Hi Gang,
Newbie here...
I've got a friend with a new startup rundll error that says windows can't find E:\windows\system32\opnmn.dll

My forum searches have not netted any info on this, other than several places where people are told to delete it as part of some other virus fix.

Here are my questions:
Q1 - is opnmn.dll needed?
Q2 - how to either install it, or kill the error message
Q3 - why would this error suddenly pop up?

Your kindness to this newbie / neophyte is much appreciated.
Feel free to email me if it's easier.
Cheers,
.James.

Dani AI

Generated

A short, practical diagnosis and next steps based on the thread so far.

The file opnmn.dll is not a normal Windows system DLL — it matches the pattern of randomly named DLLs used by the Vundo/Virtumonde family and similar adware/trojans, and those infections often create startup hooks that call a DLL that later gets deleted or quarantined. When Windows shows "RunDLL can't find … opnmn.dll" it usually means a leftover startup reference still points at that (now-missing) file — the E: drive letter in the path can mean the malware was installed to a nonstandard partition or a removable volume that’s no longer present. (securelist.com)

A safe, conservative workflow to resolve the message (do not skip the backups): create a System Restore point and export the registry hive before editing; run an up-to-date anti‑malware scanner (Malwarebytes or equivalent) in normal mode and again in Safe Mode; use Microsoft Sysinternals Autoruns to find the exact startup entry (Logon / Everything tabs) that references opnmn.dll and disable or delete that entry rather than randomly deleting registry keys; check Scheduled Tasks, the Startup folder and printer-monitor/driver entries (some rundll messages come from vendor monitor DLLs). Autoruns makes it straightforward to locate the source of the RunDLL call. (learn.microsoft.com)

Cautions and follow‑ups: do not simply silence the popup without removing the startup reference. Vundo variants can be persistent; historically tools such as VundoFix/ComboFix were used for stubborn cases, but modern on‑demand tools (Malwarebytes, AdwCleaner, reputable AV) and repeated scans in Safe Mode are the recommended route today. If infections persist or system behavior is odd (disabled services, unexpected drivers), consider offline rescue media or a reinstall as a last resort. Keep all removal logs (scan logs, Autoruns output) for diagnosis. (myantispyware.com)

The approach suggested earlier by — targeted anti‑spyware scans and producing a diagnostic log (HijackThis or Autoruns output) — is appropriate; those logs will show the exact Run key or scheduled task that still points at E:\windows\system32\opnmn.dll and allow safe removal. The original report from (the E: path) is a useful detail because it narrows where the missing file used to live. (learn.microsoft.com)

Recommended Answers

All 4 Replies

This is what happens when you just delete a virus file that is a requirement of a process remanent in the autostart menu, or which is the target of a key still in registry.... just looking at the autostart menu may tell you, but i doubt it. You could do a manual search of the registry for its keys, or run CCLEaner which will remove any orphaned keys, or run HiJackThis which should reveal any autostart programs etc that use it. Post a log here; someone will run an eye over it.

Thanks...
(now to reveal my extreme inexperience)... is the log file that I should post, generated by downloading (free?) and running HiJackThis, or do I generate one in some other way?
Cheers,
.James.

Uh-oh... :) Right, before you run that there are a couple of housekeeping things i insist/would like you to run first.... and maybe once you do you won't need help, and as a bonus you'll know more n feel good.

I would like you to download CCleaner from http://www.ccleaner.com/ and put it in a new folder. You should aim to keep this one for general use. I set it from the install checkboxes to only open from the recycle bin. It's just a neater thing.
Get Adaware SE Personal from
- install it. Update it. Explore what settings you can change in it [via the cogwheel icon up top, if you are comfortable with that... you won't hurt anything]. Put an icon on your desktop for regular use.
Next go here to get Spybot S&D :- http://www.safer-networking.org/en/download/ Update it.
Finally choose a dl site from here to get hijackthis:

Okay, with the net off...
- run Ccleaner from the recycle bin rclick menu [if you set up CCleaner as i suggested, rclicking the bin icon should give you the run Ccleaner option...]
- Do a full Adaware scan and remove all the problems it finds.
- Run SpyBot S D. Create the registry backup, then check for problems. Select and fix problems.
By now you're probably clean... at least from milder bugs.... if not then it's time for Hijackthis. Please don't try to fix things yourself , you can really break stuff, just post the log it produces in notepad.
Instructions? they don't come much better than from this site

http://www.bleepingcomputer.com/tutorials/tutorial42.html
- read warning, intro and stop there :). Now just Doubleclick the .exe in the HT folder. Then with nothing else open, not even the explorer window of the ht folder, click "Do a system scan and save a Logfile" and you will get the notepad version of the log as well on your desktop - that is the one to post here.. cutnpaste it. Please don't "fix" anything yet....
Right, get cracking.

Ccleaner and regular use... just leave checked the temp folder, temp inet folders, cookies, history if you wish.... whatever, and the app cleans em out in one click. or so. and its one of the few reg cleaners you don't have to pay for.... efficacy? well i have found that all proprietary reg cleaners find some different stuff each.... so nothing's perfect.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.