Jump to content


Photo

rundll32 error please help!


  • Please log in to reply
5 replies to this topic

#1 wallace12

wallace12

    Member

  • New Member
  • Pip
  • 3 posts

Posted 07 June 2004 - 11:20 PM

Hello,

I'm having a problem trying to open ANY Windows 98 programs, (mycomputer, folders, etc). I'm also receiving a rundll32 error when I try to shutdown my pc. I've ran my antivirus and also spybot s&d as well as lavasoft ad-aware programs but I still cannot fix the problem. I downloaded hijackthis and made a copy of my log. I'm not sure what to do next. I've pasted my log and would really appreciate any information you can give me on this.

Thanks!

Logfile of HijackThis v1.97.7
Scan saved at 11:57:32 PM, on 6/7/04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\MDM.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\WINDOWS\SYSTEM\STIMON.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\EXPLORER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\AUPDATE.EXE
C:\PROGRAM FILES\SYMANTEC\LIVEUPDATE\LUCOMSERVER.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\PROGRAM FILES\DIGSTREAM\DIGSTREAM.EXE
C:\WINDOWS\TEMP\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\GBDOJAA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\GBDOJAA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\GBDOJAA.DLL/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\SYSTEM\GBDOJAA.DLL/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\SYSTEM\GBDOJAA.DLL/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\SYSTEM\GBDOJAA.DLL/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
N3 - Netscape 7: user_pref("browser.startup.homepage", "http://home.netscape.com/"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\nt9imopu.slt\prefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "http://www.google.com/"); (C:\WINDOWS\Application Data\Mozilla\Profiles\default\nt9imopu.slt\prefs.js)
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM FILES\MYWAY\MYBAR\1.BIN\MYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: SafeGuard Popup Blocker - {B824E7B0-E8E3-4D75-895E-2C309EA4CC5D} - C:\PROGRAM FILES\SAFEGUARD POPUP BLOCKER PRO\SGPOPUPBLOCKER.DLL
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {883FAAA1-922D-45FD-8F78-45CF239BCEE8} - C:\WINDOWS\SYSTEM\ECLKGGA.DLL (file missing)
O2 - BHO: (no name) - {CED1BA94-5C6A-4BAD-A804-79A9267BF9F5} - C:\WINDOWS\SYSTEM\GBDOJAA.DLL
O2 - BHO: Core Library - {6CDF3C49-20E6-48d7-811B-9F5DD17F1D90} - C:\WINDOWS\SYSTEM\SFG748D.DLL
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAM FILES\MYWAY\MYBAR\1.BIN\MYBAR.DLL
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O9 - Extra button: AIM (HKLM)
O9 - Extra 'Tools' menuitem: Popup Blocker Options (HKLM)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macr...ash/swflash.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macr...director/sw.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupd...B?1070256992290
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.micr...922/wmv9VCM.CAB
O16 - DPF: {10000000-1000-0000-1000-000000000000} - mhtml:file://C:\ARCHIVE.MHT!http://www.008k.com/...10213/msits.exe
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot....ownload/kdx.cab

#2 Roland of Gilead

Roland of Gilead

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 07 June 2004 - 11:48 PM

A shot on the dark, but go HERE and download and run Kill2Me.

Post back if this helps or not.

Hooah!

#3 wallace12

wallace12

    Member

  • New Member
  • Pip
  • 3 posts

Posted 08 June 2004 - 12:06 AM

I just ran the kill2me but it didn't work. I'm still receiving a explorer error whenever I try to open anytime of windows program. When I click on the details tab this is the message I receive.

EXPLORER caused an invalid page fault in
module <unknown> at 0000:07c7fc6e.
Registers:
EAX=034ec7ac CS=018f EIP=07c7fc6e EFLGS=00010246
EBX=02c605c0 SS=0197 ESP=0321eacc EBP=0321eae8
ECX=50002fa8 DS=0197 ESI=02c605c8 FS=4caf
EDX=0321eadc ES=0197 EDI=0321ed6c GS=0000
Bytes at CS:EIP:

#4 Roland of Gilead

Roland of Gilead

    Member

  • Full Member
  • Pip
  • 9 posts

Posted 08 June 2004 - 12:22 AM

I just ran the kill2me but it didn't work.  I'm still receiving a explorer error whenever I try to open anytime of windows program.  When I click on the details tab this is the message I receive.

EXPLORER caused an invalid page fault in
module <unknown> at 0000:07c7fc6e.
Registers:
EAX=034ec7ac CS=018f EIP=07c7fc6e EFLGS=00010246
EBX=02c605c0 SS=0197 ESP=0321eacc EBP=0321eae8
ECX=50002fa8 DS=0197 ESI=02c605c8 FS=4caf
EDX=0321eadc ES=0197 EDI=0321ed6c GS=0000
Bytes at CS:EIP:

I suggest that you do a search (shortcut=Windows key+F) for applog, rename this applog2, reboot.

Post any results please.

Edited by Roland of Gilead, 08 June 2004 - 12:28 AM.


#5 wallace12

wallace12

    Member

  • New Member
  • Pip
  • 3 posts

Posted 08 June 2004 - 11:29 AM

I did a search like you said but that file wasn't found.

#6 BugabooBob

BugabooBob

    Member

  • Full Member
  • Pip
  • 6 posts

Posted 27 June 2004 - 10:38 AM

Wallace....

Your problem lies in the next-to-the-last line of your "HijackThis" log.

Go to the top of this page and do a SEARCH for "MSITS.EXE" and read my response to Jahrim's "Help Please" post.

Bob




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

Member of ASAP and UNITE
Support SpywareInfo Forum - click the button