Rundll32 Problem

Discussion in 'Software' started by RightGirl, Oct 13, 2004.

  1. RightGirl

    RightGirl Private First Class

    Dell Win ME
    40 GB HD
    256 MB Ram

    The message that continues to pop up is:

    Rundll32 - This program requires more conventional memory. Unload drivers or memory resident programs that use conventional memory or increast the value for minimum conventional memory in the programs memory property sheet.
    He can't open (or stay in the ones that do open) many of his programs.

    Also he says that on SOME (not all) of his programs, the font and icons are HUGE. I thought THAT was a video card issue until he told me his mom plays games she got from CDs and the fonts and video is fine for her.

    Not sure if this is 1 problem or 2.

    Any ideas?
     
  2. RightGirl

    RightGirl Private First Class

    Can anyone help me?

    :confused:
     
  3. badflash

    badflash Private E-2



    You might try this, Remember Google is and could be your best friend.

    Click here and read, What you asked could be so many things without sitting and going through it with the computer sitting in front of you ( me) its hard to get on it ( the problem to be sure). But click on the link here below and start your search for what it could be in the list,

    http://www.generation.net/~hleboeuf/erundl32.htm
     
  4. RightGirl

    RightGirl Private First Class

    That didn't work.

    The list did not point to the particular problem I listed.
    In fact, when I did a google search afterward on:

    rundll32 increase the value for minimum conventional

    which was part of the message on his PC.....
    it took me to MY post

    oh brother
    Is he just out of luck here?
    :rolleyes:
     
  5. RightGirl

    RightGirl Private First Class

    I ran Adaware and Spybot and got rid of a BUNCH of ad/mal/spy ware but did not stop the message. Can't even rightclick properties on desktop w/o getting message. Cant open config.sys or autoexec.bat w/o getting message also. Although I do have those 2 in .jpg images that I printscreened off of AIDA32. But dont know how to upload them to this thread.

    Here's the HIJACK THIS log if anyone can tell anything from it:

    Logfile of HijackThis v1.97.7
    Scan saved at 10:44:18 PM, on 10/24/2004
    Platform: Windows ME (Win9x 4.90.3000)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\SYSTEM\DEVLDR16.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\WEBSHOTS\WEBSHOTSTRAY.EXE
    C:\WINDOWS\SYSTEM\WMIEXE.EXE
    C:\PROGRAM FILES\AMERICA ONLINE 9.0\WAOL.EXE
    C:\PROGRAM FILES\COMMON FILES\AOL\ACS\ACSD.EXE
    C:\PROGRAM FILES\AMERICA ONLINE 9.0\SHELLMON.EXE
    C:\WINDOWS\SYSTEM\SPOOL32.EXE
    C:\PROGRAM FILES\AMERICA ONLINE 9.0\AOLWBSPD.EXE
    C:\WINDOWS\SYSTEM\STIMON.EXE
    C:\WINDOWS\SYSTEM\RNAAPP.EXE
    C:\WINDOWS\SYSTEM\TAPISRV.EXE
    C:\PROGRAM FILES\WINZIP\WINZIP32.EXE
    C:\UNZIPPED\HIJACKTHIS\HIJACKTHIS.EXE
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://red.clientapps.yahoo.com/customize/ie/defaults/stp/ymsgr*http://my.yahoo.com
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.rr.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://websearch.drsnsrch.com/sidesearch.cgi?id=
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Roadrunner
    N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/bookmark/7_0/home.html"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\mgy686hg.slt\prefs.js)
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_16_0.DLL
    O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
    O2 - BHO: (no name) - {60112085-E1CE-4e0e-823A-EBB1AD98804C} - C:\WINDOWS\TEMP\SIIS.DAT
    O2 - BHO: (no name) - {3EC8E271-FAB9-418a-8A8E-65AEB4029E64} - C:\WINDOWS\TEMP\SIIS.DAT
    O2 - BHO: (no name) - {8109AF33-6949-4833-8881-43DCC232B7B2} - C:\WINDOWS\TEMP\SIIS.DAT
    O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
    O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\PROGRAM FILES\MSN APPS\ST\01.02.3000.1002\EN-XU\STMAIN.DLL
    O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRAM FILES\YAHOO!\COMPANION\INSTALLS\CPN\YCOMP5_3_16_0.DLL
    O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\PROGRAM FILES\MSN APPS\MSN TOOLBAR\01.02.3000.1001\EN-US\MSNTB.DLL
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [devldr16.exe] C:\WINDOWS\SYSTEM\devldr16.exe
    O8 - Extra context menu item: &Define - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_DEF.HTM
    O8 - Extra context menu item: Look Up in &Encyclopedia - C:\Program Files\Common Files\Microsoft Shared\Reference 2001\A\ERS_ENC.HTM
    O8 - Extra context menu item: Web Savings - file://C:\Program Files\WebSavingsfromEbates\System\Temp\ebateswebsavings_script0.htm
    O9 - Extra button: Encarta Encyclopedia (HKLM)
    O9 - Extra 'Tools' menuitem: Encarta Encyclopedia (HKLM)
    O9 - Extra button: Define (HKLM)
    O9 - Extra 'Tools' menuitem: Define (HKLM)
    O9 - Extra button: Real.com (HKLM)
    O9 - Extra button: Dell Home (HKCU)
    O9 - Extra button: Ebates (HKCU)
    O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
    O12 - Plugin for .bcf: C:\PROGRA~1\INTERN~1\Plugins\NPBelv32.dll
    O14 - IERESET.INF: START_PAGE_URL=http://www.rr.com
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20020323/qtinstall.info.apple.com/qt505/us/win/QuickTimeInstaller.exe
    O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://chat.msn.com/bin/msnchat45.cab
    O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) - http://www.live365.com/players/play365.cab
    O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
    O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v45/yacscom.cab
    O16 - DPF: {7D1E9C49-BD6A-11D3-87A8-009027A35D73} (Yahoo! Audio UI1) - http://chat.yahoo.com/cab/yacsui.cab
    O16 - DPF: {E504EE6E-47C6-11D5-B8AB-00D0B78F3D48} (Yahoo! Webcam Viewer Wrapper) - http://chat.yahoo.com/cab/yvwrctl.cab
    O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
    O16 - DPF: DigiChat Applet - http://host3.digichat.com/DigiChat/DigiClasses/Client_IE.cab
    O16 - DPF: {8714912E-380D-11D5-B8AA-00D0B78F3D48} (Yahoo! Webcam Upload Wrapper) - http://chat.yahoo.com/cab/yuplapp.cab
    O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
    O16 - DPF: {4A3CF76B-EC7A-405D-A67D-8DC6B52AB35B} (QDiagAOLCCUpdateObj Class) - http://aolcc.aol.com/computercheckup/qdiagcc.cab
    O17 - HKLM\System\CCS\Services\VxD\MSTCP: Domain = aoldsl.net
    :rolleyes:
     
  6. badflash

    badflash Private E-2

    Well, sence you put that list up from hyjack this. For the love of god shut down some of that cra%p. He has 256 of ram on an M.E. running system.
    I have never seen so much running on a such small system in my life.
    Go into your system configuration (goto run and type msconfig) and shut down most of what you don't need running from that hyjack list he has to much running for what he has 256 of ram?. Thats his problem right there. Man when he does get it to boot he must have about 15 persent system resorces left to run off of. Is his list by his clock of running programs about half of his toolbar? Problem solved. What is it 600 mhz cpu in it also?
     
  7. jarcher

    jarcher I can't handle a title

    well hit ctrl>alt>del and open your task manager
    but
    first things first
    read this sticky
    http://forums.majorgeeks.com/showthread.php?t=35407

    then if you have to run hjt(and yours is not up to date and needs to be unzipped into its own folder not on the desktop)
    http://forums.majorgeeks.com/showthread.php?t=38752

    everything you need to know is in those threads

    after reading the Tutorial's above
    and you still have a problem
    post you questions here in the spyware forum:
    http://forums.majorgeeks.com/forumdisplay.php?f=35

    thank you
     
  8. badflash

    badflash Private E-2

  9. RightGirl

    RightGirl Private First Class

    I just read the first post since last night.

    I did shut down everything in msconfig start up
    the only still open is:

    system tray
    devldr16.exe (this one I keep shutting down and it is back in startup next bootup)

    I even checked the
    c:\windows\start\programs\startup
    and there's nothing in there
     
  10. RightGirl

    RightGirl Private First Class

    Forgot to mention in that last post that I had already done that, so all of that junk should not be showing up in the list.

    There's nothing in Startup except
    system tray
    devldr16.exe
     
  11. RightGirl

    RightGirl Private First Class

    it wont let me disable system restore
    Just about everything I do, I get THE MESSAGE

    RUNdll32 This program requires more conventional memory. Unload drivers or memory resident programs that use conventional memory or increase the value for minimum conventional memory in the programs memory property sheet.

    When I try to open System in Control Panel to disable system restore, it asks if I want to do that or risk some file corrupting.

    When booting into safe mode I get:

    Rundll32
    If you run an MS-DOS program in safe mode you risk corrupting the video display or experiencing other anomelies. Do you want to run the program anyway?

    No matter what message I get, it asks, do you want to run the program anyway, and then it either lets me run it, or it then gives me the MEMORY message and does not open the program.
     
  12. jarcher

    jarcher I can't handle a title


    i
    READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal:
    http://forums.majorgeeks.com/showthread.php?t=35407

    and run what you can
    and use the online scans
     
  13. RightGirl

    RightGirl Private First Class

    MSCONFIG shows only 2 files in start up:
    system tray
    devldr16.exe

    Also nothing in c:\Windows\Start\Programs\Startup

    So why is the AIDA32 list soooooo incredibly long?

    Is there another way to shut all of that down?
    I get "the memory message" every time I attempt to right click and choose properties,
    every time I highlight and attempt to get properties
    can't even shut down without ctr/alt/del and choosing SHUT DOWN
    Cant open System in Control Panel
    Also can't do ANY of the above in Safe Mode
    I always get "the message"

    I need another way to shut down the long list of JUNK in the RUNNING PROCESSES
    :rolleyes:
     
  14. badflash

    badflash Private E-2

    Run this to see if it is a memory issue or is it software

    http://www.memtest86.com/


    The other option is if all else fails you'll need to go into your registry. Or a total reformat.
     
  15. RightGirl

    RightGirl Private First Class

    As a last resort I upgraded him to Win2000.
    Then was able to shut down a BUNCH of registry items and now have minimal boot up. Problem seems to be repaired (I hope)

    However, during the upgrade, I lost the video drivers.
    I dont remember now (did this at 3AM) but somehow I was able to determine that the video card was AGP mounted and NVIDIA card.

    Is there a way to determine (AIDA32 perhaps & if so, where in AIDA32) what version of the NVIDIA card is installed without cracking the case (left my tools at work :rolleyes: )?

    I attempted to install a couple of the versions found in the Drivers listed in 2000 but those did not work. Every time I boot up it tells me it found new hardware but it offers 8 different NVIDIA card options.

    Also, when I did choose one of the options last night, it then (somewhere) told me I had an I/O conflict on 16. So deleted the drivers for that.

    Perplexed in Palmetto
     
  16. RightGirl

    RightGirl Private First Class

    [[bumped back up]]

    As a last resort I upgraded him to Win2000.

    Then was able to shut down a BUNCH of registry items and now have minimal boot up. Problem seems to be repaired (I hope)

    However, during the upgrade, I lost the video drivers.
    I dont remember now (did this at 3AM) but somehow I was able to determine that the video card was AGP mounted and NVIDIA card.

    Is there a way to determine (AIDA32 perhaps & if so, where in AIDA32) what version of the NVIDIA card is installed without cracking the case (left my tools at work :rolleyes: )?

    I attempted to install a couple of the versions found in the Drivers listed in 2000 but those did not work. Every time I boot up it tells me it found new hardware but it offers 8 different NVIDIA card options.

    Also, when I did choose one of the options last night, it then (somewhere) told me I had an I/O conflict on 16. So deleted the drivers for that.

    Perplexed in Palmetto
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds