How do I get rid of the C:/PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL

  1. #1
    cvoll35 is offline Newbie

    How do I get rid of the C:/PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL

    i don't know what this is but it pops up on my computer everytime i restart it. i have the hijack log done and it looks like this:
    Logfile of HijackThis v1.99.1
    Scan saved at 7:31:09 PM, on 4/24/05
    Platform: Windows 98 SE (Win9x 4.10.2222A)
    MSIE: Internet Explorer v6.00 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\SYSTEM\KERNEL32.DLL
    C:\WINDOWS\SYSTEM\MSGSRV32.EXE
    C:\WINDOWS\SYSTEM\MPREXE.EXE
    C:\WINDOWS\PSSVC.EXE
    C:\WINDOWS\SYSTEM\mmtask.tsk
    C:\WINDOWS\SYSTEM\3COM_DMI\3CDMINIC.EXE
    C:\WINDOWS\EXPLORER.EXE
    C:\WINDOWS\SYSTEM\SYSTRAY.EXE
    C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE
    C:\WINDOWS\SYSTEM\QTTASK.EXE
    C:\PROGRAM FILES\AIM95\AIM.EXE
    C:\PROGRAM FILES\COMMON FILES\GMT\GMT.EXE
    C:\PROGRAM FILES\PRECISIONTIME\PRECISIONTIME.EXE
    C:\PROGRAM FILES\DATE MANAGER\DATEMANAGER.EXE
    C:\PROGRAM FILES\LIMEWIRE\LIMEWIRE 4.0.8\LIMEWIRE.EXE
    C:\WINDOWS\SYSTEM\DDHELP.EXE
    C:\DMI\BIN\DNAR.EXE
    C:\DMI\BIN\NODEMNGR.EXE
    C:\WINDOWS\DESKTOP\OTHER STUFF\HIJACKTHIS.EXE

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://results.dashbar.com/search?c=...==&ver=2.1.0.0
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://mail.yahoo.com/?.intl=us
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by America Online
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
    O3 - Toolbar: DashBar Toolbar - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - C:\PROGRAM FILES\DASHBAR\DASHBAR21.DLL (file missing)
    O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun
    O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
    O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG.EXE -off
    O4 - HKLM\..\Run: [EM_EXEC] c:\mouse\system\em_exec.exe
    O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\Run: [WildTangent CDA] RUNDLL32.exe C:\PROGRA~1\WILDTA~1\APPS\CDA\CDAENG~1.DLL,cdaEngi neMain
    O4 - HKLM\..\Run: [CMESys] "C:\PROGRAM FILES\COMMON FILES\CMEII\CMESYS.EXE"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime
    O4 - HKLM\..\Run: [WhenUSave] "C:\Program Files\Save\Save.exe"
    O4 - HKLM\..\Run: [WhenUSearch] "C:\Program Files\WhenUSearch\Search.exe"
    O4 - HKLM\..\Run: [WhenUSearchWHSE] C:\Program Files\WhenUSearch\whse.exe
    O4 - HKLM\..\RunServices: [AutoShutdown] C:\WINDOWS\pssvc.exe
    O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
    O4 - HKLM\..\RunServices: [3Com DMI Agent] C:\WINDOWS\SYSTEM\3com_dmi\3CDMINIC.EXE
    O4 - HKLM\..\RunServices: [DMILDR] C:\DMI\bin\dmildr.exe
    O4 - HKLM\..\RunServices: [Win32SL] C:\DMI\BIN\Win32sl.EXE -i -p -r
    O4 - HKCU\..\Run: [AIM] C:\PROGRAM FILES\AIM95\aim.exe -cnetwait.odl
    O4 - HKCU\..\Run: [ClockSync] "C:\Program Files\ClockSync\Sync.exe" /q
    O4 - Startup: GStartup.lnk = C:\Program Files\Common Files\GMT\GMT.exe
    O4 - Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
    O4 - Startup: Date Manager.lnk = C:\Program Files\Date Manager\DateManager.exe
    O4 - Startup: LimeWire 4.0.8.lnk = C:\Program Files\LimeWire\LimeWire 4.0.8\LimeWire.exe
    O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll
    O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\PROGRAM FILES\AIM95\AIM.EXE
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\SYSTEM\MSJAVA.DLL
    O9 - Extra button: Dell Home - {F92CE140-EAE7-11D4-B0CA-00B0D015DAA9} - http://business.dellnet.com/ (file missing) (HKCU)
    O16 - DPF: Yahoo! Gin - http://yog16.yahoo.com/yog/y/nq0_x.cab
    O16 - DPF: Dialpad US Java Applet - http://www.dialpad.com/applet/src/vscp.cab
    O16 - DPF: Yahoo! Euchre - http://yog31.yahoo.com/yog/y/eq0_x.cab
    O16 - DPF: Yahoo! MahJong Solitaire - http://yog29.yahoo.com/yog/y/mjsp2_x.cab
    O16 - DPF: Yahoo! Bingo - http://yog3.yahoo.com/yog/y/xp0_x.cab
    O16 - DPF: Yahoo! PagerLite - http://jpager.yahoo.com/m6/msgr.cab
    O16 - DPF: {17D72920-7A15-11D4-921E-0080C8DA7A5E} (AimSp32 Class) - http://makeover.substance.com/save/makeover.cab
    O16 - DPF: {AE1C01E3-0283-11D3-9B3F-00C04F8EF466} (HeartbeatCtl Class) - http://fdl.msn.com/zone/Z4/heartbeat.cab
    O16 - DPF: Yahoo! Pinochle - http://yog33.yahoo.com/yog/y/uq0_x.cab
    O16 - DPF: Yahoo! Blackjack - http://yog19.yahoo.com/yog/y/jq0_x.cab
    O16 - DPF: {E2F2B9D0-96B9-4B25-B90C-636ECB207D18} - http://www.whenusearch.com/WUInstSECS.cab


    WHAT DO I DO?!? THANKS!!


  2. #2
    DJNafey is offline UK site moderator
    This file is a legitimate bit of software from Wild Tangent who are apparently a company specialising in online games. I see that you have a number of Yahoo games listed in your HiJack This log as well so I'm guessing that the Wild Tangent component didn't sneak onto your PC by any illegitimate means. However, if it's annoying you, I've heard that there's a removal tool here:

    http://support.wildgames.com/uninstall.html

    Other than that, you have a very neat, clean-looking HiJack This log The only thing that looks potentially suspicious is the last line. I only say that it's "potentially suspicious" on the basis that it's a search engine. If you've never heard of www.whenusearch.com, I'd recommend running HJT again and selecting that entry at the bottom of the list to be removed ...... just in case.

    Hope that sorts out your concerns Please let us know so that we can close this thread off .... or give you further assistance

+ Reply to Thread