I may just be stupid, but I really don't know where to begin to get all of this stuff off of my pc, I know that there is something in the system 32 file that AVG catches sometimes, and other times doesn't. It won't allow me to fix it, or give me any help. I also have the rundll32 problems that i see posted, and spyware on this thing. Please send me info on the best way to diagnose what is in here, and how to get it out... Thanks, Tom

Dani AI

Generated

Short, practical primer for this thread: rundll32.exe is normally a legitimate Windows host used to run DLL functions, but attackers commonly abuse that name or the real rundll32 process to load malicious DLLs — so seeing rundll32 activity is not proof by itself that Windows is healthy or infected. Do not start deleting files from System32; first confirm whether the running instance is the real Windows binary, where it lives, and whether its command-line or parent process looks suspicious. ’s advice to scan for spyware was the right first step; the workflow below expands that into a safer, repeatable triage. (howtogeek.com)

Immediate, prioritized actions (do these before fiddling with the registry): disconnect the PC from the network; copy only personal data (documents, photos) to external media — do not copy executables; boot into Safe Mode (or use a bootable rescue USB) and run up-to-date anti‑malware tools (Malwarebytes is a good second-opinion scanner). If a normal scan fails, perform an offline/boot-time scan (Microsoft Defender Offline or equivalent) before attempting file removal. Change online passwords only from a known-clean device after cleanup. (malwarebytes.com)

Investigation tools and what to look for: use Process Explorer to see the parent process, full command line and loaded DLLs; use Autoruns to find and export autorun/startup entries and scheduled tasks; use Sigcheck or file properties to check digital signatures and hashes, then submit suspicious files to VirusTotal before deleting anything. Save exported Autoruns/HJT logs and Process Explorer output — those logs let experienced helpers confirm whether an entry is malware or a needed Windows component. Don’t delete entries blindly. (learn.microsoft.com)

If the infection persists or items reappear after removal, collect the logs and escalate (post a fresh HijackThis/Autoruns log in a new thread as suggested). When automated and manual removal fail, the reliable escalation is an offline rescue scan or a clean OS reinstall after backing up data. For a stepwise escalation plan and sample removal workflow, consult an established removal guide before proceeding. (bleepingcomputer.com)

Recommended Answers

All 5 Replies

If you haven't done so already, scan with Adaware and Spybot and let them fix what they find. You might also want to download HijackThis, make sure it is updated to the newest version which is 1.98.2, and scan and post the results of the log here. Don't attempt to fix anything yet, because most of what is in the log is needed. But if you have spyware, one of the experts will be able to point it out to you and help you get it fixed. :) Scanning with Adaware and Spybot is a good start though. Good luck!

Adaware:
Spybot:

Check for updates on both once you have them downloaded.

HijackThis:

commented: Good advice! -- dlh +1

Deonnanicole already covered the basics, but you should have a look at this thread as well for more tips:
http://www.daniweb.com/techtalkforums/thread5690.html

Thank you, oddly enough I saw that thread just after I posted.... Hopefully with the help of what I am finding I can fix it all myself. I am learning as I go... maybe.

I have the same problem but when I open up any program it says that it has performed and illegel operation and will be shut down but it still runs somewhat. Can you help???? :sad:

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.