also @ TechSpot: Walmart's pre-Black Friday sale: $99 Xbox 360 Arcade, more
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

I have completed the 8 steps, now what?

Closed Thread
Bookmark Thread Tools
  #1  
Old 12-31-2008
Newcomer, in training
 
Member since: Dec 2008, 15 posts
I have completed the 8 steps, now what?

Ok, my computer is acting weird. But it only does this when I have Firefox opened, and when I do, every once and a while I see a window maximize above mine, but then it immediately goes away. And sometimes my computer will open up 654356354 Firefox windows all having these weird sites...and they're always the same ?5?. Also, I have been noticing my computer opening up the website sagipsul, which I googled and it led me here. Which is why I'm now registered. Any way to fix this? I have attached my logs below.

Malwarebytes and SUPERantispyware is still running...I'll upload those when they finish.
Attached Files
File Type: txt hijackthis.txt (10.1 KB, 4 views)
  #2  
Old 12-31-2008
Newcomer, in training
 
Member since: Dec 2008, 15 posts
Here is my SAS....I accidentally closed out the MBAM....how do I get it back?
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 12-31-2008
rev_olie's Avatar
TechSpot Booster
 
Location: the lab men wont tell me
Member since: Apr 2006, 602 posts
System specs
If you have left MBAM without loading the log go back in and i think there is a logs tab were you can view them in the actual MBAM program. Also go to were its installed and have a look there

C:/Program Files/Malwarebytes and then it will be called log something or other. Around that location anyhow.

I will take a look at your log tomorrow unless someone helps you sooner
Happy new year
  #4  
Old 01-01-2009
Newcomer, in training
 
Member since: Dec 2008, 15 posts
Here is the MBAM log...I re-booted like MBAM and SAS said to. Happy new year to you too! Also, when I re-booted, my firewall was off, but it turned back on by itself, and then automatic updates was off, and I manually re-enabled that.
Attached Files
File Type: txt mbam-log-2008-12-31 (23-36-46).txt (2.7 KB, 2 views)
  #5  
Old 01-01-2009
TechSpot Member
 
Member since: Dec 2008, 169 posts
System specs
O2 - BHO: {b76c0542-a909-a8bb-aa64-4c876a3b31a2} - {2a13b3a6-78c4-46aa-bb8a-909a2450c67b} - C:\WINDOWS\system32\vcmroh.dll
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
O4 - HKLM\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s
O4 - HKLM\..\Run: [CPMffddc3ac] Rundll32.exe "c:\windows\system32\yuhisona.dll",a
O4 - HKUS\S-1-5-19\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s (User 'NETWORK SERVICE')

these are the bad guys here so trash these. afterwards browse to these file locations and delete these files. If you cannot delete try booting in safe mode and deleting them. They are piggy-backing off the legitimate rundll32.exe process that is used quite frequently in windows. I've seen situations where these keys will jump back into the registry after they are deleted. let us know how it goes
  #6  
Old 01-01-2009
BlkHeartWolf's Avatar
TechSpot Member
 
Location: Minnesota
Member since: Dec 2008, 160 posts
System specs
Right Click on MyComputer icon and go to properties
Turn Off system restore
open IE and go to TOOLS OPTIONS delete temporary internet files and cookies
do a disk cleanup in your Start/accessories/system tools/ Menu

After the reboot
download malwarebytes and install
run hijackthis and malwarebytes at the same time
select any files and or keys posted in hijackthis
but on both maiwarebytes and hijackthis click fix at the same time.
then reboot immediatly.
if you forget to turn off system restore it will return no matter

reboot once complete, run hijack this and post your log here again


R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
O2 - BHO: {b76c0542-a909-a8bb-aa64-4c876a3b31a2} - {2a13b3a6-78c4-46aa-bb8a-909a2450c67b} - C:\WINDOWS\system32\vcmroh.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll

O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)

O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe
O
O4 - HKLM\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s
O4 - HKLM\..\Run: [CPMffddc3ac] Rundll32.exe "c:\windows\system32\yuhisona.dll",a
O4 - HKCU\..\Run: [Vidalia] "C:\Program Files\Vidalia Bundle\Vidalia\vidalia.exe"
O4 - HKUS\S-1-5-19\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [fisodepasu] Rundll32.exe "C:\WINDOWS\system32\mezutilo.dll",s (User 'NETWORK SERVICE')

O20 - AppInit_DLLs: avgrsstx.dll vcmroh.dll C:\WINDOWS\system32\nifudoju.dll c:\windows\system32\yuhisona.dll

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O24 - Desktop Component 1: (no name) - http://mail.google.com/mail/?tab=wm&shva=1#inbox
  #7  
Old 01-01-2009
TechSpot Member
 
Member since: Dec 2008, 169 posts
System specs
DOn't delete this one

O4 - HKLM\..\Run: [GWMDMpi] C:\WINDOWS\GWMDMpi.exe

He's one of the good guys. This is part of his modem software
  #8  
Old 01-01-2009
Newcomer, in training
 
Member since: Dec 2008, 15 posts
Ok how do I delete these files? I navigated to the file location and it wasn't there? Am I missing something? Do I do it inside one of the programs or what? Please help.

Last edited by XxSnip3xX; 01-01-2009 at 02:57 AM..
  #9  
Old 01-01-2009
rev_olie's Avatar
TechSpot Booster
 
Location: the lab men wont tell me
Member since: Apr 2006, 602 posts
System specs
Little more detail next time please guys :P

Go into Hijackthis and click scan

Then go to the keys highlighted above. place a tick in the box next to those items ONLY.

Then only after double checking them ti make sure you haven't checked a similar item pres fix selected.

Then start your PC and pres scan with logfile and post the log again t double check you got it right.
To remove this ad, sign in. To register for a new account, click here.
  
  #10  
Old 01-01-2009
Newcomer, in training
 
Member since: Dec 2008, 15 posts
Ok, here is the log after I deleted everything.
  #11  
Old 01-01-2009
Newcomer, in training
 
Member since: Dec 2008, 15 posts
Ooops! I forgot to upload it in the post above! Lol sorry here it is.
Attached Files
File Type: txt hijackthis(New Log).txt (9.7 KB, 1 views)
  #12  
Old 01-01-2009
BlkHeartWolf's Avatar
TechSpot Member
 
Location: Minnesota
Member since: Dec 2008, 160 posts
System specs
DID good

these trojan's mostly come in on a GOOGLE redirect to a different server.
While the install is Google code it lists a provider in the registry like this
KEY
hkey_users\s-1-5-21-1202660629-602609370-839522115-500\software\microsoft\internet explorer\searchurl\
• provider = gogl or googl

I am not sure why your 2 are still listed but I would remove google and re-install directly from them to ensure you do not have such a provider in your registry.
GOOGL is hard to explain and detialed so I ask trust me
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

WOLF
  #13  
Old 01-01-2009
Newcomer, in training
 
Member since: Dec 2008, 15 posts
Thanks a lot! You guys were a load of help!
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
8 steps completed, still something amiss Virus & Malware removal 8 12-31-2008 03:46 PM
Completed 8 steps Vundo virus Virus & Malware removal 3 12-06-2008 04:33 AM
Completed 8 steps Virus & Malware removal 4 12-03-2008 09:19 PM
Rustok-N, completed 8 steps Virus & Malware removal 0 12-03-2008 08:00 PM
My hijackthis log, completed all steps. Is my PC okay now? Virus & Malware removal 8 06-07-2008 01:27 PM


All times are GMT -4. The time now is 08:28 AM.