Jump to content

Nathan09

Members
  • Posts

    1
  • Joined

  • Last visited

Everything posted by Nathan09

  1. :(I am a very careful user but now I have a few sudden yet persistent malware issues similar to what is described at http://www.malwarebytes.org/forums/index.p...amp;hl=rundll32. The post did not advise to follow the instructions there and I am creating a new topic. Any help will be highly appreciated. I have XP Pro SP2 and the virus definition file for Norton was up to 9/3/09. It seemed I was able to get rid of Windows Police Pro and Advanced Virus Remover. But the following symptoms are still present: 1) There is a startup error message: rundll32: cannot load tapi.info 2) cannot run hijackThis, Malwarebytes ever after reinstallation. 3) I cannot run Norton Anti-virus manually. However the real-time monitor still works and the scheduled scan did run today and got rid of 248 instances of Trojan.vundo 4) There is a file called suviraju at Windows\system32 and it gets recreated right after I deleted it 5) There are two registry entries also getting recreated a few seconds after deletion: ...Windows\currentVersion\runonce\yodohusidi and the value is rundll32: Windows\system32\nobibipo.dll; and ...Windows\currentVersion\runonce\gayisevon and the value is rundll32: Windows\system32\vokizofe.dll 6) my dllcache directory is missing 7) Many Google search results are redirected to malware purchase sites. 8) Having IE popups from time to time. Luckily my network is working today. It did not work yesterday (IPConfig displays IP addresses but I could not make an Internet connection). Yesterday, the virus/malware disabled my taskmanager and regedit. No exe files could be run. After many, many hours of struggling, most exe files are fine now, but not hijackThis, Malwarebytes, NAV, etc. I can boot to Safemode with network but not to pure Safemode - the computer is in a domain and I don't have the Administrator password of the local domain. I do have full admin right to the box.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.