Rundll.exe virus?? Please help.

Discussion in 'Malware Help (A Specialist Will Reply)' started by mestizomagic, Dec 6, 2013.

  1. mestizomagic

    mestizomagic Private E-2

    Hello,

    I seem to have some sort of virus on my computer. It's not constant, but from time to time, there will be many, many instances of rundll.exe (sometimes hundreds), each one using between 1 and 4 MB of memory. Today I got the blue screen of death.

    I've run Malware-bytes anti-malware AND anti-rootkit. Neither found anything. I also ran Rogue Killer, but I'm not sure if any of the entries it brought up are actually problems, or if they're supposed to be there. I'll paste the log below, if anyone could help me out, I'd really appreciate it.

    I'm on an ASUS laptop running Windows 7 SP1, 64 bit.

    Here's the Roguekiller log:

    * * * * * * *

    RogueKiller V8.7.11 _x64_ [Nov 25 2013] by Tigzy
    mail : tigzyRK<at>gmail<dot>com
    Feedback : http://www.adlice.com/forum/
    Website : http://www.adlice.com/softwares/roguekiller/
    Blog : http://tigzyrk.blogspot.com/

    Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version
    Started in : Safe mode with network support
    User : Mestizo Magic [Admin rights]
    Mode : Scan -- Date : 12/06/2013 08:50:03
    | ARK || FAK || MBR |

    ¤¤¤ Bad processes : 0 ¤¤¤

    ¤¤¤ Registry Entries : 8 ¤¤¤
    [RUN][SUSP PATH] HKCU\[...]\Run : ASUS (rundll32 "C:\Users\Mestizo Magic\AppData\Local\{939D5803-CF52-4E73-8562-CCD72242C876}\ASUS\mppfbfokgj.dll",DllRegisterServer [x][x][x]) -> FOUND
    [RUN][SUSP PATH] HKCU\[...]\Run : Button Production BS (rundll32 "C:\Users\Mestizo Magic\AppData\Local\Google\Button Production BS\feddpfnb.dll",DllRegisterServer [x][-][x]) -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-3508545463-1312762450-1126272402-1000\[...]\Run : ASUS (rundll32 "C:\Users\Mestizo Magic\AppData\Local\{939D5803-CF52-4E73-8562-CCD72242C876}\ASUS\mppfbfokgj.dll",DllRegisterServer [x][x][x]) -> FOUND
    [RUN][SUSP PATH] HKUS\S-1-5-21-3508545463-1312762450-1126272402-1000\[...]\Run : Button Production BS (rundll32 "C:\Users\Mestizo Magic\AppData\Local\Google\Button Production BS\feddpfnb.dll",DllRegisterServer [x][-][x]) -> FOUND
    [HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK][PUM] HKCU\[...]\ClassicStartMenu : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND
    [HJ DESK][PUM] HKCU\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
    [HJ DESK][PUM] HKCU\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

    ¤¤¤ Scheduled tasks : 0 ¤¤¤

    ¤¤¤ Startup Entries : 0 ¤¤¤

    ¤¤¤ Web browsers : 0 ¤¤¤

    ¤¤¤ Particular Files / Folders: ¤¤¤

    ¤¤¤ Driver : [NOT LOADED 0x0] ¤¤¤

    ¤¤¤ External Hives: ¤¤¤

    ¤¤¤ Infection : ¤¤¤

    ¤¤¤ HOSTS File: ¤¤¤
    --> %SystemRoot%\System32\drivers\etc\hosts




    ¤¤¤ MBR Check: ¤¤¤

    +++++ PhysicalDrive0: ( @ ) +++++
    --- User ---
    [MBR] a456e452513bca1d2ffa50ff29a406a0
    [BSP] 76dc91ed2e1903170af3917402d654e6 : Windows 7/8 MBR Code
    Partition table:
    0 - [XXXXXX] FAT32-LBA (0x1c) [HIDDEN!] Offset (sectors): 2048 | Size: 25600 Mo
    1 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 52430848 | Size: 202291 Mo
    2 - [XXXXXX] EXTEN-LBA (0x0f) [VISIBLE] Offset (sectors): 466722816 | Size: 249048 Mo
    User = LL1 ... OK!
    User = LL2 ... OK!

    Finished : << RKreport[0]_S_12062013_085003.txt >>
    RKreport[0]_S_12052013_142542.txt
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds