Is Windows up to date on critical patches, and are you running an up to date firewall and antivirus software? Have you scanned with a spyware eliminator (www.lavasoftusa.com)?
You are infected with malicious spyware (Common Name Toolbar parasite) and probably others. First download, install, update, and run both Spybot and Ad-Aware (as ejn has already suggested). Allow these programs to get rid of all the problem files that they find.
Then, if you are still having problems, go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
You are infected with malicious spyware. First download, install, update, and run both Spybot and Ad-Aware (as ejn has already suggested). Allow these programs to get rid of all the problem files that they find.
Then, if you are still having problems, go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
Did you read any of the replies above? You are infected with spyware. Download, install, update, and run Ad-Aware and Spybot and let these programs remove all of the garbage that they find.
Go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus/Spyware Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
I have been seeing this error message and have done everything that you suggested...the only problem is that alot of the spyware can not be deleted with these programs that you have suggested. Is there any other help that you can think of for this problem.
Obviously, you didn't follow all of the advice given in my first reply, above. Of course, it's now several months later, so the advice has a changed a bit:
Go to the following site and follow the directions to download and run the analysis tool called HijackThis.
Logfile of HijackThis v1.98.2
Scan saved at 12:27:20 AM, on 12/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Obviously, you didn't follow all of the advice given in my first reply, above. Of course, it's now several months later, so the advice has a changed a bit:
Post your HijackThis log file, in one of the following forums:
Did you read any of the replies above? You are infected with spyware. Download, install, update, and run Ad-Aware and Spybot and let these programs remove all of the garbage that they find.
Go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus/Spyware Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
ejn63
9 Legend
•
87.5K Posts
0
May 29th, 2004 13:00
What program?
Is Windows up to date on critical patches, and are you running an up to date firewall and antivirus software? Have you scanned with a spyware eliminator (www.lavasoftusa.com)?
Domfu1962
2 Posts
0
May 29th, 2004 14:00
The rundll message is Error loading c:program\1common\2address\1cnbabe.dll
module could not be found someone help please.
volcano11
2 Intern
•
28K Posts
0
May 29th, 2004 15:00
You are infected with malicious spyware (Common Name Toolbar parasite) and probably others. First download, install, update, and run both Spybot and Ad-Aware (as ejn has already suggested). Allow these programs to get rid of all the problem files that they find.
http://www.lavasoft.de/index.html Ad-Aware
http://www.safer-networking.org/index.php?page=download Spybot
Then, if you are still having problems, go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
http://tomcoyote.com/hjt/
Steve
meilee1204
1 Message
0
June 29th, 2004 04:00
volcano11
2 Intern
•
28K Posts
0
June 29th, 2004 04:00
You are infected with malicious spyware. First download, install, update, and run both Spybot and Ad-Aware (as ejn has already suggested). Allow these programs to get rid of all the problem files that they find.
http://www.lavasoft.de/index.html Ad-Aware
http://www.safer-networking.org/index.php?page=download Spybot
Then, if you are still having problems, go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
http://tomcoyote.com/hjt/
Steve
Opiee29
1 Message
0
July 14th, 2004 21:00
Hi! I keep getting this message every time I log on to my comp.
C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL
I use Windows XP home edition. Can anyone tell me whats wrong and or how to fix it?? Please?
Thanks,
Opiee
volcano11
2 Intern
•
28K Posts
0
July 14th, 2004 23:00
You are also infected with spyware. Please follow the advice I offered in my reply above and below.
Steve
volcano11
2 Intern
•
28K Posts
0
July 31st, 2004 14:00
Did you read any of the replies above? You are infected with spyware. Download, install, update, and run Ad-Aware and Spybot and let these programs remove all of the garbage that they find.
http://www.lavasoftusa.com Ad-Aware
http://www.safer-networking.org/index.php?page=download Spybot
Go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus/Spyware Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
http://tomcoyote.com/hjt/
Steve
jaime11
2 Posts
0
July 31st, 2004 14:00
inspiron 8500
Do you have idea about this message?
RUNDLL Error loading Udconn.dll
this appears when start my pc
thanks
Jaime
Bec75
1 Message
0
November 3rd, 2004 20:00
I have been seeing this error message and have done everything that you suggested...the only problem is that alot of the spyware can not be deleted with these programs that you have suggested. Is there any other help that you can think of for this problem.
thanks
volcano11
2 Intern
•
28K Posts
0
November 3rd, 2004 23:00
Bec75,
Obviously, you didn't follow all of the advice given in my first reply, above. Of course, it's now several months later, so the advice has a changed a bit:
Go to the following site and follow the directions to download and run the analysis tool called HijackThis.
http://tomcoyote.com/hjt/
Generate a log file, then open it and copy and paste the text of the log file in a message in one of the following forums:
http://subratam.org/
http://www.zerosrealm.com/forums/
http://www.bleepingcomputer.com/
where a certified HijackThis expert can offer advice on how to fix the problem:
Steve
Message Edited by volcano11 on 11-03-2004 07:24 PM
CSHPigBoy
1 Message
0
December 7th, 2004 06:00
Scan saved at 12:27:20 AM, on 12/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMON~1\aol\ACS\acsd.exe
C:\WINDOWS\system32\cisvc.exe
C:\WINDOWS\System32\CTsvcCDA.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\wanmpsvc.exe
C:\Program Files\Common Files\WinTools\WToolsS.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\Program Files\Common Files\WinTools\WToolsA.exe
C:\Program Files\Common Files\WinTools\WSup.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\P2P Networking\P2P Networking.exe
C:\WINDOWS\System32\zjomcc.exe
C:\Program Files\WindowsSA\omniscient.exe
C:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\Program Files\Dell\Support\Alert\bin\NotifyAlert.exe
C:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\kdx\KHost.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\QuickTime\qttask.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\America Online 9.0\aoltray.exe
C:\Program Files\AOL Companion\companion.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpohmr08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpoevm08.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\Bin\hpoSTS08.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\SYSTEM32\notepad.exe
C:\Program Files\America Online 9.0\waol.exe
C:\Program Files\America Online 9.0\shellmon.exe
C:\Program Files\America Online 9.0\aolwbspd.exe
C:\Documents and Settings\Jaime\Local Settings\Temp\Temporary Directory 1 for hijackthis.zip\HijackThis.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.webcounter.cc/-/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://in.webcounter.cc/-/?ydtfs about:blank (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://in.webcounter.cc/-/?ydtfs about:blank (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?ydtfs (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?ydtfs (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.websearch.com/ie.aspx?tb_id=50032
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = websearch.drsnsrch.com/q.cgi?q=
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
F1 - win.ini: run=fntldr.exe
F2 - REG:system.ini: UserInit=C:\Windows\System32\wsaupdater.exe,
O1 - Hosts: 69.20.16.183 auto.search.msn.com
O1 - Hosts: 69.20.16.183 search.netscape.com
O1 - Hosts: 69.20.16.183 ieautosearch
O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\COMMON~1\WinTools\WToolsB.dll
O2 - BHO: (no name) - {8DA5457F-A8AA-4CCF-A842-70E6FD274094} - C:\PROGRA~1\COMMON~1\WinTools\WToolsT.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ISTbar - {5F1ABCDB-A875-46c1-8345-B72A4567E486} - C:\Program Files\ISTbar\istbar.dll (file missing)
O3 - Toolbar: (no name) - {2CDE1A7D-A478-4291-BF31-E1B4C16F92EB} - (no file)
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: AIM Search - {40D41A8B-D79B-43d7-99A7-9EE0F344C385} - C:\Program Files\AIM Toolbar\AIMBar.dll
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [cnspmqzxqtkkr] C:\WINDOWS\System32\zjomcc.exe
O4 - HKLM\..\Run: [Windows SA] C:\Program Files\WindowsSA\omniscient.exe
O4 - HKLM\..\Run: [Win Server Updt] C:\WINDOWS\wupdt.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
O4 - HKLM\..\Run: [VirusScan Online] "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load
O4 - HKLM\..\Run: [Power Scan] C:\Program Files\Power Scan\powerscan.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\McUpdate.exe
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe files\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [lyueuiilj] C:\WINDOWS\System32\zjomcc.exe
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [diagent] "C:\Program Files\Creative\SBLive\Diagnostics\diagent.exe" startup
O4 - HKLM\..\Run: [alchem] C:\WINDOWS\alchem.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [ASHLT] C:\WINDOWS\Ashlt.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] C:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe
O4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
O4 - HKLM\..\RunOnce: [WinTools] C:\PROGRA~1\COMMON~1\WinTools\WToolsA.exe /boot
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ksuser] C:\WINDOWS\System32\ksuser.exe
O4 - HKCU\..\Run: [spnike] C:\WINDOWS\System32\spnike.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = C:\Program Files\America Online 9.0\aoltray.exe
O4 - Global Startup: AOL Companion.lnk = C:\Program Files\AOL Companion\companion.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: hp psc 1000 series.lnk = ?
O4 - Global Startup: hpoddt01.exe.lnk = ?
O8 - Extra context menu item: &AIM Search - res://C:\Program Files\AIM Toolbar\AIMBar.dll/aimsearch.htm
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: WeatherBug - {AF6CABAB-61F9-4f12-A198-B7D41EF1CB52} - C:\Program Files\AWS\WeatherBug\Weather.exe (file missing) (HKCU)
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\calsp.dll
O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} (Installer Class) - http://www.xxxtoolbar.com/ist/softwares/v4.0/0006_regular.cab
O16 - DPF: {1D0D9077-3798-49BB-9058-393499174D5D} - file://c:\counter.cab
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,83/mcinsctl.cab
O16 - DPF: {75D1F3B2-2A21-11D7-97B9-0010DC2A6243} (SecureLogin.SecureControl) - http://secure2.comned.com/signuptemplates/ActiveSecurity.cab
O16 - DPF: {94B82441-A413-4E43-8422-D49930E69764} (TLIEFlashObj Class) - https://webchat.dell.com/Media/VisitorChat/TLIEFlash.CAB
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) - http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,20/mcgdmgr.cab
O16 - DPF: {C1C2AC28-5E4B-4228-B7A0-05E986FFCE14} (TIBSLoader Class) - http://www.directplugin.com/tl4000.dll
O16 - DPF: {DDFFA75A-E81D-4454-89FC-B9FD0631E726} - http://www.bundleware.com/activeX/DS3/DS3.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) - http://www.gamespot.com/KDX22/download/kdx.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{504AA24D-EE3C-4985-AD00-96B99A2C7035}: NameServer = 205.188.146.146
O19 - User stylesheet: C:\WINDOWS\Web\tips.ini (file missing)
O19 - User stylesheet: C:\WINDOWS\hh.htt (file missing) (HKLM)
volcano11
2 Intern
•
28K Posts
0
December 7th, 2004 12:00
Post your HijackThis log file, in one of the following forums:
http://subratam.org/
http://www.zerosrealm.com/forums/
http://www.bleepingcomputer.com/
where a certified HijackThis expert can offer advice on how to fix the problem:
Steve
jnicki08
1 Message
0
February 9th, 2005 17:00
volcano11
2 Intern
•
28K Posts
0
February 12th, 2005 00:00
Did you read any of the replies above? You are infected with spyware. Download, install, update, and run Ad-Aware and Spybot and let these programs remove all of the garbage that they find.
http://www.lavasoftusa.com Ad-Aware
http://www.safer-networking.org/index.php?page=download Spybot
Go to the following site and follow the directions to download and run the analysis tool called HijackThis. Generate a log file, then open it and copy and paste the text of the log file in a message in the Virus/Spyware Information and Removal forum where one of the HijackThis experts can offer advice on how to fix the problem:
http://tomcoyote.com/hjt/
Steve