Velocity Reviews - Computer Hardware Reviews

Velocity Reviews > Newsgroups > Computing > Computer Support > Uninstall IE

Reply
Thread Tools

Uninstall IE

 
 
Larry Allen
Guest
Posts: n/a
 
      04-22-2004
This message is intended for Mike. I don't believe my efforts to reply to
our previous dialog worked. Here is the log file from Hijack This.

I already removed four lines associated with "isearch", (the offending
program). The tool bar is gone but the program still has control of IE.
Here's the log.
Logfile of HijackThis v1.97.7


Scan saved at 2:23:41 AM, on 4/22/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\system32\CTSvcCDA.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\WINNT\system32\nvsvc32.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\system32\Tablet.exe
C:\WINNT\system32\WFXSVC.EXE
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\ZipToA.exe
C:\WINNT\Explorer.EXE
C:\WINNT\System32\UMonit2k.exe
C:\WINNT\system32\dla\tfswctrl.exe
C:\WINNT\system32\Promon.exe
C:\WINNT\system32\wfxsnt40.exe
c:\progra~1\mcafee.com\vso\mcvsescn.exe
C:\WINNT\system32\carpserv.exe
C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
C:\WINNT\system32\ctfmon.exe
C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe
C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
C:\Program Files\Iomega\Tools\IMGICON.EXE
C:\Program Files\Common Files\MySoftware\NewsFlsh.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\Program Files\QUICKENW\QWDLLS.EXE
C:\Program Files\Wacom\TabUserW.exe
c:\program files\mcafee.com\vso\mcvsmap.exe
c:\program files\mcafee.com\shared\mcinfo.exe
c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
c:\PROGRA~1\mcafee.com\vso\mcshield.exe
C:\Program Files\Symantec\WinFax\wfxctl32.exe
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\WINNT\system32\wuauclt.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Documents and Settings\Larry G. Allen\Local Settings\Temp\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} -
C:\WINNT\system32\toolbar_.dll
O2 - BHO: (no name) - {381E85DA-C12B-4E1F-DB1C-10BC142805D1} - (no file)
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} -
C:\Program Files\EarthLink TotalAccess\PnEL.dll
O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} -
C:\WINNT\system32\dla\tfswshx.dll
O2 - BHO: Guard-IE - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program
Files\Failsafe\GuardIE\PnIE.dll
O2 - BHO: (no name) - {E322F75F-1B99-469E-9D80-BB408DBC33CA} -
C:\WINNT\system32\agjfgka.dll
O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -
{8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
O3 - Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - C:\Program
Files\Failsafe\GuardIE\PnIE.dll
O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
c:\progra~1\mcafee.com\vso\mcvsshl.dll
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} -
C:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINNT\System32\UMonit2k.exe
O4 - HKLM\..\Run: [Disc Detector] C:\Program
Files\Creative\ShareDLL\CtNotify.exe
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH
Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update
Manager\sgtray.exe" /r
O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [a-winpoet-service] "C:\Program Files\WinPoET Broadband
Connection\winpppoverethernet.exe"
O4 - HKLM\..\Run: [Promon.exe] Promon.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe"
/checktask
O4 - HKLM\..\Run: [VirusScan Online]
"c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
Files\Java\j2re1.4.2_03\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3
/cleanup
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe -a
O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink
TotalAccess\TaskPanl.exe" -winstart
O4 - Startup: OptiCal Startup.lnk = C:\Program
Files\ColorVision\OptiCal\OptiCal.exe
O4 - Startup: PowerReg Scheduler.exe
O4 - Startup: PowerReg SchedulerV2.exe
O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat
5.0\Distillr\AcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
O4 - Global Startup: Controller.LNK = C:\Program
Files\Symantec\WinFax\WFXCTL32.EXE
O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk =
C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02. EXE
O4 - Global Startup: ImageFox.lnk = C:\Program Files\ACD
Systems\ImageFox\ImageFox.exe
O4 - Global Startup: Iomega Backup Scheduler.lnk = C:\Program
Files\Iomega\Iomega Backup\dtiom98.exe
O4 - Global Startup: Iomega Icons.lnk = C:\Program
Files\Iomega\Tools\IMGICON.EXE
O4 - Global Startup: Iomega Startup Options.lnk = C:\Program
Files\Iomega\Tools\IMGSTART.EXE
O4 - Global Startup: IomegaWare.lnk = C:\Program
Files\Iomega\Iomegaware\COMMANDER.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
Office\Office10\OSA.EXE
O4 - Global Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common
Files\MySoftware\NewsFlsh.exe
O4 - Global Startup: OptiCAL Startup.lnk = C:\Program Files\PANTONE
COLORVISION\OptiCAL\OptiCAL.exe
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common
Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: Quicken Startup.lnk = C:\Program
Files\QUICKENW\QWDLLS.EXE
O4 - Global Startup: QuikSync.lnk = C:\Program
Files\Iomega\QuikSync\QUIKSYNC.EXE
O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
O4 - Global Startup: USBControl.lnk = C:\Program
Files\Adaptec\USBControl\Ausbctrl.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
present
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)
O9 - Extra 'Tools' menuitem: @C:\Program
Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
http://down.plaxo.com/down/release/PlaxoInstall.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
http://a1540.g.akamai.net/7/1540/52/...ple.com/mickey
/us/win/QuickTimeInstaller.exe
O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
System Class) -
http://bin.mcafee.com/molbin/shared/...6/mcinsctl.cab
O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
http://bin.mcafee.com/molbin/shared/...16/mcgdmgr.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://download.macromedia.com/pub/s...sh/swflash.cab




 
Reply With Quote
 
 
 
 
Dan Shackelford
Guest
Posts: n/a
 
      04-22-2004
http://toolbar.isearch.com/uninstall/

On Thu, 22 Apr 2004 09:30:14 +0000, Larry Allen wrote:

> This message is intended for Mike. I don't believe my efforts to reply to
> our previous dialog worked. Here is the log file from Hijack This.
>
> I already removed four lines associated with "isearch", (the offending
> program). The tool bar is gone but the program still has control of IE.
> Here's the log.
> Logfile of HijackThis v1.97.7
>
>
> Scan saved at 2:23:41 AM, on 4/22/2004 Platform: Windows 2000 SP4 (WinNT
> 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>
> Running processes:
> C:\WINNT\System32\smss.exe
> C:\WINNT\system32\winlogon.exe
> C:\WINNT\system32\services.exe
> C:\WINNT\system32\lsass.exe
> C:\WINNT\system32\svchost.exe
> C:\WINNT\system32\spoolsv.exe
> C:\WINNT\system32\CTSvcCDA.exe
> C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
> C:\WINNT\System32\svchost.exe
> C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
> C:\WINNT\system32\nvsvc32.exe
> C:\WINNT\system32\regsvc.exe
> C:\WINNT\system32\MSTask.exe
> C:\WINNT\system32\stisvc.exe
> C:\WINNT\system32\Tablet.exe
> C:\WINNT\system32\WFXSVC.EXE
> C:\WINNT\System32\WBEM\WinMgmt.exe
> C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
> C:\WINNT\system32\svchost.exe
> C:\WINNT\system32\ZipToA.exe
> C:\WINNT\Explorer.EXE
> C:\WINNT\System32\UMonit2k.exe
> C:\WINNT\system32\dla\tfswctrl.exe
> C:\WINNT\system32\Promon.exe
> C:\WINNT\system32\wfxsnt40.exe
> c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\WINNT\system32\carpserv.exe
> C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
> C:\WINNT\system32\ctfmon.exe
> C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe C:\Program Files\Adobe\Acrobat
> 5.0\Distillr\AcroTray.exe C:\Program Files\Iomega\Tools\IMGICON.EXE
> C:\Program Files\Common Files\MySoftware\NewsFlsh.exe C:\Program
> Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program
> Files\QUICKENW\QWDLLS.EXE
> C:\Program Files\Wacom\TabUserW.exe
> c:\program files\mcafee.com\vso\mcvsmap.exe c:\program
> files\mcafee.com\shared\mcinfo.exe c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
> c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
> c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program
> Files\Symantec\WinFax\wfxctl32.exe C:\Program
> Files\Symantec\WinFax\WFXMOD32.EXE C:\WINNT\system32\wuauclt.exe
> C:\PROGRA~1\WINZIP\winzip32.exe
> C:\Documents and Settings\Larry G. Allen\Local
> Settings\Temp\HijackThis.exe
>
> R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
> res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
> HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
> res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
> HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
> res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
> HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
> res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
> HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
> res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R0 -
> HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
> res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
> HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2
> - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
> Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx O2 - BHO: (no
> name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} -
> C:\WINNT\system32\toolbar_.dll
> O2 - BHO: (no name) - {381E85DA-C12B-4E1F-DB1C-10BC142805D1} - (no file)
> O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF}
> - C:\Program Files\EarthLink TotalAccess\PnEL.dll O2 - BHO: (no name) -
> {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\system32\dla\tfswshx.dll
> O2 - BHO: Guard-IE - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program
> Files\Failsafe\GuardIE\PnIE.dll
> O2 - BHO: (no name) - {E322F75F-1B99-469E-9D80-BB408DBC33CA} -
> C:\WINNT\system32\agjfgka.dll
> O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -
> {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 -
> Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - C:\Program
> Files\Failsafe\GuardIE\PnIE.dll
> O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
> c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Pop-Up Blocker -
> {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink
> TotalAccess\PnEL.dll O4 - HKLM\..\Run: [Synchronization Manager]
> mobsync.exe /logon O4 - HKLM\..\Run: [Gene USB Monitor]
> C:\WINNT\System32\UMonit2k.exe O4 - HKLM\..\Run: [Disc Detector]
> C:\Program Files\Creative\ShareDLL\CtNotify.exe
> O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH
> Jukebox\mm_tray.exe
> O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update
> Manager\sgtray.exe" /r
> O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe O4 -
> HKLM\..\Run: [a-winpoet-service] "C:\Program Files\WinPoET Broadband
> Connection\winpppoverethernet.exe"
> O4 - HKLM\..\Run: [Promon.exe] Promon.exe O4 - HKLM\..\Run: [NvCplDaemon]
> RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run:
> [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [VSOCheckTask]
> "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
> O4 - HKLM\..\Run: [VirusScan Online]
> "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe]
> c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe]
> C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [CARPService]
> carpserv.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
> Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [QuickTime Task]
> "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run:
> [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
> O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - HKCU\..\Run: [PlaxoUpdate]
> C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe -a O4 - HKCU\..\Run: [E6TaskPanel]
> "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
> O4 - Startup: OptiCal Startup.lnk = C:\Program
> Files\ColorVision\OptiCal\OptiCal.exe O4 - Startup: PowerReg Scheduler.exe
> O4 - Startup: PowerReg SchedulerV2.exe O4 - Global Startup: Acrobat
> Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
> O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
> Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup:
> Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE O4 - Global
> Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
> O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk =
> C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02. EXE O4 - Global Startup:
> ImageFox.lnk = C:\Program Files\ACD Systems\ImageFox\ImageFox.exe
> O4 - Global Startup: Iomega Backup Scheduler.lnk = C:\Program
> Files\Iomega\Iomega Backup\dtiom98.exe O4 - Global Startup: Iomega
> Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
> O4 - Global Startup: Iomega Startup Options.lnk = C:\Program
> Files\Iomega\Tools\IMGSTART.EXE
> O4 - Global Startup: IomegaWare.lnk = C:\Program
> Files\Iomega\Iomegaware\COMMANDER.EXE O4 - Global Startup: Microsoft
> Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
> O4 - Global Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common
> Files\MySoftware\NewsFlsh.exe
> O4 - Global Startup: OptiCAL Startup.lnk = C:\Program Files\PANTONE
> COLORVISION\OptiCAL\OptiCAL.exe
> O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common
> Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O4 - Global Startup: Quicken
> Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
> O4 - Global Startup: QuikSync.lnk = C:\Program
> Files\Iomega\QuikSync\QUIKSYNC.EXE
> O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe O4
> - Global Startup: USBControl.lnk = C:\Program
> Files\Adaptec\USBControl\Ausbctrl.exe O6 -
> HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
> O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button:
> Research (HKLM)
> O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)
> O9 - Extra 'Tools' menuitem: @C:\Program
> Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM) O9 - Extra button: Related
> (HKLM)
> O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O16 - DPF:
> {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
> http://down.plaxo.com/down/release/PlaxoInstall.cab O16 - DPF:
> {41F17733-B041-4099-A042-B518BB6A408C} -
> http://a1540.g.akamai.net/7/1540/52/...ple.com/mickey
> /us/win/QuickTimeInstaller.exe
> O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
> System Class) -
> http://bin.mcafee.com/molbin/shared/...6/mcinsctl.cab
> O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
> http://bin.mcafee.com/molbin/shared/...16/mcgdmgr.cab O16
> - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
> http://download.macromedia.com/pub/s...sh/swflash.cab


 
Reply With Quote
 
 
 
 
°Mike°
Guest
Posts: n/a
 
      04-22-2004
On Thu, 22 Apr 2004 09:30:14 GMT, in
<GgMhc.4633$(E-Mail Removed) et>
Larry Allen scrawled:

>This message is intended for Mike. I don't believe my efforts to reply to
>our previous dialog worked. Here is the log file from Hijack This.
>
>I already removed four lines associated with "isearch", (the offending
>program). The tool bar is gone but the program still has control of IE.
>Here's the log.
>Logfile of HijackThis v1.97.7
>
>
>Scan saved at 2:23:41 AM, on 4/22/2004
>Platform: Windows 2000 SP4 (WinNT 5.00.2195)
>MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
>
>Running processes:
>C:\WINNT\system32\CTSvcCDA.exe


The above is a Creative CD-ROM service for Windows 9x/ME.
It is NOT used in Windows 2000.
Right click 'My Computer', select Manage / Services and Applications.
Double-click Services, right click 'Creative Services for CD-ROM
Access', and choose Properties. Set 'Startup' to Disabled.


>C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe


The above is the Machine Debug Manager, and is
only used by developers and debuggers. Terminate
the program and rename the file to mdm.exe.old .


>C:\WINNT\system32\wuauclt.exe


The above is a Windows ME (Microsoft) auto update file.



>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
>res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
>R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
>res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
>R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
>res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
>res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
>R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
>res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
>R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
>res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)


Have HijackThis fix all of the above 'Rx' entries -- these, and
the '02' entry with the same DLL file name, below, are your
problem.


>O2 - BHO: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} -
>C:\WINNT\system32\toolbar_.dll
>
>O2 - BHO: (no name) - {381E85DA-C12B-4E1F-DB1C-10BC142805D1} - (no file)
>
>O2 - BHO: (no name) - {E322F75F-1B99-469E-9D80-BB408DBC33CA} -
>C:\WINNT\system32\agjfgka.dll


Have HijackThis fix the above. See comments above.


>O9 - Extra button: Related (HKLM)
>O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)


The above two are Alexa related. You should run Ad-Aware
and/or SpyBot Search and Destroy. Alexa is NOT dangerous,
it just tracks your browsing habits, if you use the 'Show
Related Links' feature of IE.


--
Basic computer maintenance
http://uk.geocities.com/personel44/maintenance.html
 
Reply With Quote
 
 
 
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
'make uninstall' - manual uninstall DBD::Oracle; fix perllocal.pod Am Nym Perl Misc 4 05-21-2012 01:58 PM
Smart Client Install/Uninstall broken - Not able to Uninstall Rahul ASP .Net Web Services 0 04-24-2008 10:59 AM
1.7b, shockwaveflash and uninstall JustMe Firefox 3 05-01-2004 08:45 AM
How to Uninstall Cutemenu? Himm Firefox 3 02-10-2004 05:35 AM
how to uninstall -mozilla/ linux r1_97 Firefox 1 07-01-2003 08:38 PM



Advertisments