Hello wiggles malone, and welcome to TSF. You may wish to
Subscribe to this thread so that you are notified when you receive a reply. To do this click
Thread Tools (above the first post), then click
Subscribe to this Thread. Make sure it is set to
Instant Notification, then click
Subscribe.
Those entries that said "INFECTION WARNING!" in your Silent Runners log were red herrings -- they were all legit. However, I did find one entry in there that we need to take care of.
Please print out or copy this page to Notepad in order to assist you when carrying out the following instructions. If there is anything you don't understand, please ask BEFORE proceeding with the fixes. Please do these steps in order and do not skip any.
Unhide Files
Go to
My Computer > Tools > Folder Options > View tab and
select "Show hidden files and folders".
Uncheck the "Hide protected operating system files (Recommended)" option. Also make sure there is no checkmark beside "Hide file extensions for known file types". Click OK.
Antivirus Required
I notice that you do not appear to have an active antivirus program. Connecting to the Internet without antivirus protection is a "Welcome" doormat for malware. It can take as little as
eight seconds to infect an unprotected computer. Here are two very good free antivirus products which are available:
Please install one of these now. Do not install more than one antivirus program because they will conflict with each other. It is imperative that you update your antivirus software at least once a week (even more if you wish). If you do not update your antivirus software then it will not be able to catch new malware that may have come out.
Download ComboFix
Download ComboFix from one of the following links:
- http://www.techsupportforum.com/sectools/combofix.exe
- http://download.bleepingcomputer.com/sUBs/combofix.exe
Don't do anything with it yet.
Download CleanUp!
Download and install
CleanUp! but
do not run it yet.
WARNING: CleanUp! deletes
EVERYTHING out of temporary folders and
does not make backups. If you have any documents or programs that are saved in any temporary folders, please make a backup of these before running CleanUp!
WARNING: Do not run cleanup under Windows XP x64 Edition. If you're not sure if you have the 64-bit version of Windows then you probably do not; however, you can check by using IE to download the
whichcpu tool and then running it.
Download Ewido
Please download, install, and update
Ewido Anti-Spyware.
- Load Ewido and then click the Shield tab at the top
- Click on the word active to change it to inactive.
- Click the Update tab at the top:
- Under Manual update, click Start update. After the update finishes, the status bar at the bottom will display "Update successful". If you are having trouble updating, you can also download and run the manual updater.
- Under Automatic update, change the Update interval to something more reasonable like 12 or 24 hours.
- Click the Scanner tab at the top and then the Settings sub-tab:
- Under How to act?, click Recommended actions and select Quarantine.
- Under Reports, select Automatically generate report after every scan
- Close Ewido. Do not run a scan with it yet.
Disable SpySweeper
Please disable Webroot SpySweeper, as it may hinder the removal of some entries. You can re-enable it after you're clean. To disable SpySweeper:
- Go to the Options>Program Options.
- Uncheck Load at Windows Startup.
- Click Shields and uncheck all items there.
- Uncheck Home page shield.
Edit Regsitry
Go to Start→Run and type in
regedit and hit OK. Go to File→Export and save the registry somewhere as a backup. Close the Registry Editor now. Go to Start→Run and type in
notepad and hit OK. Then copy and paste the following into Notepad:
Code:
REGEDIT4
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\]
"{EB740041-E2A0-4346-A4DF-F2AFF42AB23D}"=-
Save the file as
"delete.reg". Make sure to save it with the quotes. Close Notepad. Double click on the
delete.reg file and choose
Yes to merge/add it to the registry. You may delete the file afterwards.
Reboot
Reboot your system to Safe Mode by repeatedly tapping the F8 key until the menu appears and choosing Safe Mode from the list. On some systems, this may be the F5 key so try that if F8 doesn't work. Login on with your usual account. Make sure to close any open windows.
Deletions
Fined the following file by going to to Start→Search and delete it if it still exists.
gasjzl0.dll
Run CleanUp!
Open
Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows:
- Click "Options..."
- Move the arrow down to "Custom CleanUp!"
- Put a check next to the following:
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
- Click on the "Temporary Files" and make sure the box for "Scan drives for file matching" is unchecked.
Click OK.
- Press the CleanUp! button to start the program.
Once it's finished CleanUp! will ask you to logoff/reboot. Please select
NO as we will do this later.
Run Ewido- Run Ewido and click on the Scanner tab at the top and then click on Complete System Scan. This scan can take quite a while to run, so be prepared.
- Ewido will list any infections found on the left hand side. When the scan has finished, it will automatically set the recommended action. Click the Apply all actions button. Ewido will display "All actions have been applied" on the right hand side.
- Click on Save Report, then Save Report As. Save the report so that you can find it again (like on the Desktop).
- Close Ewido.
Reboot
Reboot your system to Normal Mode.
Online Scan
Perform an online scan with Internet Explorer with
Panda ActiveScan.
- Click on the "Scan your PC" button located at the bottom of the page. A popup window should appear -- make sure you allow it if you have a popup blocker.
- Enter your e-mail address, country, and state and click Scan Now.
- Your computer will download Panda's 8 megabyte ActiveX control at this point. Follow the on-screen directions if it asks you to install the ActiveX control.
- Begin the scan by selecting My Computer. Note:
- Please turn off the real time scanner of any existing antivirus program while performing the online scan.
- Please ignore any entry it finds and the offer to buy the program to remove the entry, as we will address this later.
- Click on See report then click Save report.
- It is not necessary to remain online while it's doing the scan, but you will have to re-connect after it has finished to see the report.
Run ComboFix
Double click combofix.exe & follow the prompts. While ComboFix is running, please do not click or move the window, as this may cause the tool to stall. When the tool has finished, it will produce a log for you and save it as
C:\ComboFix.txt. Post that log in your next reply.
With Your Next Post...
Please paste the following with your next reply (in this order please):
- Ewido scan report,
- Panda Scan report,
- C:\ComboFix.txt, and
- a new HiJackThis log taken after ComboFix finishes.
Also let me know if IE is working again.