Help on getting rid of Yusmsqa.exe *32 Google Chrome Processes

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Code:
C:\Users\Michael\AppData\LocalLow\ge3916\Rekootmimrma\Njeoyqcnkfo
HKU\S-1-5-21-1158752609-1568451080-3026114070-1000\...\Run: [xbxldamb] => regsvr32.exe /s "C:\Users\Michael\AppData\Local\Adobe\xbxldamb.dll" <===== ATTENTION
C:\Users\Michael\AppData\Local\Adobe\xbxldamb.dll
HKU\S-1-5-21-1158752609-1568451080-3026114070-1000\...\MountPoints2: {150b4f78-205b-11e1-90ce-180373cf6b89} - E:\LaunchU3.exe -a
HKU\S-1-5-21-1158752609-1568451080-3026114070-1000\...\MountPoints2: {dee0e048-c622-11e2-a605-180373cf6b89} - I:\vs_professional.exe
HKU\S-1-5-21-1158752609-1568451080-3026114070-1000\...\MountPoints2: {e7568d7c-3c34-11e1-ae63-180373cf6b89} - E:\LaunchU3.exe -a
SearchScopes: HKLM-x32 - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm003^S06473^us&si=COe98e7Vl7kCFazm7AodOXsAUw&ptb=1512B2A9-6982-4B94-A8BD-1BBDDC5BF9AE&ind=2013082423&n=77fd3337&psa=&st=sb&searchfor={searchTerms}
SearchScopes: HKCU - {1173C974-5F69-41D9-A250-859A1E710F26} URL = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=D676C936-FE2E-4023-A29F-AA8ECCE878BE&apn_sauid=A46DF0AE-0458-4452-B069-CCAFC0DA7401&
SearchScopes: HKCU - {5FAD2BEB-5E0C-4311-8B41-435A2FE44BF5} URL =
SearchScopes: HKCU - {9684DF73-E106-46BF-A19A-9E838261381A} URL = http://www.mysearchresults.com/search?&c=2653&t=03&q={searchTerms}
SearchScopes: HKCU - {cf6e4b1c-dbde-457e-9cef-ab8ecac8a5e8} URL = http://search.tb.ask.com/search/GGmain.jhtml?p2=^HJ^xdm003^S06473^us&si=COe98e7Vl7kCFazm7AodOXsAUw&ptb=1512B2A9-6982-4B94-A8BD-1BBDDC5BF9AE&ind=2013082423&n=77fd3337&psa=&st=sb&searchfor={searchTerms}
ZeroAccess:
C:\$Recycle.Bin\S-1-5-21-1158752609-1568451080-3026114070-1000\$ee8a9511c8bb07ee56bc3201116cc3f9
EmptyTemp:
2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It's important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.





=============================================







Scan with Combofix:
  • Please download ComboFix by sUBs and save it to your Desktop.
    You may read how Combofix works here.
  • Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix.
    If you are unsure how to do this please read this or this Instruction.
  • Run ComboFix. Click on I Agree! & follow the prompts.
    Note: If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart your computer.
  • When finished, it will produce a report for you. Please attach log reports (ComboFix.txt) back to topic.
    (typical log location: C:\ComboFix.txt )
 
Completed the three step process. It worked well. No more processes. I have attached Fixlog.txt. Not sure if I should wait for further instructions to run ComboFix. So I will wait. Thanks.
 

Attachments

OK, Combofix is unnecessary.


• The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
checkmark.png
Remove disinfection tools
checkmark.png
Create registry backup
checkmark.png
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 

Recently browsing

Members who viewed this thread in the last 5 minutes

Back
Top