no entry point found ntdll.dll

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by AKujin, Sep 18, 2010.

  1. AKujin

    AKujin Private E-2

    i recently removed a rootkit from this machine and a few days later it came back in the shop with the start of another kit but now it is giving me an error i am unfamaliar with and malwarebytes/spybot didnt find any associated reg key or anything that has fixed this yet but here goes.

    when trying to run many programs, including combofix.exe (i really want to run combo fix the most)i get the following message

    RtlReleaseRelativeName no entry point found in ntdll.dll

    this message pops up while autoruns are starting up and when i try and more importantly while trying to run combofix.exe.

    Erd50 didnt find any system files to repair, chkdsk is clean, cannot run system restore in erd50 to try and revert files back to a previous condition as system restore tool closes itself when running. I fancy myself pretty experienced with malware removal and i have never seen this ever. WHAT AM I MISSING HERE?
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This sounds more like a problem with Windows then malware. What exactly had been removed before and recently before this occurred. And does this happen when you boot in safe mode too. Also have you tried running sfc /scannow


    Don't use System Restore, trying manually doing the equivalent of what is in the below link. You can eliminate steps when using your own special boot disk instead of the Windows Recovery Console.

    How to recover from a corrupted registry that prevents Windows XP from starting


    You did not say what version of Windows so I assumed WinXP
     
  3. AKujin

    AKujin Private E-2

    yes it is windows xp, i haven't tried a full sfc /scannow because i didnt have an install disk handy, I did however start one and it immediately asked for an install disk so that may help.

    I did use the ERD50 SFrepair tool but i don't believe its as thorough as sfc /scannow.

    another method i tried for repair was searching for all files named ntdll.dll and replacing the one in system32 with the different copies hoping this would resolve the issue, it didn't. So now im not even sure that the issue is the file itself or the registry, or blah blah etc.

    EDIT: also i tried manually registering ntdll.dll with regsvr32, and it gives me another new message for me, ntdll.dll has been loaded, but the DllRegisterServer entry point was not found...
     
    Last edited: Sep 18, 2010
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I suggest running sfc to see what happens.

    Also if necessary, use the link I gave you to do a restore of the registry hives shown. This is not a full system restore but sometimes gets a PC to be able to boot up and then a full restore may be possible.
     
  5. AKujin

    AKujin Private E-2

    II will give them both a try, I just dont want to have to recommend the cop out of a format and windows reinstall, i want to try everything for repair first.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let us know how it goes.
     
  7. AKujin

    AKujin Private E-2

    sfc scannow worked! hallelujah, then was able to use combofix, and yep still a rootkit present, this was a really really awful rootkit, never seen one this hard to remove
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the log from running Combofix. You should also download the latest version of MGtools and save it to your root folder. Then run the exe and attach the C:\MGLogs.zip.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds