Uninstall IE

Discussion in 'Computer Support' started by Larry Allen, Apr 22, 2004.

  1. Larry Allen

    Larry Allen Guest

    This message is intended for Mike. I don't believe my efforts to reply to
    our previous dialog worked. Here is the log file from Hijack This.

    I already removed four lines associated with "isearch", (the offending
    program). The tool bar is gone but the program still has control of IE.
    Here's the log.
    Logfile of HijackThis v1.97.7


    Scan saved at 2:23:41 AM, on 4/22/2004
    Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINNT\System32\smss.exe
    C:\WINNT\system32\winlogon.exe
    C:\WINNT\system32\services.exe
    C:\WINNT\system32\lsass.exe
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\spoolsv.exe
    C:\WINNT\system32\CTSvcCDA.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINNT\System32\svchost.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    C:\WINNT\system32\nvsvc32.exe
    C:\WINNT\system32\regsvc.exe
    C:\WINNT\system32\MSTask.exe
    C:\WINNT\system32\stisvc.exe
    C:\WINNT\system32\Tablet.exe
    C:\WINNT\system32\WFXSVC.EXE
    C:\WINNT\System32\WBEM\WinMgmt.exe
    C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
    C:\WINNT\system32\svchost.exe
    C:\WINNT\system32\ZipToA.exe
    C:\WINNT\Explorer.EXE
    C:\WINNT\System32\UMonit2k.exe
    C:\WINNT\system32\dla\tfswctrl.exe
    C:\WINNT\system32\Promon.exe
    C:\WINNT\system32\wfxsnt40.exe
    c:\progra~1\mcafee.com\vso\mcvsescn.exe
    C:\WINNT\system32\carpserv.exe
    C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    C:\WINNT\system32\ctfmon.exe
    C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe
    C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    C:\Program Files\Iomega\Tools\IMGICON.EXE
    C:\Program Files\Common Files\MySoftware\NewsFlsh.exe
    C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    C:\Program Files\QUICKENW\QWDLLS.EXE
    C:\Program Files\Wacom\TabUserW.exe
    c:\program files\mcafee.com\vso\mcvsmap.exe
    c:\program files\mcafee.com\shared\mcinfo.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    c:\PROGRA~1\mcafee.com\vso\mcshield.exe
    C:\Program Files\Symantec\WinFax\wfxctl32.exe
    C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
    C:\WINNT\system32\wuauclt.exe
    C:\PROGRA~1\WINZIP\winzip32.exe
    C:\Documents and Settings\Larry G. Allen\Local Settings\Temp\HijackThis.exe

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
    res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
    Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx
    O2 - BHO: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} -
    C:\WINNT\system32\toolbar_.dll
    O2 - BHO: (no name) - {381E85DA-C12B-4E1F-DB1C-10BC142805D1} - (no file)
    O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} -
    C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} -
    C:\WINNT\system32\dla\tfswshx.dll
    O2 - BHO: Guard-IE - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program
    Files\Failsafe\GuardIE\PnIE.dll
    O2 - BHO: (no name) - {E322F75F-1B99-469E-9D80-BB408DBC33CA} -
    C:\WINNT\system32\agjfgka.dll
    O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -
    {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx
    O3 - Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - C:\Program
    Files\Failsafe\GuardIE\PnIE.dll
    O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
    c:\progra~1\mcafee.com\vso\mcvsshl.dll
    O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} -
    C:\Program Files\EarthLink TotalAccess\PnEL.dll
    O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
    O4 - HKLM\..\Run: [Gene USB Monitor] C:\WINNT\System32\UMonit2k.exe
    O4 - HKLM\..\Run: [Disc Detector] C:\Program
    Files\Creative\ShareDLL\CtNotify.exe
    O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH
    Jukebox\mm_tray.exe
    O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update
    Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [a-winpoet-service] "C:\Program Files\WinPoET Broadband
    Connection\winpppoverethernet.exe"
    O4 - HKLM\..\Run: [Promon.exe] Promon.exe
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initialize
    O4 - HKLM\..\Run: [WinFaxAppPortStarter] wfxsnt40.exe
    O4 - HKLM\..\Run: [VSOCheckTask] "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe"
    /checktask
    O4 - HKLM\..\Run: [VirusScan Online]
    "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe"
    O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe
    O4 - HKLM\..\Run: [MCUpdateExe] C:\PROGRA~1\mcafee.com\agent\mcupdate.exe
    O4 - HKLM\..\Run: [CARPService] carpserv.exe
    O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
    Files\Java\j2re1.4.2_03\bin\jusched.exe
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program
    Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3
    /cleanup
    O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
    O4 - HKCU\..\Run: [PlaxoUpdate] C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe -a
    O4 - HKCU\..\Run: [E6TaskPanel] "C:\Program Files\EarthLink
    TotalAccess\TaskPanl.exe" -winstart
    O4 - Startup: OptiCal Startup.lnk = C:\Program
    Files\ColorVision\OptiCal\OptiCal.exe
    O4 - Startup: PowerReg Scheduler.exe
    O4 - Startup: PowerReg SchedulerV2.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat
    5.0\Distillr\AcroTray.exe
    O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
    Files\Adobe\Calibration\Adobe Gamma Loader.exe
    O4 - Global Startup: Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE
    O4 - Global Startup: Controller.LNK = C:\Program
    Files\Symantec\WinFax\WFXCTL32.EXE
    O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk =
    C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02.EXE
    O4 - Global Startup: ImageFox.lnk = C:\Program Files\ACD
    Systems\ImageFox\ImageFox.exe
    O4 - Global Startup: Iomega Backup Scheduler.lnk = C:\Program
    Files\Iomega\Iomega Backup\dtiom98.exe
    O4 - Global Startup: Iomega Icons.lnk = C:\Program
    Files\Iomega\Tools\IMGICON.EXE
    O4 - Global Startup: Iomega Startup Options.lnk = C:\Program
    Files\Iomega\Tools\IMGSTART.EXE
    O4 - Global Startup: IomegaWare.lnk = C:\Program
    Files\Iomega\Iomegaware\COMMANDER.EXE
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft
    Office\Office10\OSA.EXE
    O4 - Global Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common
    Files\MySoftware\NewsFlsh.exe
    O4 - Global Startup: OptiCAL Startup.lnk = C:\Program Files\PANTONE
    COLORVISION\OptiCAL\OptiCAL.exe
    O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common
    Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
    O4 - Global Startup: Quicken Startup.lnk = C:\Program
    Files\QUICKENW\QWDLLS.EXE
    O4 - Global Startup: QuikSync.lnk = C:\Program
    Files\Iomega\QuikSync\QUIKSYNC.EXE
    O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe
    O4 - Global Startup: USBControl.lnk = C:\Program
    Files\Adaptec\USBControl\Ausbctrl.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
    present
    O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)
    O9 - Extra 'Tools' menuitem: @C:\Program
    Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)
    O9 - Extra button: Related (HKLM)
    O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
    O16 - DPF: {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
    http://down.plaxo.com/down/release/PlaxoInstall.cab
    O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} -
    http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey
    /us/win/QuickTimeInstaller.exe
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
    System Class) -
    http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
    http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
    http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Larry Allen, Apr 22, 2004
    #1
    1. Advertising

  2. http://toolbar.isearch.com/uninstall/

    On Thu, 22 Apr 2004 09:30:14 +0000, Larry Allen wrote:

    > This message is intended for Mike. I don't believe my efforts to reply to
    > our previous dialog worked. Here is the log file from Hijack This.
    >
    > I already removed four lines associated with "isearch", (the offending
    > program). The tool bar is gone but the program still has control of IE.
    > Here's the log.
    > Logfile of HijackThis v1.97.7
    >
    >
    > Scan saved at 2:23:41 AM, on 4/22/2004 Platform: Windows 2000 SP4 (WinNT
    > 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    >
    > Running processes:
    > C:\WINNT\System32\smss.exe
    > C:\WINNT\system32\winlogon.exe
    > C:\WINNT\system32\services.exe
    > C:\WINNT\system32\lsass.exe
    > C:\WINNT\system32\svchost.exe
    > C:\WINNT\system32\spoolsv.exe
    > C:\WINNT\system32\CTSvcCDA.exe
    > C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    > C:\WINNT\System32\svchost.exe
    > C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
    > C:\WINNT\system32\nvsvc32.exe
    > C:\WINNT\system32\regsvc.exe
    > C:\WINNT\system32\MSTask.exe
    > C:\WINNT\system32\stisvc.exe
    > C:\WINNT\system32\Tablet.exe
    > C:\WINNT\system32\WFXSVC.EXE
    > C:\WINNT\System32\WBEM\WinMgmt.exe
    > C:\Program Files\WinPoET Broadband Connection\WrOS.EXE
    > C:\WINNT\system32\svchost.exe
    > C:\WINNT\system32\ZipToA.exe
    > C:\WINNT\Explorer.EXE
    > C:\WINNT\System32\UMonit2k.exe
    > C:\WINNT\system32\dla\tfswctrl.exe
    > C:\WINNT\system32\Promon.exe
    > C:\WINNT\system32\wfxsnt40.exe
    > c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\WINNT\system32\carpserv.exe
    > C:\Program Files\Java\j2re1.4.2_03\bin\jusched.exe
    > C:\WINNT\system32\ctfmon.exe
    > C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe C:\Program Files\Adobe\Acrobat
    > 5.0\Distillr\AcroTray.exe C:\Program Files\Iomega\Tools\IMGICON.EXE
    > C:\Program Files\Common Files\MySoftware\NewsFlsh.exe C:\Program
    > Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe C:\Program
    > Files\QUICKENW\QWDLLS.EXE
    > C:\Program Files\Wacom\TabUserW.exe
    > c:\program files\mcafee.com\vso\mcvsmap.exe c:\program
    > files\mcafee.com\shared\mcinfo.exe c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe
    > c:\PROGRA~1\mcafee.com\vso\mcvsrte.exe
    > c:\PROGRA~1\mcafee.com\vso\mcshield.exe C:\Program
    > Files\Symantec\WinFax\wfxctl32.exe C:\Program
    > Files\Symantec\WinFax\WFXMOD32.EXE C:\WINNT\system32\wuauclt.exe
    > C:\PROGRA~1\WINZIP\winzip32.exe
    > C:\Documents and Settings\Larry G. Allen\Local
    > Settings\Temp\HijackThis.exe
    >
    > R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    > res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
    > HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    > res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
    > HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    > res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
    > HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    > res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
    > HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
    > res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R0 -
    > HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    > res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated) R1 -
    > HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank O2
    > - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program
    > Files\Adobe\Acrobat 5.0\Acrobat\ActiveX\AcroIEHelper.ocx O2 - BHO: (no
    > name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} -
    > C:\WINNT\system32\toolbar_.dll
    > O2 - BHO: (no name) - {381E85DA-C12B-4E1F-DB1C-10BC142805D1} - (no file)
    > O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF}
    > - C:\Program Files\EarthLink TotalAccess\PnEL.dll O2 - BHO: (no name) -
    > {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINNT\system32\dla\tfswshx.dll
    > O2 - BHO: Guard-IE - {D2F719F3-106A-402B-9996-3A5B12ACA564} - C:\Program
    > Files\Failsafe\GuardIE\PnIE.dll
    > O2 - BHO: (no name) - {E322F75F-1B99-469E-9D80-BB408DBC33CA} -
    > C:\WINNT\system32\agjfgka.dll
    > O3 - Toolbar: @msdxmLC.dll,-1@1033,&Radio -
    > {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 -
    > Toolbar: Guard-IE - {37C8204D-97C3-4127-BB28-1BFF3FA2F7DA} - C:\Program
    > Files\Failsafe\GuardIE\PnIE.dll
    > O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} -
    > c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Pop-Up Blocker -
    > {D7F30B62-8269-41AF-9539-B2697FA7D77E} - C:\Program Files\EarthLink
    > TotalAccess\PnEL.dll O4 - HKLM\..\Run: [Synchronization Manager]
    > mobsync.exe /logon O4 - HKLM\..\Run: [Gene USB Monitor]
    > C:\WINNT\System32\UMonit2k.exe O4 - HKLM\..\Run: [Disc Detector]
    > C:\Program Files\Creative\ShareDLL\CtNotify.exe
    > O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH
    > Jukebox\mm_tray.exe
    > O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update
    > Manager\sgtray.exe" /r
    > O4 - HKLM\..\Run: [dla] C:\WINNT\system32\dla\tfswctrl.exe O4 -
    > HKLM\..\Run: [a-winpoet-service] "C:\Program Files\WinPoET Broadband
    > Connection\winpppoverethernet.exe"
    > O4 - HKLM\..\Run: [Promon.exe] Promon.exe O4 - HKLM\..\Run: [NvCplDaemon]
    > RUNDLL32.EXE NvQTwk,NvCplDaemon initialize O4 - HKLM\..\Run:
    > [WinFaxAppPortStarter] wfxsnt40.exe O4 - HKLM\..\Run: [VSOCheckTask]
    > "c:\PROGRA~1\mcafee.com\vso\mcmnhdlr.exe" /checktask
    > O4 - HKLM\..\Run: [VirusScan Online]
    > "c:\PROGRA~1\mcafee.com\vso\mcvsshld.exe" O4 - HKLM\..\Run: [MCAgentExe]
    > c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe]
    > C:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [CARPService]
    > carpserv.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program
    > Files\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [QuickTime Task]
    > "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run:
    > [CleanUp] C:\PROGRA~1\McAfee.com\Shared\mcappins.exe /v=3 /cleanup
    > O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe O4 - HKCU\..\Run: [PlaxoUpdate]
    > C:\WINNT\Plaxo\1.5.2.32\InstallStub.exe -a O4 - HKCU\..\Run: [E6TaskPanel]
    > "C:\Program Files\EarthLink TotalAccess\TaskPanl.exe" -winstart
    > O4 - Startup: OptiCal Startup.lnk = C:\Program
    > Files\ColorVision\OptiCal\OptiCal.exe O4 - Startup: PowerReg Scheduler.exe
    > O4 - Startup: PowerReg SchedulerV2.exe O4 - Global Startup: Acrobat
    > Assistant.lnk = C:\Program Files\Adobe\Acrobat 5.0\Distillr\AcroTray.exe
    > O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common
    > Files\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup:
    > Billminder.lnk = C:\Program Files\QUICKENW\BILLMIND.EXE O4 - Global
    > Startup: Controller.LNK = C:\Program Files\Symantec\WinFax\WFXCTL32.EXE
    > O4 - Global Startup: EPSON Status Monitor 3 Environment Check 2.lnk =
    > C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV02.EXE O4 - Global Startup:
    > ImageFox.lnk = C:\Program Files\ACD Systems\ImageFox\ImageFox.exe
    > O4 - Global Startup: Iomega Backup Scheduler.lnk = C:\Program
    > Files\Iomega\Iomega Backup\dtiom98.exe O4 - Global Startup: Iomega
    > Icons.lnk = C:\Program Files\Iomega\Tools\IMGICON.EXE
    > O4 - Global Startup: Iomega Startup Options.lnk = C:\Program
    > Files\Iomega\Tools\IMGSTART.EXE
    > O4 - Global Startup: IomegaWare.lnk = C:\Program
    > Files\Iomega\Iomegaware\COMMANDER.EXE O4 - Global Startup: Microsoft
    > Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    > O4 - Global Startup: MySoftware NewsFlash.lnk = C:\Program Files\Common
    > Files\MySoftware\NewsFlsh.exe
    > O4 - Global Startup: OptiCAL Startup.lnk = C:\Program Files\PANTONE
    > COLORVISION\OptiCAL\OptiCAL.exe
    > O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common
    > Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe O4 - Global Startup: Quicken
    > Startup.lnk = C:\Program Files\QUICKENW\QWDLLS.EXE
    > O4 - Global Startup: QuikSync.lnk = C:\Program
    > Files\Iomega\QuikSync\QUIKSYNC.EXE
    > O4 - Global Startup: TabUserW.lnk = C:\Program Files\Wacom\TabUserW.exe O4
    > - Global Startup: USBControl.lnk = C:\Program
    > Files\Adaptec\USBControl\Ausbctrl.exe O6 -
    > HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    > O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM) O9 - Extra button:
    > Research (HKLM)
    > O9 - Extra button: @C:\Program Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM)
    > O9 - Extra 'Tools' menuitem: @C:\Program
    > Files\Failsafe\GuardIE\PnIE.dll,-100 (HKLM) O9 - Extra button: Related
    > (HKLM)
    > O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM) O16 - DPF:
    > {08BEF711-06DA-48B2-9534-802ECAA2E4F9} (PlxInstall Class) -
    > http://down.plaxo.com/down/release/PlaxoInstall.cab O16 - DPF:
    > {41F17733-B041-4099-A042-B518BB6A408C} -
    > http://a1540.g.akamai.net/7/1540/52/20031216/qtinstall.info.apple.com/mickey
    > /us/win/QuickTimeInstaller.exe
    > O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating
    > System Class) -
    > http://bin.mcafee.com/molbin/shared/mcinsctl/en-us/4,0,0,76/mcinsctl.cab
    > O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} (DwnldGroupMgr Class) -
    > http://bin.mcafee.com/molbin/shared/mcgdmgr/en-us/1,0,0,16/mcgdmgr.cab O16
    > - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
    > http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    Dan Shackelford, Apr 22, 2004
    #2
    1. Advertising

  3. Larry Allen

    °Mike° Guest

    On Thu, 22 Apr 2004 09:30:14 GMT, in
    <GgMhc.4633$>
    Larry Allen scrawled:

    >This message is intended for Mike. I don't believe my efforts to reply to
    >our previous dialog worked. Here is the log file from Hijack This.
    >
    >I already removed four lines associated with "isearch", (the offending
    >program). The tool bar is gone but the program still has control of IE.
    >Here's the log.
    >Logfile of HijackThis v1.97.7
    >
    >
    >Scan saved at 2:23:41 AM, on 4/22/2004
    >Platform: Windows 2000 SP4 (WinNT 5.00.2195)
    >MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
    >
    >Running processes:
    >C:\WINNT\system32\CTSvcCDA.exe


    The above is a Creative CD-ROM service for Windows 9x/ME.
    It is NOT used in Windows 2000.
    Right click 'My Computer', select Manage / Services and Applications.
    Double-click Services, right click 'Creative Services for CD-ROM
    Access', and choose Properties. Set 'Startup' to Disabled.


    >C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe


    The above is the Machine Debug Manager, and is
    only used by developers and debuggers. Terminate
    the program and rename the file to mdm.exe.old .


    >C:\WINNT\system32\wuauclt.exe


    The above is a Windows ME (Microsoft) auto update file.



    >R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
    >res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    >R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
    >res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    >R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    >res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    >R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar =
    >res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    >R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
    >res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)
    >R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    >res://C:\WINNT\system32\agjfgka.dll/sp.html (obfuscated)


    Have HijackThis fix all of the above 'Rx' entries -- these, and
    the '02' entry with the same DLL file name, below, are your
    problem.


    >O2 - BHO: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} -
    >C:\WINNT\system32\toolbar_.dll
    >
    >O2 - BHO: (no name) - {381E85DA-C12B-4E1F-DB1C-10BC142805D1} - (no file)
    >
    >O2 - BHO: (no name) - {E322F75F-1B99-469E-9D80-BB408DBC33CA} -
    >C:\WINNT\system32\agjfgka.dll


    Have HijackThis fix the above. See comments above.


    >O9 - Extra button: Related (HKLM)
    >O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)


    The above two are Alexa related. You should run Ad-Aware
    and/or SpyBot Search and Destroy. Alexa is NOT dangerous,
    it just tracks your browsing habits, if you use the 'Show
    Related Links' feature of IE.


    --
    Basic computer maintenance
    http://uk.geocities.com/personel44/maintenance.html
    °Mike°, Apr 22, 2004
    #3
    1. Advertising

Want to reply to this thread or ask your own question?

It takes just 2 minutes to sign up (and it's free!). Just click the sign up button to choose a username and then you can ask your own questions on the forum.
Similar Threads
  1. r1_97

    how to uninstall -mozilla/ linux

    r1_97, Jul 1, 2003, in forum: Firefox
    Replies:
    1
    Views:
    5,100
  2. Himm

    How to Uninstall Cutemenu?

    Himm, Feb 9, 2004, in forum: Firefox
    Replies:
    3
    Views:
    454
    dantu
    Feb 10, 2004
  3. JustMe
    Replies:
    3
    Views:
    571
    Moz Champion
    May 1, 2004
  4. Colonel Blip

    Firefox - can't uninstall extensions

    Colonel Blip, Jul 30, 2004, in forum: Firefox
    Replies:
    0
    Views:
    573
    Colonel Blip
    Jul 30, 2004
  5. m
    Replies:
    1
    Views:
    528
    Andreas, The Grande Panjandrum
    Sep 21, 2004
Loading...

Share This Page