This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

dayam Run Dll Error Message

2 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I keep getting the run dll error message. Here's my HiJack log. HELP ME PLEASE THIS ERROR IS dayam ANNOYING …..appreciate it.




Logfile of HijackThis v1.98.2
Scan saved at 9:41:08 PM, on 9/16/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgamsvr.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgcc.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
C:\PROGRA~1\INTERN~2\inetmgr.exe
C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tca.exe
C:\PROGRA~1\INTERN~2\inetsvc.exe
C:\PROGRA~1\COMMON~1\tsa\tsm.exe
C:\Documents and Settings\LSU Brandon\Desktop\Spyware\Spyware Doctor\spydoctor.exe
C:\PROGRA~1\COMMON~1\tsa\ts.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\helpctr.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpSvc.exe
C:\WINDOWS\PCHealth\HelpCtr\Binaries\HelpHost.exe
c:\Program Files\Dell\SolutionCenter\DellSC.exe
C:\Program Files\Dell\Support\bin\ClientApplicationFramework.exe
C:\Program Files\Common Files\Dell\EUSW\support.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\WINDOWS\System32\msiexec.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LSU Brandon\Desktop\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
R3 - URLSearchHook: (no name) - _{1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Documents and Settings\LSU Brandon\Desktop\Trojan\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [tcactive] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe
O4 - HKCU\..\Run: [Tsa] C:\PROGRA~1\COMMON~1\tsa\tsm.exe
O4 - HKCU\..\Run: [Spyware Doctor] "C:\Documents and Settings\LSU Brandon\Desktop\Spyware\Spyware Doctor\spydoctor.exe" /Q
O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML
Greetings and welcome to TomCoyote.org!

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This! and fix these items:

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=

R3 - URLSearchHook: (no name) - _{1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file)

O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe

O4 - HKCU\..\Run: [Tsa] C:\PROGRA~1\COMMON~1\tsa\tsm.exe

O8 - Extra context menu item: &iSearch The Web - res://C:\WINDOWS\System32\toolbar.dll/SEARCH.HTML


Reboot in "safe" mode. Use the link in my signature to tell you how if necessary.

Find and delete:

c:\program files\common files\tsa <— FOLDER

c:\program files\intern~2\inetmgr.exe <— file

c:\program files\intern~2\inetsvc.exe <— file

C:\WINDOWS\System32\toolbar.dll <— file

Some malware files may be "hidden". Use the link in my signature to explain how to show "hidden" files if necessary.

Reboot in normal mode and post a new log file in this thread. :)


OPTIONAL FIX

Remove "Spyware Doctor", read about it here:

Rogue Anti-Spyware Programs
Hey man thanks a lot for responding timely. Alright I had a few problems though. I ran Hijack this and couldn't fix the inetmgr.exe. Also, when i rebooted in safe mode there was an error when i tried to delete:

:\program files\intern~2\inetmgr.exe <— file

c:\program files\intern~2\inetsvc.exe <— file

Also deleted Spyware Doctor…so here is my new HJT Log…..


Logfile of HijackThis v1.98.2
Scan saved at 7:20:42 PM, on 9/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
C:\PROGRA~1\mcafee.com\agent\McAgent.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgcc.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tca.exe
C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tcm.exe
C:\PROGRA~1\INTERN~2\inetmgr.exe
C:\PROGRA~1\INTERN~2\inetsvc.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgamsvr.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Documents and Settings\LSU Brandon\Desktop\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lsu.edu/index2.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Documents and Settings\LSU Brandon\Desktop\Trojan\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [tcactive] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
Let's try a slightly different approach…. <_<

Boot in "safe" mode.

CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!

Run Hijack This!
Click "Scan".
Then "check" the box to the left of these item(s):

O4 - HKLM\..\Run: [inetmgr] C:\PROGRA~1\INTERN~2\inetmgr.exe


Then click "Fix checked".

Reboot in "safe" mode.

Find and delete:

c:\program files\intern~2\inetmgr.exe <— file

c:\program files\intern~2\inetsvc.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)
YES INDEEED!!….the error message is completely vanquished. That solution worked just fine…probably an easy one for ya. Well, Thanks for you quick responses and GOD BLESS….think this updated log is fine:

Logfile of HijackThis v1.98.2
Scan saved at 8:00:14 PM, on 9/19/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgamsvr.exe
C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgupsvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\LSU Brandon\Desktop\HiJack This\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/myway
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.lsu.edu/index2.html
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.dell4me.com/myway
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\McAgent.exe
O4 - HKLM\..\Run: [AVG7_CC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [AVG7_EMC] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgemc.exe
O4 - HKLM\..\Run: [AVG7_RegCleaner] C:\DOCUME~1\LSUBRA~1\Desktop\SPY\avgregcl.exe /BOOT
O4 - HKLM\..\Run: [PCDRealtime] C:\WINDOWS\realtime.exe
O4 - HKLM\..\Run: [TrojanScanner] C:\Documents and Settings\LSU Brandon\Desktop\Trojan\Trojan Remover\Trjscan.exe
O4 - HKLM\..\Run: [tcactive] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tca.exe
O4 - HKLM\..\Run: [tcmonitor] C:\Documents and Settings\LSU Brandon\Desktop\Cleaner\The Cleaner\tcm.exe
O4 - HKLM\..\Run: [McRegWiz] c:\PROGRA~1\mcafee.com\agent\mcregwiz.exe /autorun
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
Good work!!!! :thumbup:

Log is clean!!!

GOD bless!!!

M68 :)

Items you may wish to consider to harden your defenses against future infections:

Read "How did I get infected in the first place?" here:

http://boards.cexx.org/viewtopic.php?t=957

Download IE-Spyad here:

https://netfiles.uiuc.edu/ehowes/www/resource.htm

IE-Spyad puts over 4000 known malicious web sites into IE's "restricted zone" to help prevent you from getting infected.

Check your browser settings here:

http://browsercheck.qualys.com/index.php

A series of "tests" (and suggested fixes) to help tweak IE's settings to help prevent infections when surfing the web.

Follow safe Internet practices:

1. Keep your virus definitions up to date, and scan your system regularly.

2. Don't open email, or download attachments from unrecognized email addresses.

3. Be careful when downloading email attachments, EVEN FROM PEOPLE YOU KNOW! Many virii, worms, and trojans infect a persons system then immeadiately spread themselves to the people in the infected persons addressbook via email attachments.

4. Be careful downloading files from the Internet. Scan all downloaded files with a reliable UP-TO-DATE antivirus program. Scan "zip" files BEFORE unzipping, and scan all unzipped files BEFORE USING THEM.

5. Keep your Windows and IE current with all the latest patches and updates.
(Personally, I'm NOT recommending SP2 for XP at this time)

Glad we could be of assistance. This topic is now closed. If you wish it
reopened, please send us an email (Click here to email) with a link to your thread.


Donations in support of this Web Site are always appreciated

Do not bother contacting us if you are not the topic starter. A valid,
working link to the closed topic is required along with the user name used.
If the user name does not match the one in the thread linked, the email will be deleted.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI