c:\WINDOWS\system32\gzmrotate.dll

Discussion in 'Malware Help (A Specialist Will Reply)' started by barnard83, Dec 18, 2007.

  1. barnard83

    barnard83 Private E-2

    I've had the message c:\WINDOWS\system32\gzmrotate.dll pop up each time I log onto my computer. It doesn't seem to be causing any major problems but it would be nice to rid of it before it develops into anything worse. How do I go about this as I've run the programmes in 'Read and run me first before asking for support' and is doesn't appear to have corrected it?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You forgot to attach the two other requested logs from ComboFix and AVG Antispyware. Please attach them.


    Please be more careful in the future following instructions. You ran MGtools.exe from here:
    C:\Documents and Settings\Matthew Barnard\My Documents\Spyware\MGtools.exe
    We specifically requested that it be run from here: C:\MGtools.exe
    Running it like you ran it can often result in improper execution. You were lucky this time but you may not be so lucky in the future. Quite often tools will not work as desired unless instructions for using them are followed.

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 11
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 9
    Java(TM) 6 Update 2
    Java(TM) SE Runtime Environment 6 Update 1
    Mozilla Firefox (2.0.0.6)
    Search Assist
    Viewpoint Media Player <-- should have been uninstalled in step 0 of the READ ME

    Then install the current version of FireFox from: Mozilla Firefox


    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: rightonadz browser optimizer - {971C3384-F75E-4562-95B3-CBE7417529BC} - C:\WINDOWS\system32\gzmrotate.dll (file missing)
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [hid_start] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\gzmrotate.dll" DllVerify

    After clicking Fix, exit HJT.

    Now delete the below files.
    C:\WINDOWS\system32\rightonadz-uninst.exe
    C:\WINDOWS\mickey32.dll

    If you have problems deleting the above files, try deleting them in safe mode.

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger.

    Make sure you tell me how things are working now!
     
  3. barnard83

    barnard83 Private E-2

    Sorry, this is all new to me. AVG did not produce a report despite following the instructions, how can i correct this?

    I followed everything else except I couldn't get Avenger to work. What script do I input?

    I restarted the computer and it was very slow to switch off but otherwise everything seems to be normal. The original message I was getting no longer appears at start-up.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Sorry! I decided not to have you run Avenger and neglected to remove the remark about the Avenger log.

    You logs are clean!

    If you are not having any other malware problems, it is time to do our final steps:
    1. If we used Pocket Killbox during your cleanup, do the below
      • Run Pocket Killbox and select File, Cleanup, Delete All Backups
    2. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt logs that was created.
    3. If we user SDFix you can delete all the SDFix related files and folders from your Desktop or whereever you installed it.
    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had your run FixWareOut, you can delete the Fixwareout.exe file and the C:\fixwareout folder.
    7. If we had you run Avenger, you can delete all files related to Avenger now.
    8. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
     
  5. barnard83

    barnard83 Private E-2

    That seems to have done the trick, thanks very much for your help. Merry Christmas.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds