Windows BBS The Place for Microsoft Windows Support! Windows, Support, Help Site

Go Back   Windows BBS > Security > General Security

General Security Post any general questions related to security, viruses or spyware here.

Register your FREE account to unlock additional features at WindowsBBS.com
Register
Welcome to WindowsBBS.com
Microsoft Windows Support

Mission Statement

WindowsBBS is an online community dedicated to easily accessible technical support for those using Microsoft operating systems and other Windows software.

Our goal is to become the leading resource for computer users that require assistance with their day-to-day computer usage, including full support for networking PC's, virus & malware removal, system upgrades and general support questions.


Discussion Forums
Operating Systems
Windows 7 Windows 7
Windows Vista Windows Vista
Windows XP Windows XP
Windows Server System Windows Server System
Windows 2000 Windows 2000
Windows 95/98/Me/NT Windows 95/98/Me/NT
Internet & Networking
Networking
Internet Explorer
Microsoft Mail
Firefox, Thunderbird
      & SeaMonkey

General Internet
Security
General Security
Malware and Virus
     Removal

Other
Other Software
Hardware
Test Posts
Community
Introductions
General Discussions
Comments
      & Suggestions

News @ WindowsBBS

Forum Sponsor
 Image

Closed Thread
 
LinkBack Thread Tools
Old 28th May 2004   #1
Inactive
 
Profile:
Join Date: May 2004
Posts: 4
Computer Experience:
Intermediate
Hoya Reputation Level


Twaintec.dll Removal?

Does anyone know any method to remove this file. I've tried just about everything and I'm at my wits end right now. I've read to try a number of things (del through safe mode, NAV removal, auto exec., ad-aware, etc.) I'm running windows XP corp. I've also gone to their website and those removal instructions do not work. I didn't install this on my cpu and I want it off


Any help would be greatly appreciated

Hoya is offline  
Didn't find the information you thought to find?
Check out these Similar Threads
Old 28th May 2004   #2
WindowsBBS Team Member
 
sparrow's Avatar
 
Profile:
Join Date: Mar 2004
Location: minneapolis
Posts: 2,283
Computer Experience:
Experienced
sparrow Reputation Levelsparrow Reputation Levelsparrow Reputation Levelsparrow Reputation Levelsparrow Reputation Levelsparrow Reputation Levelsparrow Reputation Levelsparrow Reputation Level


Post

Hoya,

As you may know, this is adware. There probably are multiple copies of the dll on your computer.

Suggest you get ad-aware and update and run it.

Suggest you then get spybot and let it delete all it finds.

Please tell us the results.


Last edited by sparrow; 28th May 2004 at 15:57.
sparrow is offline  
Old 28th May 2004   #3
WindowsBBS Team Member
 
markp62's Avatar
 
Profile:
Join Date: May 2002
Location: Coppell, TX
Posts: 3,854
Computer Experience:
Experimediate
markp62 Reputation Levelmarkp62 Reputation Levelmarkp62 Reputation Levelmarkp62 Reputation Levelmarkp62 Reputation Levelmarkp62 Reputation Levelmarkp62 Reputation Levelmarkp62 Reputation Level


http://www.snapfiles.com/get/moveonboot.html
Install MoveOnBoot, then right click on it and select to Delete on Boot, then reboot. After using, please use HijackThis, and post a log on here, I am sure there are some extra things left. The link is below.

markp62 is offline  
Old 28th May 2004   #4
Inactive
 
Profile:
Join Date: May 2004
Posts: 4
Computer Experience:
Intermediate
Hoya Reputation Level


I tried ad-aware again. Normally it would come up and say that it could not remove it but would try at next re-boot. I tried to scan again. There must have been a new update that just came out and I got it. I did a reboot and adaware deleted it...............I think. Should be OK, but I'll keep you posted.

Thanks

Hoya is offline  
Old 28th May 2004   #5
Inactive
 
Newt's Avatar
 
Profile:
Join Date: Jan 2002
Location: Concord, NC, USA
Posts: 11,217
Computer Experience:
*****
Newt Reputation Level


A hijackthis log would still be a good idea. I'm with markp62 that there is likely to be more junk you would be better without.
Newt is offline  
Old 28th May 2004   #6
Inactive
 
Profile:
Join Date: May 2004
Posts: 6
Computer Experience:
Beginner
sarni1000 Reputation Level


having the same problem ad-aware and those other programs don't seem to help, it tells me its off but and the software tells me there is no other adware on my computer but once i restart it apears again.

Any suggestians

-Sarni

sarni1000 is offline  
Old 28th May 2004   #7
Senior Member
 
Profile:
Join Date: Apr 2004
Location: Central Pennsylvania
Posts: 167
Computer Experience:
Depends on whose asking..
Triger Reputation Level


Twaintec info

Here are detailed removal instructions....I would still, however let the resident guru's here inspect your Hijack this log ...

http://www.pestpatrol.com/PestInfo/t/twain-tech.asp

Cheers
Jake

Triger is offline  
Old 28th May 2004   #8
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,524
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Hoya and sarni1000, welcome to WindowsBBS!

After installing, updating and running both Spybot and Ad-aware (run in full scan mode), please post a HijackThis log, Hoya in this thread and sarni1000 in a new thread, please.

noahdfear is offline  
Old 29th May 2004   #9
Inactive
 
Profile:
Join Date: May 2004
Posts: 6
Computer Experience:
Beginner
sarni1000 Reputation Level


posting my Hijackthis log now in a new post.

-Sarni

sarni1000 is offline  
Old 29th May 2004   #10
Inactive
 
Profile:
Join Date: May 2004
Posts: 4
Computer Experience:
Intermediate
Hoya Reputation Level


Sorry I was gone for awhile. Here is my logfile


Logfile of HijackThis v1.97.7
Scan saved at 10:10:01 AM, on 5/29/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
C:\WINDOWS\runservice.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
C:\WINDOWS\System32\WISPTIS.EXE
C:\Program Files\Outlook Express\msimn.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Matt & Angie Wheeler\Desktop\downloads\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hispeed.rogers.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200"
O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"
O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"
O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [ScanSpyware v3.5] "C:\Program Files\ScanSpyware v3.5\Scanner.exe"
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O14 - IERESET.INF: START_PAGE_URL=http://hispeed.rogers.com
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...104.4713541667
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub...sh/swflash.cab
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab

Hoya is offline  
Old 29th May 2004   #11
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,524
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Pretty clean log as far as I can tell. Scan again and place a check next to the following. Close all other windows and click fix.

R3 - Default URLSearchHook is missing
O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab

Are you still having problems? Errors?

noahdfear is offline  
Old 29th May 2004   #12
Inactive
 
Profile:
Join Date: May 2004
Posts: 4
Computer Experience:
Intermediate
Hoya Reputation Level


no problems. See my previous post. Ad aware was able to delete it, finally! I recommend people with adaware use it to get rid of this. Make sure you have all of the latest updates though
Hoya is offline  
Old 29th May 2004   #13
Staff
 
noahdfear's Avatar
 
Profile:
Join Date: Apr 2003
Location: New Bremen, Ohio U.S.A.
Posts: 12,524
Computer Experience:
~@<*+
noahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Levelnoahdfear Reputation Level

My System

Yep, and yep! Glad you're rid of it. Thanks for posting back!!
noahdfear is offline  
Old 30th May 2004   #14
SuperGeek
 
Profile:
Join Date: Dec 2002
Location: Washington state USA
Posts: 2,310
Computer Experience:
Typeos-are-Us
Lonny Jones Reputation Level


Be sure to fix this also
O4 - HKCU\..\Run: [ScanSpyware v3.5] "C:\Program Files\ScanSpyware v3.5\Scanner.exe"

Its an unsafe program http://computercops.biz/check43228previous.html
Mosiac1 is a leader in the anti spyware community

C:\install.cab delete that file to

Be sure to read our pinned or stickys
http://www.windowsbbs.com/showthread.php?t=29357
and this to
How to surf the Internet more safely with Internet Explorer: http://www.windows-help.net/features/surf-safe.html
Happy surfing

Lonny Jones is offline  
Closed Thread

Thread Tools


Similar Threads
Thread Thread Starter Forum Replies Last Post
ModeUser Toolbar Removal from IE cintoman General Security 8 20th April 2004 05:24
Microsoft Releases MSJVM Removal Tool Arie Internet Explorer 3 26th March 2004 11:50
10,000 image files removal...? civilwarstory Windows 95/98/Me/NT 7 29th February 2004 19:17
Removal of the Q811493? lringer Windows XP 3 8th May 2003 14:56
Homepage Hijackers Removal crackerjack Internet Explorer 1 1st February 2002 19:33


All times are GMT +1. The time now is 12:28.






Advertisements do not imply our endorsement of the product or service advertised.
Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.3.2
Copyright © 2002 - 2009 WindowsBBS.com. All rights reserved.
Terms of Use, Legal Information & Privacy Policy
[]