943,871 Members | Top Members by Rank

Ad:
You are currently viewing page 1 of this multi-page discussion thread
Jun 14th, 2004
0

Rundll error loading sdkzh.dll

Expand Post »
I recently tried to remove some spyware from my computer and now I get the following message (twice) every time I boot.

RUNDLL
Error loading C:\WINDOWS\sdkzh.dll
The specified module could not be found.

Running Windows XP

Thanks for the help.
Jake
Similar Threads
Reputation Points: 10
Solved Threads: 0
Newbie Poster
kjakemiller is offline Offline
4 posts
since Jun 2004
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

As this is spyware related, I'm moving it to our Security forum.

That error is probably caused by an "orphaned" run entry in your registry; the entry just being a "loose end" left over from the spyware removal. HijackThis can probably remove the entry for you if you aren't comfortable editing your Registry by hand.

Run HJT and look for an entry similar to the following:

O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\sdkzh.dll

If it exists, put a check in the box at the beginning of the entry and have HJT fix it. DO NOT HAVE HJT FIX ANYTHING ELSE AT THIS POINT!!
Last edited by DMR; Jun 14th, 2004 at 1:56 pm.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

I ran HJT and deleted the file you suggested, however I was still getting the error message. (now only once). I ran HJT again, found a similar file then deleted it, however I'm still getting the error. Ran HJT for a third time and cant find anything similar to what you suggested. Any other suggestions..I appreciate the help.
Reputation Points: 10
Solved Threads: 0
Newbie Poster
kjakemiller is offline Offline
4 posts
since Jun 2004
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

post your hjthis log here .
Team Colleague
Reputation Points: 1056
Solved Threads: 792
I hate 20 Questions
caperjack is offline Offline
12,723 posts
since Aug 2003
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

Quote originally posted by caperjack ...
post your hjthis log here .
Yup. A lot of these nasties can morph and/or reinstall themselves if you don't catch every little piece of them. Let's have that HJT log and we'll see if we can spot the culprit.

Also, did you run Ad Aware, SpyBot, CWShredder, etc. before doing your HJT scan? If not, do so before posting the fresh log.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

Sorry- I also forgot to mention that HJT only removes the Registry's reference to the files in the " O4 - HKLM\..\Run" entries; you should find and delete the actual files after fixing them with HJT.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

Below is the log...sorry it is so long, I'm hoping you can tell me I should delete most of this stuff. thanks!

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Creative\ShareDLL\CtNotify.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE
C:\Program Files\Creative\NOMAD Jukebox Zen\PlayCenter2\CTNMRUN.EXE
C:\Program Files\Creative\ShareDLL\Mediadet.exe
C:\Program Files\Microsoft Money\System\mnyexpr.exe
C:\Program Files\j2 Messenger\HotTray.exe
C:\Program Files\j2 Messenger\Dllcmd32.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\devldr32.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Documents and Settings\K. Jake Miller\My Documents\Jake Dell\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#44272
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://mshp.dll/sp.html#44272
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://mshp.dll/sp.html#44272
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O2 - BHO: AlxTB BHO - {F1FABE79-25FC-46de-8C5A-2C6DB9D64333} - C:\WINDOWS\System32\AlxTB1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {3CEFF6CD-6F08-4E4D-BCCD-FF7415288C3B} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Disc Detector] C:\Program Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [CTStartup] "C:\Program Files\Creative\Splash Screen\CTEaxSpl.EXE" /run
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [mmtask] c:\Program Files\MusicMatch\MusicMatch Jukebox\mmtask.exe
O4 - HKLM\..\Run: [EPSON Stylus C82 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0HIC1.EXE /P23 "EPSON Stylus C82 Series" /O6 "USB001" /M "Stylus C82"
O4 - HKCU\..\Run: [NOMAD Detector] "C:\Program Files\Creative\NOMAD Jukebox Zen\PlayCenter2\CTNMRUN.EXE"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MoneyAgent] "C:\Program Files\Microsoft Money\System\mnyexpr.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: j2 Tray Menu.lnk = C:\Program Files\j2 Messenger\HotTray.exe
O4 - Global Startup: Live Menu.lnk = C:\Program Files\j2 Messenger\Dllcmd32.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: MoneySide (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {0075546E-5D3D-11D2-A3E5-0060971304D8} (WTX_Installer Class) - http://www.webtrends.com/Download/Br.../wtx_setup.dll
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/downlo...22/wmv9VCM.CAB
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/05300954...p/RdxIE601.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {8C42D15B-D8C2-40AD-9A06-3F27F58AE33E} - http://www.search-climbers.com/downl...ordsUnInst.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {F104576A-91BA-40AD-91DE-2C2080133900} - http://www.searchclimbers.net/download/cab/ieplugin.cab
Reputation Points: 10
Solved Threads: 0
Newbie Poster
kjakemiller is offline Offline
4 posts
since Jun 2004
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

Among other things, you seem to have a variant of the CoolWebSearch parasite. You should download and run CWShredder; see the following for more info:
http://www.daniweb.com/techtalkforum...searchid=74106

Also, have HJT fix these:

O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/0530095...ip/RdxIE601.cab
O16 - DPF: {8C42D15B-D8C2-40AD-9A06-3F27F58AE33E} - http://www.search-climbers.com/down...wordsUnInst.cab
O16 - DPF: {F104576A-91BA-40AD-91DE-2C2080133900} - http://www.searchclimbers.net/download/cab/ieplugin.cab

There may be more to do to, but take care of the above before posting a new HJT log.
DMR
Team Colleague
Reputation Points: 221
Solved Threads: 369
Wombat At Large
DMR is offline Offline
6,439 posts
since Dec 2003
Jun 14th, 2004
0

Re: Rundll error loading sdkzh.dll

worked perfectly....Thanks for your help!
Reputation Points: 10
Solved Threads: 0
Newbie Poster
kjakemiller is offline Offline
4 posts
since Jun 2004
Apr 30th, 2006
0

Re: Rundll error loading sdkzh.dll

error loading how can i correct this problem specified module not be found if i click ok resume using the pc as normal
Reputation Points: 10
Solved Threads: 0
Newbie Poster
pro_baby2008 is offline Offline
2 posts
since Apr 2006

This thread is more than three months old

No one has posted to this discussion for at least three months. Please let old threads die and do not reply to them unless you feel you have something new and valuable to contribute that absolutely must be added to make the discussion complete. Otherwise, please start a new thread in this forum instead.
Message:
Previous Thread in Viruses, Spyware and other Nasties Forum Timeline: Rundll Error C:\progra~1\intern~3\inetkw.dll
Next Thread in Viruses, Spyware and other Nasties Forum Timeline: cmd problems





About Us | Contact Us | Advertise | Acceptable Use Policy
Forum Index | Build Custom RSS Feed


Follow us on Twitter


© 2011 DaniWeb® LLC