2011-05-12, 06:02
I too am dealing with Click.GiftLoad. I have tried removing it multiple times (including in SafeMode) without any success. I am following the sticky on posting my information.

I ran ERUNT, DDS and Spybot this morning before work and save the required information. I turned the PC off, but since I turned it on this evening the svchost.exe has been using over 75% of the CPU. I took 30 minutes just to create this post!


Spybot Results Text must follow as I have too many characters for one post.

My Spybot results text is over 300,000 characters, but the forum limits me to 64,000. I will have to submit it as a zip file.
At this time I am on another computer, as the other one has become non-responsive and I am trying to reboot it. I will post the zip file as soon as possible.

Here is the windows zipped Spybot results text.

--- Search result list ---
Click.GiftLoad: [SBI $89783858] User settings (Registry value, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION\svchost.exe

--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2011-05-15, 22:10

Please read Before You Post (http://forums.spybot.info/showthread.php?t=288)
While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

Until we deem your system clean I am going to ask you not to install or uninstall any software or hardware except for the programs we may run.

I am looking at Trendmico, Avast and AVG Anti virus on your system, more than one is overkill , will just slow down your system and cause all sorts of problems, your call but you need to go to Add Remove Programs in the Control Panel and uninstall two of them


[HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\featurecontrol\FEATURE_BROWSER_EMULATION]

Copy the entire contents inside the Quote box and Paste it into Notepad ( this will only work with Notepad ) name the file Regfix.reg and in the drop down box, save it as All Files. Save it to your desktop. Then Rightclick on the Regfix.reg file and click on Merge, when it asks you to merge with the Registry, say yes.

If you saved the file correctly it should look like this http://i24.photobucket.com/albums/c30/ken545/reg.jpg

Please download Malwarebytes from Here (http://www.malwarebytes.org/mbam-download.php) or Here (http://www.majorgeeks.com/Malwarebytes_Anti-Malware_d5756.html)

Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected .
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Post the report please

2011-05-16, 00:07

Thank you for responding to my post.:bigthumb: I have have been succesful in removing the Click.GiftLoad malware. It turns out I also had the TDL4 rootkit. I have been running Spybot, Malwarebytes and Kaspersky Antivirus multiple times the last two days and the system is still clean. This forum has been a great help.:angel:

Thanks again. You can close this issue

2011-05-16, 00:11
Been at this for over 9 years, I cant begin to tell you about the amount of people that say they fixed the issue but are still infected. Rootkits are nasty and hard to remove. I would suggest you run this program to check, but this is your call, if no reply from you in 24 hours the thread will be closed

Download aswMBR.exe (http://public.avast.com/~gmerek/aswMBR.exe) ( 511KB ) to your desktop.

Double click the aswMBR.exe to run it

Click the "Scan" button to start scan

On completion of the scan click save log, save it to your desktop and post in your next reply