hey guys. whenever i sign on to windows (XP) i get two duplicate warnings.. with the header, "Advanced INF Installer" it reads, "Error unregistering the OCX C:\Windows\iesearch.dll"
also, i don't know if it has anything to do with it, but a few icons have appeared on my desktop, (don't know how) the one of primary concern being something called "Second Thought".. the others are myPCsearch, and "Free Travel Voucher" all of which seemed to appear at the same time. i've tried getting rid of them, but to no avail-- they just keep coming back. thanks for your time.. you guys are a godsend.. --jim--
Hi Jim, Give us a log and be patient, we will take a look, since a new version of HJT was released recently, if you have any problems with any of the links, let me know. Thanks...pskelley
We need to make you aware that many, many logs are being posted. Because we are few, all volunteers with families and real jobs, we will have to ask you to be patient. We work the logs in the order they come in, if you would like us to look at your computer, please follow the instructions below. One of the experts (trained at SpywareInfo & Tom Coyote) will assist with your log as soon as possible. They may ask for a fresh log as rebooting can mutate the newest infections.
We need you to download and install an analysis and repair tool called Hijackthis.
Download the zipped file from here: http://www.majorgeeks.com/download3155.html. Please see the following link for information about downloading and other FAQ's. There is also a link there to an .exe version of HijackThis if there is anyone who absolutely can not open a .zip file. Please use this for that purpose only due to limited bandwidth, thank you.
Please unzip Hijackthis.zip or move the hijackthis.exe file into a new folder you create in the root (first) level of the C: drive. Name this folder HJT for best and safest results. Don't place it on the Wallpaper, in a temp folder, or the My Documents folder. It will create many backup files and they need to be stored in a unique Hijackthis folder. If it is properly placed it will look like this: C:\HJT\HijackThis.exe.
After downloading, and unzipping the hijackthis file into a safe folder you create (preferably a folder named HJT in the first level of the C: drive)...run Hijackthis, click on the 'scan' button and then 'save log' button.
Copy and paste the contents of the text file you save into a reply to this message. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste at http://www.tomcoyote.com/hjt
Special Notice! Hijackthis is a powerful tool that edits the brains of Windows (the Registry). DO NOT FIX anything in the Hijackthis log screen without assistance from the experts! Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system.
Stay in this thread for continuity. Reply to this message.
Thanks,
pskelley In Training at TomCoyote.com and Spywareinfo.com
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-)
Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.
Most of the Internet baddies can be killed by a one-two punch with Spybot and Adaware assuming these three factors are achieved:
1. Latest version 2. Configured correctly for running options 3. New definitions from update feature
Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.
Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.
Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.
I also like to run Windows Disk Cleanup after cleaning with those two tools. Make sure you reboot if any reboot cleanup functions of Spybot and Adaware are advised by these tools (this may happen at the end of their cleanup).
Run Disk Cleanup: type cleanmgr at Start/Run. Scan all hard drives and check all categories at the end and click OK.
If you have any problems with Disk Cleanup completing...XP users can fix it here:
Reboot and browse a bit, exit IE 6 and post a new Hijackthis log. This will clean up some of the stuff to enable final manual cleanup to be quicker.
All the best,
Texruss www.russelltexas.com Spyware Fighter Wilders Forum Slyware Warrior Tom Coyote Forum Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-) BTW...clicking on people's usernames at the left will reveal information about them if they chose to have an open profile. My credentials are available for your perusal.
Logfile of HijackThis v1.97.7 Scan saved at 3:11:19 PM, on 7/10/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Ah...Huntbar! Also known vernacularly as Wintools. The Traffic Syndicate people have earned my undying enmity against their exploit. I guess I won't get a Christmas card from them.
Run Hijackthis, scan and check the box left of these numbered line items:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.websearch.com/ie.aspx?tb_id=50167
Hit Control-Shift-Escape keys at same time. Click on Applications tab and end Task for the Wintools entry. Click on Processes tab and end any Huntbar apps:
WToolsA.exe WToolsS.exe WSup.exe
Open Windows Explorer: type the word explorer at Start/Run box and click OK:
Drill on down and delete the following files and/or folders:
Special Deletion Comments: If Wintools resists: Navigate to C:\Program Files\Common Files\Wintools
Right button click on Wintools folder icon and uncheck Read-only box. Click on Advanced tab and see if there is a security tab. Go in it and check all boxes to give you permissions over that folder.
Do the same if there is a Temp subfolder under WinTools.
Now right button click on Wintools folder and delete. If it doesn't go away then try some more investigation in those Properties. Report back on how you do for this and if these directions worked. If it deletes, exit Explorer and empty Recycle Bin.
Reboot in normal mode Windows and run Disk Cleanup: type cleanmgr at Start/Run. Scan all hard drives and check all categories at the end and click OK.
If you have any problems with Disk Cleanup completing...XP users can fix it here:
Download and run these two programs (Spybot S&D and Adaware) at the link below. Use Spybot first.
Most of the Internet baddies can be killed by a one-two punch with Spybot and Adaware assuming these three factors are achieved:
1. Latest version 2. Configured correctly for running options 3. New definitions from update feature
Chris has posted an excellent tutorial by dgosling on how to run Spybot S&D and also how to enable customized deep scanning functions for Adaware. Once you set these options they will be retained for future scans by Adaware.
Follow the directions in this detailed guide for Spybot and Adaware...print out the directions in the custom scan tutorial as a reference while you set these options for the custom setup of Adaware. These custom settings will be retained for future custom scans so don't go nuts thinking you have to do this every time you run it! It may take you five minutes to set them up, but it's worth it.
Please note the free Spybot 1.3 does have a slight bug...it detects some DSO exploits falsely. Hopefully an upgrade will fix this.The problem is not serious and should not deter people from using Spybot.
Reboot and browse a bit, exit IE 6 and post a new Hijackthis log.
Special Comments: After the final all clear is given by us you should flush your Restore Points for XP. That means disabling the Restore Point, rebooting to flush it, then re-enabling a new Restore Point. The reason why we need to do this is to purge the bad files hidden in System Restore which can't be cleaned by your antivirus programs.
I also highly recommend uninstalling Kodak's Easy Share (AKA Backweb) in Add/Remove Programs. It is my brother's most hated foistware program and pretty high on my list also).
Texruss www.russelltexas.com Spyware Fighter Wilders Forum Slyware Warrior Tom Coyote Forum Expert Malware Responder Dell Forum
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley.
Also...these longtime DellForum regulars have proven to me time and again their advice is excellent for malware questions in general and many specific items in Hijackthis logs: jimw, ddeerrff, and msgale.
BTW...clicking on people's usernames at the left will reveal information about them if they chose to have an open profile. My credentials are available for your perusal.
Logfile of HijackThis v1.97.7 Scan saved at 6:26:29 PM, on 7/10/2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
thanks! i just have a few questions-- in trying to delete 41q5hx.dll i was told that i could not, and that access was denied.(?) also, after doing everything else, i went to uninstall the Kodak Easy Share, (which i did successfully, but for some reason, i can't get Search to run. i click on it, and nothing happens, and i can't do anything for a few seconds. any ideas?? thx again... -jim-
i followed method 3 up to inserting my XP CD-ROM. i went to browse for the file needed, but i couldn't figure out how to (or why i couldn't?) access my CD-ROM drive at the Open dialog box.
the funny thing is, though, is under the administrator Windows user name, search opened fine. then, when i rebooted out of safe mode, and back to my personal user name, i had the same problem opening it! (sufferin' succotash..)
as for the WinTools folder, i couldn't find a trace of it.
finally, as for 41q5hx.dll, the check box for 'read only' was already cleared, and i still couldn't delete the file. the actual notice i get is (under "error deleting file or folder"), "cannot delete 41q5hx : access is denied. make sure the disk is not full or write-protected and that the file is not currently in use."
>the funny thing is, though, is under the administrator Windows user name, search opened fine. then, when i rebooted out of safe mode, and back to my personal user name, i had the same problem opening it! (sufferin' succotash..)
Give your profile admin rights in the Admin logon...in Control Panel/User Accounts .
>cannot delete 41q5hx : access is denied. make sure the disk is not full or write-protected and that the file is not currently in use
Hit Control-Shift-Escape keys at same time and in Processes end that task for the file. Then delete.
pskelley
933 Posts
1625
0
Posted July 7th, 2004 13:00
Hi Jim, Give us a log and be patient, we will take a look, since a new version of HJT was released recently, if you have any problems with any of the links, let me know. Thanks...pskelley
We need to make you aware that many, many logs are being posted. Because we are few, all volunteers with families and real jobs, we will have to ask you to be patient. We work the logs in the order they come in, if you would like us to look at your computer, please follow the instructions below. One of the experts (trained at SpywareInfo & Tom Coyote) will assist with your log as soon as possible. They may ask for a fresh log as rebooting can mutate the newest infections.
We need you to download and install an analysis and repair tool called Hijackthis.
Download the zipped file from here: http://www.majorgeeks.com/download3155.html. Please see the following link for information about downloading and other FAQ's. There is also a link there to an .exe version of HijackThis if there is anyone who absolutely can not open a .zip file. Please use this for that purpose only due to limited bandwidth, thank you.
http://russelltexas.com/malware/faqhijackthis.htm
Please unzip Hijackthis.zip or move the hijackthis.exe file into a new folder you create in the root (first) level of the C: drive. Name this folder HJT for best and safest results. Don't place it on the Wallpaper, in a temp folder, or the My Documents folder. It will create many backup files and they need to be stored in a unique Hijackthis folder. If it is properly placed it will look like this: C:\HJT\HijackThis.exe.
Hijackthis FAQ (Frequently Asked Questions) at: http://russelltexas.com/malware/faqhijackthis.htm
After downloading, and unzipping the hijackthis file into a safe folder you create (preferably a folder named HJT in the first level of the C: drive)...run Hijackthis, click on the 'scan' button and then 'save log' button.
Copy and paste the contents of the text file you save into a reply to this message. A lot of posters make mistakes here in copying and pasting so reread the left info sidebar called Copy and Paste at http://www.tomcoyote.com/hjt
Special Notice! Hijackthis is a powerful tool that edits the brains of Windows (the Registry). DO NOT FIX anything in the Hijackthis log screen without assistance from the experts! Most of the line items in the scanned log are normal for Windows operation. Hijackthis should identify the vast majority of your problems and enable us to help you clean them off your system.
Stay in this thread for continuity. Reply to this message.
Thanks,
pskelley
In Training at TomCoyote.com and Spywareinfo.com
Please be aware only the following DellForum members were trained at TomCoyote.com and SpywareInfo.com to help with malware like viruses, worms, adware, scumware, foistware and crudware in general. They are also the only experts specifically trained to analyze and advise on Hijackthis logs: Texruss, Baskar1234, Grinler, ChrisRLG, SpotCheckBilly, and pskelley. (If you are one of our classmates and not on this list email me for an addition to this list...we need all the help we can get *;-)