Red Cross in Win Explorer C: drive

Status
Not open for further replies.
Symptoms: red cross icon in windows explorer next to c: drive. Also, Rundll dialog box pops up on starting windows, saying specified module fddrcrny.dll file could not be found - looks like spam, I have completed all the steps in techspot.com vb topic58138 and have attached the HJT logfile, combofix log files. AVG Spyware freeversion did not allow saving report but it did find malware - which was quarantined and deleted. Panda Antiroot did not find any root problems. Many thanks for taking a look at this,
 

Attachments

  • combofixlog.txt
    19.4 KB · Views: 7
  • hijackthis.log
    7.3 KB · Views: 7
You have software in conflict with each other. I see you have both Symantec and AVG... use one or the other.
I see Symantec,
Adaware
Spybot
Shockproof
Rootkit (Panda)
AVG antispyware
AVG antivirus
Zone Alarm


I would use AVG only... or if necessary, Symantec only... and rethink everything else having to do with security.

But I would run a drive fitness test on your hard drive... and perhaps MemTest86, just so you have ruled out hardware problems.
You should go to Event Viewer (Start->Control Panel->Administrative Tools->Computer Management to see what red and yellow flags you have there and see how their timings related to the times other things go wrong.
 
The "red cross" seems to be a symptom for a virus attack. I did not look for any legit use of this symbol by Win XP to denote a trouble condition.

Here is a sample from the HJT - unusual spelling
O2 - BHO: (no name) - {F33A8BAB-2593-4DDB-A49A-2110E00DE54A} - C:\WINDOWS\system32\urqqq.dll (file missing)

I am guessing that Vundo attacks are on the rise. What happened when the tools (step 10) were run?

You are running with ZoneAlarm. If you have a router & a home network, take that network & classify it as 'internet' (Firewall ! Zones). Keep computers from cross-infections.

To completely remove all traces of Symantec/Norton, you need a version of their Norton_Removal_Tool.exe.

Owing to Raybay's experience, looking at the event logs should be done, as well. Problems with the hardware, OS, and applications can be mistakenly labeled as a 'virus' attack.
 
Definitely an infection, somebody who is experienced with Combofix will need to solve this one. I see some definite infections, but cannot offer the solution as I am not 100% experienced with combofix yet.
 
Thanks, still working on it

Thanks Raybay, I had trouble removing Norton but thanks to rf6647 advice, the Norton Removal tool did the trick, phew! more to come in next post...
 
Zone alarm adjusted..

Thanks rf6647, have made the adjustments in Zonealarm, will post screen shot of the Event log showing the problem on starting windows, in next post.....
 
event log

I have attached a screenshot of the event log showing the error that occurs after immediately after windows start up, and a screenshot of the dialog box showing the rundll error, many thanks for your assistance with this
 
Status
Not open for further replies.
Back