Windows startup problem

Druga Runda

Sleepy Substitute
Regular
Well after being up for a few days, and having some viruses in the meantime (captured by AVG straight away) I am getting this message on startup.


typical windows error message:

Cannot find the file rundll23.exe(or one of its components).Make sure that the path and filename are correct and that all required libraries are available.

and I have uninstalled Rage3D tweak in the meantime...

btw it's windows 2000 sp4.

and yes it's rundll23 not 32... .

I could post the image, but have nowhere to upload it. The error is on startup and it seems that it doesn't affect anything as far as I can tell, any ideas how to find out what it is and get rid of at least the error message if nothing else.

* googling on that filename brings nothing, probably all errors when people were reffering to rundll32

edit: I found the file with the same name in my windows\system32 folder?!? And I am running Windows 2000 - when I think of it why does windows folder exist? I haven't installed winXP or win9x on that PC before.

ummm...
I have only that system32 folder there underneath windows folder, and a few more apps and a few files in that folder besides rundll23.exe

Those are DriverNetC.exe ; run.exe ; winsock.exe

and I had this text file in the folder
called elicomp.txt

2004.04.20 01:52 Remote Administrator server is started
2004.04.21 22:20 Remote Administrator server is started
2004.04.21 22:20 Remote Administrator server is started
2004.04.21 22:20 bind_socket fails
2004.04.21 22:22 Remote Administrator server is started
2004.04.21 22:23 Remote Administrator server is started
2004.04.21 22:23 bind_socket fails
2004.04.21 22:28 Remote Administrator server is started
2004.04.21 22:28 Remote Administrator server is started
2004.04.21 22:28 bind_socket fails
2004.04.21 22:32 Remote Administrator server is started
2004.04.21 22:32 Remote Administrator server is started
2004.04.21 22:32 bind_socket fails
2004.04.21 22:35 Remote Administrator server is started
2004.04.21 22:35 Remote Administrator server is started
2004.04.21 22:35 bind_socket fails

ummmm



Well I have three objectives
1. find out that nothing is broken
2. get rid of the startup error message
3. if possible find out what does this file do - virus or what?
4. someone trying to hack me... btw I have a software and hardware firewall for that effect with ports open for a few P2P apps.

Help :!: :)


*** OK it is probably an attempted hack... I remember trying to install a file that pretended to be e-mule... and well I can see two of those .exe files trying to get out on the net ; that drivernetc.exe and winsock.exe but blocked by my software firewall... meh... (and loaded on windows startup... )

How do I delete all that stuff, :)

OK there is more

ASPNET user account... it's in group users... (ie new computer account meh)

- found what it is
What is this new user account for? What created it?

The aspnet_wp or ASP.NET Machine Account is created when the Microsoft .Net Framework 1.1 is installed onto a Windows XP computer. The user is created for the asp.net worker process used in Microsoft's Internet Information Services to fully support ASP.net on your web server (This is pretty much its only use, it is not used to run normal .net managed executables) . There is not a need to worry about this users presence, it was not created in malicious way.

ASP.net is a programming framework built on the common language runtime (Microsoft .net framework) that can be used on a server to build powerful Web applications. For more information on ASP.net see here
however I don't remember installing .net framework on my PC??? in last 2-3 months since reformat - but you never know :). Is it just a Windows XP thing? anyone knows? Should I delete, or not?

ok edit one more time

when trying to remove that windows folder (that was by the way created on 20th of April, I get admdll.dll is in use... now that doesn't sound nice... as well as the above mentioned files... well killed them all and well deleted... now we will see what happens next. There must be some registry entries as well, but I guess they can't do anything without the files...

to add the last... just checked AVG log - yes 20th of april virus infection - Backdoor.R3C.H and Backdoor.R3C.F apparently healed OK, but why did it leave the other files to load?



ahhh **** here is some info finally
http://securityresponse.symantec.com/avcenter/venc/data/backdoor.r3c.b.html
but that is the B version...

The Trojan can do any of the following:

* Deliver system and network information to the hacker
* Modify system configurations
* Open/close the CD-ROM drive tray
* Restart/close Windows
* Execute/copy/delete/rename files

and I have not seen that registry entry mentioned there in my registry

how do I delete all stuff this virus spread?
ideas if someone here had experience with this new one please...

* and the last - reading a little it seems that the virus somehow misdiagnosed me as WinXP? what other reason would it have to copy itself ~or to create windows folder on my machine??? Meh those later versions are a bit different I guess.
 
adn last, run AVG in the safe mode as well, and well no viruses reported... It seems that I just need to get rid of that startup error message...

edit: to add again I have run system mechanic; 30 day free trial version and it has cleaned my registry etc...

but there is one more instance of this rundll23 in my registry in the key

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\Currentversion\Winlogon

key called shell
type Reg_SZ
Data Explorer.exe and this rundll23.exe

This must be starting this error message as I guess it's trying to locate the file.
OK, I assume I should not delete the whole key, and assume that taking the value out from the data field should kill this popup error - correct?

I think I'll do it nhow as it's late and I am annoyed to max with wasting this evening on this virus...

Well backup and delete the value...
 
Conclusion

Well success :) so far.

The startup message is gone and looks I've cleaned up everything.

Well overall annoying as any infection but I am glad as it seems that it's sorted out :) :) :)
 
Back
Top