PDA

View Full Version : main2_w, 150 (internal error)


Tigris
10-18-2003, 09:51 PM
Help, i have been stubburnly trying to install my university pharmacology's software but those idiots decided that it would be neat to use a 1970 visual basic approach to design their program and i get the error mentioned in the title

main2_w, 150 (internal error)

I have been desperately trying to make up for lost info over the semester but id still like to see it work once before my exam in a couple of weeks.

Paul Komski
10-19-2003, 03:36 AM
Hi Tigris and Welcome.

Are you sure this isn't a hardware error (such as a dirty or otherwise faulty installation CD) rather than a VB error?

ErnieK
10-19-2003, 04:26 AM
Tigris
have you tried to copy the complete CD onto your desktop and install from there? the only reference I can find on the net for your error also has to do with a CD.
http://www.askmehelpdesk.com/cgi-bin/yabb/YaBB.cgi?board=pcs;action=display;num=1053720525

Tigris
10-20-2003, 05:49 AM
There is no cd, its all downloaded zips, but i seem to have found one way to run it.
In my task manager i found a clandestine thread and after ending it the program ran.
The process was called rundll.exe and from what i can find on the net its either from a trojan or a virus, thing is no matter what i do i cant detect it and the process is always there when i start the system.

Any suggestions on how to find the son of a b**ch.

Paul Komski
10-20-2003, 01:34 PM
rundll.exe (and rundll32.exe) is a normal and necessary system file which can open dll library files and execute routines and subroutines within them. It is normally found in your windows directory but can be a target of viral attack.

To detect infection run an up-to-date antivirus scan of your whole system.

Some more details about exactly what you are doing, on what OS and with which application - or any other additional information - would help in getting to the bottowm of your problem.

You can cut down on the processes running at startup by using msconfig or by booting into safe mode.

mjc
10-20-2003, 02:08 PM
You could also post a HijackThis (http://mjc1.com/mirror/hjt/ )log.

Tigris
10-20-2003, 10:17 PM
i just got norton systemworks 2003 analysed my whole system (p4 2.4ghz with win2k) and after letting it do everything from disk repair to the actual antivirus all i got it to do is tell me system32.exe is now missing everytime i start up.
After much cursing and reading the second to last post i am now at a loss.

I was trying to run a visual basic compiled program i downloaded (for my lab work) and it just wouldnt; after looking through the running processes and researching every single one on the net i decided that rundll was a virus (obviously i was wrong but the only info on the net about it referred to a virus) and closed it down and then my program ran fine.

So i thought yay, now however after loosing system32 in the process and finding out rundll is supposed to be there i am a tad clueless.

Tigris
10-20-2003, 10:37 PM
this is my hijackthis log (thanks for pointing out the app to me)Logfile of HijackThis v1.97.3
Scan saved at 3:31:31 p.m., on 21/10/2003
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v5.00 SP4 (5.00.2920.0000)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\WINNT\system32\crypserv.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINNT\System32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\PROGRA~1\NORTON~2\SPEEDD~1\nopdb.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\System32\MsPMSPSv.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.exe
C:\Program Files\Common Files\Symantec Shared\SymTray.exe
C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
C:\Program Files\ahead\InCD\InCD.exe
C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe
C:\Program Files\Common Files\CMEII\CMESys.exe
C:\Program Files\Microsoft Hardware\Mouse\point32.exe
C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\WINNT\system32\rundll32.exe
C:\Program Files\OEM\802.11 Wireless LAN\OEMWlanMonitor.exe
C:\Program Files\Common Files\GMT\GMT.exe
C:\Program Files\Common Files\Symantec Shared\Nmain.exe
C:\Program Files\MSN Messenger\msnmsgr.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Zip\Apps\hijackthis\HijackThis.exe
C:\WINNT\system32\ntvdm.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {136A9D1D-1F4B-43D4-8359-6F2382449255} - (no file)
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: (no name) - {111995B6-5116-42EC-8AAD-687784C11F62} - (no file)
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [LiveNote] livenote.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\Smtray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINNT\System32\NeroCheck.exe
O4 - HKLM\..\Run: [InCD] C:\Program Files\ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\PANICW~1\POP-UP~1\dpps2.exe"
O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [POINTER] C:\Program Files\Microsoft Hardware\Mouse\point32.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtray.exe SetReg
O4 - HKLM\..\RunServices: [CMD] cmd32.exe
O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHook
O4 - HKLM\..\RunOnce: [SymTray - Norton SystemWorks] C:\Program Files\Common Files\Symantec Shared\Symtrdr.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: OEM WLAN Monitor Utility.lnk = C:\Program Files\OEM\802.11 Wireless LAN\OEMWlanMonitor.exe
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O13 - DefaultPrefix: [url]http://prolivation.com/cgi-bin/r.cgi?[/url]
O13 - WWW Prefix: [url]http://prolivation.com/cgi-bin/r.cgi?[/url]
O16 - DPF: Microsoft WFC Forms Designer - file://D:\VJ98\wfcforms.cab
O16 - DPF: Visual Studio 6 Extensibility Libraries - file://D:\VJ98\vstudio6.cab
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - [url]http://messenger.zone.msn.com/binary/msgrchkr.cab[/url]
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - [url]http://www.apple.com/qtactivex/qtplugin.cab[/url]
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - [url]http://active.macromedia.com/director/cabs/sw.cab[/url]
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - [url]http://messenger.zone.msn.com/binary/MineSweeper.cab[/url]
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - [url]http://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB[/url]
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - [url]http://messenger.zone.msn.com/binary/MessengerStatsClient.cab[/url]
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - [url]http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?37868.955474537[/url]
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - [url]http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab[/url]
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - [url]http://messenger.zone.msn.com/binary/SolitaireShowdown.cab[/url]

i have removed the c:\winnt\system32\system32.exe stuff bcause the symantec help pages told me to please tell that it wasnt the stupidest move since the sale of manhattan for a few glass beads.

mjc
10-21-2003, 01:34 AM
Close all browser windows, then in HijackThis check off the boxes next to the following and then the Fix button....

O2 - BHO: (no name) - {136A9D1D-1F4B-43D4-8359-6F2382449255} - (no file)

O3 - Toolbar: (no name) - {111995B6-5116-42EC-8AAD-687784C11F62} - (no file)

O4 - HKLM\..\Run: [CMESys] "C:\Program Files\Common Files\CMEII\CMESys.exe" <= Gator..... http://www.pchell.com/support/gator.shtml


O4 - HKLM\..\RunServices: [CMD] cmd32.exe <= http://www.viruslibrary.com/virusinfo/Worm.P2P.Tanked.htm

O4 - Global Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe <= Gator..... http://www.pchell.com/support/gator.shtml




Nope, system32.exe is a virus......and more than safe to remove.

Tigris
10-21-2003, 01:56 AM
Thank you very very very very very much, do you have any idea how many times the virus replicated i must have had a thousand cmd32 clones with just about every name possible.

Now im gonna try and ran the program without endind rundll but i think it still wont run.
Ive seen what program calls for it in that hijack log its the nview drivers for my video card and i think the university software just doesnt like it.
If it runs double yeppee if not just yeppee, after all finding and deleting a spyware/virus/trojan (yes i had all three) is a always a bonus.

Once again thank you.