Author Topic: Runddl32.exe detected as threat - Logs attached - PART 1  (Read 5395 times)

0 Members and 1 Guest are viewing this topic.

mfish

  • Guest
Runddl32.exe detected as threat - Logs attached - PART 1
« on: August 17, 2011, 10:04:16 PM »
As soon as I start Internet Explorer Avast detects rundll32.exe as a threat.  And then the message keeps popping up periodically.

I've ran an Avast boot time scan, AvastMBR, Malware Bytes, and OTL and the probelm still persists.

Please help me remove this.  Thanks.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #1 on: August 17, 2011, 10:42:27 PM »
malwarebytes was not updated when you did the scan. Database version: 7477  latest is 7791.....well maybe it was....i see the scan is dated yesterday


have you tested the rundll32.exe file at www.virustotal.com
« Last Edit: August 17, 2011, 10:44:54 PM by Pondus »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #2 on: August 17, 2011, 11:42:46 PM »
OK nothing jumps out at me there so lets look at the drivers

Download and Install CombofixDownload ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop *

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

mfish

  • Guest
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #3 on: August 18, 2011, 12:10:48 AM »
I'll try the methods out this evening.....part 2 of the OTL log is attached to this post so everything is now under one post

mfish

  • Guest
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #4 on: August 18, 2011, 01:36:44 AM »
Here is the combofix log.

Also, attached is a screenshot of the Avast warning I get.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #5 on: August 18, 2011, 08:37:06 PM »
OK I think I have found it now - something new

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :OTL
    MOD - [2011/07/07 15:08:50 | 000,135,168 | ---- | M] () -- C:\Users\Matt\AppData\Local\SyncHelpWan\DesktopCommsUsb.dll
    O4 - HKU\S-1-5-21-2076991497-3898917214-2073273038-1000..\Run: [DesktopCommsUsb] C:\Users\Matt\AppData\Local\SyncHelpWan\DesktopCommsUsb.dll ()


    :Files
    ipconfig /flushdns /c
    C:\Users\Matt\AppData\Local\SyncHelpWan

    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [EMPTYFLASH]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

mfish

  • Guest
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #6 on: August 19, 2011, 02:57:29 PM »
Part 1 of the log is attached

mfish

  • Guest
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #7 on: August 19, 2011, 02:58:02 PM »
Part 2 of the log is attached

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #8 on: August 19, 2011, 09:04:05 PM »
Any further alerts ?

mfish

  • Guest
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #9 on: August 20, 2011, 02:09:37 PM »
I have gotten the alerts since going through your procedures!!  I think its fixed.  Thank you so much for your help.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Runddl32.exe detected as threat - Logs attached - PART 1
« Reply #10 on: August 20, 2011, 02:58:39 PM »
Could you upload the following file to Avast please via the virus chest as undetected malware - before I remove my tools

c:\_OTL\moved files\C:\Users\Matt\AppData\Local\SyncHelpWan\DesktopCommsUsb.dll