Computing.Net > Forums > Security and Virus > removal of yod.htm

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

removal of yod.htm

Reply to Message Icon

Original Message
Name: gilloz
Date: October 4, 2006 at 08:16:21 Pacific
Subject: removal of yod.htm
OS: WinXP PRO
CPU/Ram: AMD2100+/512MB
Manufacturer/Model: Home Brew
Comment:

My neighbor's computer has a file, yod.htm, which resides in C:\Windows, which puts a message of spyware infection on the desktop which I can't get rid of. I am unable or do not have access to change any settings in the registry, msconfig, file folders, nothing anywhere. It totatlly locks me out of making any changes in any windows. This file does not load in Safe Mode. Tried using Command Prompt to delete it, but it just keeps coming back. Spybot, AdAware, Windows Defender, AVG antivirus does not get rid of this. Any information or help would be appreciated. Thanks.


Report Offensive Message For Removal


Response Number 1
Name: jabuck
Date: October 4, 2006 at 08:36:07 Pacific
Reply:

From you neighbors computer.Please post a Hijack This log so that the files associated with the virus/spyware/hijacker can be identified. Please download HJTsetup.exe from this link http://www.thespykiller.co.uk/files/HJTsetup.exe to your desktop.
Doubleclick on the HJTsetup.exe icon on your desktop. By default it will install to C:\Program Files\Hijack This. Continue to click "next" in the setup dialogue boxes until you get to the "Select Addition Tasks" dialogue.
Put a check by "Create a desktop icon" then click "Next" again.

Continue to follow the rest of the prompts from there.
At the final dialogue box click "Finish" and it will launch Hijack This.

Before running the scan rename hijackthis.exe as that sometime helps locate the baddies. Go to start> search> files and folders> type in the top space "hijackthis.exe" without the quotes> click search> when it is found in the right pane (looks like a pile of dynamite)>right click on it> click rename> rename it "show.exe" without the quotes> click a blank space on the screen.

Click on the "Do a system scan and save a logfile" button. It will scan and the log should open in notepad.
Click on "Edit > Select All" then click on "Edit > Copy" to copy the entire contents of the log and post it in this thread.

Do not fix anything yet unless you know what you are doing. This is a powerful tool that can crash the computer if used improperly.

Please download SmitRemFix from this link http://siri.urz.free.fr/Fix/SmitfraudFix.zip Then extract the contents to your desktop.

Do not run any other option than the one requested as doing so will damage the desktop of an uninfected computer

Open the "SmitfraudFix" folder and double-click "smitfraudfix.cmd"
Select option #1 - Search by typing 1 and press "Enter"; a text file will appear, which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

Note : process.exe is detected by some antivirus programs (AntiVir, Dr.Web, Kaspersky) as a "RiskTool"; it is not a virus, but a program used to stop system processes. Antivirus programs cannot distinguish between "good" and "malicious" use of such programs, therefore they may alert the user.



Report Offensive Follow Up For Removal

Response Number 2
Name: gilloz
Date: October 4, 2006 at 08:49:02 Pacific
Reply:

Jabuck: Thanks, we'll give this a try. I will get back to you with some results. I have to wait for my neighbor to gain access to his computer when he is available and ready.


Report Offensive Follow Up For Removal

Response Number 3
Name: gilloz
Date: October 8, 2006 at 10:43:31 Pacific
Reply:

Jabuck: My neighbor decided to go ahead with a complete clean re-install of his OS instead. I made a copy of your response and will file it in my troubleshooting notebook for future use. Thanks for the information. Just wanted to give you this feedback. Thanks again.


Report Offensive Follow Up For Removal

Response Number 4
Name: jabuck
Date: October 8, 2006 at 11:54:58 Pacific
Reply:

Thank for the feedback, nice of you to lets us know the resolve.


Report Offensive Follow Up For Removal

Response Number 5
Name: lee oulton
Date: October 13, 2006 at 09:07:46 Pacific
Reply:

Thanks buddy you just saved me abuot 4 hours work!! i've been removing this B**CH manually and it was a nightmare,and you've just turned it in a wonderful dream about naked women on a bouncy castle!!!


Report Offensive Follow Up For Removal







Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: removal of yod.htm

Any body heard of a program called
    Summary: HELP! Any body heard of a program called cpanel? Its something that has been installed on my computer like a spy ware ore something. What the program did was too change my dns. No problem change it ba...
www.computing.net/answers/security/any-body-heard-of-a-program-called-/6854.html

manual removal of troj_imiserv.c
    Summary: I have looked extensively for a manual removal of troj_imiserv.c. Can anybody help? ...
www.computing.net/answers/security/manual-removal-of-trojimiservc/13794.html

Removal of Trojan.win32.Monder.amb
    Summary: removal of: Trojan.win32.Monder.amb this is a newer virus and I can't find any info on. the security software i use, can not delete it, disinfect it, neurtilize it. I need help on getting rid of it. T...
www.computing.net/answers/security/removal-of-trojanwin32monderamb/23062.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software