GBDialler

Status
Not open for further replies.
Hi there.

I am having problems with a brand new pc. After only a handful of times on the web, the GBDialler appeared in my connections list, and no matter how many times I delete it, it reappears after a few minutes.

I followed the instructions posted by RealBlackStuff, and have attached the Hijack this .txt log. Any help would be much appreciated.

Cheers, sim
 
Hello and welcome to Techspot.

Boot into safe mode. See how HERE. http://www.bleepingcomputer.com/forums/tutorial61.html

Turn off system restore.(XP/ME only) See how HERE. http://www.bleepingcomputer.com/forums/tutorial56.html

In Windows Explorer, turn on "Show all files and folders, including hidden and system". See how HERE. http://www.bleepingcomputer.com/forums/tutorial62.html

Open your task manager by holding down the ctrl and alt keys and press the delete key.

Click on the processes tab and end process for(if there).

rdgGB2404.exe
rdgGB2427.exe

Close task manager.

Click start/run and type regsvr32 /u C:\WINDOWS\SYSTEM32\winszd32.dll into the run box and press the enter key.

Run HJT with no other programmes open. Have HJT fix the following, by placing a tick in the little box next to(if there).

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {4EDD7E56-3BAA-13B6-D0D4-4A6A2FE914A6} - http://69.50.173.166/1/rdgGB2404.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1136295802718
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1136297348421
O16 - DPF: {74CD40EA-EF77-4BAD-808A-B5982DA73F20} (YazzleActiveX Control) - http://yax-download.yazzle.net/YazzleActiveX.cab?refid=1123
O16 - DPF: {97B79133-88F0-45F0-8D57-0F2EF27D9C66} - http://85.255.114.166/1/rdgGB2427.exe
O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab?refid=5071
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing

O20 - Winlogon Notify: winszd32 - C:\WINDOWS\SYSTEM32\winszd32.dll

Click the fix checked button.

Close HJT.

Locate and delete the following bold files(if there).

C:\WINDOWS\SYSTEM32\winszd32.dll

rdgGB2404.exe
rdgGB2427.exe


Boot into normal mode and turn system restore back on.

Please post a fresh HJT log.

Regards Howard :wave: :wave:
 
Status
Not open for further replies.
Back