There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
Virus & Other Malware Removal
Tag Cloud
acer asus bios bsod computer crash desktop drive driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory missing monitor motherboard mouse network operating system printer problem ram registry router slow software sound toshiba trojan uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > Virus & Other Malware Removal >
rundll32.exe - Bad Image (In Progress)

Reply  
Thread Tools
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
30-Jan-2010, 04:43 PM #16
yes press continue then

download gmer rootkit detector from http://gmer.net

unzip it & double click the gmer.exe file

It will do a quick scan automatically, when that finishes if it says "rootkit activity detected" then Stop there & press copy & post back the log it makes.
Do NOT allow it to perform a full scan at this time

If there is No warning of rootkit activity then select the rootkit tab & press scan. When it finishes press copy & post back the log it makes
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
funky105's Avatar
Member with 36 posts.
 
Join Date: Aug 2009
Experience: beginner
30-Jan-2010, 05:19 PM #17
Its doing the scan but i noticed that only the
C:/ <--- is cheked an is being scanned , shouldnt the other drives also be scanned ,because i have
E:/
and
J:/
Uncheked

Or it doesnt matter !?

-=Before i asked this question, i had the scan already running, it crashed, i restarted my pc becaus the whole pc crashed with it +DDD=-
now, should i scan again !?

Last edited by funky105; 30-Jan-2010 at 05:44 PM..
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
30-Jan-2010, 06:30 PM #18
you only need to scan the system drive with a rootkit detector not extra drives
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
30-Jan-2010, 06:31 PM #19
close everything before you scan especially browsers

try the scan again
funky105's Avatar
Member with 36 posts.
 
Join Date: Aug 2009
Experience: beginner
30-Jan-2010, 07:15 PM #20
well i did the scan, i left it scanning went AFK for about 20 minutes , came back and all i see is the Desktop background and the Mouse cursor, and i couldn't do nothing.
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
31-Jan-2010, 04:52 AM #21
OK reboot & tell me if you are having any problems now at all
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
31-Jan-2010, 04:53 AM #22
run tdss killer from http://support.kaspersky.com/viruses...?qid=208280684

post back with its log and we can go from there
funky105's Avatar
Member with 36 posts.
 
Join Date: Aug 2009
Experience: beginner
31-Jan-2010, 06:06 AM #23
well i launched TDSSKiller.zip and this is what it showed :
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
31-Jan-2010, 06:15 AM #24
That is because you ran it from temporary folder

download it to desktop
Unzip it so the tdsskiller.exe is on desktop & run it again
funky105's Avatar
Member with 36 posts.
 
Join Date: Aug 2009
Experience: beginner
31-Jan-2010, 06:19 AM #25
again, the same even if i run it from the desktop !
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
31-Jan-2010, 01:21 PM #26
in that case it can't be finding anything


download the free trial of http://www.prevx.com/freescan.asp

Double click the file to install it

scan with it

if it finds a rootkit it will offer to fix it, let it do the fix. if it finds anything else, report what it finds please

It is only free to deal with rootkits and some adwares but will suggest you buy it to fix anything else

before you do that ( if you decide to ) post its report so we can advise if it is necessary or whether we can deal with it another way

to get the report

right click the prevx icon in sys tray

select configure monitoring, then select the tools tab & save scan results

attach that file here to your next reply ( it might be too big to attach so zip it first)
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
funky105's Avatar
Member with 36 posts.
 
Join Date: Aug 2009
Experience: beginner
31-Jan-2010, 04:03 PM #27
I saved it to my desktop, i dont know if it is installed or something but it started a scan and there is 1 infection found !

there are 2 options :

Scan my pc again or Cleanup now but thats not the problem as i understand it i need a license to cleanup now !

So what should i do next ?
funky105's Avatar
Member with 36 posts.
 
Join Date: Aug 2009
Experience: beginner
31-Jan-2010, 04:11 PM #28
scan.log
Attachment Blocked
Attachments in the HJT forum are often designed to solve a specific issue and not meant to be used without instructions specific to your computer. If you want help specific to your computer, please post a HiJackThis Log. If you started this thread, please make sure you are logged in to be able to view attachments.
dvk01's Avatar
Moderator & Malware Removal Specialist with 37,220 posts.
 
Join Date: Dec 2002
Location: Loughton, Essex, UK
31-Jan-2010, 05:14 PM #29
That is finding a worm in one of the grand theft auto files but doing a search suggests it might be a false alarm

we had better check the file

Download suspicious file packer from http://www.safer-networking.org/en/tools/index.html (direct download http://www.safer-networking.org/files/sfp.zip )

Unzip it to desktop, open it & paste in the contents of the quote box below, press next & it will create an archive (zip/cab file) on desktop

please upload that to http://www.thespykiller.co.uk/index.php?board=1.0 so we can examine the files

Just press new topic, fill in the needed details and just give a link to your post here & then press the browse button and then navigate to & select the files on your computer, When the file is listed in the windows press send to upload the file

Quote:

e:\jaskiro_190gb\ruuda\gta iv game\grand theft auto iv\lua51.dll

are you having any problems at the moment
__________________
Derek Microsoft MVP/Windows - Security | Thespykiller | Security & Privacy
Find out all about the European Wild Hedgehog, what you can do to save it from extinction Hedgehog Rescue
funky105's Avatar
Member with 36 posts.
 
Join Date: Aug 2009
Experience: beginner
31-Jan-2010, 05:33 PM #30
Reply

Tags
error

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 01:49 AM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.