Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Been wrestling with this: Virtumonde & sagipsul
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Been wrestling with this: Virtumonde & sagipsul
I noticed something amiss when Security Center would not enable. Then, if I tried to go out to McAfee, Norton, or any other virus product site, my browser wouldn't go there. Other behavior made me suspicious. So, after hours of researching and working on the problem, I've found and followed the suggested 8-step program leading to the attached (combined) logfiles. Please note, all three logfiles are in the attached file.
I don't know if I'm clean yet, but want somebody with a trained eye to tell me if things are back on track. Thanks in advance! (Oh, and I had some rootkit installed that was found and removed using Avenger. After that, other efforts began to uncover malware. ) Last edited by tlfromva; 01-04-2009 at 03:42 PM.. |
|
#2
|
|||
|
|||
|
Code:
C:\WINDOWS\system32\lgoxtu.dll (Trojan.Vundo) -> Delete on reboot. Rescan with MBAB & SAS (run as pairs) until clean or something that cannot be cleaned. HJT scan informs what has not been handled (computer restart before HJT scan) Caught by HJT. Code:
O20 - AppInit_DLLs: ……. lgoxtu.dll Establish a new clean restore point and Clear your existing System Restore points:
|
|
|
|
#3
|
|||
|
|||
|
Thanks!
After reading this yesterday, I got two clean scans in a row and set a new restore point. Things look like they're operating pretty normally now. Thank you.
Should I continue to keep SAS installed and running? I'm also running Spybot S&D as well as NOD32. |
|
#4
|
|||
|
|||
|
Code:
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe I scan with updated MBAB & SAS about once a month. So far they confirm my resident protections are working. I think it is very risky not to use a firewall. Your experiences may indicate it is not needed. I do not feel comfortable recommending particular applications. |
|
#5
|
|||
|
|||
|
I firewall mostly at my router, actually. And recently fired up the one built in Windows.
|
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Solution to sagipsul, virtumonde, etc. | Virus & Malware removal | 0 | 01-04-2009 05:52 PM | |
| Virtumonde.dll please help | Virus & Malware removal | 8 | 10-10-2008 11:18 PM | |
| Virtumonde? | Virus & Malware removal | 6 | 09-17-2008 01:17 AM | |
| Virtumonde | Virus & Malware removal | 2 | 09-11-2008 09:37 AM | |
| Wrestling with Vista64 Sound | Audio and Video | 3 | 11-11-2007 01:38 AM | |
All times are GMT -4. The time now is 03:33 PM.



