also @ TechSpot: Microsoft's Indian online store hacked, passwords and user data exposed
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Download Now:

Sagipsul popups

Thread Tools Search this Thread
  #1  
Old 12-28-2008
Newcomer, in training
 
Member since: Dec 2008, 20 posts
I need help removing Sagipsul

Okay I did the 8 steps here are my logs.

Please help me, this is driving me nuts.

Symptoms :

I am using firefox and I am getting pop ups that resize then disapper. I click the alt-tab button and I can see the programs in the back ground, I also get this sagipsul popup everyonce and awhile.
Attached Files
File Type: log hijackthis.log (6.2 KB, 2 views)
File Type: log hijackthis.log (7.2 KB, 1 views)
File Type: txt mbam-log-2008-12-28 (20-38-52).txt (1.2 KB, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 12-28-2008 - 21-36-27.log (10.9 KB, 0 views)

Last edited by kimsland; 12-29-2008 at 09:49 PM..
  #2  
Old 12-29-2008
Newcomer, in training
 
Member since: Dec 2008, 20 posts
Any help would be appreciated. Thanks.
  #3  
Old 12-29-2008
Ex-TechSpotter
 
Member since: Dec 2007, 18,354 posts
Well lets try to get it at least running again
Run the Norton Removal Tool: http://service1.symantec.com/Support...05033108162039

Then re-open HJT, and tick all the following entry boxes, and select fix

Quote:
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_11\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SNM] C:\Program Files\SpyNoMore\SNM.exe /startup
O4 - HKCU\..\Run: [AdobeUpdater] C:\Program Files\Common Files\Adobe\Updater5\AdobeUpdater.exe
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
O4 - HKUS\S-1-5-19\..\Run: [lawumayizo] Rundll32.exe "C:\WINDOWS\system32\hofalobu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [lawumayizo] Rundll32.exe "C:\WINDOWS\system32\hofalobu.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
Restart
Then update Avira, and run a full scan
  #4  
Old 12-29-2008
Newcomer, in training
 
Member since: Dec 2008, 20 posts
Okay I performed what you told me.

Avria had 3 detections and I deleted them.

What next???
Attached Files
File Type: txt hijackthis1.txt (5.3 KB, 2 views)
  #5  
Old 12-29-2008
Ex-TechSpotter
 
Member since: Dec 2007, 18,354 posts
Looks a lot better
A few "file missing" entries in HJT log that can be ticked and fixed (but really no issue)

How's it all running? lots better ?
  #6  
Old 12-30-2008
Newcomer, in training
 
Member since: Dec 2008, 20 posts
It's running a lot better thanks for all your help!!!

I ran malwarebytes again and it came up with a few detections.

Here's the log:

Is there anything I need to do to make sure it's gone/
Attached Files
File Type: txt mbam-log-2008-12-29 (23-34-17).txt (1.8 KB, 2 views)
File Type: txt hijackthis2.txt (5.4 KB, 1 views)
  #7  
Old 12-30-2008
Ex-TechSpotter
 
Member since: Dec 2007, 18,354 posts
Well I know it's strange
But you must keep running Malwarebytes (also check for updates each time)
Until it's clean (zero entries found)
That's the truth of the matter
  #8  
Old 12-30-2008
Newcomer, in training
 
Member since: Dec 2008, 20 posts
kimsland,

Thanks for all your help, it is greatly appreciated.

I rescanned using Malwarebytes and SuperAntispyware.

Both times came up clean.

I am going to update both and update Avria then I'll rescan.

Hopefully I got everything.
Closed Thread

Similar Topics
Topic Replies Forum
Sagipsul Popups (yes...another one) 0 Virus and Malware Removal
Sagipsul popups help 1 Virus and Malware Removal
Im getting sagipsul popups! 0 Virus and Malware Removal
Sagipsul Popups 24 Virus and Malware Removal
Popups, Sagipsul, Help 5 Virus and Malware Removal

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 10:54 AM.