Sagipsul and gadcom combo attack on my computer

Status
Not open for further replies.
Hi..
I was on the internet last week when suddenly there are pop-ups coming out. One of them is sagipsul and after i ran a spybot program, i detected gadcom.exe existing in my pc.

I just formatted my computer before it happened and I used AVG-free and ad-aware programs, hoping that they can fix the problems, but they failed. so i followed the 8-steps viruses/spyware/malware removal as suggested.

so here are the logfiles:

there are 2 log files of superantispyware as i ran it twice.

please help me on this matter and thanks in advance.
 
Please go back and update and run Malwarebytes again: No action taken.
This means that you did not check the line:
# When the scan is complete, click OK, then Show Results to view the results.
# Be sure that everything is checked, and click Remove Selected.
Check the #11 screen shot here:
http://www.bleepingcomputer.com/malware-removal/remove-vundo-virtumonde

Open ZoneAlarm and temporarily disable the firewall:
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

Please re-open HiJackThis and scan.Check the boxes next to all the entries listed below.
O2 - BHO: {dc9c3de5-b9e5-a678-0714-c23b3d644b67} - {76b446d3-b32c-4170-876a-5e9b5ed3c9cd} - C:\WINDOWS\system32\nrjhrq.dll (file missing)
O20 - AppInit_DLLs: nrjhrq.dll
O20 - Winlogon Notify: xxywxYOF - xxywxYOF.dll (file missing)
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis and reboot into Safe Mode:

Right click on Start> Explore> Windows System32> right click> Delete on any of the following files if present:.
nrjhrq.dll
xxywxYOF.dll
PMNON.DLL.
Reboot into Normal mode.
(xxywxYOF.dll is a file from Trojan.WinFixer.Process)

Please update and scan again with Malwarebytes, ( being sure to check for removal) SuperAntispyware (also being sure to check the entry '* Make sure everything found has a checkmark next to it,*) and follow with a new HijackThis scan. Attach all three logs.
 
Status
Not open for further replies.
Back