PDA

View Full Version : Something keeps trying to add registry value



asuchar
2008-12-27, 10:02
Hi everyone...
my first time here. Recently ran into malware + trojan problems.
Took me a long time to resolve but heres what I did:-
Ran Spybot S&D, scanned and fixed
Ran Spyware Doctor, scanned and fixed
And so my popups and adware stopped and I thought my PC was fixed...
When I restarted, upon startup I recieved "RUNDLL" error

something about failing to run "damorume.dll"

So I ran registry mechanic and it showed the same error
And I repaired it. Immediately during repair, TeaTimer detected the change and showed that something was trying to delete the value. I knew Registry Mechanic was doing it so I allowed it
Immediately after the repair registry mechanic repaired and deleted the value, Teatimer detected that something was trying to add the value again, and this time I denied the add
I thought the problem was fixed then, so I restarted the computer and again I recieved the same Rundll error.
I scanned with registry mechanic again and this time there was no damorume.dll error
So my guess is some program keeps trying to add the registry value at startup before teatimer is fully loaded

Heres the log:


12/26/2008 11:45:06 PM Allowed (based on user decision) value "ISTray" (new data: "") deleted in System Startup global entry!
12/27/2008 12:04:53 AM Allowed (based on user decision) value "CPMbfe4d7c7" (new data: "") deleted in System Startup global entry!
12/27/2008 12:05:01 AM Allowed (based on user decision) value "wulipowune" (new data: "") deleted in System Startup global entry!
12/27/2008 12:05:04 AM Allowed (based on user decision) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:11:53 AM Allowed (based on user decision) value "wulipowune" (new data: "") deleted in System Startup global entry!
12/27/2008 12:12:02 AM Denied (based on user decision) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:12:08 AM Denied (based on user decision) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:12:13 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:12:18 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:12:25 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:12:30 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:15:43 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:15:46 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:15:52 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:15:58 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:07 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:13 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:18 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:24 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:29 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:35 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:44 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:50 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:16:57 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:02 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:09 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:14 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:19 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:26 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:31 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:36 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:41 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:46 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:49 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:17:57 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:00 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:02 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:04 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:08 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:11 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:13 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:18 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:23 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:34 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:39 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:44 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:49 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:18:54 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:06 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:11 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:16 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:22 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:27 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:33 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:38 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!
12/27/2008 12:19:45 AM Denied (based on user blacklist) value "wulipowune" (new data: "Rundll32.exe "C:\WINDOWS\system32\damorume.dll",s") added in System Startup global entry!

All those multiple times it denied are highlighted in blue (I told spybot to remember the decision)

Is there anyway I can stop the thing that keeps trying to re-add the registry value for damorume.dll? Theres no problem with malware or anything since spybot fixed it, but its kind of annoying to recieve the rundll error on startup...

Thanks in advance

asuchar
2008-12-27, 10:16
Oh and here's a screenshot of all the processes running on my computer at this moment

http://img117.imageshack.us/img117/1797/processeslz4.jpg

Zenobia
2008-12-27, 19:29
To run on the better safe than sorry side of things,you should probably get checked out in malware removal.

The procedures are here:
http://forums.spybot.info/showthread.php?t=288

Malware removal:
http://forums.spybot.info/forumdisplay.php?f=22

Besides providing the log asked for and following the procedures,make sure you tell them details about why you are there,or just show them this topic here with a link.

nogoonoo
2009-03-07, 22:36
I'm having the same problem (different file names, but same problem):

Did you find a resolution?


3/7/2009 2:23:21 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:23:27 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:23:33 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:23:39 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:23:45 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:23:51 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:23:58 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:03 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:10 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:16 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:22 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:28 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:36 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:41 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:47 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:24:55 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:25:01 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:25:07 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:25:14 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:25:19 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:25:25 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!
3/7/2009 2:25:31 PM Denied (based on user blacklist) value "nanoworaza" (new data: "Rundll32.exe "C:\WINDOWS\system32\sonuleme.dll",s") added in System Startup global entry!

drragostea
2009-03-08, 03:42
I would suggest you visit the Malware Removal Forums and get this checked out.
http://www.prevx.com/filenames/X3736006209086921813-0/SONULEME2EDLL.html
-
A search for the term "nanoworaza" came back empty-handed in Google.