View Single Post
Join Date: Jul 2008
Posts: 2,806
Reputation: jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all jholland1964 is a name known to all 
Solved Threads: 160
Featured Poster
jholland1964 jholland1964 is offline Offline
Posting Maven

Re: i Cant stop the Mass Amounts of Pop Ups

 
0
  #8
Jan 2nd, 2009
I am very familiar with the link provided, this is the one we all use.
If you don't have an XP disk then no, you cannot install the recovery partition. But it may all ready be on the computer.
If you would prefer not to run the program then you can try to fix with some fixes via HJT but the log shows there is still infection there and this may only stop it from running at the present, not actually remove it.
I have not had experience with people losing use of their computer while running combofix under supervision but this is your choice so we will forgo running it and attempt to remove this infection using HJT and then doing manual search and removals.

Anyway,
Run HJT again and place check marks next to the following entries:
O4 - HKUS\S-1-5-19\..\Run: [lolafegaku] Rundll32.exe "C:\WINDOWS\system32\fupuvuyu.dll",s (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [lolafegaku] Rundll32.exe "C:\WINDOWS\system32\fupuvuyu.dll",s (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [lolafegaku] Rundll32.exe "C:\WINDOWS\system32\fomihari.dll",s (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [lolafegaku] Rundll32.exe "C:\WINDOWS\system32\fomihari.dll",s (User 'Default user')

O20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GOEC62~1.DLL C:\WINDOWS\system32\zewuzano.dll
O22 - SharedTaskScheduler: {EC43E3FD-5C60-46a6-97D7-E0B85DBDD6C4} - SSODL - (no file)
O23 - Service: lxcz_device - - C:\WINDOWS\system32\lxczcoms.exe

Once you have placed the check marks then click the Fix Checked button.
Exit HJT.
Reboot the computer.
Run a new HJT scan and save the log and post it back here.
There will then be some manual searches and removals you will have to try.
Last edited by jholland1964; Jan 2nd, 2009 at 2:04 pm.
Reply With Quote