avg virus vaulted rundll32.exe & all exe programs won't work
Welcome, Guest. Please login or register. Did you miss your activation email?


Britec Computer Tech Help Support Forums  « Microsoft Support  « Windows XP Support « avg virus vaulted rundll32.exe & all exe programs won't work
Pages: [1]
  Print  
Author Topic: avg virus vaulted rundll32.exe & all exe programs won't work  (Read 2089 times)
akumakawa
Newbie
*
Posts: 3


View Profile
« on: March 31, 2011, 11:18:38 AM »

I believe that I have been given a false detection warning for the past few days on files. I was unconcerned about the pop up notices from AVG telling me to virus vault these files since I had believed at the time that it was true.

About two hours ago I got another pop up about some trojan. I was doing something at the time and just clicked on the thing to move it to the virus vault. After wards I noticed my browser was gone (crashed). I decided to restart.

Once my pc was restarted I noticed any application I tried to run would not work. I couldn't even get my system restore to work.

I realized the issue lay with rundll32.exe and it must have been moved to the vault. I went online found a copy of the file and replaced it but nothing worked. I don't know where my system restore disk is or I even had one.

The worst part is that I can't get the file to run at all. I go to start run and type cmd and I get a "open with" box because it can't find rundll32.exe to open any applications. It gives me a list of applications like firefox and photoshop from the list to try to open the file with.

I have a 2005 HP Pavilion a1540n with XP Home edition SP2.
I have the 2011 AVG Free antivirus.

I can't find my specs since that requires rundll32.exe as well.

Funny enough I can access the internet with Firefox (I hit something for help and my default browser loaded (I had all sorts of errors though because rundll32.exe is missing but it's working)). Internet Explorer I can't. It requires me to download the exe file.

I'm at a complete loss at what to do. I can't find my xp disk (I don't think it ever came with my computer as I have system restore built in).

How can I fix rundll32.exe if I can't run it?
Logged
Britec
Administrator
Hero Member
*****
Posts: 3498



View Profile
« Reply #1 on: March 31, 2011, 12:13:13 PM »

 Azn akumakawa

Welcome to the forum

You MIGHT be infected with Virut. A very nasty virus. Hard to get rid of it.

Or something like these Virtumonde / Msevents / Trojan.vundo

Lets get you some help, please follow instructions below


Please Boot to Safe Mode with Networking...

Please download and run the below tool named Rkill

There are 4 different versions. If one of them won't run then download and try to run the other one.

Vista and Win7 users need to right click Rkill and choose Run as Administrator

You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

* Rkill.com
* Rkill.scr
* Rkill.pif
* Rkill.exe

* Double-click on the Rkill desktop icon to run the tool.
* If using Vista or Windows 7 right-click on it and choose Run As Administrator.
* A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
* If not, delete the file, then download and use the one provided in Link 2.
* If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs (it can take a few trys to get it to run).
* Do not reboot until instructed.
* If the tool does not run from any of the links provided, please let me know.


Then try this if needed?
--------------------------------------------------------------------------------------------------------


If RKILL will not run at all, give exeHelper a try

Please download exeHelper.com or exeHelper.scr to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).


Then try this
--------------------------------------------------------------------------------------------------------------------

How to run a scan with Malwarebytes' Anti-Malware

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

    * Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
    * If an update is found, it will download and install the latest version.
    * Once the program has loaded, select "Perform Quick Scan", then click Scan.
          o If the program won't start, go to MBAM's program folder (normally C:\Program Files\Malwarebytes' Anti-Malware), rename mbam.exe to a random file name (keep the .exe extension) and double-click on it to start the program.

    * The scan may take some time to finish,so please be patient.
    * When the scan is complete, click OK, then Show Results to view the results.
    * Make sure that everything is checked, and click Remove Selected.
    * When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note Below)
    * The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.

Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.



Troubleshooting MBAM Problems


Some malware targets Malwarebytes' Anti-Malware and other cleaning tools to prevent you from using them to clean your system.

Unable to Run MBAM

If you attempt to run the installer for MBAM and it won't run, or starts and closes, using Windows Explorer go to the folder you saved the install program and try renaming it to one of the following file names:

    * iexplore.exe
    * explorer.exe
    * userinit.exe
    * winlogon.exe
    * mbam.scr



Then double-click on the renamed file to try to run it. If that doesn't work, try one of the other file names above. If you are still unable to run the MBAM installer, then download and run this program to try to kill the malware process:
« Last Edit: March 31, 2011, 12:15:06 PM by Britec » Logged



akumakawa
Newbie
*
Posts: 3


View Profile
« Reply #2 on: March 31, 2011, 03:13:48 PM »

Thank you for the response. After spending hours trying to figure out what was wrong and going in circles I hit the panic mode.

 You Rock


I ran my pc in safe mode. DL and installed RKill and exeHelper both:

I then ran Malwarebytes (since I already had it installed).

I was prompted to restart.

However it fixed nothing.

So I went back to safe mode and did system recovery to March 29th. It worked. The issue I had with rundll32.exe was fixed. I was extremely happy.

However you mentioned that you believe that I am infected. So I did the prudent thing and went back into safe mode because I want to make sure that I got rid of the virus/trojan (since I've been having these avg pop ups for a week now).

I ran rkill and got this message:

This log file is located at C:\rkill.log.
Please post this only if requested to by the person helping you.
Otherwise you can close this log when you wish.

Rkill was run on 03/31/2011 at 15:49:27.
Operating System: Microsoft Windows XP


Processes terminated by Rkill or while it was running:

C:\WINDOWS\system32\verclsid.exe


Rkill completed on 03/31/2011 at 15:49:29.


When I first ran it another file was terminated in addition to that one. And exeHelper again mentioned that it reset two file types one of them being exe.

When I first ran Malwarebytes (in quick scan) it said that 3 files were infected and they were registry files.

This time nothing popped up.

I restarted and everything seems to be running fine. I plan on running a full scan of Malwarebytes and my AntiVirus as well.


So everything should be cleared up, right?
« Last Edit: April 01, 2011, 03:09:22 AM by Britec » Logged
Britec
Administrator
Hero Member
*****
Posts: 3498



View Profile
« Reply #3 on: April 01, 2011, 03:11:24 AM »

You might want to take a look at this link below its all about C:\WINDOWS\system32\verclsid.exe

http://support.microsoft.com/kb/918165

So your computer is running ok now? no issues? clean scans?
Logged



akumakawa
Newbie
*
Posts: 3


View Profile
« Reply #4 on: April 01, 2011, 05:55:45 AM »

Huh. I've never had any issues like those mentioned in the link. Maybe because I had the patch installed as well?

So far so good. My anti-virus scan can back clean besides tracking codes. I'm running a full scan of malwarebytes right now.

Is there any other programs I should dl to scan my computer to make sure it is clean? Any that check to make sure there are no registry errors?

Or do you think I'm good right now?

So was I really infected?

Again thank you for all the help you provided.  You Rock
Logged
Britec
Administrator
Hero Member
*****
Posts: 3498



View Profile
« Reply #5 on: April 01, 2011, 08:25:25 AM »

I would run scans to make sure the system is clean.
Logged



Pages: [1]
  Print  
 
Jump to: