Win32\Sillydl.agc Please Help!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by fastest963, Jun 14, 2006.

  1. fastest963

    fastest963 Private E-2

    I have posted on bleepingcomputer.com, subratam.org and others but no one has ever replied.:(

    Please help me...

    When ever I run for a while Internet Explorer I get an anti-virus message saying that Win32\Sillydl.agc was found in "C:\Documents and Settings\Bob\Local Settings\Temporary Internet Files\Content.IE5\(always a different folder)\(something)[1].exe" and then it deletes it. Then about 1 second later it says that another file with the same virus is infected in "C:\Windows\Temp" and then it deletes it also.

    I checked out Temporary Internet Files and a part file from "http://installare.net/(something)/(something).php" and then I click on properties and the cache name is the same as the infected .exe file. I have never visited this website and to make sure there wasn't a link in another website, I just kept doing random searches in google and it still came up.

    I added this website to the "restristed sites" in internet explorer and I had ZoneAlarm block this website's content (none of these worked!) I looked around in ZoneAlarm and I noticed that some .tmp files were ran and the firewall let them pass. I thought that this was the problem and so I beffed up the firewall's program security! - I will post back to tell you if that helped!!

    But, please help becuase I cannot figure out the problem and I don't know If I should change the "windows temp" folder to someplace else or change the "Temporary Internet Files" to someplace else. - Will either one of these help?

    ...or should I just stop using Internet Explorer and use Firefox?

    I am running a custom build pc with a 1.8 GHz Processor, 496 Ram (internal graphics card = 16mb). It is about 2 years old. It has Windows Professional SP2.

    I included a "Hijack This" log becuase maybe the problem is in there, but I don't think so.

    I will run the "Bitdefender Online Scanner" and post the results later. But, does anyone have any tips or hints, or have they gone through the same problem! I also am thinking about installing "Windows Defender", but I already have "Spybot: Search and Distroy" and that is rated much higher. Should I try "WinGuard 2006 Pro" or South bay's "NoAds"??

    Thanks very much in advance
     

    Attached Files:

  2. AbbySue

    AbbySue MajorGeeks Administrator

    Hi fastest963:)

    You do not need to purchase anything in order to clean your computer or protect it. It doesn't matter if you are using free utilities or ones you purchase, no one tool does it all. SpyBot will detect things that Windows Defender won't and WD will find things that SB won't, etc. We have found the various steps outlined in the read & run me first to be the most effective process with a 100% success rate if you follow our instructions, and then give the requested feedback if questions are asked.

    To get started, please follow ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support

    Make sure you check version numbers and get all updates.

    - Very Important: Make sure you tell us the results from running the tutorial...was anything found? Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested? etc.


    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis and attach a log:

    Downloading, Installing, and Running HijackThis


    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too (these scans are covered in steps 6 & 7 of the READ & RUN ME sticky)
    Bitdefender
    Panda Scan
    HijackThis
     
  3. fastest963

    fastest963 Private E-2

    I will post another Hijack This log later today but here is my BitDefender Log!

    I deleted and unregistered winzoa32.dll with Killbox.


    I didn't have time last night to run Panda Scan (I have dial-up internet:rolleyes:) but I did run the BitDefender scan and I will run it again on Friday becuase the scan was 92% done when I stopped it, becuase I had my night shift to go to.

    Thanks so far
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well if you got rid of it then you may be clean. I would like to see a Panda log though. It often reveals things that other scans do not.

    You should also do the below.


    Delete all files in the below two folders ( where you need to replace the [Current User Account] text with the actual user account name you are logged into. )

    C:\Documents and Settings\[Current User Account]\Local Settings\Temp
    C:\WINDOWS\TEMP

    There could be a couple files or subfolders in the above to folders that Windows will not let you delete because they are in use.

    Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
     
    Last edited: Jun 15, 2006
  5. fastest963

    fastest963 Private E-2

    I will run it tonight and I will post the log, either tonight or sometime on Friday.

    I will also respond and say if I think that my computer is clean (no more antivirus messages!)

    Thanks so much (so far)
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     
  7. fastest963

    fastest963 Private E-2

    Thanks so much guys!!

    My computer is fixed and I think it was becuase I deleted the winzoa32.dll and other things found by Bitdefender's Online Scan!!

    Attached it the last log of the scan. (the things it found were in System Restore, which I stoped and created a new restore point!)

    Note: I could not get Panda Scan to work ... It kept saying the site was invalid after it finished downloading
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds