For about a week I've been trying to shake the Favoriteman virus. It's there when I run my spyware but it seems to have no real imapct on my system. I do get the occasional change to my brower toolbar, or the addition of a mystery link to a games site, but no real ill-effects. I try to remove it with Ad-aware, Spybot S&D, and CWShredder (even in safe mode), but it comes back. Ad-aware says that the file im64.dll cannot be removed from my sys32 because it is not a "valid image".??? Is there some way to get rid of this bug? Attached is my most recent HJT log, created after using the above noted cleaners:

Logfile of HijackThis v1.98.0
Scan saved at 6:53:44 PM, on 11/08/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Utilites\Norton AntiVirus 2002\navapsvc.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\ZipToA.exe
C:\WINDOWS\System32\CTHELPER.EXE
C:\PROGRA~1\Utilites\NORTON~1\navapw32.exe
C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
C:\Program Files\ASUS\Probe\AsusProb.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\SpeedFan\speedfan.exe
C:\Program Files\Utilites\Hijack This\HijackThis.exe

O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Utilites\SPYBOT~1\SDHelper.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Utilites\Norton AntiVirus 2002\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Utilites\Norton AntiVirus 2002\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\Utilites\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [Jet Detection] "C:\Program Files\Creative\SBLive\PROGRAM\ADGJDet.exe"
O4 - HKLM\..\Run: [Iomega Startup Options] C:\Program Files\Iomega\Common\ImgStart.exe
O4 - HKLM\..\Run: [Iomega Drive Icons] C:\Program Files\Iomega\DriveIcons\ImgIcon.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Program Files\Burner Stuff\CloneCd\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Startup: Run Time.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Quicken Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O12 - Plugin for .pdf: C:\Program Files\Internet Explorer\PLUGINS\nppdf32.dll
O16 - DPF: {05317530-B882-449D-9421-18D94FA3ED34} (OSInfo Control) -
O16 - DPF: {08C818C3-2F1E-11D0-9223-00A0244D2920} (ChartFX IE Client Object) -
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) -
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) -
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.
O16 - DPF: {861DB4B6-3838-11D2-8E50-002018200E57} (MrSIDI Control) -
O16 - DPF: {CC05BC12-2AA2-4AC7-AC81-0E40F83B1ADF} (Live365Player Class) -
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15008/CTPID.cab

Thanks

Joe

Dani AI

Generated

Short expert note tied to the thread: FavoriteMan is a persistent adware family that often survives simple scanner runs by using an autostart/persistence mechanism and by keeping its DLL locked or replaced on boot. is right to suggest a manual removal attempt, but the common reason Ad-Aware reports a DLL as "not a valid image" is that the file is either locked by a running process, damaged (not a proper PE/DLL), or is being reinstalled via a Run key/service/scheduled task.

A practical removal workflow used by experienced helpers:

  • Make a full backup (important registry export or system image) and disconnect the PC from the network to stop re-install callbacks.
  • Boot to Safe Mode (F8) or use a trusted rescue environment (boot CD/USB). Use Process Explorer (or Task Manager) -> Find Handle or DLL -> search for im64.dll. If a process has it open, close the handle or terminate that process, then delete the file.
  • If the file cannot be deleted, schedule its removal on reboot (PendingFileRenameOperations) or delete it from a booted rescue CD so no Windows process can lock it.
  • Use Autoruns or HijackThis to remove any Run keys, services, Scheduled Tasks, Browser Helper Objects, or toolbar entries that reference the DLL. Verify each removal before fixing; back up the registry first.
  • Run at least two updated scanners (AV + antispyware) and, if available, an offline rescue scan from vendor rescue media. Clear temporary files and check the Hosts file and Winsock LSPs for tampering.

If the DLL keeps returning after these steps it means an installer or hidden service is restoring it; locating and removing that installer (often another file or a service) is required. When in doubt, restoring from a clean backup or a clean OS reinstall is the sure remedy for a machine with persistent, hidden reinstallers.

Try deleting im64.dll manually. Try the removal instructions given

Be a part of the DaniWeb community

We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.