Logs from 8-step process for Doug8765

Status
Not open for further replies.

Doug8765

Posts: 275   +8
Hi -
I attach the logs that the 8-step analysis process requests.

Before running the 8-step process (and all during the running of the 8-step process) my computer was afflicted with the sagipsul.com virus. Before trying this 8-step process I had tried a bunch of other antivirus steps. None seemed to work and may have made things worse. I did find that (again, before this 8-step process) upon boot-up I was told by Windows that a couple system32 dlls were not what Windows was looking for, but when I googled the dlls in question I found that other sites said those dlls were bad dlls.

Right now, after running the 8-step process, my teen daughter is using the computer right now and is currently not experiencing the sagipsul.com virus.

I would appreciate knowing what to do next. Thank you.

Doug Roberts
 
MBAM cleaning was not finished until restarting the computer.
Code:
Memory Modules Infected:
C:\WINDOWS\system32\wvUkHXRL.dll (Trojan.Vundo.H) -> Delete on reboot.
C:\WINDOWS\system32\sjjrxl.dll (Trojan.Vundo) -> Delete on reboot.

Delete files listed in the code box. Then
Scan with HJT, tick & fix. Restart computer.
Code:
O4 - HKUS\S-1-5-18\..\Run: [lejuhabiyo] Rundll32.exe "C:\WINDOWS\system32\jutizowi.dll",s (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [lejuhabiyo] Rundll32.exe "C:\WINDOWS\system32\jutizowi.dll",s (User 'Default user')
O20 - AppInit_DLLs: C:\WINDOWS\system32\zoroviro.dll,C:\WINDOWS\system32\kevusowe.dll sjjrxl.dll
O20 - Winlogon Notify: byxneevl - byXNeEVl.dll (file missing)

Update & rescan with MBAM & SAS to demonstrate that the computer is clean.

Post logs if issues remain.
 
Hi -
All those files were not on my computer so I am rerunning Malwarebytes, SuperAntiSpyware and HijackThis.

My daughter says that none of presenting symptons seem to occur, so I am hopeful...

Many, many thanks for everything you and your associates do.

Doug
 
Whilst you're at it, startup Hijackthis again, and place a tick next to these two Malwares, then fix them

O4 - HKUS\S-1-5-18\..\Run: [lejuhabiyo] Rundll32.exe "C:\WINDOWS\system32\jutizowi.dll",s (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [lejuhabiyo] Rundll32.exe "C:\WINDOWS\system32\jutizowi.dll",s (User 'Default user')
 
Status
Not open for further replies.
Back