Home > General > Gomyhit?


Tech Support Guy is completely free -- paid for by advertisers and donations. You need to Sign In to add your own tags. scanning hidden files ... Join our site today to ask your question.

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> No action taken. Edited by paulmo, 26 October 2008 - 08:43 AM. A computer I am working on is infected with the GoMyHit Malware. Also "copy/paste" a new HijackThis log file into this thread. https://www.bleepingcomputer.com/forums/t/140051/gomyhit-and-other-nasties/

Newer Than: Search this thread only Search this forum only Display results as threads Useful Searches Recent Posts More... C:\WINDOWS\SYSTEM32\AppCert\wnl32.dll (Trojan.Downloader) -> Delete on reboot. I suggest you follow my suggestions. Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra

start up, automatic repair, &... Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site. Since this is your first time signing in, please provide a display name for yourself. Click the View tab.

C:\WINDOWS\system32\pggwnr.dll (Trojan.Vundo) -> No action taken. http://www.bing.com/search?q=ip%3A103.224.182.210 Every domain that is featured on the IP Find a record of every other site with the exact IP gomyhit.com has, from Bing Alexa Traffic Pageviews Bounce % Search Click here to join today! his explanation C:\WINDOWS\SYSTEM32\AppCert\wnl32.dll (Trojan.Downloader) -> Delete on reboot.

The best way to find out is with the "site:" query. The connection is automatically restored before CF completes its run. downloading other malware programs seems redundant. Logs will be closed if you haven't replied within 3 days If you would like to for the help you received.

Here's the hijack this log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:01:28 AM, on 10/4/2008 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot http://www.techsupportforum.com/forums/f10/solved-gomyhit-problem-214759.html Please re-enable javascript to access full functionality. [Resolved]gomyhit won't go away: hijackthis log file Started by paulmo , Oct 25 2008 06:02 PM Page 1 of 2 1 2 Next This Click here to Register a free account now! Clicking on either of these takes you to gomyhit.com.

C:\WINDOWS\SYSTEM32\AppCert\wsil32.dll (Trojan.Downloader) -> Delete on reboot. Show Ignored Content As Seen On Welcome to Tech Support Guy! All rights reserved. the link redirects to GoMyHit.com.I have run Smitfraudfix, I ran these but I still have the popups, i have access now to task manager, control panel.Thanks for any help with this!eleazarHere's

This site is completely free -- paid for by advertisers and donations. dragged to combofix...forgot to disable spyware doctor though. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Delete on reboot. Yes, my password is: Forgot your password?

Short URL to this thread: https://techguy.org/756019 Log in with Facebook Log in with Twitter Log in with Google Your name or email address: Do you already have an account? Give it atleast 20-30 minutes to finish if needed. This should highlight the text.

If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

It's free. Logs will be closed if you haven't replied within 3 days If you would like to for the help you received. Thank You ~Andrew Remove Advertisements Sponsored Links TechSupportForum.com Advertisement « Sonic Module Installation attemps xp | Hotkeys don't work » Thread Tools Show Printable Version Download Thread Search this It will be viewable by everyone.

C:\WINDOWS\system32\qkfdhuul.dll (Trojan.Agent) -> No action taken. Stay with this topic until I give you the all clean post. It's 100% free. scanning hidden autostart entries ...

Please download ATF Cleaner by Atribune. The forum is run by volunteers who donate their time and expertise.Want to help others? gomyhit (or so I think) Discussion in 'Virus & Other Malware Removal' started by julieu89, Oct 4, 2008. Phillips66guy replied Jan 16, 2017 at 8:43 PM What Are You Watching?

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe C:\WINDOWS\SYSTEM32\nvsvc32.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\WINDOWS\PCHEALTH\HELPCTR\Binaries\helpsvc.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\MMDiag.exe C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe C:\Program Files\MusicMatch\MusicMatch Jukebox\mim.exe . ************************************************************************** . Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn\yt.dllO2 - BHO: Ask Search Assistant BHO - {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} - C:\Program Files\AskSBar\SrchAstt\1.bin\A2SRCHAS.DLLO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - C:\WINDOWS\SYSTEM32\AppCert\filter.drv (Trojan.Downloader) -> Quarantined and deleted successfully. Notes: 1.Do not mouse-click Combofix's window while it is running.

When finished, it shall produce a log for you. IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Save ComboFix.exe to your Desktop Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. Click here to view the most popular tags for all sites.

Spyware Doctor won't remove it. Learn more. I suggest you do this: Double-click My Computer. Download - ATF Cleaner» Double-click ATF-Cleaner.exe to run the program.