Rundll32.exe strange problem

chip2006uk

New Member
Ok hello again everyone, I recently posted about a problem with explorer.exe here http://www.vistax64.com/general-discussion/154824-explorer-exe-being-pain.html#post718134 which I believed to have found the solution. Well although I found the cause of the problem and (thought) I had fixed it it seems like this isnt the end.

Basically a bit of background first, After stupidly downloading a very suspicious file the option to open the task manager dissapears, after finding a fix to this (thanks to Brink) I realised that explorer would every so often stop responding and restart, this started to happen alot and eventually I found a .dll file that was causing this, after deleting it I thought that was that.

Now to the matter at hand - The other day explorer was once again being slow so I looked in the task manager processes and found this (this screenshot was taken just now,)
capture2kj7.jpg


And thats only about a third of the rundll32.exe processes that are running at the moment.

So yeah needless to say this is bogging down the system and subsequently really getting on my nerves. Ive also done about a million virus searches with various different programs all updated and in safe mode and although each one has found some sort of virus (off the top of my head i recall TR/vundo and a couple of others) the problem is still there

Anyway the file the *seems* to be the problem is this one (this is in the autoruns program).
capture3fh2.jpg


The file is called 1c1a6320 (just under the PC tools firewall) but unfortunately the image path is seemingly generated at random each time it activates itself. Everytime I delete that file things run smooth for a while but then sooner or later it comes back with a randomly generated file name. Im pretty sure the rundll32.exe and this file are connected, I would say Im about 95% sure, everytime I find a lot of rundll32.exe's running im pretty certain that this file will have activated itself.

Argh my laptops been playing up ever since I downloaded that one file, I hate myself for downloading such an obviously suspicious file. How can one little file cause so much aggro? :cry:

Any help would be appreciated :) Wont be able to reply to for a while but I should be able to in the next 3 hours or so
 

My Computer

In the next 3 hours, i'll be sleeping :)

Yes you are infected and to cure, deleting a file or 2 is not enough you have to follow a certain procedure depending of the virus found.
Run hijackthis and attach the log file here ( HijackThis Logfileauswertung )

Maybe a moderator could transfer this thread in the adequate section.
 

My Computer

Logfile of HijackThis v1.99.1
Scan saved at 00:44:24, on 02/06/2008
Platform: Unknown Windows (WinNT 6.00.1905 SP1)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:
C:\Program Files\PowerForPhone\PowerForPhone.exe
C:\Windows\ASScrPro.exe
C:\Windows\VMSnap1.exe
C:\Program Files\TalkTalk\bin\sprtcmd.exe
C:\Program Files\Apoint2K\ApMsgFwd.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Apoint2K\HidFind.exe
C:\Program Files\Apoint2K\Apntex.exe

C:\Windows\system32\rundll32.exe
(DMEX Edit: Over 200 variations of this program running)



R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = Live Search:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search:
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Welcome to AOL UK in partnership with talktalk
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = MSN.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = Live Search:

O2 - BHO: (no name) - {240A2128-ACD4-4124-87AF-527124CAAC38} - C:\Windows\system32\vtUlMdaw.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {BAC0A6E4-796D-4129-B7BA-150D5C446BFB} - C:\Windows\system32\iIBrsPjj.dll
O3 - Toolbar: (no name) - {89175504-FC6D-43A2-BB07-E3247659C95A} - (no file)
O4 - HKLM\..\Run: [osCheck] "C:\Program Files\Norton Internet Security\osCheck.exe"
O4 - HKLM\..\Run: [VMSnap1] C:\Windows\VMSnap1.exe

O4 - HKLM\..\Run: [TalkTalk] "C:\Program Files\TalkTalk\bin\sprtcmd.exe" /P TalkTalk
O4 - HKLM\..\Run: [MSServer] rundll32.exe C:\Windows\system32\vtUlMdaw.dll,#1

O17 - HKLM\System\CCS\Services\Tcpip\..\{B072C319-4EA9-4552-
AA00-F70606A6E0FA}: NameServer = 62.24.252.134 62.24.252.135
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WI1F86~1\MESSEN~1\MSGRAP~1.DLL
O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)
O23 - Service: SupportSoft Sprocket Service (TalkTalk) (sprtsvc_TalkTalk) - Unknown owner - C:\Program Files\TalkTalk\bin\sprtsvc.exe" /service /p TalkTalk (file missing)
O23 - Service: SpeedTouch 330 Manager (st330service) - THOMSON Telecom Belgium - C:\Program Files/Thomson/ST330/service/st330service.exe
O23 - Service: SupportSoft RemoteAssist - SupportSoft, Inc. - C:\Program Files\Common Files\Supportsoft\bin\ssrc.exe
owner - C:\Program Files\Common Files\Supportsoft\bin\tgsrvc.exe" /p TalkTalk (file missing)
O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Unknown owner - C:\Windows\system32\UAService7.exe

Edited by DMEX: Trimmed log of all known legitimate programs.



Ok theres a hijackthis log, since everyone will be asleep at this time (including me now :D) I might have to bump this in the morning.

Night all
 
Last edited by a moderator:

My Computer

Back
Top