Adtomi




Posted by Ganon

I have this Adtomi spyware/malware on my computer... It keeps coming back after I delete it. I have used Adaware and Spybot S&D and some other tools, but none of them seem to be able to get rid of it permanently. Anybody have any suggestions about how to get rid of it?




Posted by loony636

You could format your computer...But, if you don't want to go that drastic, look for a registy entry. Then type msconfig in run and goto startup and stop it starting up a start up. Or just format your computer, its probably the easiest thing to do.

Just out of interest...what does the virus do to your computer? And what is its name. If you know the name of it, go to mcafee.com or norton.com and search for the virus. It should have instructions on how to delete it permanently.




Posted by NegativeTrend

Please offer better recomendations then formatting.

Now for a real fix:
1)Ctrl-Alt-Del and kill these processes
7uqj7z9a.exe
pbl8ey0e.exe
prmvr.exe
systemroot+\chq7gv5g.exe
systemroot+\j95i15ei.exe
systemroot+\jq34042x.exe
systemroot+\ndcx3xyq.exe
systemroot+\wt35w0g1.exe
ystckao32.exe

2)Delete the start up registry keys via SpyBot Search & Destroy or Start>Run>msconfig>Startup Tab

3)Reboot

4)Unregister the dlls Start>Run>regsvr32 /u Windows\system\browserhelper.dll
and \system32\browserhelper.dll

5)Remove these keys via regedit Start>Run>Regedit
HKEY_CLASSES_ROOT\clsid\{b549456d-f5d0-4641-bced-8648a0c13d83}
HKEY_CLASSES_ROOT\software\microsoft\windows\currentversion\explorer\browser helper objects\{b549456d-f5d0-4641-bced-8648a0c13d83}
HKEY_CURRENT_USER\software\adtomi
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run\v7gh03g7.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\yahoostock

6)Delete these files if present
7uqj7z9a.exe
pbl8ey0e.exe
prmvr.exe
systemroot+\chq7gv5g.exe
systemroot+\j95i15ei.exe
systemroot+\jq34042x.exe
systemroot+\ndcx3xyq.exe
systemroot+\system\browserhelper.dll
systemroot+\system32\browserhelper.dll
systemroot+\wt35w0g1.exe
ystckao32.exe

7)Start>Run>%TEMP% and delete all temp files