.dll's in my startup menu. Kaspersky cant fix

Closed
tigz54 - May 15, 2008 at 02:33 PM
 tigz54 - Jun 7, 2008 at 01:39 PM
I posted this on another thread but it will probably be better here.

this could be a lifesaver for me. Here is my problem:
A little while ago, I was surfing the internet (google actually), and out of nowhere, I got like 6 popups, and mozilla froze up. Since I NEVER get popups, I knew somethign was wrong right away. I opened Ad-aware, and did a full scan, cleaned everything up, and was done. I tried openning Mozilla again, but it was REALLY slow, and froze every few seconds. Also, my CPU was running at 80-100% constantly. I opened up task manager and looked at my processes and I noticed I had 3 rundll32.exe running. after some reseach on another computer, I found out that rundll32.exe is a valid system file that is used to execute .dll files. This didnt seem right becasue I am familiar with my normal process list and rundll32 usually isnt on there. I tried to close them, but they just opened back up agian as soon as I had done so. I tried rebooting, with no effect. finally, I opened up the startup programs manager and found that there was a bunch of files that usually arent on there. dwjgq.dll, ljDSIbx.dll, and MSServer (which I found was a name linked to a ssQgGXNH.dll). I tired disabling and deleting said startup entries, but they just reappeared when I refreshed the list. I then found that the entries were all linked to files that are executed by rundll32.exe in my C:\Users\Sasha\AppData\Local\Temp\ folder. I did an advanced search of hidden/system files for .dll and found them. I tried to delete them manually, which didnt work beacuse they were in use by rundll32.exe, which I couldnt close. Finally, I installed and ran Kaspersky antivirus 7 Pro and ran a full scan, which found and cleaned a bunch of trojans and viruses, but it did not touch the .dll files. I manually scaned them, but kaspersky couldnt find anything wrong. Mozilla still freezes (and I get the "busy" mouse graphic", which leads me to think it is doing something) every few seconds, and I still cant fix this problem. I am at a loss. please help
browser: Mozilla Firefox 2
O.S: Vista premium
Computer: HP desktop - very fast, FIOS internet.
my email is tigz_54@yahoo.ca
Related:

3 responses

yes i have the same problem and i dont know how to fix. please help us.
0
Coming up with the same issues. Also tried using IE 7 and get a bunch of popups....started about the same time frame.
0
I believe I have fixed it (or at least temporarily resolved the problem)
a couple things I found out:
rundll.exe is a valid windows app, so dont try to mess with it. it is just being used by the malware.
any of the files I mentioned can be deleted in safe mode via the cmd prompt

heres what I did:
1. write down the exact location of the files on paper. look up and write down cmd commands that would allow me to force delete files. check:

for delete commands:
http://technet2.microsoft.com/windowsserver/en/library/b4f9443f-e501-4a85-93e3-805ee3edad471033.mspx?mfr=true
https://ss64.com/nt/

for dir commands (this navigates your computer the specified folder - I think you need to do this beore you can delete the files):
http://technet2.microsoft.com/windowsserver/en/library/a6aaf662-4153-4f8c-873e-58d91aedc1ea1033.mspx?mfr=true

2. restart my comp, boot in safe mode with the command prompt. use above commands and try to delete the files. you may have to mess around with different combinations of the command line. took me a while to get it right, but I don't remember exactly what command I ended up using. Also, I think the prompt told me that the deletion didnt work, even though it did.

3. restart comp again, do a FULL computer scan with kaspersky or whatever you use, and ad-aware. makes sure your definitions are up to date. after full scans and another comp restart (just for good measure) check the folder that the malware files were in (again - for me it was C:\Users\Sasha\AppData\Local\Temp\). for me they were gone.

4. go to your startup manager and delete the suspicious entries. they should stay deleted.


hope this helps. i anyone else can verify that this worked or provide another solution that would be great
0