Home > General > Atlbd32?

Atlbd32?

DO NOT RUN IT YET Download CWSserviceRemove and unzip it to your desktop. Click the Stop button. chaslang, Jul 26, 2004 #23 chaslang MajorGeeks Admin - Master Malware Expert Staff Member Before starting the steps below, I want you to make sure you have Ad-aware and SpyBot S&D Here is my report.

Im so mad. Okay, you said "I fixed the entries in HijackThis but they keep coming back." Which entries came back? Pool 2 - http://download.games.yahoo.com/games/clients/y/potd_x.cab O16 - DPF: Yahoo! File/Folder Deletions Delete the following Files indicated in RED and Folders indicated in BLUE if they still exist.

You can try booting to safe mode and running about:Buster. Well heres my HijackThis log: Logfile of HijackThis v1.98.0 Scan saved at 7:29:11 PM, on 7/23/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe Logfile of HijackThis v1.99.1 Scan saved at 6:50:52 PM, on 10/07/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Unable to get Internet Explorer version!

chaslang, Jul 26, 2004 #28 Dobbs734 Private E-2 yea, i've been using the F8 method for restarting in safe mode. Thank you, Mike Riskus Logfile of HijackThis v1.97.7 Scan saved at 12:14:32 PM, on 9/8/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe When it finishes Click OK. 13.0) Run CCleaner and on the Windows tab (you'll see when you run it) leave the defaults and click Run Cleaner. 13A) Search the registry for Dobbs734, Jul 22, 2004 #1 chaslang MajorGeeks Admin - Master Malware Expert Staff Member Have you done a search for AppInit_DLLs in your registry to see what is shown there?

If this link is important, then ill wait to do anything, otherwise just tell me what it is and ill continue with the process.Thanks!Click to expand... That's the Hijack This! I'm working out a procedure for you right now. http://www.geekstogo.com/forum/topic/43083-aboutblankstartpage-dudll-trojan-resolved/ cause that log is long! :] Last edited by a moderator: Jul 23, 2004 beanier, Jul 23, 2004 #4 NeoNemesis Moutharrhea beanier said: Just in case you havent, read the

MAKE SURE TO BE PHYSICALLY DISCONNECTED FROM INTERNET. Check a HijaakThis log in each user account! During this time, the website or our forums won’t be accessible. Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab O16 - DPF: Yahoo!

I fixed the entries in HijackThis but they keep coming back. button to start the program. Last edited: Jul 25, 2004 chaslang, Jul 25, 2004 #17 Dobbs734 Private E-2 Arite, what i am trying say when "I fixed the entries in HijackThis but they keep coming back.", Please re-enable javascript to access full functionality.

from notepad select the files again (all of them) and right click, select "copy". Dobbs734, Jul 26, 2004 #26 chaslang MajorGeeks Admin - Master Malware Expert Staff Member Dobbs734 said: So far, i've done the updates for all of the anti-spyware programs. Now navigate thru the registry to: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall Click the [+] next to uninstall. Once disconnected, do not connect again until I tell you to do so. 1) Make sure you have enabled viewing of Hidden Files and Folders with Windows Explorer.

Poker - http://download.games.yahoo.com/games/clients/y/pt1_x.cab O16 - DPF: Yahoo! In kill box goto "file" and "paste from clipboard" Quote: C:\WINDOWS\system32\atlyd.exe C:\WINDOWS\system32\sdkep32.exe C:\WINDOWS\atlbd32.exe C:\WINDOWS\ntwz32.exe C:\WINDOWS\sdkic32.exe C:\WINDOWS\ntcn.exe C:\WINDOWS\crsf32.exe C:\WINDOWS\netoj.exe C:\WINDOWS\atlyb32.exe C:\WINDOWS\sysob.exe C:\WINDOWS\crkx.exe C:\WINDOWS\system32\javayl32.exe C:\WINDOWS\iegl.exe C:\WINDOWS\addqd.exe C:\WINDOWS\javaws.exe C:\WINDOWS\jvgqf.dll C:\WINDOWS\winrn.exe C:\WINDOWS\winlz.exe C:\WINDOWS\system32\winwc32.exe C:\WINDOWS\appoc.exe C:\WINDOWS\system32\sysjx32.exe Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab O16 - DPF: {10000000-1000-0000-1000-000000000000} - file://C:\Program Files\Internet Explorer\whwsdgtv.exe O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/zuma/default/popcaploader_v5.cab O16 - DPF: {EDFCDAF5-95D9-40E9-BBE6-10C33190C3EF} (cGameControl Class) - http://zone.msn.com/bingame/rmcb/default/RumbleCube.cab I disconnected physically from Select all the files below, right click, select "copy", go to killbox, select "File", then "Paste from clipboard" now click the Red and white "X" to the right and answer "yes"

Open up the 'Ab LogFile.txt' (which was created in the same folder as AboutBuster) and post the log here. I am trying to run a virus scan from Panda or Trend but the machine won't connect to the Internet although it pings IPs OK. I pretty sure this is a virus but I can't get at my usual tools.

Pyramids - http://download.games.yahoo.com/games/clients/y/pyt1_x.cab Thanks again.

Last edited: Aug 6, 2004 edrod13, Aug 6, 2004 #6 Cricket Shiro Usagi Joined: Sep 14, 1999 Messages: 34,001 Location: Kaneohe, Hawaii Hey edrod13, is khanhhuynh4u your neighbor? Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, I do see a file from the HSA problem. Select the following and click 'Kill process' for each one if they are still listed (they shouldn't be - but double check): C:\WINDOWS\crbq.exe Start HijackThis Fix Open Hijack This and click

Click Exit once you are done. I ran CWShredder and it cam up clean I also ran SpyBot S&D and AdAware. Register now to gain access to all of our features, it's FREE and only takes one minute. Click the OK button and it should exit.

Since it will not connect to the internet I can't run either the Panda Active Scan or the TrendMicro Scan (I think the user may have been able to run one The link in my post works (click on "Hijack This!"). Can my two post here be deleted. Stop Potentially Runnning Processes Go into HijackThis->Config->Misc.

Then continue running and let's see how everything is working. It is geared just for you. Join Date: Jul 2005 Posts: 28 OS: xp I think its still here :( Logfile of HijackThis v1.99.1 Scan saved at 10:26:37 AM, on 11/07/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) Click Update button to see if there are any updates.

Dismiss Notice spyware help Discussion in 'Online Security' started by khanhhuynh4u, Aug 4, 2004. IN FACT DO NOT REBOOT OR SHUTDOWN YOUR PC EITHER. Lastly whenever I restart I get four error messages saying that atlbd32.exe has encountered a problem and has been closed. Make sure you print these or save them to a file on your PC because I am going to have you disconnect your PC from the internet at a certain point

Pool 2 - http://download.games.yahoo.com/games/clients/y/potd_x.cab O16 - DPF: Yahoo! Now also look in c:\windows\Prefetch for all of the above files deleted in steps 7 and 8. I hope you are not doing these steps while connected. AppInit_DLLs is part of every NT, 2K, and XP system.

do not save Hijack This to a temporary folder (or your desktop for that matter)... Read this. It asks me if I want to send the error report but not knowing whqt this program is I haven't done so. Were you saying you found it and it was blank?

Now save the file (yes as an empty file).