Running Windows XP Professional OS. Upon startup and practically every 5-10 minutes while working on the computer, I get a RUNDLL pop-up stating "Error loading C:\Documents and Settings\asmith\Local Settings\Application Data\Mzonikodad.dat The specified module could not be found."

A thorough search of the internet finds nothing or no one who has heard of Mzonikodad.dat.

Any suggestions other than a dump and a restore?

Dani AI

Generated

A RUNDLL "module not found" popup means something (usually a startup or scheduled entry) is calling rundll32 to load a module that no longer exists. The filename reported by (mzonikodad.dat in a per‑user AppData path) strongly suggests a leftover autorun or task left behind after an infection or an incomplete uninstall. The Windows command-line reference for rundll32 explains the basic mechanism and why a missing file produces that dialog (see Microsoft docs for rundll32).

A practical, non-destructive approach: first perform thorough scans (antimalware/AV), then hunt for the broken autorun. Common manual checks that find the offending reference are: show hidden/system files and search all drives for the filename; inspect per-user and All Users Startup folders and Scheduled Tasks; and search the registry (use regedit -> Edit → Find for the filename) and review values under the usual startup keys (for example, HKLM\Software\Microsoft\Windows\CurrentVersion\Run and HKCU\Software\Microsoft\Windows\CurrentVersion\Run). Always export any key or value before deleting it and work from Safe Mode when possible. If the file is found, renaming it (add a .old) lets autorun attempts fail silently while preserving the sample for analysis/scanning.

For a single-tool, authoritative listing of every autorun location use the Sysinternals Autoruns utility — it shows the exact command line that invokes rundll32, the registry value or shortcut that triggers it, and flags broken/missing files so the offending entry can be disabled or removed safely (see Autoruns documentation).

Cautions: back up the registry or create a restore point before edits, do not delete keys blindly, and treat an XP machine as higher risk because it is out of support. If evidence of persistent compromise remains after removing the startup reference, a clean install is the only guaranteed way to ensure full remediation.

Certainly NOT restore. Sounds to me as if you may have or have had infection on there that may have been removed but the start up entries or service from this infection has NOT been removed so the computer is looking for that file, because the infection has created the need for this file.
I would advise you do the following:
Please Download ATF-Cleaner.exe by Atribune
You can put ATF-Cleaner on your Desktop for easy access.

RUN ATF-Cleaner.exe.

-- Click on ATF-Cleaner to run it
-- Where it says Select Files To Delete, Check the Select All Option
-- Click Empty Selected > OK

If you use Firefox browser, do this also:

* Click Firefox at the top and choose Select All from the list.
* Click the Empty Selected button.
* NOTE : If you would like to keep your saved passwords, click No at the prompt.
Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily. The log can also be opened by going to Start > All Programs > Malwarebytes' Anti-Malware > Logs > log-date.txt.
Reboot the computer

Please Run the ESET Online Scanner and attach the ScanLog with your post for assistance.

* You will need to use Internet Explorer to to complete this scan.
* You will need to temporarily Disable your current Anti-virus program.

* Be sure the option to Remove found threats is checked at and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt. Please post that log for us as directed below.

After that please download HiJackThis and run a System Scan with it and save the log.

Post back here with copy/pastes of all three of those logs.

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.