Trojan Horse Downloader.generic6.AEPH

Status
Not open for further replies.
I have been getting a lot of pop-ups on internet explorer recently. I ran avg and found that I have adware. I recently read a thread on this website about this same problem (topic58138) called 8-step Viruses/Malware Removal Instructions. I did all the steps up to the pont of attaching the logs. I just did Hijackthis and am now posting the hijackthis log. I do not know what to do with this information. If you could tell me how to get rid of this adware, it would be greatly appreciated.
Thank You.
 
Run HJT again and remove the following

C:\Program Files\??crosoft\r?ndll.exe
O4 - HKCU\..\Run: [Buxbiomr] "C:\Program Files\??crosoft\r?ndll.exe"
O20 - AppInit_DLLs: avgrsstx.dll uwjqou.dll
(O20 - AppInit_DLLs: avgrsstx.dll uwjqou.dll) <- This is your Trojan.

Post another log when done.
Also you should follow the removal instructions.https://www.techspot.com/vb/topic109461.html
 
This entry is also of great concern:
C:\WINDOWS\YMANTE~1\nopdb.exe
O4 - HKCU\..\Run: [Redo] "C:\WINDOWS\YMANTE~1\nopdb.exe" -vt ndrv
Note the misspelling. Extremely likely to be malware.
 
new HJT log

Deleted O4 - HKCU\..\Run: [Redo] "C:\WINDOWS\YMANTE~1\nopdb.exe" -vt ndrv
Deleted O4 - HKCU\..\Run: [Buxbiomr] "C:\Program Files\??crosoft\r?ndll.exe"
O20 - AppInit_DLLs: avgrsstx.dll uwjqou.dll
Anything else I need to do?
 
Yes! You must have missed These from reply 2 and 3;
C:\WINDOWS\YMANTE~1\nopdb.exe
C:\Program Files\??crosoft\r?ndll.exe
Click the link in my first post within this thread and follow the instructions found there.
Return here and post logs.
 
Status
Not open for further replies.
Back