Go Back   Cyber Tech Help Support Forums > Software > Malware Removal

Notices

Malware Removal Discussion about Trojans, viruses, hoaxes, firewalls, spyware, and general Security issues. If you suspect your PC is infected with a virus, trojan or spyware app please include any supporting documentation or logs

Reply
 
Topic Tools
  #1  
Old February 28th, 2009, 12:28 PM
jonboy123 jonboy123 is offline
Senior Member
 
Join Date: Jan 2009
O/S: Windows 10 Pro
Location: Leicester, UK
Posts: 295
RUNDLL Error Messages in XP

I am getting two rundll error messages when I boot up this laptop.
error loading C:\WINDOWS\system32\rkvpnso.dll
error loading C:\WINDOWS\system32\xmtqmth.dll

Here is the Hijack this log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:20:45, on 28/02/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16791)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\a-squared Free\a2service.exe
C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\Explorer.EXE
C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe
C:\Program Files\QuickTime\QTTask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\WINDOWS\fxstaller.exe
C:\WINDOWS\system32\jlrqk.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\algs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = http://go.microsoft.com/fwlink/?LinkId=54843
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.wanadoo.co.uk/cd_redirects/st35install.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - c:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: e404 helper - {0D574C9F-71F9-4F3C-BA6D-CF9C0E1E3EE8} - C:\Program Files\Helper\1205710993.dll (file missing)
O2 - BHO: (no name) - {1640E000-B92A-441B-8D1B-C84221A4DDCE} - (no file)
O2 - BHO: (no name) - {1CFB02FC-86E0-4D70-BC21-F82423E3D071} - (no file)
O2 - BHO: (no name) - {1F8295F7-9B8F-42AC-AD18-9324390C2E94} - (no file)
O2 - BHO: (no name) - {23BBE47A-B3E7-4291-AFF7-25752D1675A7} - (no file)
O2 - BHO: (no name) - {30E9E754-0192-4090-9A30-390380C5ACB7} - (no file)
O2 - BHO: (no name) - {334EE246-C48C-43F0-AB30-354A2A83A25E} - (no file)
O2 - BHO: (no name) - {36B9C047-3AFA-4243-B298-31C80E1830A9} - (no file)
O2 - BHO: (no name) - {36EE5A10-4361-45D1-BE6C-DD876C0D6162} - (no file)
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: (no name) - {3E0903C8-FF32-4573-81C1-688562029563} - (no file)
O2 - BHO: {f8a9003f-a5c7-4a2b-c754-f44663e8dbe3} - {3ebd8e36-644f-457c-b2a4-7c5af3009a8f} - (no file)
O2 - BHO: (no name) - {458C9F8E-2EE0-44A8-A298-7243C33E88EB} - (no file)
O2 - BHO: (no name) - {468F806B-990E-42CB-AF4D-061A8DECB469} - (no file)
O2 - BHO: (no name) - {47C644D6-2F12-45CE-A5CF-CD1BD0C07D76} - (no file)
O2 - BHO: (no name) - {4B844DB0-FF95-4B35-8282-EDD2CE0FE9AE} - (no file)
O2 - BHO: Orange - {4E7BD74F-2B8D-469E-A6FB-F862B587B57D} - C:\PROGRA~1\orange4\orange4.dll
O2 - BHO: (no name) - {5128152F-5D84-49B3-A419-6DE854CF254B} - (no file)
O2 - BHO: (no name) - {54146236-A6E7-4CCB-B719-0BBE78200408} - (no file)
O2 - BHO: (no name) - {55E25E3A-B60F-49D9-866B-E5A923CE1D15} - (no file)
O2 - BHO: (no name) - {5666C151-BCCA-4ABD-B052-7EEA9B2932C8} - (no file)
O2 - BHO: (no name) - {56912671-079F-4975-82E6-34F48B0FD518} - (no file)
O2 - BHO: {a42ab36e-70cf-5a4b-8ff4-b861c9b6f5c5} - {5c5f6b9c-168b-4ff8-b4a5-fc07e63ba24a} - C:\WINDOWS\system32\bifdmbex.dll (file missing)
O2 - BHO: (no name) - {60C3EBED-5637-4C57-A692-84EFE3C48229} - C:\WINDOWS\system32\vtsqn.dll (file missing)
O2 - BHO: (no name) - {67DCD3C1-512A-4D49-BDE6-21C34FC5C240} - (no file)
O2 - BHO: (no name) - {6860A44B-5D3E-433D-A7B5-D517F810D0E7} - C:\Program Files\NetProject\sbmdl.dll (file missing)
O2 - BHO: (no name) - {6BA24777-7F6D-4E42-9769-25950D4F2592} - (no file)
O2 - BHO: {db2c3a1e-efb2-a16b-9074-f50d593f3e07} - {70e3f395-d05f-4709-b61a-2bfee1a3c2bd} - (no file)
O2 - BHO: (no name) - {7C989651-F849-4F71-9CBA-3243EE3FE96C} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8244FDB3-096A-45DF-88F1-3A1973DA20B3} - (no file)
O2 - BHO: (no name) - {88A74C29-5693-4133-8602-E427FB7C6971} - (no file)
O2 - BHO: (no name) - {89ED130C-164B-4522-9BF8-685EA46404F7} - (no file)
O2 - BHO: (no name) - {8AA8E87C-B9C7-4354-ABA8-B5B30A28BB83} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: (no name) - {A7FFBCA0-8491-4544-89ED-612780929B2A} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O2 - BHO: {ba2aa9b3-5f5d-88ca-4844-35951e368aca} - {aca863e1-5953-4484-ac88-d5f53b9aa2ab} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\sw g.dll
O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O2 - BHO: (no name) - {C10DE791-5F1C-476F-ABDD-1C97E2CDEF7B} - (no file)
O2 - BHO: (no name) - {C4C76A3D-B78C-4CFE-87E9-681779F43B06} - (no file)
O2 - BHO: Google Dictionary Compression sdch - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - C:\Program Files\Google\Google Toolbar\Component\fastsearch_219B3E1547538286.dll
O2 - BHO: (no name) - {D4ABAEB7-9681-493F-AD9F-5C4ED851A3CD} - (no file)
O2 - BHO: (no name) - {D6840EDF-8BF0-46CC-86A1-39AB97F5DC01} - C:\WINDOWS\system32\vturq.dll (file missing)
O2 - BHO: (no name) - {D6F9759E-5704-47E1-B547-6B1235BCCBAA} - (no file)
O2 - BHO: e404 helper - {DF47DD37-AC11-4A93-8E16-2B2364AF0897} - C:\Program Files\Helper\1206387915.dll (file missing)
O2 - BHO: (no name) - {E2F8F7C7-954D-4336-BA99-27BFBEB73DAF} - C:\WINDOWS\system32\wvutrol.dll (file missing)
O2 - BHO: (no name) - {EA159446-1DDC-48FC-AE98-4B9EF3D4490A} - (no file)
O2 - BHO: (no name) - {FAE04E4C-3DF5-40AA-A8D9-F4BBD5881F2C} - (no file)
O2 - BHO: (no name) - {FC1938BD-DD2E-4787-8476-918E94CF0F82} - (no file)
O2 - BHO: (no name) - {FD42ADBB-0E61-4D0C-A14B-AA68AA1A2570} - (no file)
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Orange - {4E7BD74F-2B8D-469E-A6FB-F862B587B57D} - C:\PROGRA~1\orange4\orange4.dll
O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O3 - Toolbar: &Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar.dll
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [02387afb] rundll32.exe "C:\WINDOWS\system32\yntqxmth.dll",b
O4 - HKLM\..\Run: [BM010b4967] Rundll32.exe "C:\WINDOWS\system32\rkvnpnso.dll",s
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [Device Detector] "C:\Program Files\Common Files\ACD Systems\EN\DevDetect.exe" -autorun
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [Windows UDP Control Center] fxstaller.exe
O4 - HKLM\..\Run: [PromoReg] C:\WINDOWS\system32\jlrqk.exe
O4 - HKLM\..\Run: [Application Layer Gateway Service] C:\WINDOWS\system32\algs.exe
O4 - HKLM\..\Run: [Window UDP Control Servic] winlogon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKLM\..\Policies\Explorer\Run: [some] C:\Program Files\NetProject\scit.exe
O4 - HKUS\S-1-5-18\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [ctfmon.exe] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O9 - Extra button: (no name) - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.safeiegate.com/redirect.php (file missing)
O9 - Extra 'Tools' menuitem: IE Anti-Spyware - {9034A523-D068-4BE8-A284-9DF278BE776E} - http://www.safeiegate.com/redirect.php (file missing)
O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\STEVE MEAKIN\Start Menu\Programs\IMVU\Run IMVU.lnk
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.orange.co.uk
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-GB/.../GAME_UNO1.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab56986.cab
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: wvutrol - wvutrol.dll (file missing)
O22 - SharedTaskScheduler: inoperable - {1b40d2ad-d237-4544-b1e1-0bf75bf8fcc0} - C:\WINDOWS\system32\jdxah.dll (file missing)
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Program Files\a-squared Free\a2service.exe
O23 - Service: Memory Check Service (AcerMemUsageCheckService) - Acer Inc. - C:\Acer\Empowering Technology\ePerformance\MemCheck.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe

--
End of file - 12796 bytes
Reply With Quote
  #2  
Old March 2nd, 2009, 04:19 AM
Jintan's Avatar
Jintan Jintan is offline
Cyber Tech Help Moderator
 
Join Date: Dec 2004
Posts: 52,284
Awaiting a verification here for now.
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Topics
Topic Topic Starter Forum Replies Last Post
Rundll error gasper49 Windows XP 2 October 23rd, 2009 05:37 PM
Rundll32.exe and Rundll error messages Europete Windows XP 0 August 17th, 2008 05:40 PM
RUNDLL Error - please help Ben.Quo Applications 0 February 22nd, 2007 04:52 PM
rundll error hdavila Windows XP 2 May 3rd, 2006 07:42 PM
Rundll Error jimb11 Windows ME 1 April 6th, 2004 03:26 PM


All times are GMT +1. The time now is 12:52 AM.