Getting rundll error cannot find gzmrt.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bairdclan, Dec 8, 2007.

  1. Bairdclan

    Bairdclan Private E-2

    Hi I hope somebody can help me.

    When I start up my PC I am getting a rundll error cannot find gzmrt.dll. I think it is caused by malware or a trojan or something. Can anybody help me, it is causing various problems on my pc.

    Thanks in advance

    Bairdclan

    Edit : Removed inline Hijackthis log
     
    Last edited by a moderator: Dec 8, 2007
  2. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Welcome to Majorgeeks!

    If your suspecting malware as the cause, then please run the guide below and attach the logs created, this will give a good overall picture of what could be infecting your PC, then our malware experts can issue you some more removal instructions if needed.

    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. Bairdclan

    Bairdclan Private E-2

    Hi Halo,

    Thanks for the help. I am having trouble with IEXPLORER, so it is taking me a while to get back online. I am now running through the cleaning scripts.

    The problem I am having is the iexplorer process is starting but no window. I have to go to the windows task manager to kill the process before I can try to start iexplorer again. Can this be a part of the malware problem ?

    Cheers

    Bairdclan
     
  4. Bairdclan

    Bairdclan Private E-2

    I have followed the directions given and uploaded what file I had. I had previously ran Spybot and removed a lot of the problems listed. I still seem to get the rundll error on start up "cannot find gzmart.dll" and iexplore.exe is not starting properly. It is creating a process but no window pops up. I have to kill the process and then after a few attempts iexplore starts. Then after a while iexplore does not work again but there is a process and I have to again kill it.

    I hope ou can help me.

    Regards

    Bairdclan
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to run the other scans that were requested and attach the logs. I'm referring to the first steps that request ComboFix and AVG Antispyware to be run and logs to be posted.


    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of software:
    Java 2 Runtime Environment, SE v1.4.1_02

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: UltraEdit Toolbar - {4E7BD74F-2B8D-469E-85AA-FD60BB9AAE22} - C:\PROGRA~1\UE_TOO~1\UE_TOO~1.DLL (file missing)
    O3 - Toolbar: (no name) - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - (no file)
    O3 - Toolbar: UltraEdit Toolbar - {4E7BD74F-2B8D-469E-85AA-FD60BB9AAE22} - C:\PROGRA~1\UE_TOO~1\UE_TOO~1.DLL (file missing)
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} - http://software-dl.real.com/166a013cbe4d58c10406/netzip/RdxIE601.cab

    After clicking Fix, exit HJT.

    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt
    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now please download the newest version of MGtools form here: MGtools.exe
    Save it to C:\MGtools.exe as previously requested in the READ ME. Then run MGtools.exe by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
    Last edited: Dec 11, 2007
  6. Bairdclan

    Bairdclan Private E-2

    Thanks for you reply Chaslang,

    I will try your suggestion out tonight when I get home. I did run combofix and AVG but I did not see any log files. I will try again, although AVG did come up with two trojans and three cookie redirectors.

    Question: Do I need to place my pc again in normal startup in msconfig to do these tests ?

    Regards

    Bairdclan
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your PC should always be in normal startup. There is no reason for it not to be. Why are you not in normal startup?
     
  8. Bairdclan

    Bairdclan Private E-2

    Thanks for your help,

    I am posting the MGlogs.zip and the avenger.txt file. I am still having problems with iexplorer though.

    Regards

    Bairdclan
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not download the new version of MGtools as requested in message number 5. Thus you still have a problem that GetRunKey did not work properly.

    Also according to your logs you have never run ComboFix. That is why you have no log for it.

    Your logs show no signs of malware. You may need to look elsewhere to resolve problems with Internet Explorer. Perhaps you have software conflicts or missing components of Windows. You could try running sfc /scannow from the Start, Run box.

    You could also try uninstalling some of the toolbars (Google, Yahoo, SnagIt, Norton).

    Other than the above, you may wish to post as much detail as possible about your problem in the Software Forum. Also test whether the problem occurs if you boot into safe mode.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds