I need help with RundII32 & RunDll errors

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by silvernblack, Dec 16, 2009.

  1. silvernblack

    silvernblack Private E-2

    Hello everyone, I am new here, and first off I just want to say thank you to the support experts who are helping us boneheads that got infected. A few days ago I was on justin tv watching an NFL football game that was blacked out in my area, then the following day, my web browser started redirecting to all these different websites in order to coax me, I knew something was wrong. I had the AT&T Mcafee free anti-virus software but evidently it didn't block some type of cryptor virus and trojan horse SHeur2.BYOY onto my system. I am fairly certain that's when I got the virus, because prior to that I was not having any type of issues. I subsequently, installed AVG, thats how I was able to identify the names of the culprits. I removed it with AVG, I also used an online scanner called Eset, I also used microsoft tool malware remover, ran full scans, defragmentized my hard drive, everything I possibly could to ensure a clean sweep. I was trying to run anti-malware bytes too, but it wont load after installing it, it gives two pop up windows with error messages; "vbAccelerator SGrid II Control run-time error 'o.' and run-time error '440': Automation error. I contacted Malware.org support and they advised me to download this file from microsoft(I have the link provided by malware support staff if anybody cares to give it a try? Just ask me and I will reply back along with a resolution alternative incase that doesn't work, it may work for you?) it didn't work for me, now I am :confusedawaiting another response from them regarding that. Anyhow, I think my computer may still me infected because when it boots up and is initializing the pop up windows appear each with different error messages; "RundII32.exe Bad Image" is in the header of the box, below that is the following message "The application or DII c: windows\system32\notepad.dll is not a valid windows image. Please check this against your installation diskette." The second error pop up shows "RundII" in the header, then below it "Error loading C:\windows\system32notepad.dII %1 is not a valid win32 application." I was also getting another message but that one went away. it had a similar extension except that one said "the specified module could not be found." Now i followed everything to clean an infected computer per the "read me first," instructions and have the super anti spyware report log and root log available, will attach these files consequently upon being directed to do so. My computer is not currently redirecting to these phony hacker websites now, but am very concerned that some strains or traces are still on my system files hiding, I stayed up all night educating my self with mass amounts of data and processes to gain the upper hand, I visited different forums but chose majorgeeks because I like the level of care I saw by reading how they helped other members with these type of concerns, I tip my hat to all of you that commit your time and livelihoods in assisting the less prudent in these type of cases, truly appreciate your presence. Especially to those of us whom don't have any employment right now or limited with very little income. Thankyou.:confused
     
  2. silvernblack

    silvernblack Private E-2

    Here are only two reports I was able to perform. thanks. Malwarebytes would not load, see original thread, MG tools would not because of error type 2, I followed the resolution path changed the appropriate key in registry editor, it still popped up with an error message. Now there is another suggestion in the resolution that is mentioned however it was too vague for me to follow, something about the error may be due to the "command.com file" but didn't attempt to mess with that, because I would a shot in the dark for me.
     

    Attached Files:

  3. silvernblack

    silvernblack Private E-2

    Sorry, I forgot to mention what type of OS I am running its windows XP home edition service pack 2.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    In the future, I recommend that you do not write execessively long run on paragraphs like you did in your first message. They are too hard to read and find important points. Remember, we are reading literally several hundred messages per day and eye strain is a problem. Messages like that will normally not be read in there entirety.

    Break things down into smaller paragraphs and keep to one idea/concept in a paragraph. Also please don't post any unnecessary extraneous information.


    It probably ran to some extent anyway. Did you bother checking for the log. Please attach the MGlogs.zip file so we can try to continue.


    Also let's try the beta version of ComboFix which is named KittyFix.exe

    Download ComboFix from http://download.bleepingcomputer.com/sUBs/Beta/KittyFix.exe and save it to your Desktop.

    Note: This is a beta version of combofix and might be unstable but tests done so far have proved it works well

    Note: It is important that it is saved directly to your desktop and run from the desktop and not any other folder on your computer.
    • Now Exit/Close/Disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
    • Close any open browsers and any other programs you might have running.
    • Double click on kittyfix.exe & follow the prompts.
      • If you are using windows XP It might display a pop up saying that "Recovery console is not installed, do you want to install?" Please select yes & let it download the files it needs to do this
    • When finished, it will produce a report for you. Please attach the "C:\ComboFix.txt" to your next message.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds