Recent Feedback
How do I uninstall d.yimg.com from my computer? It keeps popping up every time I try to open an email message. I originally downloaded bearshare.com to access music, but uninstall it. But it did not effectively eliminate this d.yimg site.
Optional Information: Computer OS: Windows Vista Browser: Firefox Already Tried: I went to Best Buy to see if they could uninstall it but no luck.
Hi , Welcome to
Please download the free version of malwarebytes from http://download.cnet.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?part=dl-10804572&subj=dl&tag=button
Download and run a quick scan.
Post the results..
What Happens Now?Your chat has ended, but you can still work with your Expert to get an answer to your question if you have not yet received one.Come back to this page at any time to see additional information from your Expert. You will also receive an email when your question is updated. If you want to send a message to your Expert, use the box below.If you have already received a satisfactory answer to your question, click the Accept button above. Experts are credited for each accepted answer they provide.
As requested, I downloaded Malwarebytes and ran a scan. Below is response. Where do I go from here?:
Malwarebytes Anti-Malware (Trial) 1.60.1.1000
www.malwarebytes.org
Database version: v2012.04.07.06
Windows Vista Service Pack 2 x64 NTFS
Internet Explorer 9.0.8112.16421
joe :: JOE-PC [administrator]
Protection: Enabled
4/7/2012 9:53:37 AM
mbam-log-2012-04-07 (09-53-37).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 197458
Time elapsed: 11 minute(s), 21 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
Registry Keys Detected: 9
HKCR\AppID\{0D82ACD6-A652-4496-A298-2BDE705F4227} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKCR\AppID\{7025E484-D4B0-441a-9F0B-69063BD679CE} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKCR\AppID\{8258B35C-05B8-4c0e-9525-9BCCC70F8F2D} (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A078F691-9C07-4AF2-BF43-35E79EECF8B7} (Adware.Softomate) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{89F88394-3828-4d03-A0CF-8203604C3DA6} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D4233F04-1789-483c-A137-731E8F113DD5} (Adware.Hotbar) -> Quarantined and deleted successfully.
HKCR\AppID\BRNstIE.DLL (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKCR\AppID\mozillaps.dll (Adware.ClickPotato) -> Quarantined and deleted successfully.
HKCR\AppID\Pltfrm.DLL (Adware.ClickPotato) -> Quarantined and deleted successfully.
Registry Values Detected: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform|ShopperReports 3.0.497.0 (Adware.HotBar) -> Data: -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform|SRS_IT_E8790570B7765B5634A191 (Malware.Trace) -> Data: -> Quarantined and deleted successfully.
Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced|Start_ShowSearch (PUM.Hijack.StartMenu) -> Bad: (0) Good: (1) -> Quarantined and repaired successfully.
Folders Detected: 0
Files Detected: 3
C:\Users\joe\AppData\Local\Temp\nso6539.tmp\bringtofront.exe (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
C:\Users\joe\Downloads\IWantThis.exe (Adware.GamePlayLabs) -> Quarantined and deleted successfully.
C:\Users\joe\Downloads\setup(2).exe (Trojan.Dropper) -> Quarantined and deleted successfully.
(end)
Ok.I see several adware and trozan virus being deleted by malwarebytes.Your system is severely infected.Now download and run combofixhttp://www.bleepingcomputer.com/combofix/how-to-use-combofixDownload and run ccleaner freehttp://www.filehippo.com/download_ccleaner/Post combofix log and how's the system behaving after the runs.Ps.:All tools and download links i give are free..so if youa re asked to pay for some tool dont do so..Contact me back.
After I downloaded Malware , I removed all the viruses identified by Malware. I will now download and run combofix then download and run cclearer free as recommended by you. Will this continue to just resolve my issue to get ride of d.yming because it still shows up? Combofix would not run the program unless I removed my MyAfee Internet Security. This process has become to complicated and troublesome, therefore I do not believe you can reslove my issue. Consequently, I do not expect any charges to be billed to my credit card.
Wow.You really want to give up. An infected system only results in loss of personal information and identity theft.I have seen worse..You can get a second opinion from any other computer expert.Anyway i will let the final decision with you..
Combofix subsequently advised that the prorgam was in run mode, so it was activated. I proceeded to download ccleaner free. During the process of registering Optimizer Pro, I was requested to pay for the service. You advised me to notify you if payment was requested since free on your end. I am not quiting yet, so please advise where I go from here.
Ok.
Thanks for returning back..You need to stick with me till all the virus is removed.d.yimg.com i can help you remove it in one shot..
But i need your remove all the infections in the system first.Now Optimizer Pro is not the software i wanted to run.The virus seems to be redirecting you to a wrong website..
Now can you please download and install hijack this from link below:
http://www.filehippo.com/download_hijackthis/
Click on the green download button near to DownloadLatest Version1.34MB
Let me know if you can download and run it..
I downloaded latest version 1.34MB and ran it...what now?
Ok..run it.
Click do a system scan and save a log file
Attachments are only available to registered users.
Post the log file