What OS?
CoolATIGuy
Main Topics
Browse All TopicsI have a customers computer that is causing me great grief. First of all, it had the begal.n virus (which I was able to get rid of using the program from symantec as well as ran a check with a bootable floppy from AVG to be sure it was clean). It also wont let me get into msconfig nor anything in the control panel so I can try and clean up the rest of this machine. I believe it is infected with a lot of spyware, and when I try to run adaware, spybot or any other program I get 'cant run a dll as an app error'. I thought I'd try going into msconfig, but I get the dll error there. I even tried this in safe mode. Help please! I also tried creating a new user profile in safe mode and get the dll error. Im lost here. Thanks in advance!
This Question has been solved and asker verified All Experts Exchange premium technology solutions are available to subscription members.
Experts Exchange has been collecting answers to technology questions since 1996…3 million and counting! If you have a question, chances are we already have your answer.
If you can't find the exact answer you're looking for, ask our exclusive community of 50,000 experts. You’ll get a personalized answer from a trusted professional.
Thousands of free tech tips, tricks, how-to’s and tutorials are available in our peer reviewed articles section. See for yourself how smart our experts are, no login required.
Access the answers to your technology questions today.
30-day free trial. Register in 60 seconds.
Members of the expert community talk about why the experience at Experts Exchange is different than what you will find anywhere else.

Try it out and discover for yourself.
30-day free trial. Register in 60 seconds.
Join the community of experts here and help other tech pros by answering question in your area of expertise. You can earn FREE access to all Experts Exchange's premium features and resources.
Checkout http://techrepublic.com.co
CoolATIGuy
OS is XPHome
Here is the log from Hijakthis:
Logfile of HijackThis v1.97.7
Scan saved at 9:41:22 PM, on 7/28/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\Explorer.EXE
C:\Documents and Settings\Administrator\Des
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
R1 - HKCU\Software\Microsoft\Wi
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
F2 - REG:system.ini: UserInit=C:\WINDOWS\System
O2 - BHO: (no name) - {20239CAD-9608-49E2-8E0D-D
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-2
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-F
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-0
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\pho
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tf
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [S3apphk] S3apphk.exe
O4 - HKLM\..\Run: [PS2] C:\hp\drivers\keyboard\PS2
O4 - HKLM\..\Run: [checktime] c:\program files\HPSelect\Frontend\ct
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\
O4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\VERIZO~1\SUPPO
O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\SYSTEM32\XTAWJ.
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\sdkqh32.dll,Ins
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [sounoft] sounoft.exe
O4 - HKLM\..\Run: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automo
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\jopnyc
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\gxwnbh
O4 - HKLM\..\Run: [DjrL.exe] C:\documents and settings\owner_2\local settings\temp\DjrL.exe
O4 - HKLM\..\Run: [B4693369] C:\WINDOWS\System32\fjqzez
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\Run: [intlgntc] C:\WINDOWS\System32\intlgn
O4 - HKLM\..\Run: [Microsoft Update Machine] javaw.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\RunServices: [sounoft] sounoft.exe
O4 - HKLM\..\RunServices: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\RunServices: [8F7BBF0F] C:\WINDOWS\System32\fjqzez
O4 - HKLM\..\RunServices: [Microsoft Update Machine] javaw.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [winupd.exe] C:\WINDOWS\System32\winupd
O4 - HKCU\..\Run: [Plug and Play] C:\WINDOWS\wininet32.exe
O4 - HKCU\..\Run: [Remote Packet Capture Protocol v.2.0] C:\WINDOWS\runwin32.exe
O4 - Startup: AutoPlay.exe
O4 - Global Startup: GoBack.lnk = C:\Program Files\Roxio\GoBack\GBTray.
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\Shado
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\Back
O9 - Extra button: Control Pad (HKLM)
O9 - Extra 'Tools' menuitem: Control Pad (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O16 - DPF: {02BCC737-B171-4746-94C9-0
O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0
O16 - DPF: {10000000-1000-0000-1000-0
O16 - DPF: {166B1BCA-3F9C-11CF-8075-4
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1
O16 - DPF: {30528230-99F7-4BB4-88D8-F
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-A
O16 - DPF: {65E7DB1D-0101-4100-BD66-C
O16 - DPF: {74D05D43-3236-11D4-BDCD-0
O16 - DPF: {87067F04-DE4C-4688-BC3C-4
O16 - DPF: {8B1BC605-C593-4865-8F5B-0
O16 - DPF: {90C9629E-CD32-11D3-BBFB-0
O16 - DPF: {9EB320CE-BE1D-4304-A081-4
O16 - DPF: {9F1C11AA-197B-4942-BA54-4
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-4
O16 - DPF: {EF99BD32-C1FB-11D2-892F-0
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-5
Turn off ur System restore and fix the following entries......
==========================
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
O2 - BHO: (no name) - {20239CAD-9608-49E2-8E0D-D
O2 - BHO: . - {D34F08C5-4F18-477c-86CB-1
O4 - HKLM\..\Run: [2P6WFAX43ZHE7C] C:\WINDOWS\SYSTEM32\XTAWJ.
O4 - HKLM\..\Run: [SM1BG] C:\WINDOWS\SM1BG.EXE
O4 - HKLM\..\Run: [Image] rundll32 C:\WINDOWS\sdkqh32.dll,Ins
O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe "C:\Program Files\WildTangent\Apps\CDA
O4 - HKLM\..\Run: [Adstartup] C:\WINDOWS\System32\automo
O4 - HKLM\..\Run: [Cryptographic Service] C:\WINDOWS\System32\jopnyc
O4 - HKLM\..\Run: [System Update] C:\WINDOWS\System32\gxwnbh
O4 - HKLM\..\Run: [DjrL.exe] C:\documents and settings\owner_2\local settings\temp\DjrL.exe
O4 - HKLM\..\Run: [B4693369] C:\WINDOWS\System32\fjqzez
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\Run: [intlgntc] C:\WINDOWS\System32\intlgn
O4 - HKLM\..\Run: [Microsoft Update Machine] javaw.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dump
O4 - HKLM\..\RunServices: [sounoft] sounoft.exe
O4 - HKLM\..\RunServices: [soundcontrl] soundcontrl.exe
O4 - HKLM\..\RunServices: [8F7BBF0F] C:\WINDOWS\System32\fjqzez
O4 - HKLM\..\RunServices: [Microsoft Update Machine] javaw.exe
O4 - HKCU\..\Run: [winupd.exe] C:\WINDOWS\System32\winupd
O4 - HKCU\..\Run: [Plug and Play] C:\WINDOWS\wininet32.exe
O4 - HKCU\..\Run: [Remote Packet Capture Protocol v.2.0] C:\WINDOWS\runwin32.exe
O4 - Startup: AutoPlay.exe
O4 - Global Startup: hp center UI.lnk = C:\Program Files\hp center\137903\Shadow\Shado
O4 - Global Startup: hp center.lnk = C:\Program Files\hp center\137903\Program\Back
O16 - DPF: {0FC6BF2B-E16A-11CF-AB2E-0
O16 - DPF: {10000000-1000-0000-1000-0
O16 - DPF: {3AF4DACE-36ED-42EF-9DFC-A
O16 - DPF: {65E7DB1D-0101-4100-BD66-C
O16 - DPF: {87067F04-DE4C-4688-BC3C-4
O16 - DPF: {8B1BC605-C593-4865-8F5B-0
O16 - DPF: {90C9629E-CD32-11D3-BBFB-0
O16 - DPF: {9EB320CE-BE1D-4304-A081-4
==========================
If u cannot access System Restore, then leave it,,,, and fix the above entries, Restart ur machine and perform some online virus scans !!!!
CHECK FOR ONLINE VIRUS SCAN:
--------------------------
1. http://us.mcafee.com/root/
2. http://security.symantec.c
3. http://housecall.trendmicr
4. http://www.pandasoftware.c
5. http://www.pcpitstop.com/a
then download these tools and install Adaware and Spybot !!!!!
==========================
AdAware ==> http://www.spychecker.com/
SpyBot ==> http://www.spychecker.com/
CoolWebShredder ==> http://www.spychecker.com/
ToolBar Cop >> http://www.mvps.org/srames
Stinger >> http://vil.nai.com/vil/sti
==========================
After that Follow these Instructions:
1. First turn Off ur System Restore
2. Boot into safemode and Login as Administrator
3. Run the AntiVirus tool and delete all viruses it found
4. Run the Spyware Removal tools and delete everything they detect
5. Then goto C:\Documents and Settings\ur usernmae\Local Settings\Temp and delete all files present here
6. Goto C:\Documents and Settings\ur usernmae\Local Settings\Temporary Internet Files, and delete the folder of ContentIE
7. Goto C:\Documents and Settings\ur usernmae\Cookies, and delete all cookies present here.
8. Reboot back in Normal Mode and check if problems are gone
9. If YES then Great, otherwise run the Hijakcthis scan, and post the LOG file here
10. After making sure that every junk stuff is deleted, and System is Clean, Turn On the System Restore again !!!
see my second post :)
and if after fixing those entries, u still get those errors, then try a SFC scan,,,,,,
Goto START>RUN and type sfc /scannow
u will need ur WinXP CD in order to fix the corrupted windows system files, if found by scan.
and if still nothing helps u, then go ahead and perform a Repair so that atleast we can run some programs =\
How to Perform an In-Place Upgrade (Reinstallation) of Windows XP:
http://support.microsoft.c
Or this site explains a Repair with pics:
http://www.webtree.ca/wind
You may not be able to fix the sp.html about:blank hijacker with hijackthis. That's the one that brings up a search page that you can't get out of. CWShredder might get it depending upon the variant but also probably not. For the ones that hijacthis doesn't kill, you might be able to download process explorer from http://sysinternals.com and kill more virus processes that way which would allow you to delete their executables and dlls without having to go into the rc. If you kill enough of them, then you might get msconfig back, but if not, you can go into the registry and delete the startup entries in the run and runservice keys that are likely launching some of them.
I was able to get ad-aware to run in safe mode. Any other app in safe mode just does not run (no erro), but I get the dll when trying to run anything in normal mode. Imalso getting a bunch of 'backup' files in safe mode everytime I look there are more!
I will go to sysinternals.com and try that next. I am just afraid if I put this PC on the network it would infect the rest of my machines. I have internet running through a server (I have to, using a satallite connection for internet).
These are the processes that are running on my computer. You should be able to kill everything except these and still be online and running. The svchost.exe processes are hosts to multiple service processes. Sometimes viruses run in there also. When you highlight a process, you will see the modules (dll's) it contains in the lower window, if you don't, go to the view tab and select DLL's in the Lower Pane View instead of Handles and make sure the Lower Pane View entry above it has a checkmark so that you will have a lower split window. When you highlight a process, look at the dll's that are running under it in the lower window and see if there are any that don't have a Microsoft name listed. These would be suspects. You can then do a wildcard search on the computer *.* which should list every file in the computer, although you really need to download a good search tool because ms native search won't list all the files and won't tell you it isn't. Agent Ransack is free and very thorough for search. Likewise, Registrar Lite is very thorough for registry. Regedit and Regedt32 are very bad about missing items in searches. To do a wildcard of the whole computer in Agent Ransack, just leave the search field blank and click search. Then sort by name, then find your suspect files, note the timestamps and then sort by timestamp and see what other files have the same timestamp.You can then google the filenames and see if they correlate to any viruses.
CSRSS.exe
explorer.exe
Isass.exe
Services.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
svchost.exe
SMSS.exe
System Idle Process
System
Winlogon.exe
procexp.exe (process explorer)
iexplore.exe (or your browser name)
Alot of spyware is designed to stop you from contacting online scanners and prevent local scanners from running. My theory is that if you can kill the spyware process, you might be able to start the antivirus programs and remove the virus. What I definitely would not do is reboot because you will just reload everything thats set to run at startup.
WinTasks Process Library
Looks like windows native burner possibly. Also, earlier I said that dlls without Microsoft names were suspect. That doesn't mean that spyware hasn't infested a Microsoft dll. Dll's can be modified rather easily and while Windows File Protection is supposed to protect the system files from being changed, it probably works about as well as other Windows stuff. I've hacked into explorer and changed the logo and hacked into mshtml.dll and changed stuff and Windows File Protection didn't notice the difference though not sure if I ever ran SFC against the hacked versions to see if it picked them up. You might also try that though, run System File Checker to see if it catches any modified windows files.
tfswctrl - tfswctrl.exe - Process Information
Process File: tfswctrl or tfswctrl.exe
Process Name: DLA Packet Writing Software
Description: Application that is used to write data to CDs directly from Windows applications, without using the actual CD Writing software.
Company: Hewlett-Packard
System Process: No
Security Risk ( Virus/Trojan/Worm/Adware/S
Common Errors: N/A
The repair install shouldn't destroy any data. But as SheharyaarSaahil said, you have to reinstall the apps. One of the files that you mentioned above that was still running was the native ms burner I think. Are you sure you can't burn with that. Also, what was the server you mentioned earlier. Did it have a specific name that you could see before it went down.
The error I constantly get when ever I try to access any control panel apps is: Run a DLL as an App. Run a DLL as ann App has encountered a problem and needs to close, we are sorry for the inconvenience. Please tell MS about this problem.
I am now going to move the customers 'data' to another folder and try a 'repair' of the OS. I will keep you all posted!
OK, I ended up doing a new install of XP with my OEM disk... nothing else worked. I installed it to the C drive and left the D drive in tact (D is the 'recovery' drive for HP since they dont issue CD's anymore). I also made a 'backup' directory on D for my clients data. Now the problem is that I can't get back any HP applications nor drivers that are needed for this machine. THis is a Pavillion 522n. I simply want this machine to work normally again, even if it is back to square one. HP said by hitting the f10 key it would do its own system recover but that failed. Any suggestions? I am indesparate need for all the MultiMedia (video, etc) drivers.
I don't see any ethical problem with putting your legally purchased copy of xp onto any machine that you want to put it on. You just have to raise your right hand and swear that you won't put it on any other machines also. I'll wait a second while you swear...................OK
I'll keep looking for something you can use. All of this nonsense is about Microsoft, being our favorite monopolist, using it's monopolistic power to pressure the vendors into not providing hard media with the machines. Just like every other big business, they are trying to build a limitation into the lifespan of the product to improve their sales. Microsoft is doing it under the guise of reducing piracy, which I guess they think sounds better to the public.
http://h10025.www1.hp.com/
THank you so much for all your persistance with this timothyflyer! THis is the 3rd HP that I have had recovery issues this year and HP is really getting me angry! I did go to their site and they do not have the drivers (specifially I am looking for video drivers). I called HP and they said for $35 I can purchase the CD's.. I tried to get a discount but it did not work. Maybe I am not mean enough! I really hate HPs! I actually went to all the web pages you went to.. no there is no download anymore I found out from their site. I went to your URL and I have the same one and there are no drivers on it that would help. I may have to suck up to HP and purchase the CD's. I'll call my customer and see if they created the recovery CDs like they were supposed to when they first turned on the machine. If not, I will have to charge them. THe only problem I am having with the OEM copy of XP is that it wont register and I never get a 'live' person on the Microsoft phone line to tell them what I am trying to do! I had done this once and was able to get to a live person with a compaq machine a few months ago,, but now they changed the process perhaps.
Any more suggestions? I looked up the motherboard, ASUS P4GLA and there are no video drivers on the site. Going nuts here!
I'll look around and get back with you in a few minutes. I'm assuming the ASUS board is onboard video.
I built a machine for a friend awhile back on a real tight budget and bought an Abit board that I think was designed specifically for the oem's. Finding ANYTHING for it was a nightmare unless your fluent in Chinese.
From the looks of it, I would say it was a proprietary build. Got 24 googles on p4gla, 500 something on p4 gla at which point I noticed correlation between gl and intel and somehow ended up at this site with guy with same problem and he solved it this way- I guess the video drivers are in the chipset drivers but not sure. If you can't make it out from the excerpt, I would go to the forum and read the whole thread for more clues. The excerpt is for the same machine as yours a 522n
I'm going to have to run now but I'll check back later to see if I can help on anything.
http://forum.osnn.net/arch
from link above
Ok.. I was able to figure it out. What you have to do with machines like this after you reformat and delete there partition and start from scratch. You have to find out the chipset because HP's customer care won't know what the video card and or driver because it's on board. You have to find the "chipset" from either hp or going through your BIOS. Then you have to go to your chipset makers website, in this case it was intel. There chipset for this machine was "Intel 845GL" after going there you have to go though the letters on intels website to finally get to this chipsets drivers. Install and reboot. What a huge pain in the ass this was to find this, but if you have an HP and lose all your info, do what I did here..
I think #2 and #5 on this page will take care of the usb and audio
http://downloadfinder2.int
Also, the hp driver download page link I posted earlier had burner updates on it. Alot of times, the update is the complete program so assuming the update doesn't freak on the xp pid, you might be able to replace the burner program (RecordNow). There are programs that can change that pid also though I haven't used one.
I was able to finally get the sound drivers installed! I went to the device manager and let it search on the internet for the drivers and it worked! Now I am checking out everything else before I close this issue. Thanks to all who hellped! Tim, you put a lot of time into this for me, and I do appreciate it!
Business Accounts
Answer for Membership
by: SheharyaarSaahilPosted on 2004-07-28 at 18:30:44ID: 11663036
Hello mchyzik =)
.com/suppo rtfiles/ Hi jackThis19 80.exe
Can u run this tool,,, let me check if this is really a virus destruction or u have written the error incorrectly :)
Download HijackThis, run it and Post the Log File here:
http://www.wilderssecurity