Hi everyone,

I have a computer that is running windows 2000 and upon loading i get 2 error messages. they are as follows:

Error loading C:\Docume~1\Dwilli~1\locals~1\TEMP\__c00A361C.dat
Error loading C:\Docume~1\Dwilli~1\locals~1\TEMP\__c001ecb5.dat

This started to happen after AVG did a virus scan yesterday and found a virus. It says it took care of it but these still come up. I have since then did some research (mainly for .dll files not .dat files) and people said to run spy bot, or other spy ware removal products. I had run spybot, it took care of a handful of items, rebooted now i get a third error message along those lines. I am unsure as how to handle the .dat files. here is my HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 9:43:14 AM, on 8/19/2008
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINNT\Explorer.EXE
C:\WINNT\system32\RUNDLL32.EXE
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Program Files\Trillian\trillian.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exe
C:\Program Files\AutoCAD 2007\acad.exe
C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\AdskCleanup.0001
C:\Program Files\Common Files\Autodesk Shared\WSCommCntr1.exe
C:\Program Files\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINNT\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINNT\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [WinVNC] "C:\Program Files\UltraVNC\WinVNC.exe" -servicehelper
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [__c00A361C] rundll32.exe "C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\__c00A361C.dat",B
O4 - HKCU\..\Run: [A00F31E43D5.exe] C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\_A00F31E43D5.exe
O4 - HKCU\..\Run: [__c001ECB5] rundll32.exe "C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\__c001ECB5.dat",B
O4 - HKCU\..\Run: [__c0015D8B] rundll32.exe "C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\__c0015D8B.dat",B
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')
O4 - Startup: Trillian.lnk = C:\Program Files\Trillian\trillian.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Program Files\Common Files\Autodesk Shared\acstart17.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1204643661398
O16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/2.0.0.1/sysreqlab2.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mwtarch.mwtarch.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mwtarch.mwtarch.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mwtarch.mwtarch.com
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Autodesk Network Licensing Service - Autodesk, Inc. - C:\Program Files\Common Files\Autodesk Shared\Service\AdskNetSrv.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINNT\system32\nvsvc32.exe
O23 - Service: VNC Server (winvnc) - UltraVNC - C:\Program Files\UltraVNC\WinVNC.exe

--
End of file - 5528 bytes

Looks like AVG removed the files but left the registry keys. Search the registry for the full file names and delete each entry.

Looks like AVG removed the files but left the registry keys

They are still being loaded at startup from the respective locations. The files have not been deleted.

Just clear your temp files using CCleaner

Open HijackThis and click on Do a system scan only and place a check on the following(if they still exist) :


R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
O4 - HKCU\..\Run: [__c00A361C] rundll32.exe "C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\__c00A361C.dat",B
O4 - HKCU\..\Run: [A00F31E43D5.exe] C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\_A00F31E43D5.exe
O4 - HKCU\..\Run: [__c001ECB5] rundll32.exe "C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\__c001ECB5.dat",B
O4 - HKCU\..\Run: [__c0015D8B] rundll32.exe "C:\DOCUME~1\DWILLI~1\LOCALS~1\Temp\__c0015D8B.dat",B
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

Also, if this is not a website/proxy you recognise, then place a check against them too :

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = mwtarch.mwtarch.com
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = mwtarch.mwtarch.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = mwtarch.mwtarch.com

Close all open windows and click Fix Checked.

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to
    • Update Malwarebytes' Anti-Malware
    • and Launch Malwarebytes' Anti-Malware
  • then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.

Please post this log in your reply along with a new Hijackthis logfile

Cyber Punk, why do you think the files have not been deleted? The original poster was receiving the following messages:

Error loading C:\Docume~1\Dwilli~1\locals~1\TEMP\__c00A361C.dat
Error loading C:\Docume~1\Dwilli~1\locals~1\TEMP\__c001ecb5.dat

If the files were still there they would be loaded, correct?

Hi, thanks for your review.
Yes, that's a perfect argument. It may have been deleted, but sometimes, files tend to show these errors even though they are present in the system.

I'm telling you from my personal experience. I once had a Vundo file in my temp directory and even though it was present, it used to show that error at startup.

I regret any hard feeling.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.