Really annoying potential virus!

Status
Not open for further replies.
ARGHHHHHHHHHHHHHHH!!!

I tried, I really did!

I went through a whole bunch of programs and did an online scan, but then in the middle of all this my whole computer froze and I had to close everything. It started behaving wierdly and renaming "My Computer" to "Folder". Windows Media Player suddenly couldn't find any music files, but as far as I could see, everything was still there.

I decided to restart, panicking majorly by this point. It did a disk check on C, something it never normally does, and ended up deleting a long list of indexes or something like that.

Finally, it tried to start up but got stuck just before the log-on screen with a cursor and a windows logo (seemed to be a different resolution to normal, everything was very small) in the centre of the screen.

I'm now using my mum's computer (super-slow!), having tried and failed to start mine up in safe mode and with the "last good settings".

I figured maybe I did something wrong when configuring the startup in msconfig or something?

Is there any way I can do a system restore at the stage I'm at now, or anything like that? My computer has EVERYTHING on it, and now it's not working and it's a big shock :(

Please help :(

- Danjb
 
Did you disable everything in msconfig >startup? Maybe that will help out a lil bit. Were you able to install Prevx?
 
Well, I'd configured the startup to a stage that worked, restarted and everything was fine.

Then I used that msconfig cleaner program, and looked through the list. It looked like all the programs I'd set to startup weren't in this list, so I figured this must just be all the other random things that I didn't want (that weren't selected in my actual startup), so I pressed select all and cleaned them up.

When it froze and started bugging up was when I was using CCleaner, just after an online scan (micro-trend?) had finished.
 
Nah, that's what I _had_ done before it bugged up (sorry, misleading).

So it's still broke :(
 
How can I delete it if it doesn't start up?

My bro found a suggestion of turning the PC on with the Windows CD in the drive and loading it up from there to get into a repair install.



EDIT:
Ok, so I went into the recovery console and tried a number of things, including "del C:\WINDOWS\system32\rundll32.exe" but no luck :(

I'm all out of ideas, cept using that windows cd that I can't find :'(
 
Description:
rundll32.exe is a process which executes DLL's and places their libraries into the memory, so they can be used more efficiently by applications. This program is important for the stable and secure running of your computer and should not be terminated.


Why would he want to delete rundll32.exe??????



C:\WINDOWS\system32\rundll32.exe <-- If there was another entry after the parameter that loads a suspicious file, then you might have spyware but this isnt the case. If you want to see if its loading spyware follow this below

To know the module which is executed by Rundll32, proceed further. Without any third-party tools, here is a neat way to track down what the Rundll32 is executing. Open a Command Prompt window and type the following command:
tasklist /m /fi "IMAGENAME eq rundll32.exe" >C:\rundll32.txt
Now, open the file C:\rundll32.txt file and identify the "odd" modules. (filter out the system files and dependencies used by Rundll32.exe. The odd one (in this example) is the timedate.cpl file. Yes. I had the Date/Time dialog open and this is what Rundll32.exe was executing.

The above is just an example and you may use this method to find out the module loaded by the rundll32.exe process. If an unknown module was found, it may be a Malware.
 
I did delete rundll32.exe but it didn't really matter in the end, it changed nothing.

Anyways, good news! I found a way of getting on using some sort of Compaq recovery tool and quickly backed up all my files.

I reckon I would've then been fine to keep using it but I decided I might as well restore the whole system to factory settings and become squeaky clean :D
 
Status
Not open for further replies.
Back
Top Bottom