Stubborn Virus Contained By Norton But Not Killed, Is My RUNDLL32.exe Corrupt? HELP!

Status
Not open for further replies.

saucell

Distinguished
Jul 13, 2013
4
0
18,510
hey guys, it looks like i have a stubborn virus on my computer that is contained by norton but not getting fixed.

i installed a program i thought had a false positive, everything was fine for a week or so and then today norton started protecting me from something on my computer. i cant find the virus and kill it with norton, malware bytes, or avg.

when i start my computer norton immediately blocks something from the temp file calling it a "downloader" and its identified as "ge157.tmp.exe" from the temp folder. immediately following this norton is blocking "RUNDLL32.exe " from my windows folder literally every second, as if its trying to attack my computer, it looks like its targeting norton also. please look at these two pics to see what im dealing with:




i ran microsoft malicious software removal and it did not find anything. is my RUNDLL32.exe compromised? i obviously have a virus, but none of these programs are able to find it and kill it. norton is able to contain it but that's it. should i delete the RUNDLL32.exe file and then replace it with an official one? please help me guys, thank you!

EDIT- i think i found it thanks to ccleaner, its something from a company called "Buzzdock" thats an ad virus thing pretending to be from microsoft. can i just delete this file and everything will be fine guys? do i need to replace the RUNDLL32 after i delete it with a genuine file? please let me know, heres the pic:



when you open the containing folder from ccleaner it looks like the real RUNDLL32 was replaced with a virus one, after i delete the bad one how do i replace it with a genuine one? heres a pic, thanks guys:

 

saucell

Distinguished
Jul 13, 2013
4
0
18,510
thank you mathewbouma. when i installed the program norton did not let that buzzdock install any folders or anything, but in the C:\ProgramData\BuzzDock folder there were two small files that i think were causing the problem. i deleted those files in safe mode and so far norton hasn't had to protect me from anything since then. the scheduled task still shows up in ccleaner, but i don't think i will mess with it since it might delete the rundll32 file.

one quick question, when i uninstalled avg it looks like it left a little bit of stuff on my computer. im still having an "avg service process" running in the background. can i boot in safemode and delete the avg folder that still has a few things in it? would this potentially mess anything up? thank you mathewbouma
 

mathewbouma

Commendable
Mar 9, 2016
3
0
1,520


If you can find the program in programs, and uninstall it, it would be better, or there is an avg remover tool that you could use here: http://www.avg.com/ww-en/utilities
 
G

Guest

Guest
OMG thank god you killed it!
I have some sort of virus phobia and I freak out when I get one xD
hope you don't get it again and remember.. the real protection is between the keyboard and the chair!
 
Status
Not open for further replies.