Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Rundll32.exe virus  (Read 3544 times)

0 Members and 1 Guest are viewing this topic.

ILikePie

    Topic Starter


    Greenhorn

    Rundll32.exe virus
    « on: August 12, 2008, 09:46:32 AM »
    Hi everyone I have this problem with my computer:
    Every time I run something advanced-ish(control panel,folder options,etc.) I get an ms-dos window with top saying
    C:\Windows\system32\rundll32.exe and then says "Program to big or fat to run" but it flashes on and off.
    And when i reboot my computer it comes up again this time for 15 seconds and it closes.
    What is gong on here? 

    kpac

    • Web moderator


    • Hacker

    • kpac®
    • Thanked: 184
      • Yes
      • Yes
      • Yes
    • Certifications: List
    • Computer: Specs
    • Experience: Expert
    • OS: Windows 7
    Re: Rundll32.exe virus
    « Reply #1 on: August 12, 2008, 09:51:34 AM »
    Start here: http://www.computerhope.com/forum/index.php/topic,46313.0.html

    A malware removal specialist will take over from here.

    ILikePie

      Topic Starter


      Greenhorn

      Re: Rundll32.exe virus
      « Reply #2 on: August 12, 2008, 09:56:16 AM »
      UH I have tried scaning before.... nothing

      kpac

      • Web moderator


      • Hacker

      • kpac®
      • Thanked: 184
        • Yes
        • Yes
        • Yes
      • Certifications: List
      • Computer: Specs
      • Experience: Expert
      • OS: Windows 7
      Re: Rundll32.exe virus
      « Reply #3 on: August 12, 2008, 10:00:05 AM »
      With what? Norton, McAfee? They won't pick up certain things.

      If you want to get clean, please follow my instructions.

      Carbon Dudeoxide

      • Global Moderator

      • Mastermind
      • Thanked: 169
        • Yes
        • Yes
        • Yes
      • Certifications: List
      • Experience: Guru
      • OS: Mac OS
      Re: Rundll32.exe virus
      « Reply #4 on: August 12, 2008, 10:01:16 AM »
      With what? Norton, McAfee? They won't pick up certain things.

      If you want to get clean, please follow my instructions.
      We need the three logs. (SAS, MBAM + HJT)

      ILikePie

        Topic Starter


        Greenhorn

        Re: Rundll32.exe virus
        « Reply #5 on: August 12, 2008, 12:35:25 PM »
        well i got the first log I just can't open it for some reson....

        ILikePie

          Topic Starter


          Greenhorn

          Re: Rundll32.exe virus
          « Reply #6 on: August 12, 2008, 12:54:29 PM »
          Here is the MBAM one:
          Malwarebytes' Anti-Malware 1.24
          Database version: 1045
          Windows 5.1.2600 Service Pack 2

          11:52:47 AM 8/12/2008
          mbam-log-8-12-2008 (11-52-47).txt

          Scan type: Quick Scan
          Objects scanned: 43850
          Time elapsed: 10 minute(s), 31 second(s)

          Memory Processes Infected: 0
          Memory Modules Infected: 0
          Registry Keys Infected: 22
          Registry Values Infected: 1
          Registry Data Items Infected: 0
          Folders Infected: 0
          Files Infected: 1

          Memory Processes Infected:
          (No malicious items detected)

          Memory Modules Infected:
          (No malicious items detected)

          Registry Keys Infected:
          HKEY_CLASSES_ROOT\Interface\{04a38f6b-006f-4247-ba4c-02a139d5531c} (Adware.Minibug) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Typelib\{3c2d2a1e-031f-4397-9614-87c932a848e0} (Adware.Minibug) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{c13d4627-02f5-4b03-897a-bf6a90022dd2} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\CLSID\{2b96d5cc-c5b5-49a5-a69d-cc0a30f9028c} (Adware.Minibug) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx (Adware.Minibug) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\minibugtransporter.minibugtransporterx.1 (Adware.Minibug) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{0be385a3-85a5-4722-b677-68dae891ff21} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{272c0d60-0561-4c83-b3db-eb0a71f9d2eb} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{284477e4-a7cb-4055-9e1b-0ea7cba28945} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{70ca4938-6a0f-4641-a9a9-c936e4c1e7de} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{7468213e-010e-4ec6-a17d-642e909ba7ec} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{a916af3c-976d-4358-8736-95bea0b5fd2c} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{b86f4810-19a9-4050-9ac9-b5cf60b5799a} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{bb5b7e14-f8b4-4365-a24d-f4965c33e1ee} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{be45f056-e005-437b-be88-23acf70b0b6a} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{e2032ec2-a9ac-4ed7-9bdb-ebecacf076f2} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{c636f1fc-6ae4-4e6a-90ab-6d61d821a0dd} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{cb971ac0-6408-40da-a540-92f9f256f51f} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{d5694dfe-43b6-4e05-aa29-8c556c968973} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{ebab4a71-8c34-461a-b57d-dd041d439555} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{f06fea43-0cc3-4bf6-a85b-5efb1c07aa4b} (Adware.WhenUSave) -> Quarantined and deleted successfully.
          HKEY_CLASSES_ROOT\Interface\{fc94a0f7-9c7c-4ae2-9106-5c212332b209} (Adware.WhenUSave) -> Quarantined and deleted successfully.

          Registry Values Infected:
          HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.

          Registry Data Items Infected:
          (No malicious items detected)

          Folders Infected:
          (No malicious items detected)

          Files Infected:
          C:\Program Files\Common Files\Real\WeatherBug\MiniBugTransporter.dll (Adware.Minibug) -> Quarantined and deleted successfully.

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Rundll32.exe virus
          « Reply #7 on: August 12, 2008, 02:50:48 PM »
          The HijackThis log is needed also.