After download Spybot Search & Destroy on my computer, I couldn’t open any files on my Desktop, Control Panel to remove or deleted any software, and use the wireless internet, the message C:\WINDOW \SYSTEM32\RUNDLL32EX, pop up. What should I do to remove the message? The software on my computer is Window XP Professional.

Dani AI

Generated

The popup referencing "C:\WINDOWS\SYSTEM32\RUNDLL32EX" is a red flag. The legitimate Windows binary is rundll32.exe; a name like rundll32ex is not standard and usually means either a malicious dropper, a corrupted/misnamed system file, or a broken Run/registry entry calling a non-existent file. described classic persistence/permission symptoms (desktop items not opening, Control Panel inaccessible, networking broken). is correct to question the installer source, and is right that system file damage can produce similar effects — the two causes look the same from the user side.

Practical diagnostic checklist (for technicians):

  • Boot to Safe Mode (press F8 at startup). Safe Mode often prevents the malicious autostart from loading so you can inspect safely.
  • Look for a file named rundll32ex.exe in C:\Windows\System32. If present, check Properties (publisher, version). A non-Microsoft or unsigned binary is suspect.
  • Use autorun/process inspection tools (Microsoft Sysinternals Autoruns and Process Explorer) to search for any startup entries that reference that filename or unknown DLLs. Focus on Run keys, RunOnce, scheduled tasks, services, shell extensions and Winlogon entries.
  • If the malware has disabled Task Manager/Regedit, Autoruns run from a removable drive or a rescue environment will often still work.
  • Create and scan with a bootable rescue scanner (Kaspersky Rescue Disk, ESET Rescue/bootable AV, Bitdefender Rescue). Offline scans can remove entrenched malware that runs at boot.

Cautions and next steps:

  • Do not manually delete system files unless they are confirmed malicious; quarantine/rename first and note original paths.
  • Back up personal data using a live USB (Linux) before attempting destructive fixes.
  • Windows XP is end-of-life; even a cleaned machine will remain vulnerable. After successful removal, a full reinstall or migration to a supported OS is the safest long-term solution.

Technician checklist items to capture for deeper analysis: exact popup text, full file path and file properties of any rundll32ex file, Autoruns output, and rescue-scan logs.

Recommended Answers

All 2 Replies

I will suggest to repair the Xp installation from the original CD. It seems that some relevant files had been removed or damaged.

Hope this helps

Downloading of SpyBot Search and Destroy would not cause this problem unless you did not get the real program. Where did you get the program?
The only download sites for this program are those listed on it's website:

http://www.safer-networking.org/en/mirrors/index.html

You need to follow the steps given here:
http://www.daniweb.com/hardware-and-software/microsoft-windows/viruses-spyware-and-other-nasties/threads/134865

You obviously are posting from another computer since you say you cannot access the internet with the affected computer so use this computer to download the programs, put them onto a flash drive and use that to put the programs onto the affected computer, then run the programs and post back with the logs.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.