View Full Version : Adtomi
Ganon
22nd April 2005, 06:10 PM
I have this Adtomi spyware/malware on my computer... It keeps coming back after I delete it. I have used Adaware and Spybot S&D and some other tools, but none of them seem to be able to get rid of it permanently. Anybody have any suggestions about how to get rid of it?
loony636
23rd April 2005, 05:21 AM
You could format your computer...But, if you don't want to go that drastic, look for a registy entry. Then type msconfig in run and goto startup and stop it starting up a start up. Or just format your computer, its probably the easiest thing to do.
Just out of interest...what does the virus do to your computer? And what is its name. If you know the name of it, go to mcafee.com or norton.com and search for the virus. It should have instructions on how to delete it permanently.
NegativeTrend
23rd April 2005, 08:53 AM
Please offer better recomendations then formatting.
Now for a real fix:
1)Ctrl-Alt-Del and kill these processes
7uqj7z9a.exe
pbl8ey0e.exe
prmvr.exe
systemroot+\chq7gv5g.exe
systemroot+\j95i15ei.exe
systemroot+\jq34042x.exe
systemroot+\ndcx3xyq.exe
systemroot+\wt35w0g1.exe
ystckao32.exe
2)Delete the start up registry keys via SpyBot Search & Destroy or Start>Run>msconfig>Startup Tab
3)Reboot
4)Unregister the dlls Start>Run>regsvr32 /u Windows\system\browserhelper.dll
and \system32\browserhelper.dll
5)Remove these keys via regedit Start>Run>Regedit
HKEY_CLASSES_ROOT\clsid\{b549456d-f5d0-4641-bced-8648a0c13d83}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{b549456d-f5d0-4641-bced-8648a0c13d83}
HKEY_CURRENT_USER\software\adtomi
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run\v7gh03g7.exe
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\yahoostock
6)Delete these files if present
7uqj7z9a.exe
pbl8ey0e.exe
prmvr.exe
systemroot+\chq7gv5g.exe
systemroot+\j95i15ei.exe
systemroot+\jq34042x.exe
systemroot+\ndcx3xyq.exe
systemroot+\system\browserhelper.dll
systemroot+\system32\browserhelper.dll
systemroot+\wt35w0g1.exe
ystckao32.exe
7)Start>Run>%TEMP% and delete all temp files
vBulletin® v3.8.4, Copyright ©2000-2010, Jelsoft Enterprises Ltd.