1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

worm_rbot.ein / missing system file!

Discussion in 'Malware and Virus Removal Archive' started by essentialcandi, 2006/04/22.

Thread Status:
Not open for further replies.
  1. 2006/04/22
    essentialcandi

    essentialcandi Inactive Thread Starter

    Joined:
    2006/04/22
    Messages:
    4
    Likes Received:
    0
    Hi

    I downloaded an attachment today which turned out to contain a virus. AVG flagged the file up immediately, then closed.

    It would appear that the virus closes all antivirus apps, therefore I then ran an online scan of my harddrives using HouseCall.

    HouseCall informed me that the worm worm_rbot.ein (I think) had infected a file within c:\windows\system32, but could not access the file as it was in use.

    I opened task manager and ended the process, and before I could do anything further, HouseCall removed the file! The log produced said the file could not be cleaned.

    Now however I have a huge problem. Everytime I attempt to open any application from the start menu, or directly from the exe on the HDD, windows tells me the file cannot be found, and to try searching for the file.

    All the exes for the programs exist and are the correct file size, thus I believe that the file which HouseCall removed appears to have been an essential system app which allows applications to be opened. I know the apps still work because if I access a Microsoft Word doc for example, Word itself opens to display the document.

    I believe the removed file must somehow control the opening of apps on the system. the file was in the system32 or system folder within windows. I am running XP Home Ed. and I think the file started with "r" and was definetly an .exe file. The window for HouseCall closed so quickly that I couldn't see the worm name or file infected.

    Now the only program I appear to be able to open is Internet Explorer!

    Can anyone advise me? As all my applications are currently unusable, and I can't even access control panel (apparently it can't find rundll32.exe either, even though I have downloaded a new copy from the net).

    Please advise if possible. If anyone knows the file which was removed, or anything about the worm, it would be greatly appreciated.

    Thanks.

    GT
     
  2. 2006/04/22
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
    essentialcandi - Welcome to the Board :)

    I can only guess that the file in question is rundll32.exe.

    Although you have downloaded a version I suggest you follow the MS practice outlined in this KB article ....

    Cannot find the Rundll32.exe file when you open Control Panel

    If that does not resolve the problem try this article ....

    Error message caused by Sircam32 virus when you start a program which gives a link to a removal tool ....

    http://www.symantec.com/avcenter/venc/data/w32.sircam.worm@mm.removal.tool.html

    Running the tool will do nothing if that is not the cause of the problem and will do no harm. As you posted the deed was done by Housecall.

    If you still have problems and are able to do so run System File Checker

    Start > Run > type in sfc /scannow > OK noting the space before the forward slash and have your XP CD handy. Hit retry as many times as it takes. SFC exits without any closing dialogue - to see which files, if any were replaced look in Event Viewer.

    If the problem persists and you are able use System Restore to restore to a point prior to downloading and opening the attachment.

    When you have your computer up and running again I would turn off System Restore, which removes the restore points, one of which may contain the virus, then turn it back on and atart afresh. You would not want to restore that virus in the future :)
     

  3. to hide this advert.

  4. 2006/04/22
    PeteC

    PeteC SuperGeek Staff

    Joined:
    2002/05/10
    Messages:
    28,896
    Likes Received:
    389
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.