C:\WINDOWS\system32\rundll32.exe missing

Discussion in 'Malware Help (A Specialist Will Reply)' started by sschlech, Apr 17, 2005.

  1. sschlech

    sschlech Private E-2

    My computer isn't running properly. I can't find rundll32.exe. I can't add a new user account to try to correct the problem, can't right click on my computer (get the same error), and can't restore to previous date. I have purchased registry mechanic and already ran it, but that hasn't fixed the problem either. HELP!?!? Thanks.
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  3. sschlech

    sschlech Private E-2

    I have attached the hijack log per your request. I GREATLY appreciate your
    help on this.
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Are you familiar with PC MightyMax?



    Please print out these instructions so that you can operate with All Browser Windows CLOSED.

    Please make sure System Restore is OFF and the Viewing of Hidden Files & Folders is Enabled as per the tutorial.


    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O2 - BHO: (no name) - {354AB737-9F7A-427D-F432-543951A811C9} - (no file)
    O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
    O2 - BHO: (no name) - {6E894291-02A4-4625-A20B-4FDF957D8905} - (no file)
    O2 - BHO: (no name) - {9CE808E9-9F22-CF85-2334-BCA9309A5BC3} - C:\WINDOWS\system32\yogpvlpt.dll

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)

    O16 - DPF: {9522B3FB-7A2B-4646-8AF6-36E7F593073C} (cpbrkpie Control) - http://a19.g.akamai.net/7/19/7125/1441/ftp.coupons.com/v3123/cpbrkpie.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.


    NOW:
    Download Pocket KillBox

    Now, Copy and Paste C:\WINDOWS\system32\yogpvlpt.dll into the box – If it exists, it will show up in Blue. Check the option to Delete on Reboot and Click the Red X and Yes to the confirmation message. A message will ask if you want to reboot now – Click NO.

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    After doing ALL of the above, REBOOT!

    Scan with HijackThis and attach the new log.
     
  5. sschlech

    sschlech Private E-2

    I 'tried' to turn off system restore but was unable to do to ....rundll.32 missing. (Ughhhhh!) Although, I did turn it off in the spybot program. I followed the rest of the email and have attached the latest hijack file.
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is now clean!

    If your problem remains you will need to post this problem in the Software Forum. Those guys will get you all fixed up. Your most likely going to have to extract this file from the original disk.

    You should also see this thread on How to Protect yourself from malware!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds