Sagispul and probably other viruses

By Smarch Weather ยท 4 replies
Jan 3, 2009
  1. I deleted some bad things with Malwarebytes and spyware programs, but sagispul and I'm assuming more things remain.

    Any help is appreciated.
    Here are my logs:
  2. Smarch Weather

    Smarch Weather TS Rookie Topic Starter

    I have CA Security Center from my internet provider. It finds two Vundo things and something else, but whenever I try to quarantine them, the program freezes. Any advice?
  3. rf6647

    rf6647 TS Maniac Posts: 829

    Except for your last post, things have been handle with 2 questionable findings.

    HJT scan. Tick & fix. Restart computer.
    O2 - BHO: {7c0e3507-2645-d75b-86d4-abaceb9187c2} - {2c7819be-caba-4d68-b57d-54627053e0c7} - C:\WINDOWS\system32\eaxsed.dll  >> not listed
    O4 - HKLM\..\Run: [Tjinoqevoy] rundll32.exe "C:\WINDOWS\etogurinazobes.dll",e  >> not listed
    Before reacting to CA, I suggest rescan with MBAB & SAS (run as pairs) until clean or something that cannot be cleaned.

    HJT scan informs what has not been handled (computer restart before HJT scan)

    Also, if CA is complaining about quarantined files, then

    Establish a new clean restore point and Clear your existing System Restore points:
    • New
      • Go to Start > All Programs > Accessories > System Tools > System Restore>
      • Select Create a restore point> OK.
    • Clear Old
      • go to Start > Run > cleanmgr > Select the More options tab >
      • Choose the option to clean up System Restore > OK

        • This will remove all restore points except the new one you just created.
  4. Smarch Weather

    Smarch Weather TS Rookie Topic Starter

    MBAB doesn't find anything anymore. When I try to delete this:
    O4 - HKLM\..\Run: [Tjinoqevoy] rundll32.exe "C:\WINDOWS\etogurinazobes.dll",e >>

    in HJT, it just reappears the next time I do a scan. How do I find the file in the registry and delete it?

  5. rf6647

    rf6647 TS Maniac Posts: 829

    This is the third time today to call out the big gun! If ComboFix passes on fixing the O4, then it is undocumented for one of the O23 items.

    Please run ComboFix & HJT. ComboFix cleans & provides diagnostic information that is used to find enabling infection that remain or just residue. As with most scans, the repeat scan looks for any infection that is now unmasked or a clean run. Always assess if symptoms remain.

    Supporting information
Topic Status:
Not open for further replies.

Similar Topics

Add your comment to this article

You need to be a member to leave a comment. Join thousands of tech enthusiasts and participate.
TechSpot Account You may also...