure you list - below is the first HJT file. Before you close this topic, please can you suggest any additional available software that would be necessary/suitable for removing the infections mentioned?

The source file may be in use." Only one of them was successfully deleted, egidsuyd.dll. Click the Statistics/Logs tab.Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.It will open in your default text editor (such as Notepad/Wordpad).Please highlight everything in the notepad, then right-click and choose copy.Click close Please Uninstall this. ____________________ We need to download some tools to use later. 1) Download About:Buster from here. Remove KZIPSHELL.DLL virus (How to remove KZIPSHELL.DLL from Chrome, Mozilla Firefox, IE) Remove GAMETOPPAGE.ORG virus (How to remove GAMETOPPAGE.ORG from Chrome, Mozilla Firefox, IE) Remove FIRSTHITNEWS.RU virus (How to remove FIRSTHITNEWS.RU

I ran it and it said it didn't find anything. Use WINSNARE PUP Manual Removal Guide How to clean TONGJI.DLL virus? Exit Ewido. When I would try to publish changes to the website, I would get an error message that FrontPage had received a reply from the server that it could not parse, and

Use TONGJI.DLL Manual Removal Guide Categories Adware Backdoor Downloader Fake Antivirus Fake]> good-file How to Manual KeyLogger Malicious Malware Packed Rootkits Spyware Suspicious Trojan Trojan-Dropper]> Trojan-Ransom Uncategorized Unclassified Unknow Virus Win32-PUP-gen Two problems, both of my making I think. under "Advanced" no need to tick any of these (but you can if you want, and realise what they do) Applications tab... Remove "Ads by NEWSFOR24PRO.COM" virus in 5 minutes!

or read our Welcome Guide to learn how to use this site. IMPORTANT: Malware files can be camouflaged with the same file names as legitimate ones. Are you sure you wish to proceed?" click OK. C:\Documents and Settings\gnoon\Cookies\[email protected][1].txt -> TrackingCookie.Euroclick : No action taken.

  1. Make sure that Set all elements to: shows Quarantine (1), if not click on the link and choose Quarantine from the popup menu. (2) At the bottom of the window click
  2. The left pane displays folders that represent the registry keys arranged in hierarchical order.
  3. It should now change to inactive.
  4. I will uninstall later I suppose.

Restart your pc.As well as the above,also post a new Hijackthis log please. Back to top #7 xfofww xfofww Topic Starter Members 4 posts OFFLINE Local time:07:27 AM Posted 10 May 2007 - 08:41 AM My PC is running much better. Important - You need to click "Save report" and Save it to your desktop, or you wont have a log reboot post a new hijackthis log + the ewido log cheers Click OK.Make sure everything in the white box has a check next to it, then click Next.It will quarantine what it found and if it asks if you want to reboot,

Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Clean:- (if you use them) Firefox/Mozilla (optional - leave the cookies - see note) Opera Sun Java ZoneAlarm ... No infected files were found.

Click on Complete System Scan to start the scan process.

Blogs Advanced Search Forums Spyware Help Trojan suspected - HijackThis log posted Page 1 of 2 12 Last Jump to page: Results 1 to 10 of 13 Thread: Trojan suspected - Open HijackThis, scan and when complete, remove the following entries by checking the box to the left and clicking 'fixed checked': R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blankR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Remove "Ads by ONCLKDS.COM" virus in 5 minutes! Back to top Back to Virus, Trojan, Spyware, and Malware Removal Logs 0 user(s) are reading this topic 0 members, 0 guests, 0 anonymous users Reply to quoted postsClear BleepingComputer.com

Using the site is easy and fun. Done! Note: Do not mouseclick combofix's window whilst it's running. However, it has been an interesting learning experience.Here is the jotti report.Service load: 0% 100% File: 7616F2B6AF.sys Status: OK MD5 bfd02bdbee3b8e85320bb375cfee9433 Packers detected: - Scanner results Scan taken on 10 May

Click on Change state next to Resident shield. Save the file to your desktop, with the default name of uninstall_list Copy & Paste the entire contents of that file in your in your next post. I had to unload Norton to install Panda as part of the prep work, and I now have ZoneAlarm as a two-way firewall. Also, about the time that the problems with the malware started, I encountered a problem with FrontPage when maintaining part of the web site for my homeowners association.

Follow Manual Removal Instructions AverScanner AverScaner- EveryDay Malware Scan Popular Posts Solved! C:\Documents and Settings\gnoon\Cookies\[email protected][9].txt -> TrackingCookie.Questionmarket : No action taken. I re-ran HijackThis and here is it's scan log:Logfile of HijackThis v1.99.1Scan saved at 8:05:51 PM, on 11/25/2006Platform: Windows 2000 SP4 (WinNT 5.00.2195)MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:C:\WINNT\System32\smss.exeC:\WINNT\system32\winlogon.exeC:\WINNT\system32\services.exeC:\WINNT\system32\lsass.exeC:\WINNT\system32\svchost.exeC:\WINNT\system32\LEXBCES.EXEC:\WINNT\system32\spoolsv.exeC:\WINNT\system32\LEXPPS.EXEC:\WINNT\system32\netdde.exeC:\Program Files\Authentium\Command AntiVirus\avinitnt.exeC:\Program You can install the RemoveOnReboot utility from here.FilesView all Spy.Goldun filesView mapping details[%SYSTEM%]\IfxWlxEN.dll[%SYSTEM%]\fcagwl.dll[%SYSTEM%]\k86.bin[%SYSTEM%]\jkkjihe.dll[%SYSTEM%]\a9k.bin[%SYSTEM%]\jkkklmk.dll[%SYSTEM%]\CBXYVUS.DLL[%SYSTEM%]\winopn32.dll[%SYSTEM%]\WinCtrl32.dll[%SYSTEM%]\eeekp.sys[%SYSTEM%]\mljifee.dll[%SYSTEM%]\winrnt32.dll[%SYSTEM%]\ddcyw.dll[%SYSTEM%]\dn8o01l3e.dll[%SYSTEM%]\dskquota32.dll[%SYSTEM%]\a99k.bin[%SYSTEM%]\yayxuvv.dll[%SYSTEM%]\mv0ol9d31.dll[%SYSTEM%]\fpls0337e.dll[%SYSTEM%]\pmnnm.dll[%SYSTEM%]\winmmt32.dll[%WINDOWS%]\pxysdb.dat[%SYSTEM%]\winrge32.dll[%SYSTEM%]\mod_st.dat[%SYSTEM%]\sysfldr.dll[%SYSTEM%]\BYXVWXU.DLL[%SYSTEM%]\fccbccc.dll[%SYSTEM%]\msg117.dll[%SYSTEM%]\rqRKCspQ.dll[%SYSTEM%]\youma1.dll[%SYSTEM%]\pmod11.dll[%SYSTEM%]\gport_.dll[%SYSTEM%]\krnlcab.sys[%SYSTEM%]\awtqnkh.dll[%SYSTEM%]\gebyx.dll[%SYSTEM%]\msg118.dll[%SYSTEM%]\ws_3s32.dll[%SYSTEM%]\xxop81.dll[%SYSTEM%]\fccbyaw.dll[%SYSTEM%]\qomnkih.dll[%SYSTEM%]\mljkifg.dll[%SYSTEM%]\sebdpx.sys[%SYSTEM%]\sebdpp.dll[%SYSTEM%]\fslljxt.dll[%SYSTEM%]\rtadta.sys[%SYSTEM%]\rtadtm.dll[%SYSTEM%]\irrql5951.dll[%SYSTEM%]\gutujgl.dll[%SYSTEM%]\winosz32.dll[%SYSTEM%]\Systen.dll[%SYSTEM%]\wvUkLEXo.dll[%SYSTEM%]\winzlo32.dll[%WINDOWS%]\Pcom\atmgrtok.dll[%SYSTEM%]\winjyg32.dll[%SYSTEM%]\rgadta.sys[%SYSTEM%]\rgadtm.dll[%SYSTEM%]\ljjgdcb.dll[%SYSTEM%]\byxvtrp.dll[%SYSTEM%]\ssqpo.dll[%SYSTEM%]\ntpdxt.sys[%SYSTEM%]\ddccy.dll[%SYSTEM%]\ziczubj.dll[%SYSTEM%]\pptpr.dll[%SYSTEM%]\pptpr.sys[%SYSTEM%]\acup.sys[%SYSTEM%]\pmnnnlm.dll[%SYSTEM%]\rqrop.dll[%SYSTEM%]\winjgf32.dll[%SYSTEM%]\eeekp.dll[%SYSTEM%]\dtvgtgn.dll[%SYSTEM%]\awttrsp.dll[%SYSTEM%]\q668lgju16o8.dll[%SYSTEM%]\winuns32.dll[%SYSTEM%]\winemx32.dll[%SYSTEM%]\winjyp32.dll[%SYSTEM%]\winmqx32.dll[%SYSTEM%]\htproc32.dll[%SYSTEM%]\wintfj32.dll[%SYSTEM%]\geBsspnM.dll[%SYSTEM%]\jkkIAQIa.dll[%SYSTEM%]\wineak32.dll[%SYSTEM%]\exodpt.sys[%SYSTEM%]\exodpt.dll[%PROGRAM_FILES%]\IBM\Personal Communications\atmgrtok.dll[%SYSTEM%]\winbue32.dll[%SYSTEM%]\winzwr32.dll[%SYSTEM%]\xatcore.dll[%SYSTEM%]\winpsa32.dll[%SYSTEM%]\wintuh32.dll[%SYSTEM%]\nnnommn.dll[%SYSTEM%]\ntpdxt.dll[%SYSTEM%]\winwea32.dll[%SYSTEM%]\winexz32.dll[%SYSTEM%]\winzdn32.dll[%SYSTEM%]\pmnmklmm.dll[%SYSTEM%]\winubg32.dll[%SYSTEM%]\winwly32.dll[%SYSTEM%]\winetn32.dll[%SYSTEM%]\piofmap.dll[%SYSTEM%]\bltsprx2.dllScan your File System for Spy.GoldunHow to Remove Spy.Goldun from the Windows Registry^The Windows registry stores important system

I tried to manually delete some of the viruses but the computer said they were in use and wouldn't let me delete them. Right-click the AVG Anti-Spyware Tray Icon and select Exit. Popups seem to be gone and I am no longer getting the loading up of the CPU usage which was slowing it down tremendously. Logfile of HijackThis v1.99.1 Scan saved at 20:32:05, on 4.10.2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe

I've never seen a computer that had so much crud on it. If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members. Click on the Scanner button in the left menu, then click on Complete System Scan. To resolve this, restart the computer and try again.

Use WFO.EXE Removal Guide How to TOTALLY delete ONLINE-GUARDIAN-V2.EXE virus? doubleclick the ccsetup.exe file and install the program... For Automatic Spy.Goldun Removal please use Exterminate It! C:\VundoFix Backups\ws_3s32.dll.bad -> Trojan.Virtumod : Cleaned with backup (quarantined). ::Report end Logfile of HijackThis v1.99.1 Scan saved at 14:47:26, on 7.10.2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00

When installing, under "Additional Options" uncheck "Install background guard" and "Install scan via context menu". 2.