also @ TechSpot: StarCraft 2 to lack LAN support, a PC exclusive
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.

Go Back   TechSpot OpenBoards > Operating Systems & Software > Virus & Malware removal

Sagipsul Virus please help

Reply
Bookmark Thread Tools
  #1  
Old 01-05-2009
Newcomer, in training
 
Member since: Jan 2009, 4 posts
Sagipsul Virus please help

I believe I have a Sagipsul virus. I followed the 8 steps listed in other threads, but my browser still tries to connect to a web adress such as: sagipsul.com/...
I will try to post my recent logs with this
Attached Files
File Type: txt mbam-log-2009-01-05 (23-50-45).txt (1,016 Bytes, 3 views)
File Type: log SUPERAntiSpyware Scan Log - 01-05-2009 - 19-39-16.log (465 Bytes, 2 views)
File Type: log hijackthis.log (9.9 KB, 1 views)
Reply With Quote
  #2  
Old 01-05-2009
kimsland's Avatar
TS Special Forces
 
Member since: Dec 2007, 16,737 posts
Uninstall your McAfee Antivirus
Then run the McAfee Removal Tool

Install Avira free AntiVirus

Start up Malwarebytes again; Update it; then run a full scan (remove all found Malwares)
You need to run this multiple times, until all hidden Malwares are uncovered and removed
By the way, your 5 other posts have been removed from someone elses Introduce yourself thread. You Do Not Need 5 Posts to get support here
Reply With Quote
Login to remove this ad - join the TechSpot Community for free.
  #3  
Old 01-06-2009
Newcomer, in training
 
Member since: Jan 2009, 4 posts
I removed McAfee, then used the removal tool.
I installed Avira.
Ran Malwarebytes at least 4 times. The last 2 reported no infected objects.
Could you please have a look at my most recent logs which I have attached, I think I have removed all malicious software.
Thank you very much for your advice Kimsland

This is the most recent Malwarebyte log file. After updating I found 1 more infected object.
Attached Files
File Type: txt mbam-log-2009-01-06 (19-38-31).txt (854 Bytes, 1 views)
File Type: log hijackthis.log (8.8 KB, 1 views)
File Type: log SUPERAntiSpyware Scan Log - 01-06-2009 - 20-10-44.log (465 Bytes, 1 views)
File Type: txt mbam-log-2009-01-06 (20-22-01).txt (905 Bytes, 0 views)

Last edited by kimsland; 01-06-2009 at 06:27 PM.. Reason: merged 2 posts
Reply With Quote
  #4  
Old 01-06-2009
TechSpot Booster
 
Location: Illinois, USA
Member since: Feb 2007, 900 posts
System specs
Your almost there. Update MBAB & SAS. Your version of MBAM is about 100 updates behind the current version.

Rescan with MBAB & SAS (run as pairs) until clean or something that cannot be cleaned.

HJT scan informs what has not been handled (computer restart before HJT scan)

Caught by HJT.
Code:
O20 - AppInit_DLLs: hupxmc.dll
  • Confirm file has been deleted.
  • 'Regedit' can be used to delete references to file
  • Or wait for updated MBAM to clean this reference.
If symptoms remain, post new logs and describe conditions.


Following clean scans, Establish a new clean restore point and Clear your existing System Restore points:
  • New
    • Go to Start > All Programs > Accessories > System Tools > System Restore>
    • Select Create a restore point> OK.
  • Clear Old
    • go to Start > Run > cleanmgr > Select the More options tab >
    • Choose the option to clean up System Restore > OK
      • This will remove all restore points except the new one you just created.
Reply With Quote
  #5  
Old 01-06-2009
Newcomer, in training
 
Member since: Jan 2009, 4 posts
I updated SAS and Malwarebytes.
Ran them both at the same time. Both gave clean reports (attached)
Restarted computer.
Ran HJT, (log attached)

Thanks for your help. Is my system clean now?
Attached Files
File Type: log SUPERAntiSpyware Scan Log - 01-06-2009 - 22-25-15.log (465 Bytes, 1 views)
File Type: txt mbam-log-2009-01-06 (23-02-05).txt (854 Bytes, 2 views)
File Type: log hijackthis.log (9.0 KB, 3 views)
Reply With Quote
  #6  
Old 01-06-2009
TechSpot Booster
 
Location: Illinois, USA
Member since: Feb 2007, 900 posts
System specs
Add note - RE: O6 items
Quote:
Originally Posted by kimsland
I agree with IE Reset
I've had users (and even support) argue with me that this will reset all IE settings, even settings that the user may want!

My answer is: Well we are presently removing Malware. Any BHOs or restrictions that sites may require, will need to be put back in, just as it was done before (ie they got them somewhere ) Note: most of these edititions (or additions) to IE are automatic anyway !

Just quote IE Reset at will


Ok! And I need to improve my wording - run as pair - should been understood as 'back-to-back'. Run MBAN. Run SAS. Repeat sequence until clean. I have this trouble when I try to save a few words. I was trying to correct the other interpretation where repeatedly run the first until clean and then repeat for the second.

Perhaps Kimsland will drop in on this thread. I do not recall how to control this or make it normal other than to reset the Internet Explorer settings (RIES)
Code:
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Toolbars\Restrictions present
PostScript
HJT Tick & Fix
Code:
O20 - AppInit_DLLs: hupxmc.dll
Establish a new clean restore point and Clear your existing System Restore points:
  • New
    • Go to Start > All Programs > Accessories > System Tools > System Restore>
    • Select Create a restore point> OK.
  • Clear Old
    • go to Start > Run > cleanmgr > Select the More options tab >
    • Choose the option to clean up System Restore > OK
      • This will remove all restore points except the new one you just created.

Last edited by rf6647; 01-07-2009 at 01:36 PM.. Reason: Add note ; P.S.
Reply With Quote
  #7  
Old 01-07-2009
Newcomer, in training
 
Member since: Jan 2009, 4 posts
ok cleared my restore points.
ran SAS and malwarebytes after each other. logs attached.
used HJT to remove 020 as instructed above.
Reset internet Explorer.
ran HJT again, log is below.

Thanks for all your help. Is my sistem clean now?
Attached Files
File Type: txt mbam-log-2009-01-07 (19-30-34).txt (853 Bytes, 2 views)
File Type: log SUPERAntiSpyware Scan Log - 01-07-2009 - 18-21-47.log (465 Bytes, 1 views)
File Type: log hijackthis.log (8.5 KB, 2 views)

Last edited by glambaws; 01-07-2009 at 06:27 PM..
Reply With Quote
Login to remove this ad - join the TechSpot Community for free.
  #8  
Old 01-08-2009
TechSpot Booster
 
Location: Illinois, USA
Member since: Feb 2007, 900 posts
System specs
I believe your system is clean.

The 'toolbar restriction' is probably coming from one of them (such as Goo gle, Real, Mes senger, Java, or anything appearing as a button or menu item).

Tick/fix of O6 entries is not a fix. It suppresses the appearance in the log (unless re-generated by some program action that is reflected here). See #O6Diag

CCleaner has a 'registry' analyze/fix capability. Perhaps it can flag other keys that trigger the O6 toolbar restriction.

An perhaps it is 'residue' in its own right. HJT in safe mode has remove entries that were not touchable in normal mode.

If you have any doubts, Combo_fix scan can be used. In addition to its ability to root out stubborn infections, it picks out residue left by other scanners, and provides diagnostic information. (Combo_fix is spelled without '_' )

Two more cosmetic changes -
O9 - Extra button: Sky - {08E730A4-FB02-45BD-A900-01E4AD8016F6} - http://www.sky.com (file missing)
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - >> mcafee installer

Tag back with logs or other concerns.

Last edited by rf6647; 01-08-2009 at 06:32 AM.. Reason: tutorial reference
Reply With Quote
Reply

Tags
8 steps, malware, sagipsul, virus
Thread Tools


Similar Topics
Topic Category Replies Last Post
Sagipsul.com Virus Virus & Malware removal 5 01-09-2009 01:14 AM
Help with sagipsul virus Virus & Malware removal 3 01-05-2009 08:53 AM
Sagipsul Virus Virus & Malware removal 4 01-02-2009 08:34 PM
Sagipsul virus help Virus & Malware removal 7 01-02-2009 06:06 PM


All times are GMT -4. The time now is 03:07 PM.