![]() |
| ||
| Re: Antivirus 2009 downloader + pop ups Malwarebytes' Anti-Malware 1.31 This scan as been done after i have previously ran the scan before a reboot and i get no pop ups. Next time i run my pc i will most likely have the virus back. |
| ||
| Re: Antivirus 2009 downloader + pop ups hmmm. You posted a link for the download of hijackthis instead of posting the log. Please post the log from hijackthis. |
| ||
| Re: Antivirus 2009 downloader + pop ups I asked whether this was the correct version lol. anyway. Logfile of Trend Micro HijackThis v2.0.2 |
| ||
| Re: Antivirus 2009 downloader + pop ups Can you please do the following. =============== You will have to disable Spybot's Teatimer before we begin, as it will interfere with the fix. To do this can you start Spybot and go to the Mode button and select Advanced. Go to Tools > Resident and uncheck the box next to Tea-Timer. Make sure that the icon in the system tray is no longer there. If it is, just right click on it and select "Exit". Download ResetTeaTimer.bat. Double click ResetTeaTimer.bat to remove all entries set by TeaTimer. Do not forget to re-enable teatimer when we are done :). If teatimer gives you a warning afterwards that some changes were made, allow this instead of blocking it. =============== Scan with HijackThis and then place a check next to all the following, if present: R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = O2 - BHO: (no name) - {7c291722-bc81-482c-ba4f-efbc4dbff141} - C:\WINDOWS\system32\gopikobi.dll (file missing) O4 - HKLM\..\Run: [CPMab2ce949] Rundll32.exe "c:\windows\system32\wotupogo.dll",a O4 - HKUS\S-1-5-19\..\Run: [tolonajari] Rundll32.exe "C:\WINDOWS\system32\sesotoja.dll",s (User 'LOCAL SERVICE') O4 - HKUS\S-1-5-20\..\Run: [tolonajari] Rundll32.exe "C:\WINDOWS\system32\sesotoja.dll",s (User 'NETWORK SERVICE') O20 - AppInit_DLLs: C:\WINDOWS\system32\zagubura.dll Now, close all instances of Internet Explorer and any other windows you have open except HiJackThis, click "Fix checked". =============== Locate and delete the following item(s), if present. Make sure you are able to view system and hidden files/ folders: files... c:\windows\system32\wotupogo.dll C:\WINDOWS\system32\sesotoja.dll C:\WINDOWS\system32\zagubura.dll - Note that some of these file(s)/folder(s) may or may not be present. If present, and cannot be deleted because they're 'in use', try deleting them in Safe Mode by doing the following:
- Reboot. =============== After rebooting, rescan with hijackthis and post back a new log. Please let me know how your pc is now. |
| ||
| Re: Antivirus 2009 downloader + pop ups No more annoying missing dll message on startup, pop ups or dlls you mentioned. But when trying to remove the entry from startup it now tries to add system32\sesotoja.dll", s.. ofc i deny the change, but this still means that some sort of process is active :-/. Logfile of Trend Micro HijackThis v2.0.2 My new log file. thx for the help btw. |
| ||
| Re: Antivirus 2009 downloader + pop ups You are running hijackthis from a temporary folder. Please move it to a permanent folder before your next post. == Please download ComboFix by sUBs from HERE or HERE
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine. |
| All times are GMT -4. The time now is 4:05 am. |
Forum system based on vBulletin Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©2003 - 2009 DaniWeb® LLC