Page 1 of 2
Virus question + System Resources
Posted: Sun Jun 30, 2002 2:37 am
by Weasel
Here is my question to anyone who can answer, is this
RUNDLL32.EXE NvQTwk.NvCplDaemon.ini
RUNDLL32.EXE
The virus this page is talking about?
My reason for asking, I can hit Ctrl, Alt, Del and bring up my close program box and I have two Rundll32 running. Trying to shut down one of them will freeze my computer and call for a major reboot.
The cause of me asking..System Resources at 83% and I cannot figure out how to get this number lower. Everytime I load a game up it will freeze after about 10 minutes.
Programs running at the time it happens.
Systray
Starter
Rundll32
Rundll32
I have deleted all my games (and installed only one back) and have 7 gigs of harddrive avaibl, 192 mb of ram.
Posted: Sun Jun 30, 2002 5:33 am
by Demis
Actually daemon is a backround applications for windows and always runs, the only problem is that they shouldn't be two of them, i have the same entry in my registry as you weasel but its only one.
From the suptoms(high number(%) of system resourses) it looks like a work of the trojan klez, what antivirus do you have installed?
Posted: Sun Jun 30, 2002 12:43 pm
by Weasel
I have Norton Antivirus 2000 installed and it 'claims' no virus are present on my computer..(I'm beginning to have my doupts).
Would you suggest a different antivirus program?
(BTW...I shut down my computer last night to see if the System Resources would change when I booted up today.
88% !! It gained 5% while being turned off?)
Posted: Sun Jun 30, 2002 2:50 pm
by Mr Sleep
Originally posted by Weasel
I have Norton Antivirus 2000 installed and it 'claims' no virus are present on my computer..(I'm beginning to have my doupts).
How updated is it?
You might want to buy a newer Norton AV, 2002 has some new features that also help like email scanning.
Posted: Sun Jun 30, 2002 4:55 pm
by Weasel
Originally posted by Mr Sleep
How updated is it?
You might want to buy a newer Norton AV, 2002 has some new features that also help like email scanning.
Thinking along the same line...I downloaded the trial version of Norton 2002.
Scanned and it found Backdoor.Autoupder . I quaratined it. Then downloaded a uninstaller from Nortons web site. The uninstaller says no Backdoor.Autoupder found.
Idea's?
Posted: Sun Jun 30, 2002 6:26 pm
by Demis
I have made a little search on the virus,
check
this article, do you think that you might have this virus, from the symptoms you mentioned it might be possible but i'm not sure.
Posted: Sun Jun 30, 2002 7:51 pm
by Weasel
Originally posted by Demis
I have made a little search on the virus,
check this article, do you think that you might have this virus, from the symptoms you mentioned it might be possible but i'm not sure.

The file IO Class is there and I will delete it as instructed on the page.
***Delete any registry keys that reference the files mentioned in the characteristics section of this description
***Delete the files mentioned in the characteristics section of this description
These, I admit are out of my knowledge.
Posted: Sun Jun 30, 2002 8:04 pm
by Weasel
Well I'm at a loss.
I now have (4) Rundll32 in my close program box.
System resources still at 88% as well.
So will reformatting my whole harddrive solve this?
(Don't worry I will not do this as of yet..I will need to talk to my ISP provider first to see when they can come and reinstall the cable program first. A week most likely to get them to come out. Right now I can get on line and don't want to make it where I can't.)
Next will be...how to reformat and be sure to get this fixed?
Posted: Sun Jun 30, 2002 8:13 pm
by Demis
Originally posted by Weasel
***Delete any registry keys that reference the files mentioned in the characteristics section of this description
***Delete the files mentioned in the characteristics section of this description
These, I admit are out of my knowledge.
As far as i can tell it requires some registry editor. Messing with registry might cause some trouble[problems, but if you feel you could try it go ahead
run
regedit and do a search for the files mentioned in the article and delete them one by one. When you do this restart and do another search, now for
files and folder and deleted the actual files stated there.
However i reccomend that you do the file search first to see if indeed these files exist in to your computer. If they are indeed there do the reg edit thing and delete them afterwards.

Posted: Sun Jun 30, 2002 9:04 pm
by Weasel
A file search only turned up one of the files
**Msvcp60.dll (401,462 bytes) - This is not a trojan file, but rather a Microsoft C++ Runtime Library used by other trojan components. This .DLL is typically found in the SYSTEM directory on non-infected systems. A second copy may be found in the WINDOWS directory on infected systems.**
No second copy of it though.
I will try to look back later and see if anyone has any thoughts...Computer locking up every 5 minutes now.

Posted: Mon Jul 01, 2002 2:00 am
by Weasel
Well I'm back on-line..somewhat at least.
Me being the person I am..reinstalled windows to try and correct the problem. Wiped out my internet connection, all my updated drivers, all my updates period. Caused IE 5.5 to not recongize my cable connection....the list is very long. (I should have just reformatted..(Looks like I did)
Had to use Netscape to even get back on line.. (The Rundll32 are gone) Download IE 6 and now will start to down load all the stuff I some how deleted in this process.
Will check the system resources when I have the program downloaded from Gateway (again)
Posted: Mon Jul 01, 2002 4:07 pm
by fable
@Weasel, you might want to invest in something like Norton Systemworks. It has plenty of excellent tools: a cookie remover, a hard drive cleaner, a disk doctor to look for invalid files, a cache cleaner, and a registry editor that allows you to search for all instances of a given word or phrase.

Posted: Mon Jul 01, 2002 5:27 pm
by Demis
Originally posted by Weasel
(I should have just reformatted..(Looks like I did)
You should

, have you consider imaging?
Posted: Mon Jul 01, 2002 9:27 pm
by Weasel
Originally posted by fable
@Weasel, you might want to invest in something like Norton Systemworks. It has plenty of excellent tools: a cookie remover, a hard drive cleaner, a disk doctor to look for invalid files, a cache cleaner, and a registry editor that allows you to search for all instances of a given word or phrase.
I have Nortons Uninstall 6.0 , but now have a serious problem. I cannot install anything. During my install of windows something went wrong and now the Install Wizard of Microsoft is saying it is busy...all the time.
Originally posted by Demis
You should
, have you consider imaging?
Looks like I'm going to have to reformat still.
Imaging? (I don't understand the question.)
I have never did a full reformat before any tips or advice would be welcomed from anyone.
1.Saving my links
2.Try to save Zone Alarm exe. so I can install it before I get back on-line.
3.Wipe everything else out.
(I have nothing of value on the computer and would like to be sure to wipe it clean.)
It's a Gateway computer with a two disc..** System Restoration CD and **Operating System Backup CD.
I'm fixing to head to Gateways site and se if they have a recommended way to reformat....but I have little faith in them.
T -5 days to format.
Posted: Tue Jul 02, 2002 7:08 am
by Demis
Originally posted by Weasel
Looks like I'm going to have to reformat still.
Imaging? (I don't understand the question.)
Drive image, you create a hard disk image for backup. Usually you keep the image file on another disk/partition, you format your primary disk and by restoring the image you don't even have to reinstall windows or programs, depending on what you have installed when you created the hard disk image. It can also save you when system crashes occur and you have to reformat.
Power Quest Drive Image and
Norton Ghost are 2 softwares that provide drive image.
I believe Norton ghost is included into Systemworks and also gives the option to create a drive image directly to cd-r.
I have never did a full reformat before any tips or advice would be welcomed from anyone.
1.Saving my links
2.Try to save Zone Alarm exe. so I can install it before I get back on-line.
3.Wipe everything else out.
(I have nothing of value on the computer and would like to be sure to wipe it clean.)
Since it's a Gateway pc i'm not sure how it works when formating
i guess you have to format and then run "Operating System backup cd"
Posted: Sat Jul 06, 2002 12:21 am
by Weasel
Thanks for the help Demis, Mr.Sleep and Fable
I have finally gotten my computer acting right. The Rundll32 turned out to be the Video Card quick tweet. For some reason it kept making copies of its self. I finally turned it off using MSCONFIG and have gotten my resources down to only 8% being used...(24% while on line
Posted: Sat Jul 06, 2002 4:40 am
by Demis
Glab to hear that @Weasel

, i assume that you didn't have to reformat either ?
Posted: Sat Jul 06, 2002 11:02 am
by Weasel
@Demis, no reformatting.
I'm still thinking about going ahead and reformatting though. This computer is two years old, and I have installed/uninstalled alot of games on it. Maybe a clean slate will stop any problems in the future. During this episode, I wiped almost everything off, so I really want be losing anything. (I have Civ3 reinstalled, but the new patch is causing lock ups
...something the old patch didn't, so I just went back to the old one) First I'm going to call Gateway (And my ISP) and make sure I understand how to go about reformatting and getting it all back on....then I will decide for sure.
Posted: Sat Jul 06, 2002 7:44 pm
by Demis
Reformating every once in a while can do only good, but it's wise to check everything out before you do it

Posted: Mon Jul 08, 2002 6:01 am
by Mr Sleep
I reformat on a regular basis and it really helps speed and the effectiveness of Windows as a whole. There are a lot of complicated intricacies to backing up all of your settings. Like favourites folders, internet settings, Email...the list goes on.
You might be able to rent a CD Writer and then back up all the data?