1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved RunDLL (Error loading) Vista Home Premium

Discussion in 'Malware and Virus Removal Archive' started by AlanR, 2011/04/23.

  1. 2011/04/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    While installing Java....UNCHECK any pre-checked toolbar and/or software offered with the Java update

    Note 2...If you don't want to run another extra service, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer
     
  2. 2011/04/28
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    Thanks Broni...Item 1 was not offered that I could see and I have unchecked Java Quick Starter now I found it Duh!

    JarvaRa

    Have downloaded JavaRa and unzipped it...but the JarvaRa.exe landed on my desktop, not in the folder. Ran this and clicked 'Remove Older Versions' and it came back with "Could not find JavaRa.def! Be sure the definition file resides in the same directory JavaRa.exe is in

    My question is...how do I get it in?

    However, this is the script that it gave me:

    JavaRa 1.16 Removal Log.

    Report follows after line.

    ------------------------------------

    The JavaRa removal process was started on Thu Apr 28 22:29:19 2011

    Found and removed: C:\Program Files\Java\jre1.6.0_13

    Found and removed: C:\Users\Alan\AppData\LocalLow\Sun\Java\jre1.6.0_13

    Found and removed: C:\Users\Alan\AppData\LocalLow\Sun\Java\jre1.6.0_14

    Found and removed: C:\Users\Alan\AppData\LocalLow\Sun\Java\jre1.6.0_15

    Found and removed: C:\Users\Alan\AppData\LocalLow\Sun\Java\jre1.6.0_17

    Found and removed: C:\Users\Alan\AppData\LocalLow\Sun\Java\jre1.6.0_18

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0001-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0002-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0003-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0004-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0005-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0006-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0007-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0008-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0009-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0010-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0011-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0012-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0013-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0014-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0015-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0016-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0017-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0018-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0019-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0020-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0021-ABCDEFFDCBA}. The error returned was 124.

    There was an error removing \Mozilla Firefox\extensions\{CAFEEFAC-0016-0022-ABCDEFFDCBA}. The error returned was 124.
     

  3. to hide this advert.

  4. 2011/04/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You did just fine.
    Go on....
     
  5. 2011/04/28
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    Here is the OTL Fixes text log Broni:

    All processes killed
    ========== OTL ==========
    Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\\{AEB6717E-7E19-11d0-97EE-00C04FD91972} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AEB6717E-7E19-11d0-97EE-00C04FD91972}\ not found.
    Registry key HKEY_USERS\S-1-5-21-948891049-2262682744-2781767659-1000_Classes\.com\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-948891049-2262682744-2781767659-1000_Classes\ComFile\ not found.
    HKEY_LOCAL_MACHINE\Software\Classes\.com\\|comfile /E : value set successfully!
    Registry key HKEY_USERS\S-1-5-21-948891049-2262682744-2781767659-1000_Classes\.exe\ deleted successfully.
    Registry key HKEY_USERS\S-1-5-21-948891049-2262682744-2781767659-1000_Classes\exefile\ not found.
    HKEY_LOCAL_MACHINE\Software\Classes\.exe\\|exefile /E : value set successfully!
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Alan
    ->Temp folder emptied: 2000 bytes
    ->Temporary Internet Files folder emptied: 120274327 bytes
    ->Java cache emptied: 30397333 bytes
    ->FireFox cache emptied: 73440989 bytes
    ->Flash cache emptied: 351192 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 43 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 214.00 mb


    [EMPTYFLASH]

    User: Alan
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default

    User: Default User

    User: Public

    Total Flash Files Cleaned = 0.00 mb


    OTL by OldTimer - Version 3.2.22.3 log created on 04282011_231334

    Files\Folders moved on Reboot...

    Registry entries deleted on Reboot...
     
  6. 2011/04/28
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    Security Check File log:

    Results of screen317's Security Check version 0.99.7
    Windows Vista Service Pack 2 (UAC is enabled)
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    avast! Free Antivirus
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    Java(TM) 6 Update 13
    Java(TM) 6 Update 25
    Out of date Java installed!
    Adobe Flash Player 10.2.153.1
    Adobe Reader 9.4.4
    Out of date Adobe Reader installed!
    Mozilla Firefox (3.6.16)
    Mozilla Thunderbird (3.1.9)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    system32 AvastSvc.exe -?-
    Alwil Software Avast5 AvastUI.exe
    ``````````End of Log````````````
     
  7. 2011/04/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Uninstall Java(TM) 6 Update 13.

    Update Adobe Reader

    You can download it from http://www.adobe.com/products/acrobat/readstep2.html
    After installing the latest Adobe Reader, uninstall all previous versions.
    Note. If you already have Adobe Photoshop® Album Starter Edition installed or do not wish to have it installed UNcheck the box which says Also Download Adobe Photoshop® Album Starter Edition.

    Alternatively, you can uninstall Adobe Reader (33.5 MB), download and install Foxit PDF Reader(3.5MB) from HERE.
    It's a much smaller file to download and uses a lot less resources than Adobe Reader.
    Note: When installing FoxitReader, make sure to UN-check any pre-checked toolbar, or any other garbage.
     
  8. 2011/04/29
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    ESET scan

    Scan results for ESET show no threats found...so no text file to post to you Broni.


    ####################




    QUESTION ABOUT AVAST

    I have a question to ask you about 'Avast' as although my security center is showing 'Avast' is running and I have just had an automatic update from them, things have changed slightly.

    When I boot up I have lost the bottom tray 'Orange Icon' and the onscreen 'Avast Blob Icon' does not say 'SECURED'.
    The only way that I can put this right is to double click the 'Application Icon' either in the start menu or a shortcut
    that I have created on the Desktop, each time I bootup.

    1) Is this indicative that all is not fully correct with Avast...although all appears well enough?
    2) Is there a way to correct the situation?

    ####################



    Java Unistall Update 6.0.130

    I have tried to uninstall this through the control panel but it does not want to go. I have allowed the following to go through, when asked by 'User Account Control' but nothing seems to happen?

    'Unidentified Publisher

    Update
    6.0.130
    Sun Microsystem


    I did notice a 'Transfereing data from stat.flashtalking.com in the bottom left of screen...it this ok??
     
    Last edited: 2011/04/29
  9. 2011/04/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Happens when? Which browser?

    Leave that Java alone then.

    Just to be on a safe side, I'd reinstall Avast.

    ====================================================

    Your computer is clean :)

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. Run defrag at your convenience.

    11. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    12. Please, let me know, how your computer is doing.
     
  10. 2011/04/29
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    Quote:
    I did notice a 'Transfereing data from stat.flashtalking.com in the bottom left of screen...it this ok??

    Broni Question
    Happens when? Which browser?

    ANSWER
    Using Firefox Browser 3.6.16

    When as stated below.

    I tried to uninstall Java Update 6.0.130

    I tried to uninstall this through the control panel. A panel came up named 'User Account Control' asking for permission to access the internet. It had the following details on it:

    'Unidentified Publisher

    Update
    6.0.130
    Sun Microsystem

    As this coincided with my request to uninstall the Java update I agreed, but nothing happened with the uninstall.

    I did notice a 'Transfereing data from stat.flashtalking.com in the bottom left of screen...and it still showed bottom left of my screen after I have rebooted.

    Normally this would say 'DONE' when your chosen site has loaded, but as I was getting no where trying to do this uninstall I just happen to notice this statement of data transfer.

    That flashtalking,com statement justy showed up again while I was wring this to you, but has now gone. I was watching my PC and the light certainly showed activity when I saw it.

    It has gone again now...strange or what?
     
    Last edited: 2011/04/29
  11. 2011/04/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Leave Java alone. Continue with other steps.
     
  12. 2011/04/30
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    Broni here is my cleanup restor file txt with OTL:

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Alan
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 17970556 bytes
    ->Java cache emptied: 0 bytes
    ->FireFox cache emptied: 54313932 bytes
    ->Flash cache emptied: 844 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 3281 bytes
    %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 69.00 mb


    [EMPTYFLASH]

    User: Alan
    ->Flash cache emptied: 0 bytes

    User: All Users

    User: Default

    User: Default User

    User: Public

    Total Flash Files Cleaned = 0.00 mb



    OTL by OldTimer - Version 3.2.22.3 log created on 04302011_185918

    Files\Folders moved on Reboot...
    C:\Users\Alan\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MIZZTU4K\background-banner-right-v3[1].jpg moved successfully.

    Registry entries deleted on Reboot...
     
  13. 2011/04/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Whenever ready...
     
  14. 2011/04/30
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    Broni, thank you so much for your very kind and attentive help with this problem that I encountered.Your friendly attitude and support made this process much easier for me as I was more than a little daunted at first.

    My computer is working just fine thank you, and seems to have a little more spring in its step, with pages loading somewhat faster than previous.

    I am now working through the other items that are listed on your last 'DO post' to me, from 3 onwards. I intend to be more vigilant in future with the advice and additions that you advise/suggest.

    I am a little concerned about uninstalling/reinstalling Avast (we discussed earlier) as I have read that sometimes it can go wrong. It being recommended to download and use the 'Avast uninstall utility' on their site. Your comments on this would be very welcome.

    I don't now want to create a new mess for myself.

    Alan
     
  15. 2011/04/30
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good news :)

    Since you'll be reinstalling Avast, using its removal tool will be unnecessary.

    Good luck and stay safe :)
     
  16. 2011/05/01
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0
    Reinstall Avast


    Broni, can you be a little more specific for me please about the 'Reinstallation' of Avast.

    Is there a place on my computer that I go to 'Reinstall', or is there a place on the Avast
    website that has a link to a 'Reinstallation download'.

    Or... do I just download a new Avast.exe file and install it on top of the version on my PC.


    Sorry to trouble you again, but I need to be sure of what I am doing before I start. I have
    read some nasty stories of people getting this wrong and causing all sorts of problems.

    Thank you again

    Alan
     
  17. 2011/05/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  18. 2011/05/01
    AlanR

    AlanR Well-Known Member Thread Starter

    Joined:
    2008/02/28
    Messages:
    48
    Likes Received:
    0

    Thank you again Broni, that went well.

    Take care

    Alan
     
  19. 2011/05/01
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Cool beans :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.