Endpoint Protection

 View Only
  • 1.  Help with Rundll errors

    Posted May 18, 2009 06:16 PM
    Endpoint appeared to get rid of the following viruses gikosiha, jahamure and sabiyogi. Now I still have 2 issues: 1) at start up I get multiple rundll error messages saying that gikosiha.dll, jahamure.dll and sabiyogi.dll can not be found, 2) My computer does not shut down it keeps restarting until I physically hold in the power button.
    Are these problems related? They appeared at the same time. Any suggestions? Thanks!!!


  • 2.  RE: Help with Rundll errors

    Posted May 18, 2009 06:44 PM
    When you say that Endpoint has successfully removed those viruses what do you mean. Are you still seeing them running in your task manager? Has SEP said it has quarantined or deleted those viruses? I don't know how familiar or comfortable you are with your system registry but you should check to see if there are traces of the virus left there as well. Also in the outbreak of a virus, whether it was deleted or not, you should start up your machine in safe mode and do a full system scan. When you do this make sure system restore is off. So make sure you have done the full scan in safe mode and post back with a little more information.
    Cheers,
    Grant


  • 3.  RE: Help with Rundll errors

    Posted May 18, 2009 07:04 PM
    Look at the manual removal instructions for each virus in
    http://www.symantec.com/norton/security_response/threatexplorer/azlisting.jsp


  • 4.  RE: Help with Rundll errors
    Best Answer

    Posted May 19, 2009 12:01 AM
    mecomerce,

    1. It looks like that the computer are still looking for registry entries for that dlls. if these are the virus dlls, please search them on your

    registry,  -> Start -> Run -> Regedit
    startup,  -> Start -> Run -> MSconfig -> Startup tab
    services  -> Start -> Run -> MSconfig -> Services Tab

    Startup folders

    1.  C:\Documents and Settings\All Users\Start Menu\Programs\Startup
    2.  C:\Documents and Settings\profile_name\Start Menu\Programs\Startup

    if they have entries and delete them. (search them 1 by 1)

    2. As with the shutdown, try to post some system/application logs here.



  • 5.  RE: Help with Rundll errors

    Posted May 24, 2009 05:11 PM
    Paul, Thanks I used your suggestion registry, -> Start -> Run -> Regedit and deleted all references to  gikosiha.dll, jahamure.dll and sabiyogi.dll it appears to have solved the problem as I no longer get the run dll errors at startup. My PC still does not shutdown.... It keeps restarting and I still must force shutdown by holding in the power button. Where would I find the system/application logs so that I can post them?


  • 6.  RE: Help with Rundll errors

    Posted May 24, 2009 08:10 PM
    Hi, I am happy it solved the problem, regarding the Application and System Logs, go to

    Start -> Run > type: eventvwr.msc > click ok.
    On the left colum you will see the System and Application Categories, browse thru the events.


  • 7.  RE: Help with Rundll errors

    Posted May 24, 2009 09:21 PM
    FFup,

    There are many issues for your pc not to shutdown problem; some of them are

    1. List of bad device driver or bad device itself causing shutdown problems : ( Check your device manager, make sure that all of your drivers are updated)

    2. Wrong VGA driver will also cause shutdown problem

    3. Faulty memory (RAM); I suggest you to do a mem test. (15 - 20 mins will do)

    4. Hard drive data corruption - Run checkdsk utility

    5. Rundll32.exe maybe corrupted. (can you check if this file exists on you windows folder C:\windows\System32\, you may want to replace it with the copy from your i386 folder or Installation CD.