This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Rundll error on startup.. google occationally redirects to ads

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hey there. I haven't noticed a strange error which appears once on startup of my machine which only says.. RUNDLL ERROR Error running C:/Documents I assume there is more to the path but it does not show. I have also notinced some occasional redirections to ads when im searching for something on google and click a link. I have AVG free which I update and scan regularly but have found nothing. Any help would be much appreciated! Here is the results of the DDS scan. DDS.txt posted below and attach.txt attached as stated in the rules. Thank you guys in advance! DDS (Ver_10-03-17.01) - NTFSx86 Run by [removed] at 1:16:36.82 on Tue 22/06/2010 Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_20 Microsoft Windows XP Professional 5.1.2600.3.1252.61.1033.18.3326.2388 [GMT 10:00] AV: AVG Anti-Virus Free *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF} ============== Running Processes =============== C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost -k DcomLaunch svchost.exe C:\WINDOWS\System32\svchost.exe -k netsvcs svchost.exe svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\Program Files\AVG\AVG9\avgchsvx.exe C:\Program Files\AVG\AVG9\avgrsx.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\WINDOWS\RTHDCPL.EXE C:\Program Files\Everything\Everything.exe C:\WINDOWS\system32\DeltaIITray.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Razer\Tarantula\razerhid.exe C:\Program Files\Razer\DeathAdder\razerhid.exe C:\Program Files\Winamp\winampa.exe C:\PROGRA~1\AVG\AVG9\avgtray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\DAEMON Tools Pro\DTProAgent.exe C:\Program Files\Steam\Steam.exe C:\Program Files\SteamWatch\SteamWatchTray.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe C:\PROGRA~1\INTERN~2\mum.exe C:\WINDOWS\system32\rundll32.exe C:\Documents and Settings\Slynk\Application Data\regsdkrl32\regsdkrl29.exe C:\Program Files\UltraMon\UltraMon.exe C:\Program Files\UltraMon\UltraMonTaskbar.exe svchost.exe C:\Program Files\AVG\AVG9\avgwdsvc.exe C:\Program Files\Java\jre6\bin\jqs.exe C:\Program Files\SteamWatch\SteamWatch.exe C:\Program Files\Razer\DeathAdder\razertra.exe C:\Program Files\NeoSmart Technologies\ToolTipFixer\ToolTipFixer.exe C:\WINDOWS\system32\mousenh32.exe C:\Program Files\Razer\DeathAdder\razerofa.exe C:\Program Files\Razer\Tarantula\razertra.exe C:\Program Files\AVG\AVG9\avgemc.exe C:\Program Files\AVG\AVG9\avgnsx.exe C:\Program Files\AVG\AVG9\avgcsrvx.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Documents and Settings\Slynk\Desktop\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://www.google.com/ BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg9\avgssie.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll uRun: [CTFMON.EXE] c:\windows\system32\ctfmon.exe uRun: [DAEMON Tools Pro Agent] "c:\program files\daemon tools pro\DTProAgent.exe" uRun: [Steam] "c:\program files\steam\Steam.exe" -silent uRun: [SteamWatchTray] c:\program files\steamwatch\SteamWatchTray.exe uRun: [InternodeUsage] c:\progra~1\intern~2\mum.exe uRun: [Desktop Cleanup Wizard] rundll32.exe "c:\documents and settings\slynk\local settings\application data\desktop cleanup wizard\dskclean.dll", StartProt uRun: [regsdkrl32] c:\documents and settings\slynk\application data\regsdkrl32\regsdkrl29.exe mRun: [LClock] c:\program files\lclock\LClock.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 9.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [RTHDCPL] RTHDCPL.EXE mRun: [Everything] "c:\program files\everything\Everything.exe" -startup mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [M-Audio Taskbar Icon] c:\windows\system32\DeltaIITray.exe mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [Tarantula] c:\program files\razer\tarantula\razerhid.exe mRun: [DeathAdder] c:\program files\razer\deathadder\razerhid.exe mRun: [WinampAgent] "c:\program files\winamp\winampa.exe" mRun: [AVG9_TRAY] c:\progra~1\avg\avg9\avgtray.exe mRun: [Acronis Toolbar Helper] rundll32.exe c:\documents and settings\slynk\local settings\application data\desktop cleanup wizard\dskclean.dll, StartProt dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE dRunOnce: [_nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\ultramon.lnk - c:\windows\installer\{af0fa6d7-96f3-468a-abb7-28be006ea8e9}\IcoUltraMon.ico uPolicies-explorer: ForceClassicControlPanel = 1 (0x1) dPolicies-explorer: ForceClassicControlPanel = 1 (0x1) IE: E&xport to Microsoft Excel - c:\progra~1\micros~3\office12\EXCEL.EXE/3000 IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office12\REFIEBAR.DLL DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg9\avgpp.dll Notify: AtiExtEvent - Ati2evxx.dll Notify: avgrsstarter - avgrsstx.dll AppInit_DLLs: c:\windows\system32\syspol32.dll SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll SecurityProviders: msapsspc.dll, schannel.dll, credssp.dll, digest.dll, msnsspc.dll ================= FIREFOX =================== FF - ProfilePath - c:\docume~1\slynk\applic~1\mozilla\firefox\profiles\yug45wtd.default\ FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\ FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} —- FIREFOX POLICIES —- c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_colors", true); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.use_native_popup_windows", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.enable_click_image_resizing", true); c:\program files\mozilla firefox\greprefs\all.js - pref("accessibility.browsewithcaret_shortcut.enabled", true); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.high_water_mark", 32); c:\program files\mozilla firefox\greprefs\all.js - pref("javascript.options.mem.gc_frequency", 1600); c:\program files\mozilla firefox\greprefs\all.js - pref("network.auth.force-generic-ntlm", false); c:\program files\mozilla firefox\greprefs\all.js - pref("svg.smil.enabled", false); c:\program files\mozilla firefox\greprefs\all.js - pref("ui.trackpoint_hack.enabled", -1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.debug", false); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.agedWeight", 2); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.bucketSize", 1); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.maxTimeGroupings", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.timeGroupingSize", 604800); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.boundaryWeight", 25); c:\program files\mozilla firefox\greprefs\all.js - pref("browser.formfill.prefixWeight", 5); c:\program files\mozilla firefox\greprefs\all.js - pref("html5.enable", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.allow_unrestricted_renego_everywhere__temporarily_available_pr ef", true); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.renego_unrestricted_hosts", ""); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.treat_unsafe_negotiation_as_broken", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl.require_safe_negotiation", false); c:\program files\mozilla firefox\greprefs\security-prefs.js - pref("security.ssl3.rsa_seed_sha", true); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.download.backgroundInterval", 600); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("app.update.url.manual", "http://www.firefox.com"); c:\program files\mozilla firefox\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-ja", "mozff"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.name", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("extensions.{972ce4c6-7e08-4474-a285-3208198ce6fd}.description", "chrome://browser/locale/browser.properties"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add", "addons.mozilla.org"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("xpinstall.whitelist.add.36", "getpersonas.com"); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("lightweightThemes.update.enabled", true); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.allTabs.previews", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.hide_infobar_for_outdated_plugin", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("plugins.update.notifyUser", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("toolbar.customization.usesheet", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.enable", false); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.max", 20); c:\program files\mozilla firefox\defaults\pref\firefox.js - pref("browser.taskbar.previews.cachetime", 20); ============= SERVICES / DRIVERS =============== R0 amdide1;amdide1;c:\windows\system32\drivers\amdide1.sys [2010-1-17 9096] R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\drivers\avgldx86.sys [2010-6-21 216200] R1 AvgMfx86;AVG Free On-access Scanner Minifilter Driver x86;c:\windows\system32\drivers\avgmfx86.sys [2010-6-21 29584] R1 AvgTdiX;AVG Free Network Redirector;c:\windows\system32\drivers\avgtdix.sys [2010-6-21 242896] R2 avg9emc;AVG Free E-mail Scanner;c:\program files\avg\avg9\avgemc.exe [2010-6-21 916760] R2 avg9wd;AVG Free WatchDog;c:\program files\avg\avg9\avgwdsvc.exe [2010-6-21 308064] R2 SteamWatch;SteamWatch;c:\program files\steamwatch\SteamWatch.exe [2010-6-21 18944] R2 ToolTipFixer;ToolTipFixer;c:\program files\neosmart technologies\tooltipfixer\ToolTipFixer.exe [2008-10-15 61952] R2 UltraMonUtility;UltraMon Utility Driver;c:\program files\common files\realtime soft\ultramonmirrordrv\x32\UltraMonUtility.sys [2006-9-24 11776] R2 winbackupdumper-id19T5e6l2szc-;Windows System Backup Dumper;c:\windows\system32\mousenh32.exe [2010-6-22 11776] R3 DAdderFltr;DeathAdder Mouse;c:\windows\system32\drivers\dadder.sys [2010-6-21 22784] R3 DELTAII;Service for M-Audio Delta Driver (WDM);c:\windows\system32\drivers\MAudioDelta.sys [2010-6-21 302472] R3 TarFltr;Razer Tarantula USB Keyboard;c:\windows\system32\drivers\UsbFltr.sys [2010-6-21 45440] R3 UltraMonMirror;UltraMonMirror;c:\windows\system32\drivers\UltraMonMirror.sys [2006-9-24 3584] S2 acrosysbackup_exT5e6l2szc-;Acronis System Backup;c:\windows\system32\wirepots.exe [2010-6-22 8704] S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-6-21 1684736] =============== Created Last 30 ================ 2010-06-21 14:51:27 0 d—–w- c:\docume~1\slynk\applic~1\Waves Audio 2010-06-21 14:50:06 0 d—–w- c:\program files\Waves 2010-06-21 14:48:59 0 d—–w- c:\program files\Image-Line 2010-06-21 14:47:51 2 —-a-w- c:\documents and settings\slynk\tenmy.ini 2010-06-21 14:47:51 0 d—–w- c:\docume~1\slynk\applic~1\regsdkrl32 2010-06-21 14:47:46 38912 —-a-w- c:\windows\system32\b_syspol32.dll 2010-06-21 14:47:46 140288 —-a-w- c:\windows\system32\pcre3.dll 2010-06-21 14:47:45 8704 —-a-w- c:\windows\system32\wirepots.exe 2010-06-21 14:47:45 717671 —-a-w- c:\documents and settings\slynk\regsdkrl29.exe 2010-06-21 14:47:45 38912 —-a-w- c:\windows\system32\wirepots.dll 2010-06-21 14:47:45 38912 —-a-w- c:\windows\system32\syspol32.dll 2010-06-21 14:47:45 11776 —-a-w- c:\windows\system32\mousenh32.exe 2010-06-21 14:47:27 86016 —-a-w- c:\windows\unvise32.exe 2010-06-21 14:47:09 0 d—–w- c:\program files\GForce 2010-06-21 14:33:33 0 d—–w- C:\VST 2010-06-21 14:30:32 0 d—–w- c:\program files\Spectrasonics 2010-06-21 14:29:44 0 d–h–w- C:\$AVG 2010-06-21 14:23:53 0 d—–w- c:\docume~1\slynk\applic~1\Ableton 2010-06-21 14:23:43 368640 —-a-w- c:\windows\system32\ReWire.dll 2010-06-21 14:23:43 233472 —-a-w- c:\windows\system32\REX Shared Library.dll 2010-06-21 14:23:32 0 d—–w- c:\program files\Ableton 2010-06-21 04:46:51 0 d—–w- c:\program files\common files\ODBC 2010-06-21 04:46:48 0 d—–w- c:\program files\common files\SpeechEngines 2010-06-21 04:46:25 0 d—–r- c:\documents and settings\all users\Documents 2010-06-20 22:22:56 0 d—–w- c:\docume~1\slynk\applic~1\Internode 2010-06-20 22:22:36 0 d—–w- c:\program files\Internode 2010-06-20 22:15:52 0 d—–w- c:\program files\SteamWatch 2010-06-20 22:14:56 0 d—–w- c:\program files\Steam 2010-06-20 21:09:22 0 d—–w- c:\docume~1\slynk\applic~1\Office Genuine Advantage 2010-06-20 20:40:28 0 d—–w- c:\docume~1\alluse~1\applic~1\avg9 2010-06-20 20:19:23 0 d—–w- c:\docume~1\slynk\applic~1\Realtime Soft 2010-06-20 20:19:18 0 d—–w- c:\program files\UltraMon 2010-06-20 20:19:18 0 d—–w- c:\program files\common files\Realtime Soft 2010-06-20 20:19:18 0 d—–w- c:\docume~1\alluse~1\applic~1\Realtime Soft 2010-06-20 19:43:05 0 d—–w- c:\docume~1\alluse~1\applic~1\DAEMON Tools Pro 2010-06-20 19:42:41 0 d—–w- c:\docume~1\slynk\applic~1\DAEMON Tools Pro 2010-06-20 19:41:47 0 d—–w- c:\program files\DAEMON Tools Pro 2010-06-20 19:37:36 0 d—–w- c:\program files\AVG 2010-06-20 19:28:36 0 d—–w- c:\program files\M-Audio 2010-06-20 19:17:21 0 d—–w- c:\program files\ATI Technologies 2010-06-20 19:17:19 0 d—–w- c:\program files\ATI 2010-06-20 19:16:10 0 d—–w- c:\program files\Everything 2010-06-20 19:13:08 0 d—–w- c:\program files\AMD 2010-06-20 19:10:33 0 d—–w- c:\program files\Realtek 2010-06-20 18:58:37 0 d—–w- c:\program files\VideoLAN 2010-06-20 18:58:26 0 d—–w- c:\program files\NeoSmart Technologies 2010-06-20 18:56:28 0 d-sh–w- c:\documents and settings\all users\DRM 2010-06-20 18:56:16 0 d–h–w- c:\program files\WindowsUpdate 2010-06-20 18:56:13 0 d—–w- c:\program files\Online Services 2010-06-20 18:56:06 0 d—–w- c:\program files\Windows Media Connect 2 2010-06-20 18:55:37 0 d—–w- c:\program files\common files\MSSoap 2010-06-20 18:53:56 0 d—–w- c:\program files\LClock 2010-06-20 18:53:52 0 d—–w- c:\program files\MSN Gaming Zone 2010-06-20 18:53:33 0 d—–w- c:\program files\Windows NT ==================== Find3M ==================== 2010-06-20 23:32:33 242896 —-a-w- c:\windows\system32\drivers\avgtdix.sys 2010-06-20 20:42:25 12464 —-a-w- c:\windows\system32\avgrsstx.dll 2010-06-20 20:42:19 216200 —-a-w- c:\windows\system32\drivers\avgldx86.sys 2010-06-20 19:40:27 685816 —-a-w- c:\windows\system32\drivers\sptd.sys 2010-06-20 19:35:45 411368 —-a-w- c:\windows\system32\deployJava1.dll 2010-06-20 18:54:32 21640 —-a-w- c:\windows\system32\emptyregdb.dat 2010-05-06 10:36:27 919040 —-a-w- c:\windows\system32\wininet.dll 2010-05-02 02:04:16 1860352 —-a-w- c:\windows\system32\win32k.sys 2010-04-20 05:30:08 285696 —-a-w- c:\windows\system32\atmfd.dll ============= FINISH: 1:16:48.65 ===============

Attachments:

Posted Image


DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista and Windows 7 users:
1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.



Please download GooredFix from one of the locations below and save it to your Desktop
Download Mirror #1
Download Mirror #2
  • Ensure all Firefox windows are closed.
  • To run the tool, double-click it (XP), or right-click and select Run As Administrator (Vista).
  • When prompted to run the scan, click Yes.
  • It doesn't take long to run, once it is finished move onto the next step



Download TDSSKiller and save it to your Desktop.

  • Make sure all other windows are closed and to let it run uninterrupted.
  • Extract the file and run it.
  • Reboot your machine and see if the infection is gone
Ah thanks for the reply. I did already try this coz I was reading in the self help section but it didn't work.. I actually decided it was quicker and easier to just reinstall windows and restart my system every time I installed a new program because I had a hunch that one of these programs I downloaded from the net was causing the run dll error and infecting me.. I narrowed it down and deleted that program installer and reinstalled windows again. There was probably a better way to do things but it worked. No run dll errors and a fresh start haha Thanks again for your reply :)

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI