2
   

How do I remove this annoying toolbar!

 
 
snowtiger68
 
  1  
Reply Mon 4 Oct, 2004 04:13 pm
Blaah, it's still there :_(
0 Replies
 
snowtiger68
 
  1  
Reply Mon 4 Oct, 2004 04:27 pm
http://img.photobucket.com/albums/v189/azukas/extra-toolbars.gif
0 Replies
 
Grand Duke
 
  1  
Reply Mon 4 Oct, 2004 04:33 pm
Very weird. If you press the "Print Screen" button (top left of keyboard), then open Paint or Draw or something and hit Paste, you can take an exact copy of the screen and save it as a jpeg. I'm wondering which of the items in the Hijack-This log it could be.
0 Replies
 
snowtiger68
 
  1  
Reply Mon 4 Oct, 2004 04:47 pm
Re: I have the same problem
Well I came here cause I saw someone ells having exactly the same kind of problem, this one is my guess about which one it is, if you look into log I sent earlier:

snowtiger68 wrote:
I have used hijack this... "fixed the problems" but those annoing toolbars keep on coming back Sad

This is my LOG:
Logfile of HijackThis v1.97.7
Scan saved at 23:23:55, on 4.10.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.wthtalqiqiaevdmsssdfi.us/15MD3cNpFXUEA9Q7QEGQtb88BsoqbUVGN1iMCHIAKv6_YikY1DsLF2qRsoSTynQz.asp


secondly when I delete it from the log, it just changes it's name... but looks basecally the same....
0 Replies
 
Grand Duke
 
  1  
Reply Mon 4 Oct, 2004 04:51 pm
I'm getting out off my depth here, Snowtiger, so I think we'll have to wait for someone who's more knowledgeable to help. I am sorry I wasn't of more assistance.
0 Replies
 
snowtiger68
 
  1  
Reply Mon 4 Oct, 2004 04:56 pm
ok thanks, that's exactly what I did Smile
here it is:


http://img.photobucket.com/albums/v189/azukas/printscrn.gif
0 Replies
 
snowtiger68
 
  1  
Reply Mon 4 Oct, 2004 04:57 pm
Grand Duke wrote:
I'm getting out off my depth here, Snowtiger, so I think we'll have to wait for someone who's more knowledgeable to help. I am sorry I wasn't of more assistance.


thank you so much for your time, I think I'm more out of it than anyone LOL Laughing
0 Replies
 
snowtiger68
 
  1  
Reply Mon 4 Oct, 2004 05:38 pm
I'll be back tomorrow to see if anyone came up with the solution Smile
0 Replies
 
Don77
 
  1  
Reply Tue 5 Oct, 2004 04:22 am
Hi Salley,
Go to Add/Remove programs and remove Messengerplus!
Reboot your computer,

Next search for these files and give us any info on them you can.

O4 - HKLM\..\Run: [Joy32] F:\PROGRA~1\BIBUSE~1\junk beep phone.exe
O4 - HKLM\..\Run: [Warn Nurb Bold Bows] F:\Documents and Settings\All Users\Application Data\Acidmeetwarnnurb\Support data.exe

Post back and let us know please
0 Replies
 
swilliams
 
  1  
Reply Thu 7 Oct, 2004 05:57 am
No, i don't have 'hijack this'
Hi, this is Sally.

I don't have 'hijack this' install yet. If you could send me the website that would be great Very Happy


Sally
0 Replies
 
swilliams
 
  1  
Reply Thu 7 Oct, 2004 05:59 am
But i don't want to remove the messenger plus
Hi Don77,

I still want to use messenger plus. But if i remove the messenger plus, doesn't that mean that i cannot use it??


Sally
0 Replies
 
snowtiger68
 
  1  
Reply Fri 8 Oct, 2004 07:25 am
you just have to dowload t again Razz

snow
0 Replies
 
Rhamag
 
  1  
Reply Fri 8 Oct, 2004 08:10 am
Hijack-This should download automatically if you click here. Good luck!
0 Replies
 
swilliams
 
  1  
Reply Fri 8 Oct, 2004 11:47 pm
Thanks, i'll give it a go and will let you know whether it worked or not :wink:

Sally
0 Replies
 
Don77
 
  1  
Reply Sat 9 Oct, 2004 07:49 am
Hi again Sally,
Sorry I was away for a bit,

If you want to use it, reinstall it, but check the box to NOT install SPONSOR products
0 Replies
 
swilliams
 
  1  
Reply Sat 9 Oct, 2004 07:22 pm
I have downloaded 'Hijack This'. I have pressed 'scan' and not quite sure to what to do next. This is my log below. If someone could help me step by step on what to do next, that would be great!

My log is as follows:


R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://mxsgmgnpmcoqq.uk/LeSTghWk7DsBHszjdIcMEBUH00g3SCPhi3p0K3PaF2Fkt25TkoiGGZG4gobm2Qn4.asp
O2 - BHO: (no name) - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\2.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O2 - BHO: (no name) - {08AE31A0-778E-6B15-ABF2-4A22F4222F44} - C:\PROGRA~1\USERPO~1\LOAD EACH.exe
O2 - BHO: (no name) - {536DC406-EA50-6F4D-FDCB-51C430F7B788} - C:\PROGRA~1\USERPO~1\LOAD EACH.exe
O2 - BHO: (no name) - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Program Files\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: (no name) - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: My &Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\MSN Apps\MSN Toolbar\01.02.3000.1001\en-us\msntb.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [Smapp] C:\Program Files\Analog Devices\SoundMAX\SMTray.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [InternodeUsage] C:\PROGRA~1\INTERN~2\mum.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKLM\..\Run: [GSICONEXE] GSICON.EXE
O4 - HKLM\..\Run: [DSLAGENTEXE] dslagent.exe USB
O4 - HKLM\..\Run: [AVG_CC] C:\PROGRA~1\Grisoft\AVG6\avgcc32.exe /STARTUP
O4 - HKLM\..\Run: [start seek] C:\PROGRA~1\MEOW01~1\Funk Lite Flaw.exe
O4 - HKLM\..\Run: [BLVDNIS] C:\WINDOWS\BLVDNIS.exe
O4 - HKLM\..\Run: [dvd43] C:\Program Files\dvd43\dvd43_tray.exe
O4 - HKLM\..\Run: [PowerDVD] C:\Program Files\CyberLink\PowerDVD\PowerDVD.exe /autostart
O4 - HKLM\..\Run: [msnappau] "C:\Program Files\MSN Apps\Updater\01.02.3000.1001\en-us\msnappau.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [ballstyletitlechin] C:\Documents and Settings\All Users\Application Data\sign license ball style\Dvd window.exe
O4 - HKLM\..\Run: [idol deaf option cdrom] C:\Documents and Settings\All Users\Application Data\mpegstupididoldeaf\reflog.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [System Soap Pro] C:\Program Files\System Soap Pro\soap.exe min
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\2.bin\mwsoemon.exe
O4 - HKCU\..\Run: [a²] "C:\Program Files\a2\a2guard.exe"
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\2.bin\MWSOEMON.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm414
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: Research (HKLM)
O9 - Extra button: Researcher (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {19E28AFC-EAE3-4CE5-AC83-2407B42F57C9} (MSSecurityAdvisor Class) - http://download.microsoft.com/download/0/5/c/05c905f4-dd30-427d-a3de-373c3e5552fc/msSecAdv.cab?1083573003078
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache/funwebproducts/SmileyCentralInitialSetup1.0.0.6.cab
O16 - DPF: {421A63BA-4632-43E0-A942-3B4AB645BE51} - http://download-ak.systemsoap.com/ssoap/pptproactauthakamai/systemsoappro.cab
O16 - DPF: {68A2C3BD-7809-11D3-8ACF-0050046F2F9A} (AXELPlayer Class) - http://www.mindavenue.com/Downloads/AXELPlayerAX_Win32.cab
O16 - DPF: {6F74F92E-8DD8-4DDE-8FB8-CBB882A68048} (Microsoft Office XP Professional Step by Step Interactive) - file://C:\Program Files\Microsoft Interactive Training\O10C\mitm0026.cab
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78E} (SassCln Object) - http://www.microsoft.com/security/controls/SassCln.CAB
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{8AC44727-8F90-4BF8-826D-E9C0DE2A6860}: NameServer = 192.231.203.132 192.231.203.3




Thanks,
Sally
0 Replies
 
Flikster
 
  1  
Reply Wed 3 Nov, 2004 10:45 am
Annoying toolbar
Do a search for vtlbar1.dll (Start..Find)
you probably cant delete it there .
If you can reboot into DOS (for Win98 machines)...

then type CD system

then type del vtlbar1.dll and it should go thereafter.
0 Replies
 
swilliams
 
  1  
Reply Fri 5 Nov, 2004 01:05 am
So, just so i know,

I type 'cd system' in where?

Sally
0 Replies
 
Flikster
 
  1  
Reply Fri 5 Nov, 2004 01:43 am
If you have Win98 SE then you can reboot the system into DOS.
But make sure you have that file to delete first, otherwise no point.
I'm not sure what XP users do. Does XP have ability to go into DOS?

Anyway assuming you can get into DOS. you will see when the poota boots up...

C:\WINDOWS\

then type in

CD system

then you see

CD\WINDOWS\SYSTEM\

thats where the nasty file is...

then type

del (Filename) without the brackets and *poof* it's gone.

Hope that helps
0 Replies
 
swilliams
 
  1  
Reply Sat 6 Nov, 2004 03:07 am
Hey Flikster,

I got windows XP, do you think that would have the DOS?? Anyway i'll check.

Will let you know if that helps

Very Happy Sally
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.05 seconds on 06/25/2025 at 12:16:09