rundll32.exe going nuts

Discussion in 'Malware Help (A Specialist Will Reply)' started by memorymoon, May 11, 2008.

  1. memorymoon

    memorymoon Private E-2

    Hi there

    Seems like my rundll32.exe going nuts here.
    It i starting and stopping all the time. and the Mousepointer is blinking all the time
    And it is using ALOT of cpu

    MY OS are: XP Home, SP3

    Pasting a copy of my hijackthis

    Thanks in advance for all the help i can get
    /////////////////////////
     

    Attached Files:

    Last edited by a moderator: May 11, 2008
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Your problems may not be malware. The below will tell us. However also answer this, did you problems begin before or after installing SP3?


    Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. memorymoon

    memorymoon Private E-2

    Hi there and thank u!

    I attached the superatispy and the malwarebytes log
    And i did some cleaning.. seems ok now.
    No, the problem started a few days after the SP3 was installed.
    On the files u will see the problems i had. But after cleaning.. the rundll32 problem is gone :) ..i hope

    Then i attached the new hijackthis log
    Is there any more steps i should take?
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi memorymoon,

    Since the two scans did show some malware, it would be a good idea for you to download and install the MGTools to make sure there aren't any remnants of those trojans left. If there are any files left, the malware will just start up again. Here's the link for the tools: Using MGTools

    I think it would be worth your time to run them (takes two minutes) and attach the logs and have Chaslang look at them for you.

    abri
     
  5. memorymoon

    memorymoon Private E-2

    Hi abri, thank you for the tip
    And here are the log:)
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The only issues I see are non-malware. And several are things that the READ & RUN ME already stated.

    From Step 1 of the READ & RUN ME:
    1. You are using MSconfig to control startups. See what we recommended in step 1 of the READ & RUN ME.
    2. Uninstall the below software:
      • Java(TM) 6 Update 3
      • Messenger Plus! Live <-- We strongly recommend not trusting/using this application.

    Now also do the below to remova a leftover from Windows Live Messenger.

    Run C:\MGtools\analyse.exe by double clicking on it. This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    After clicking Fix, exit HJT.

    Now let's cleanup from running the READ ME.

    If you are not having any other malware problems, it is time to do our final steps:
    1. You can uninstall SUPERAntiSpyware now.~
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\cf" /u
        • Notes: The space between the cf" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\cf folder from combofix.
    3. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    8. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  7. memorymoon

    memorymoon Private E-2

    chaslang;
    Thanks for all the help. All the things you said are done, and the comp is even faster. :)
    Is Superantispyware something to have installed for later use?

    M/
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You can keep it it you wish. But I would change the options so that it does not run at startup. It is a useful scanner as is Malwarebytes.
     
  9. memorymoon

    memorymoon Private E-2

    Ok, i did install it again after the reboot cus the rundll32.exe did again started to go nuts. Scanning the same way as i did the first time right now

    the rundll32 is starting and stopping all the time (again), and on the running process it shows up to 5 or 6 rundll32.exe at the same tinme, and uses a lot of cpu and memory.
    I have checked that the rundll32.exe only are in system32, and nowhere else

    Somehow i suspect the bluetooth to controll the thing.. hmm..

    attaching the hijackthis.log
    and the startuplist.txt

    EDIT: found this now:
    found this
    w32/Dloader.GBVM
     

    Attached Files:

    Last edited: May 12, 2008
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please do not attach HijackThis logs that you run. It needs to be installed properly and renamed (like it was with MGtools) to be effective.

    Where did you find w32/Dloader.GBVM and what program found it? Was it Norman?? Could be a false positive so I need to know exactly where it believes the problem is located.
     
  11. memorymoon

    memorymoon Private E-2

    The w32/Dloader.GBVM was found by Norman when i tryed to install the Malwarebytes again.
    Then i downloaded the malwarebytes from a second site on the list, then ok..
    Then under the scan, Norman found more of the w32/Dloader.GBVM in the cache... 4 more. Still running the scan on superAntispyware and malwarebytes.

    Norman also deleted the hide.reg under the installation of MGtools

    Attaching the MGlogs.zip
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then it is a know false positive issue with Norman that they need to address. They are detecting MBAM as a problem when it is not.

    Another false positive. All that registry fix does is to set hidden files and folders back to normal defaults. Seems like Norman has some issues they need to resolve.
     
  13. memorymoon

    memorymoon Private E-2

    Thanks.
    I did call norman today, and they is now looking at the files i downloaded and looking at this thread :)
    And the resolved my problem over remote for free.
    Somehow they said my service host file was corrupt my malware... still waiting for a mail that explains better. Will update u on this!
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are they referring to one of their own files??? Or did you mean the below file which is part of Windows:
    C:\WINDOWS\system32\drivers\etc\hosts

    While we did not look at the contents of your host file, the size appears to be what would be expected for a Windows default.
     
  15. memorymoon

    memorymoon Private E-2

    The answer i finally got was... the service host went nuts cus of the malware tried to infect the SD brick i had the machine.
    When i took the SD brick out... all the problems "went away"..

    Well..hmm..
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I still don't know what you (or they) mean by "the service host". Also what is an SD brick?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds