Home > Hijack Log > Hijack Log: Help Zedo

Hijack Log: Help Zedo

Copy everything in the Quote box below, and paste it in the box that opens: Files to delete: C:\WINDOWS\system32\rlkakhm.dll C:\WINDOWS\system32\actskn45.ocx C:\WINDOWS\system32\pmkhh.dll C:\WINDOWS\system32\wvusqqo.dll C:\WINDOWS\system32\opqss.ini C:\WINDOWS\system32\opqss.bak1 C:\WINDOWS\system32\rnoojdsi.dll C:\WINDOWS\system32\bbeeg.bak1 C:\WINDOWS\system32\bccdd.bak1 C:\WINDOWS\system32\bccdd.bak2 C:\WINDOWS\system32\cfhkj.bak1 C:\WINDOWS\system32\dccdd.bak1 C:\WINDOWS\system32\egjlm.bak1 Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? I'm not quite certain how to use this website in it's entirety... Register a free account to unlock additional features at BleepingComputer.com Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Source

So when you see that Panda has found only cookies, that is not really a threat.THANK YOU SO MUCH!!!! http://www.lavasofts...p?showtopic=357 Back to top #5 msmith808 msmith808 Newbie Members 5 posts Posted 21 May 2006 - 05:59 PM Thanks Ad Astra - can someone with experience in reading HIJACK Logs please Get the download here: http://noahdfear.geekstogo.com Doubleclick it and choose install. After doing the above, you should work thru the below link: How to Protect yourself from malware!

http://www.javacools...areblaster.html Back to top #3 msmith808 msmith808 Newbie Members 5 posts Posted 21 May 2006 - 04:22 PM alright!! There isn't anything harmful about them. No-one ever admitted that they purposely installed software to download "free"porn...yet their modem keeps dialing numbers that charge back to their phone bill.

Message was edited by: CSquare CSquare 0 Kudos Posted by CajunTek ‎01-07-2006 07:40 AM Security Expert View All Member Since: ‎10-07-2003 Posts: 20,976 Message 5 of 7 (148 Views) Re: Hijack They just keep clicking buttons, giving permission to install all sorts of wonderful software. I used all the basic tools at first to try to remove them including SmitRem, CWShredder, SmitFraudFix, Lop Uninstaller, Look2Me Uninstallers, VundoFix, etc. The darn Zedo window keeps poppin up though.

Hijack Log: Help! I unfortunately haven't been keeping up on the latest antivirus/antispyware news. Mark it as an accepted solution!I am not a Comcast employee.Was your question answered?Mark it as a solution! 0 Kudos Posted by csquare ‎01-07-2006 02:37 AM Regular Contributor View All Member thanks for any additional assistance you can give 04-26-200611:13 PM #4 1972vet Member Join Date Mar 2006 Posts 275 Points 35 Sure, I'm aware of that, just wasn't aware of how

Choose clean, then put a check next to Perform action on all infections in the left corner of the box so you don't have to sit and watch Ewido the whole Close HiJackThis. Yep.. But the last I checked, antivirus programs such as Avast and Kapersky didn't necessarily protect you from spyware and adware such as this.

When the scan finishes, click on "Save Report". I am an XFINITY Forum Expert and I am here to help.We ask that you post publicly so people with similar questions may benefit.Was your question answered? Say hello! Alternate download for Smitrem is here: http://www.downloads.subratam.org/smitRem.exe 3a.

You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created If you are running Windows XP or Windows ME, do the below: go back to step 8 of the this contact form Get 1:1 Help Now Advertise Here Enjoyed your answer? TANSTAAFL!!I am not a Comcast employee, I am a paying customer just like you!I am an XFINITY Forum Expert and I am here to help. If it is then click on it to uncheck it.Use the Add Reply button and Copy/Paste the information back here.

O4 - Startup: spamsubtract.lnk = C:\Program Files\interMute\SpamSubtract\SpamSubtract.exe O4 - Global Startup: America Online 8.0 Tray Icon.lnk = C:\Program Files\America Online 8.0\aoltray.exe O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Program We will also need the log from Smitrem: The tool will create a log named smitfiles.txt in the root of your drive, eg; Local Disk C: or partition where your operating Get a free online AV scan at Panda's ActiveScan and when it finishes save the log at the end to post back here. http://softsystechnologies.com/hijack-log/hijack-log-thank-you.html Help Home Top RSS Terms and Rules All content Copyright ©2000 - 2015 MajorGeeks.comForum software by XenForo™ ©2010-2016 XenForo Ltd.

Username Forum Password I've forgotten my password Remember me This is not recommended for shared computers Sign in anonymously Don't add me to the active users list Privacy Policy Log in C:\WINDOWS\SYSTEM32\oqqsuvw.ini C:\WINDOWS\SYSTEM32\oqqsuvw.ini2 C:\WINDOWS\SYSTEM32\oqqsuvw.bak C:\WINDOWS\SYSTEM32\oqqsuvw.bak1 C:\WINDOWS\SYSTEM32\oqqsuvw.bak2 C:\WINDOWS\SYSTEM32\oqqsuvw.tmp C:\WINDOWS\system32\wvusqqo.dll C:\WINDOWS\SYSTEM32\yycdd.ini C:\WINDOWS\SYSTEM32\yycdd.ini2 C:\WINDOWS\SYSTEM32\yycdd.bak C:\WINDOWS\SYSTEM32\yycdd.bak1 C:\WINDOWS\SYSTEM32\yycdd.bak2 C:\WINDOWS\SYSTEM32\yycdd.tmp C:\WINDOWS\system32\ddcyy.dll If Killbox does not reboot or you get a Pending Operations type error message just reboot your Connect with top rated Experts 21 Experts available now in Live!

Then reboot into >>>safe mode<<< Click Here for instructions 4.

Regards, Disabled Vet Disabled Veteran U.S.C.G. Upon reboot, you can reset your desktop background. but I'm still getting infected with crap liike this. Download SDFix and save it to your desktop.(either one Go to Solution +1 4 Participants rpggamergirl LVL 47 Anti-Virus Apps36 Anti-Spyware23 aleghart LVL 32 Anti-Virus Apps4 Anti-Spyware1 JohnK813 LVL 14 Anti-Virus

checking for PSGuard.com key PSGuard.com key not present! Sorry bubbarox for the confusion. P.S. Check This Out Reboot.

Disabled Veteran U.S.C.G. Look for the *New Topic* Button near the top right when viewing the forums. O2 - BHO: Helper Class - {3670A914-63C2-4E67-8C9B-370AE1922143} - C:\Program Files\BChanger\bchanger.dll HKLM\..\Run: [BootSkin Startup Jobs] "C:\PROGRA~1\Stardock\WINCUS~1\BootSkin\BootSkin.exe" /StartupJobs HKLM\..\Run: [Ad-Watch] C:\Program Files\Lavasoft\Ad-Aware 2007\Ad-Watch2007.exe (since it's not doing a very good job) Reboot into Safe Mode.

It will create a folder named WinPFind35u on your desktop.Note: You must be logged on to the system with an account that has Administrator privileges to run this program.Close ALL OTHER I consider myself a pretty good spyware removal expert, but I ALMOST was stumped the other day when a customer's computer was infected with these strange "Powered by Zedo" ad popups. How to start the computer in Safe mode 6. Click on Start.

They can be considered (by some) a privacy risk and you may want to clean out spyware cookies periodically, but they cannot run programs on your computer or hurt it in