![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
LinkBack | Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
rundll32.exe not found error. Cannot run dds or GMER
Hello,
My computer is infected with this virus/spyware System Security Version 4.52. I am unable to open a browser to get the logs files mentioned in the instruction on how to remove the malware. I tried using my laptop to download dds.scr and gamer.exe and copied to the infected PC. But the program wont run or do anything. It seems that the whole computer is hijacked. Please help. Thanks Anu |
|
|
| Important Information |
|
Join the #1 Tech Support Forum Today - It's Totally Free!
TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free. Join TechSupportforum.com Today - Click Here |
|
|
#2 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
Re: System Security Version 4.52 virus
Here is the latest update. When I logon now, I get the popup saying cannot find rundll32.exe Application not found. After I click ok, nothing works. I cannot open any application.
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
rundll32.exe not found error. Cannot run dds or GMER
I am unable to run GMER or DDS on the computer because of the rundll32.exe not found error. When I opened browwer, It prompted to open with popup. I clicked firefox again and it opened the broswer. I did a free online scan from Kaspersky and found I have numerous trojans. The log is attached here. Please help.
Thanks -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0 REPORT Saturday, August 1, 2009 Operating System: Microsoft Windows XP Professional Service Pack 3 (build 2600) Kaspersky Online Scanner version: 7.0.26.13 Program database last update: Saturday, August 01, 2009 19:42:06 Records in database: 2570735 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ E:\ F:\ G:\ H:\ Scan statistics: Files scanned: 128914 Threat name: 10 Infected objects: 17 Suspicious objects: 1 Duration of the scan: 02:44:44 File name / Threat name / Threats count c:\windows\system32\iasex.dll/c:\windows\system32\iasex.dll Infected: Trojan-Spy.Win32.Agent.aytn 1 c:\windows\system32\evdoserver.dll/c:\windows\system32\evdoserver.dll Infected: Trojan.Win32.Koblu.ang 1 C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IOLDCW4Y\w[1].bin Infected: Trojan-Downloader.Win32.DlfBfkg.ry 1 C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\IOLDCW4Y\w[2].bin Infected: Trojan-Downloader.Win32.DlfBfkg.ry 1 C:\SW\Microsoft Money 2007 Home & Business.iso Infected: not-a-virus:Monitor.Win32.Ardamax.k 1 C:\WINDOWS\Fonts\cooecp.tlb Infected: Trojan-Dropper.Win32.Agent.aven 1 C:\WINDOWS\Fonts\logcde.dll Infected: Trojan-Dropper.Win32.Agent.aven 1 C:\WINDOWS\Fonts\services.exe Infected: Trojan-Spy.Win32.VB.bvw 1 C:\WINDOWS\Fonts\windef.dll Infected: Trojan-Dropper.Win32.Agent.aven 1 C:\WINDOWS\Fonts\windef.Log Infected: Trojan-Dropper.Win32.Agent.aven 1 C:\WINDOWS\Fonts\winpaged.ocx Infected: Trojan-Dropper.Win32.Agent.aven 1 C:\WINDOWS\system32\EvdoServer.dll Infected: Trojan.Win32.Koblu.ang 1 C:\WINDOWS\system32\ghaf8jkdfd.dll1 Infected: Trojan-Downloader.Win32.Agent.ckkp 1 C:\WINDOWS\system32\Iasex.dll Infected: Trojan-Spy.Win32.Agent.aytn 1 C:\WINDOWS\system32\LA37A.tmp.exe Infected: Trojan-Downloader.Win32.PepperPaper.ja 1 C:\WINDOWS\system32\net.net Suspicious: Packed.Win32.PECompact 1 C:\WINDOWS\system32\vhosts.exe Infected: Trojan-Downloader.Win32.Agent.azg 1 C:\WINDOWS\Temp\xtva1jk.exe Infected: Trojan-Downloader.Win32.Agent.ckkp 1 The selected area was scanned. |
|
|
|
|
#4 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2009
Location: Florida
Posts: 650
OS: Windows XP
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Hello, and welcome to TSF.
I am currently reviewing your log. I will be back with a fix for your problem as soon as possible. Please subscribe to this thread to get immediate notification of replies as soon as they are posted. To do this click Thread Tools, then click Subscribe to this Thread. Make sure it is set to Instant Notification, then click Subscribe. Please be patient with me during this time. |
|
|
|
|
#5 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2009
Location: Florida
Posts: 650
OS: Windows XP
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Hello again anu1,
One or more of the identified infections is a backdoor trojan. This allows hackers to remotely control your computer, steal critical system information and download and execute files. If you do any banking or other financial transactions on the PC or if it should contain any other sensitive information, please get to a known clean computer and change all passwords where applicable, and it would be wise to contact those same financial institutions to apprise them of your situation. How Do I Handle Possible Identify Theft, Internet Fraud and CC Fraud? When Should I Format, How Should I Reinstall For the time being I will proceed on the assumption you wish to clean up your computer and have provided some more things I would like you to try and do. Note the GMER scan I have for you is different than the one in our initial instructions. If you do not wish to continue and would rather reformat or reinstall let me know in your next reply. Download GMER Rootkit Scanner from here to your desktop.
**Caution** Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries If no success with GMER give this one a try:
Also please run the following:
In your next reply please provide either the GMER or RootRepeal log if successful with running one of them and the two logs from RSIT Thank you, thewall |
|
|
|
|
#6 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Hello,
Thanks for helping me out. I am unable to run any of the exe's you mentioned. When I double click the exe, it prompts me with a window saying Choose the program you want to open this file with? and gives all programs installed in the computer? Please advice. Thanks |
|
|
|
|
#8 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
Re: rundll32.exe not found error. Cannot run dds or GMER
System Security is no more there. I found the directory where the files were there and deleted it. Since then atleast I can use explorer and my desktop does not have that blue screen saying my computer is infected and asking me to buy some software.
|
|
|
|
|
#9 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2009
Location: Florida
Posts: 650
OS: Windows XP
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Here's what I want you to try first:
Navigate to this directory using Windows Explorer -> C:\Documents and Settings\All Users\Application Data Look for a folder named like this - 12365489 (all numbers) Drag that folder over to Desktop while you are still in Explorer and drop it there. Now reboot the machine. If you can find the folder and complete the instruction try to run the tools I gave you in post #5. |
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Hello,
There is no folder called Application Data under C:\Documents and Settings\All Users If its hidden, I dont have the folder option under tool menu to select show hidden files. It seems everything in my computer is messed up. |
|
|
|
|
#11 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2009
Location: Florida
Posts: 650
OS: Windows XP
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Try this next:
Download This file to your Desktop and double click on it. After doing so see if you can get the tools to run. It's getting late so it will probably be tomorrow before I am back to work on this but don't despair we'll keep trying to straighten it out. |
|
|
|
|
#13 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2009
Location: Florida
Posts: 650
OS: Windows XP
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Hi anu1, I'm back.
Let's try running what we did in post #11 but this is a different file: Download This file to your Desktop and double click on it. After doing so see if you can get the tools to run. ................................................. If you can't I need for you to go to Start>>Control Panel>>Folder Options and click on File Types. There should be quite a few entries showing up in there. Let me know if there are, you don't have to be all that specific I just need to know if they are there. |
|
|
|
|
#14 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Hello,
I had to leave out of state this morning for work. I will be back home on Saturday. I will test this file once I reach home. Thanks for all your help and this site. |
|
|
|
|
#16 (permalink) |
|
Registered User
Join Date: May 2008
Posts: 74
OS: XP SP2
|
Re: rundll32.exe not found error. Cannot run dds or GMER
Hello,
I followed the steps you mentioned and I am getting the same popup window. Choose the program you want to use to open the file. Also there is no folder option under control panel. I guess its hijacked by this virus |
|
|
|
|
#17 (permalink) |
|
Analyst, Security Team
Join Date: Jun 2009
Location: Florida
Posts: 650
OS: Windows XP
|
Re: rundll32.exe not found error. Cannot run dds or GMER
I might as well be straight up with you here and let you know things are not looking real good right now. You may need to start thinking about a reformat due to the damage that has been done to your computer. Some of these new rogues are really tearing machines up bad. It seems that is you don't want to buy their nefarious products then they will do their best to just screw up your whole computer.
We are going to try ComboFix. Let's just hope it will run. Please download ComboFix from this location: HERE * IMPORTANT !!! Save ComboFix.exe to your Desktop
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures. ![]() Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message: ![]() Click on Yes, to continue scanning for malware. When finished, it will produce a log for you. Please include the C:\ComboFix.txt in your next reply. |
|
|
| Thread Tools | |
|
|