Page 1 of 2 12 LastLast
Results 1 to 10 of 15

Thread: Bleh, I've had it. I need help...

  1. Registered TeamPlayer Adretheon's Avatar
    Join Date
    06-07-07
    Posts
    10,524
    Post Thanks / Like
    Blog Entries
    7
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: Adreatheon PSN ID: Adretheon Steam ID: Adretheon
    #1

    Bleh, I've had it. I need help...

    OMG! Ok, I wasn't gunna post and ask cause I thought I'd be able to take care of it, but apparently I was wrong. I think I gots a virus...

    I sent a friend of mine a link to something at the beginning of the week, it wouldn't install right on her comp so I installed it on mine to see if it was just the program having issues or her comp. It installed fine with me, but a few mins after that her comp practically bricked out. It crashed and shut down, and now she can't turn it on w\o it getting stuck. , yea I know I feel bad...so then this happened to me and now I'm worried.

    Every min. or so I get a 2nd rundll32 process pop up in my processes. When it does my comp bogs down for a couple seconds. Web pages load slow, CS:S down spikes to 15fps and is practically unplayable, and stuff is either crashing or when I load it up its just a black box with a broken toolbar. I thought I had gotten rid of it cause I used AVG and it found stuff and removed it, but I was wrong it keeps coming back. I swear I've tried like 4 scans and every time it either doesn't catch anything or it says it's been deleted. I also just had CS:S crash on me cause it said that a model for Pira loaded wrong. Yea, that got me worried. You guys have any suggestions? Cause this is getting real irritating...

  2. Registered TeamPlayer
    Join Date
    04-17-07
    Posts
    20,817
    Post Thanks / Like
    Blog Entries
    4
    #2

    Re: Bleh, I've had it. I need help...

    Try some other AV products (they all tend to catch different things)
    Try Sys Restore to prior to the installation
    Download Process Explorer and try and identify just what is kicking off the rundll32 process that you see the error on
    Report Back

  3. Registered TeamPlayer Adretheon's Avatar
    Join Date
    06-07-07
    Posts
    10,524
    Post Thanks / Like
    Blog Entries
    7
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: Adreatheon PSN ID: Adretheon Steam ID: Adretheon
    #3

    Re: Bleh, I've had it. I need help...

    [img width=700 height=519]http://img139.imageshack.us/img139/6261/boow.jpg[/img]

    Idk, what I'm looking at, heh. The 2nd rundll (2120) is the problem. And the red thing on the second half comes up when the rundll does. (\sessions\1\BaseNamedObjects\f03019a9)

  4. Registered TeamPlayer Arreo's Avatar
    Join Date
    06-01-07
    Posts
    13,940
    Post Thanks / Like
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: TheCynicalOne Steam ID: Arreo
    #4

    Re: Bleh, I've had it. I need help...

    What AV's have you tried?

    You might also want to run HijackThis and post a log of it's results.

  5. Registered TeamPlayer Adretheon's Avatar
    Join Date
    06-07-07
    Posts
    10,524
    Post Thanks / Like
    Blog Entries
    7
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: Adreatheon PSN ID: Adretheon Steam ID: Adretheon
    #5

    Re: Bleh, I've had it. I need help...

    AVG and Zone alarms for sure. I honestly can't remember the others. I know I ran Windows Malicious software(or whatever it's called). I'll go do HijackThis and post up.

  6. Registered TeamPlayer Adretheon's Avatar
    Join Date
    06-07-07
    Posts
    10,524
    Post Thanks / Like
    Blog Entries
    7
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: Adreatheon PSN ID: Adretheon Steam ID: Adretheon
    #6

    Re: Bleh, I've had it. I need help...

    Logfile of Trend Micro HijackThis v2.0.2
    Scan saved at 2:44:35 PM, on 4/23/2009
    Platform: Windows Vista SP1 (WinNT 6.00.1905)
    MSIE: Internet Explorer v8.00 (8.00.6001.18372)
    Boot mode: Normal

    Running processes:
    C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
    C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe
    C:\Windows\SysWOW64\rundll32.exe
    C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe
    C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
    C:\PROGRA~2\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.ex e
    C:\Program Files (x86)\Steam\Steam.exe
    C:\Program Files (x86)\Mozilla Firefox\firefox.exe
    C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.texasteamplayers.com/inde...6513ae1236;www
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
    R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    R3 - URLSearchHook: AIM Toolbar Search Class - {03402f96-3dc7-4285-bc50-9e81fefafe43} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    O1 - Hosts: 82.98.231.89 url.adtrgt.com
    O1 - Hosts: 82.98.231.89 googleads2.gdoubleclick.net
    O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - (no file)
    O2 - BHO: (no name) - {2b122617-f8ad-4f1f-92aa-a225acab4ee7} - (no file)
    O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
    O2 - BHO: AIM Toolbar Loader - {b0cda128-b425-4eef-a174-61a11ac5dbf8} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    O3 - Toolbar: AIM Toolbar - {61539ecd-cc67-4437-a03c-9aaccbd14326} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
    O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
    O4 - HKLM\..\Run: [mulelotosa] Rundll32.exe "C:\Windows\system32\puvivoru.dll",s
    O4 - HKLM\..\Run: [Rbewilarejuc] rundll32.exe "C:\Windows\bstala.dll",e
    O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files (x86)\Zone Labs\ZoneAlarm\zlclient.exe"
    O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
    O4 - HKCU\..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent
    O4 - HKCU\..\Run: [Uniblue RegistryBooster 2] c:\program files (x86)\uniblue\registrybooster 2\StartRegistryBooster.exe
    O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
    O4 - Startup: Adobe Gamma.lnk = C:\Program Files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
    O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\reader_sl.exe
    O8 - Extra context menu item: &AIM Toolbar Search - C:\ProgramData\AIM Toolbar\ieToolbar\resources\en-US\local\search.html
    O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
    O9 - Extra button: AIM Toolbar - {0b83c99c-1efa-4259-858f-bcb33e007a5b} - C:\Program Files (x86)\AIM Toolbar\aimtb.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O10 - Unknown file in Winsock LSP: c:\windows\system32\nvlsp.dll
    O13 - Gopher Prefix:
    O16 - DPF: {4871A87A-BFDD-4106-8153-FFDE2BAC2967} (DLM Control) - http://dlm.tools.akamai.com/dlmanage...ex-2.2.4.1.cab
    O20 - Winlogon Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
    O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
    O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
    O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspn et_state.exe (file missing)
    O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
    O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
    O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
    O23 - Service: FLEXnet Licensing Service 64 - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe
    O23 - Service: ForceWare Intelligent Application Manager (IAM) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcAppFlt. exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
    O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
    O23 - Service: MSCamSvc - Unknown owner - C:\Program Files\Microsoft LifeCam\MSCamS64.exe (file missing)
    O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
    O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
    O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
    O23 - Service: ForceWare IP service (nSvcIp) - Unknown owner - C:\Program Files\NVIDIA Corporation\NetworkAccessManager\bin32\nSvcIp.exe
    O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
    O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
    O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
    O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
    O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
    O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
    O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
    O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
    O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\SysWOW64\ZoneLabs\vsmon.exe
    O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
    O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
    O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
    O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
    I'm guessing all those (file missing)'s aren't supposed to say that.

  7. Registered TeamPlayer Arreo's Avatar
    Join Date
    06-01-07
    Posts
    13,940
    Post Thanks / Like
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: TheCynicalOne Steam ID: Arreo
    #7

    Re: Bleh, I've had it. I need help...

    First thing I see is exactly what you suspected:

    O4 - HKLM\..\Run: [mulelotosa] Rundll32.exe "C:\Windows\system32\puvivoru.dll",s
    O4 - HKLM\..\Run: [Rbewilarejuc] rundll32.exe "C:\Windows\bstala.dll",e
    Those two processes look so incredibly shady. So you were correct in thinking that it was the rundll32 that was at least part of the problem.

  8. Registered TeamPlayer Adretheon's Avatar
    Join Date
    06-07-07
    Posts
    10,524
    Post Thanks / Like
    Blog Entries
    7
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: Adreatheon PSN ID: Adretheon Steam ID: Adretheon
    #8

    Re: Bleh, I've had it. I need help...

    YAY, I'm not paranoid!

  9. Registered TeamPlayer Adretheon's Avatar
    Join Date
    06-07-07
    Posts
    10,524
    Post Thanks / Like
    Blog Entries
    7
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: Adreatheon PSN ID: Adretheon Steam ID: Adretheon
    #9

    Re: Bleh, I've had it. I need help...

    So wait, should I check those 2 and do "fix selected"?

  10. Registered TeamPlayer Arreo's Avatar
    Join Date
    06-01-07
    Posts
    13,940
    Post Thanks / Like
    Stat Links

    Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help... Bleh, I've had it. I need help...
    Gamer IDs

    Gamertag: TheCynicalOne Steam ID: Arreo
    #10

    Re: Bleh, I've had it. I need help...

    Quote Originally Posted by Adretheon
    So wait, should I check those 2 and do "fix selected"?
    GO ahead and try, then restart the computer and run the HijackThis again and see if they are still there. My guess is they will regenerate (possibly with new names).

Page 1 of 2 12 LastLast

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Tags for this Thread

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •  
Title