also @ TechSpot: Asus P7P55D Deluxe Motherboard Review
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Completed 8-step Removal Instructions

Closed Thread
Bookmark Thread Tools
  #1  
Old 01-04-2009
Newcomer, in training
 
Member since: Jan 2009, 3 posts
Completed 8-step Removal Instructions

I just want to make sure that my computer has been cleaned of the sagipsul.com pop up thing since I have been having those annoying pop ups for the past couple of days. The 3 logs have been attached. Thanks.
Attached Files
File Type: txt mbam-log-2009-01-04 (16-30-29).txt (1.0 KB, 3 views)
File Type: log SUPERAntiSpyware Scan Log - 01-04-2009 - 16-30-39.log (465 Bytes, 0 views)
File Type: log hijackthis.log (13.5 KB, 1 views)
  #2  
Old 01-04-2009
Banned
 
Member since: Dec 2008, 333 posts
System specs
No, it's still there. Download and run [URL="http://download.bleepingcomputer.com/sUBs/ComboFix.exe"]combofix[/URL].

Then post the Combofix log.

Those 8 Steps need to be updated.
To remove this ad, sign in. To register for a new account, click here.
  
  #3  
Old 01-04-2009
Banned
 
Member since: Dec 2008, 333 posts
System specs
Delete this one:

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=wcgnhc.dll

Not sure about:

2009-01-05 c:\windows\Tasks\AE3D9E9891860F94.job
- c:\docume~1\nelson\applic~1\coolco~1\elseboltmeta.exe

2009-01-05 c:\windows\Tasks\fksxhedb.job
- c:\windows\system32\rundll32.exe [2004-08-03 17:56]

Me thinkst you wanna kill those. Something just added those scheduled tasks.
  #4  
Old 01-04-2009
Newcomer, in training
 
Member since: Jan 2009, 3 posts
Ran combofix

I just ran combofix and have attached the log
Attached Files
File Type: txt ComboFix.txt (15.0 KB, 3 views)
  #5  
Old 01-05-2009
Banned
 
Member since: Dec 2008, 333 posts
System specs
Instructions to delete Rapid Antivirus, a rogue malware application you have installed:

Delete registry values:
HKEY_CURRENT_USER\Software\Rapid Antivirus
HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run ieupdate

Delete files:
%UserProfile%\\Application Data\\install_511_MHw0MXwwfHx8fHx8fHw_\\base2.dat
%UserProfile%\\Application Data\\install_511_MHw0MXwwfHx8fHx8fHw_\\base.dat
%UserProfile%\\Application Data\\install_511_MHw0MXwwfHx8fHx8fHw_\\spline.dat
%UserProfile%\\Application Data\\install_511_MHw0MXwwfHx8fHx8fHw_\\Desc.dat
%UserProfile%\\Application Data\\Rapid Antivirus\\Rapid Antivirus.ini
%profile%\\application data\\Rapid Antivirus\\base.dat
%profile%\\application data\\Rapid Antivirus\\base2.dat
%profile%\\application data\\Rapid Antivirus\\desc.dat
%profile%\\application data\\Rapid Antivirus\\Rapid Antivirus.ini
%profile%\\application data\\Rapid Antivirus\\spline.dat
%program_files%\\Rapid Antivirus\\howtobuy.txt
%program_files%\\Rapid Antivirus\\id.dat
%program_files%\\Rapid Antivirus\\license.txt

Delete directories:
c:\windows\system32\config\systemprofile\Application Data\s_4610_fHx8fHx8fDEyNDM0MDQ4ODN8_
%UserProfile%\Application Data\install_511_MHw0MXwwfHx8fHx8fHw_
%UserProfile%\Application Data\Rapid Antivirus

[url]http://www.2-spyware.com/remove-rapid-antivirus.html[/url]
  #6  
Old 01-10-2009
Newcomer, in training
 
Member since: Jan 2009, 3 posts
Cant Find Registry Values

I used the link you provided me with but I was unable to find values in my registry so I could get rid of it.

Also i cannot find the files in my computer that I need to delete

Last edited by yohyoh; 01-10-2009 at 02:32 AM.. Reason: Add more information
  #7  
Old 01-10-2009
kimsland's Avatar
TS Special Forces
 
Location: Australia
Member since: Dec 2007, 17,007 posts
Well Malwarebytes has updated the program revision and definitions since last you used it. So this may be a good idea to run it again

But personally I'd say remove McAfee (just a resource hog, and it didn't help you this time anyhow ! )

-------------------------

Uninstall your McAfee Antivirus
Then run the McAfee Removal Tool

Un-install: Viewpoint (Removal Tool: http://prm753.bchea.org/viewpointkiller.zip)

Install Avira free AntiVirus

Start up Malwarebytes again; Update it; then run a full scan (remove all found Malwares)
You need to run this multiple times, until all hidden Malwares are uncovered and removed

Then it may work better
Closed Thread

Tip: Download Advanced SystemCare 3 Freeware - 1 Click A Day to Clean, Repair, Protect & Optimize your PC.

Thread Tools


Similar Topics
Topic Category Replies Last Post
Step 8 of 8-step Removal Instructions Virus & Malware removal 3 01-07-2009 10:58 AM
Completed 8 step removal - log files attached Virus & Malware removal 6 12-11-2008 04:48 AM
Completed 8-step removal, am I clean? Virus & Malware removal 33 12-07-2008 10:57 PM
Step 8 of the 8-step Viruses/Spyware/Malware Preliminary Removal Instructions Virus & Malware removal 1 10-09-2008 11:50 AM
completed the removal instructions but... Virus & Malware removal 6 12-22-2006 06:06 PM


All times are GMT -4. The time now is 04:49 AM.