This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Log From My Scan

6 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

ok, you need to show hidden files so please do the following.
Copy the contents of the code box to a plain text (notepad) document, name it showhidden.vbs and save it as type all files. Double click to run it. If you get a malicious script warning click to allow it to continue, it is perfectly safe.
'Windows XP and 2000 only
'sets the search  and explorer settings to show all files
'by Mosaic1
Dim Wshshell
  Set Wshshell= Wscript.CreateObject("Wscript.Shell")
   Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\IncludeSubFolders", 1, "REG_DWORD"

  Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SearchHidden", 1, "REG_DWORD"

  Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\SearchSystemDirs", 1, "REG_DWORD"




Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Hidden", 1, "REG_DWORD"

  Wshshell.RegWrite "HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced\ShowSuperHidden", 1, "REG_DWORD"




MsgBox "Done"
 
Wscript.quit

Once that is done, boot into safe mode, then run HijackThis! and place a check mark in next to each of the following.
Close all browser windows and shut down all other programs with a placeholder in the taskbar.
Click "fix checked."
O2 - BHO: (no name) - {0000607D-D204-42C7-8E46-216055BF9918} - C:\WINDOWS\mxTarget.dll
O3 - Toolbar: TheSearchMall.com Bar - {4B8F38C7-62FC-4762-B9A0-27E63F768167} - C:\WINDOWS\System32\winsrm32.dll (file missing)
O4 - HKLM\..\Run: [nfcegplah] C:\WINDOWS\System32\nbwggw.exe

Do NOT reboot yet

Delete the following

File
You should be able to see it now since running the script
C:\WINDOWS\System32\nbwggw.exe

Search your computer for rundll32.exe which is a valid windows file, you will find copies of it unless it has been deleted which is a problem in itself. It is a hidden file so that may be why you couldn't find it before. We need to know the full path to each copy that you find with that exact filename in order to determine if there is one in the wrong place, which can cause the problem you are having with accessing folder options.

Once that is done, Reboot normally

Post a fresh log to this thread along with where you found rundll32.exe.
ok here we go,

ok this is what i found of the rundll32.exe files and there copies:

1 found in: C:\WINDOWS
Rundll32

16 found in: C:\WINDOWS\Prefetch
names:
RUNDLL32.EXE-3C0531AF.pf
RUNDLL32.EXE-3E3F12BA.pf
RUNDLL32.EXE-428BCB33.pf
RUNDLL32.EXE-43CC5001.pf
RUNDLL32.EXE-4A4B0488.pf
RUNDLL32.EXE-4B8DF6C2.pf
RUNDLL32.EXE-611C9EEE.pf
RUNDLL32.EXE-62956992.pf
RUNDLL32.EXE-658F4704.pf
RUNDLL32.EXE-68114D96.pf
RUNDLL32.EXE-6E8D4657.pf
RUNDLL32.EXE-6FC4EFC6.pf
RUNDLL32.EXE-70FBE249.pf
RUNDLL32.EXE-74BC2D81.pf
RUNDLL32.EXE-753ED060.pf

1 found in: C:\WINDOWS\SYSTEM32
name:
rundll32

1 found in: C:\WINDOWS\SYSTEM32\dllcache (this was highlighted in blue text color)

ok now here its gets wierd cause i was trying to copy and paste to reduce typing and i think something went wrong… :/

ok i made a copy of this prefetch thingy
RUNDLL32.EXE-3C0531AF.pf(and placed it on my dektop in safe mode and left it there cause i didnt want to delete it or anything cuase i didnt know what i was doing)

but this one is wierd it doesnt match with any of the prefetch things
RUNDLL32.EXE-4FF9832D.pf (i also made a copy of this one by mistake but it doesnt even match any of the prefetchs, i hope im making at least some sense here) ok and here is the new log

Logfile of HijackThis v1.97.7
Scan saved at 8:29:41 PM, on 6/8/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Owner\Desktop\Hijack this\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by SaskTel
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = ;localhost;
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn7\ycomp5_3_16_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn7\ycomp5_3_16_0.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [BurnQuick Queue] C:\WINDOWS\BQTray.exe
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://www.mysask.com
O16 - DPF: Yahoo! Chess - http://download.games.yahoo.com/games/clients/y/ct1_x.cab
O16 - DPF: Yahoo! Pool 2 - http://download.games.yahoo.com/games/clients/y/potd_x.cab
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwa…director/sw.cab
O16 - DPF: {29C13B62-B9F7-4CD3-8CEF-0A58A1A99441} - http://fdl.msn.com/public/chat/msnchat41.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…nst20040510.cab
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} - http://download.microsoft.com/download/F/6…922/wmv9VCM.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shock…ash/swflash.cab
O16 - DPF: {E87A6788-1D0F-4444-8898-1D25829B6755} - http://fdl.msn.com/public/chat/msnchat4.cab
This one is your problem: C:\WINDOWS\Rundll32 Delete that one, leave the one in the system32 folder and the one in the dllcache alone. Don't worry about the ones in preftech, they aren't actually the file, just information that windows uses to be able to load programs faster. If you delete something in there windows will build a new file the next time you run the program so go ahead and delete the copies you made. Try folder options now and let us know how they work. Your HijackThis! log is clean.
omg it works thank you so much for your help. im so glad there are people like you to help people like me (computer illiterate). again thank you so much your the best.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI