Welcome Guest ( Log In | Click here to Register a free account now! )
Welcome to Bleeping Computer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.
To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.
![]() ![]() |
Feb 1 2008, 09:56 AM
Post
#1
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 1-February 08 Member No.: 187,657 |
It started out as a Trojan.Vundo, i ran multiple anti-spyware/cleaners. Then i found a program called "VundoFix" it seemed to have worked, but caused 3 .dll run errors on startup. Yesterday AVG found the trojan horse generic9.aibf, it healed it, but found it again this morning. I don't know what to do anymore. |
|
|
|
Feb 1 2008, 12:46 PM
Post
#2
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 14,074 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
RunDLL32.exe is a legit Windows file that loads .dll files which too can be legit or malware related.
The "Cannot find...", "Could not run..." or "Error loading..." message usually occurs when the .dll file(s) that was set to run at startup has been deleted and it becomes an orphaned registry entry. Windows is trying to load this file(s) but cannot locate it since the file was removed during an anti-virus or anti-malware scan, or the uninstall of a program. However, the associated registry entry remains and is telling Windows to load the file when you boot up. When Windows loads, it looks for any files associated with registry entries for programs that are set to run at startup. If the file was removed but not the registry entry, Windows will display an error message. You need to remove this registry entry so Windows stops searching for the file when it loads. To resolve this, download Autoruns, search for the related entry and then delete it.
Please download ATF Cleaner by Atribune & save it to your desktop. DO NOT use yet. Please download and install SUPERAntiSpyware Free
Double-click ATF-Cleaner.exe to run the program.
Scan with SUPERAntiSpyware as follows:
-------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() |
|
|
|
Feb 2 2008, 07:21 PM
Post
#3
|
|
|
New Member ![]() Group: Members Posts: 2 Joined: 1-February 08 Member No.: 187,657 |
SUPERAntiSpyware Scan Log
http://www.superantispyware.com Generated 02/01/2008 at 03:02 PM Application Version : 3.9.1008 Core Rules Database Version : 3393 Trace Rules Database Version: 1385 Scan type : Complete Scan Total Scan Time : 00:06:22 Memory items scanned : 224 Memory threats detected : 0 Registry items scanned : 6573 Registry threats detected : 6 File items scanned : 627 File threats detected : 4 Adware.Vundo Variant HKLM\Software\Classes\CLSID\{80BB55D5-0982-4A14-95AE-B5B293FF85B6} HKCR\CLSID\{80BB55D5-0982-4A14-95AE-B5B293FF85B6} HKCR\CLSID\{80BB55D5-0982-4A14-95AE-B5B293FF85B6}\InprocServer32 HKCR\CLSID\{80BB55D5-0982-4A14-95AE-B5B293FF85B6}\InprocServer32#ThreadingModel C:\USERS\APPDATA\LOCAL\TEMP\EFCYV.DLL HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks#{80BB55D5-0982-4A14-95AE-B5B293FF85B6} HKCR\CLSID\{80BB55D5-0982-4A14-95AE-B5B293FF85B6} It found it all and removed it, but I've tried to system restore around 7 times, and i get a message after it attempts to restore and restart, "System Restore did not complete successfully. Your computers files and settings were not changed. Details: An unspecified error occurred during System Restore" Also, Windows Security Center doesn't detect my anti-virus, or windows defender anymore, but both of them are working and running. My W-LAN signal is showing I'm not connected to the internet, although i am. If i need to post in another sub-forum or whatever about the other problems just tell me, but i figured it all had to do with the virus since it just started doing all this when i got the virus. Thanks. This post has been edited by mungun: Feb 2 2008, 08:54 PM |
|
|
|
Feb 2 2008, 10:01 PM
Post
#4
|
|
![]() Bleepin' Janitor ![]() ![]() ![]() ![]() ![]() ![]() Group: Global Moderator Posts: 14,074 Joined: 9-July 05 From: Virginia, USA Member No.: 26,513 |
Sometimes, the Security Center stops recognizing an antivirus or firewall program. Here is one possible solution that may work:
If System Restore is not working, check to make sure it is started and set to automatic. Go to Start > Run and type: services.msc
If this still does not help, then follow these steps to "Reinstall System Restore". "How to troubleshoot System Restore" "System Restore Knowledge Base articles & Troubleshooting" Start a new topic in the Networking forum in regards to your W-LAN. -------------------- "THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"
Microsoft MVP - Windows Security 2007-2009 ![]() |
|
|
|
![]() ![]() |
| Lo-Fi Version | Time is now: 9th January 2009 - 06:20 AM |