This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

can anyone help me remove dcmhelp.exe?

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I can't seem to get rid of dcmhelp.exe–here's the HJT log. Hijack THis Baseline Log: Logfile of HijackThis v1.99.1 Scan saved at 2:42:45 PM, on 4/24/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\WINDOWS\dcmhelp.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\HijackThis.exe N3 - Netscape 7: user_pref("browser.startup.homepage", "https://distancelearning.usm.edu/webct/ticket/ticketLogin?action=print_login&request_uri=/webct/homearea/homearea/"); (C:\Documents and Settings\dozinslosh\Application Data\Mozilla\Profiles\default\se0j87pe.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\dozinslosh\Application Data\Mozilla\Profiles\default\se0j87pe.slt\prefs.js) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: hpoddt01.exe.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O17 - HKLM\System\CCS\Services\Tcpip\..\{FEC38B48-6BCC-4405-AEBE-661B93C34B53}: NameServer = 208.137.128.8 208.137.128.6 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\WINDOWS\dcmhelp.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
CLOSE ALL WINDOWS (even this one) AND PROGRAMS!!!!
Run Hijack This!
Click "Do a systen scan only".
Then "check" the box to the left of these item(s):

O23 - Service: Dcom Helper (DcmHlp) - Unknown owner - C:\WINDOWS\dcmhelp.exe

Then click "Fix checked" and close HijackThis!

Now,please go to:

Start –> Run

In the box type in services.msc then hit (or click OK)

In the Name column in the next screen look for:

Dcom Helper

it.

In the dialogue box that pops up, check in the Path to executable box.

It should say: C:\WINDOWS\dcmhelp.exe

That's how to be sure you have the right one.

Now, click Stop to stop that rogue process.

In the Startup type box, change it to Disabled.

Click Apply then OK

Close the services.msc window.

Reboot in "safe" mode.

Find and delete:

C:\WINDOWS\dcmhelp.exe <— file

Some malware files may be "hidden".
Be sure to show hidden files when looking for these file(s) and/or folder(s).

Reboot in normal mode and "copy/paste" a new log file into this thread. :)

If you're interested, here is what that is:

W32/Sdbot-AJA

Since that worm makes some registry changes, we'll have a little bit more work to do to get you back to "normal".
Hello! Thanks for your reply. Here is a new log: Logfile of HijackThis v1.99.1 Scan saved at 7:38:40 PM, on 4/25/2006 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Program Files\ewido anti-malware\ewidoctrl.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe C:\Program Files\HijackThis.exe N3 - Netscape 7: user_pref("browser.startup.homepage", "https://distancelearning.usm.edu/webct/ticket/ticketLogin?action=print_login&request_uri=/webct/homearea/homearea/"); (C:\Documents and Settings\dozinslosh\Application Data\Mozilla\Profiles\default\se0j87pe.slt\prefs.js) N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C:\Documents and Settings\dozinslosh\Application Data\Mozilla\Profiles\default\se0j87pe.slt\prefs.js) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Global Startup: hpoddt01.exe.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: IMAPI CD-Burning COM Service (ImapiService) - Roxio Inc. - C:\WINDOWS\System32\ImapiRox.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
After further investigation, "recovery" from this worm is to "set the modified registry values back to their original value".

Since we don't know what that was, I'll leave well enough alone.

The only one I can see that should probably be changed is:

HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
"DoNotAllowXPSP2"=0

If/when you decide to update to SP2. The worm changed the value to 1, which could inhibit udating to SP2.

Did you realize you are way behind on Windows and IE updates?

This is one reason you have contracted this infection.

From the log, I'm guessing you have a HP computer. There were several recent Windows updates that caused problems with many HP computers. If you're serious about updating, I can post the numbers of the two updates you should consider NOT installing.

Other than being behind on updates, the log looks clean.

How's the machine behaving now?
:unsure:
It's better and working faster without the dcom helper running in the background. Regarding the Windows Updates: a few days ago, I cleaned the computer here on the TCF, and thought I was bug free. The person who helped me recommended that I install service pack 1a, so I did, but right after I installed it, the computer started to behave badly, and got very slow, and was almost not functional when I tried to go online. So I uninstalled the service pack and that's when I noticed the DCOM help running in the processes. I have a Gateway computer that's about 5 years old. What should I do about the service packs/updates? Also, should I remove that HKEY line you mentioned?
Well…. It appears you may be caught "between a rock and a hard place".

NOT updating Windows/IE leaves you vulnerable to a plethera of infections.

Given your recent experience with the updates, I can see why you might be less apt to install any updates.

I guess you'll have to decide.

If it was me, I would backup all my important data and attempt the updates.

If you decide to go to SP2, order the cd here (it's free):

XP SP2 CD

That's where/how I received mine, and it took less than 2 weeks to arrive.

That page also has other info about SP2 you should read carefully.

About that registry value, don't delete it. Change the value to 0 (ZERO - NOT the letter o) (if necessary). I can help with this if you need it.

I hope this has helped.
:)
This topic is now closed.

If you need this topic reopened, please request this by sending an email to us at the following link

(Click for address)
Include your post user name and detail why you need it reopened with a valid link to your post.
Any bad links or emails that are not from the original poster will be deleted without response.
Any emails without the subject "Reopen" will be deleted without being looked at.

If this is not your thread please start a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI