1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

ladhide5.dll

Discussion in 'Malware and Virus Removal Archive' started by AOPA Roger, 2005/04/10.

Thread Status:
Not open for further replies.
  1. 2005/04/12
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    These files are stuck real good. WINNT\TEMP\NAV has 4 folders under it, all with various files. One folder is called manual. In it is one file, a pdf. I cannot delete it manually or using Move on Boot. Move on Boot has worked for me before, I have had it already downloaded. Every file I added, there was a dialog box that said "failed ". But if I deleted a junk file using this tool, I got the same dialog box that says succeeded. Does this need to be tried in safe mode?

    As far as the other, AUTOEXEC.NT, I think the updates were just called secruity updates, March 21 and then IE 6.0 service pack one, a GDI and detection tool and a .net framework update.
     
  2. 2005/04/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Download and install Process Explorer, unzip and open, then click file>save as and put on your desktop. Open and copy/paste it here.
     

  3. to hide this advert.

  4. 2005/04/12
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    Hope I did this right.Process PID CPU Description Company Name
    System Idle Process 0 97.03
    Interrupts n/a Hardware Interrupts
    DPCs n/a 0.99 Deferred Procedure Calls
    System 8
    SMSS.EXE 248 Windows NT Session Manager Microsoft Corporation
    CSRSS.EXE 276 Client Server Runtime Process Microsoft Corporation
    WINLOGON.EXE 296 Windows NT Logon Application Microsoft Corporation
    SERVICES.EXE 324 0.99 Services and Controller app Microsoft Corporation
    svchost.exe 524 Generic Host Process for Win32 Services Microsoft Corporation
    agentsvr.exe 756 Microsoft Agent Server Microsoft Corporation
    spoolsv.exe 556 Spooler SubSystem App Microsoft Corporation
    svchost.exe 588 Generic Host Process for Win32 Services Microsoft Corporation
    gearsec.exe 604 gearsec GEAR Software
    OLLaunch.exe 616 Quicken Online Backup Launcher Intuit Inc.
    OLRegCap.exe 664 Registry Capture Module Intuit Inc.
    ptssvc.exe 92 ptssvc KODAK
    regsvc.exe 752 Remote Registry Service Microsoft Corporation
    retrorun.exe 772 Retrospect Dantz Development Corporation
    mstask.exe 836 Task Scheduler Engine Microsoft Corporation
    stisvc.exe 888 Still Image Devices Monitor Microsoft Corporation
    WinMgmt.exe 964 Windows Management Instrumentation Microsoft Corporation
    mspmspsv.exe 992 WMDM PMSP Service Microsoft Corporation
    svchost.exe 808 Generic Host Process for Win32 Services Microsoft Corporation
    LSASS.EXE 336 LSA Executable and Server DLL (Export Version) Microsoft Corporation
    explorer.exe 1212 Windows Explorer Microsoft Corporation
    devldr32.exe 1396 DevLdr32 Creative Technology Ltd.
    ahqtb.exe 1340 Creative AudioHQ Creative Technology Ltd.
    CTLauncher.exe 1376 Creative Launcher Creative Technology Ltd
    anvshell.exe 940 ASUS nVidia Series Shell AsusTeK Computer Inc.
    hpztsb03.exe 1304 HP
    EM_EXEC.EXE 1256 Control Center Logitech Inc.
    CreateCD50.exe 1260 Roxio Create CD Roxio
    Directcd.exe 1416 DirectCD Application Roxio
    OneTouch.exe 1424 Maxtor OneTouch Detection Maxtor
    MXOALDR.EXE 1048 Maxtor MXO Auto Loader Application Cypress Semiconductor
    qttask.exe 708 Apple Computer, Inc.
    Reminder.exe 1436
    EasyShare.exe 1444 Kodak EasyShare software Eastman Kodak Company
    bagent.exe 1460 Quicken Background Agent Intuit Inc.
    sqlmangr.exe 1476 SQL Server Service Manager Microsoft Corporation
    SpySub.exe 1484 SpySubtract Program EXE InterMute, Inc.
    OLSysTray.exe 1200 Quicken Online Backup System Tray Intuit Inc.
    OUTLOOK.EXE 1520 Microsoft Outlook Microsoft Corporation
    IEXPLORE.EXE 1352 Internet Explorer Microsoft Corporation
    WinRAR.exe 1468
    procexp.exe 1564 0.99 Sysinternals Process Explorer Sysinternals

    Process: Procexp Pid: -2

    Type Name
     
  5. 2005/04/12
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    Gotta sign off for the night,
    Thanks
     
  6. 2005/04/12
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    This one's got me scratchin my head. :confused: I was hoping to see some sign of NAV in the Process Explorer log, which might explain the files in the temp folder being undeletable (in use). Maybe something else will come to me in my dreams. :rolleyes: Goodnight, and happy to 'try' helping.
     
  7. 2005/04/13
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    I just deleted all these files the hard way. I had to open theproperties tab and set to full control and was able to delete. Now I will go to the registry tool and see if anything is left in there. If not I will try to install.

    Rog
     
  8. 2005/04/13
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Download Pocket Killbox from here: http://www.downloads.subratam.org/KillBox.zip

    Extract the file to a folder, then open and double-click on Killbox.exe to run it. Click the folder icon next to the address window and browse to a NAV folder within the temp folder and select it. Check the box to delete on reboot and click the red X to the right. Click Yes, then NO to the reboot now prompt. Repeat for each of the Nav folders/files and when done, allow reboot.


    EDIT

    Looks like I was too late :D
     
  9. 2005/04/13
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    That would have been a big help. Now I have used Reg seeker, searched fro all norton and symantec. Deleted. File search for all Norton and symantec. Deleted. Cleaned the registry and upon trying to install, I get the same error. :(
    I thought I had it licked this morning when I was able to delete all the temp files.
    I had one installer type file in the WINNT TEMP folder that I got rid of. I am going to reboot and try again.

    Still nothing.
     
    Last edited: 2005/04/13
  10. 2005/04/13
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    Dave, I went back to Symantec.com/install and was able to find more information about deleting temp files. I don't remember why but under My Computer Advanced Enviroment variables, I had set TEMP and TMP to different files. TMP was=C\WINNT\TEMP where TEMP=C\local settings\temp. I also shut down many process, but this caused the blue screen of death. It restarted ok and I re-cleaned the temp files and it installed with no problems.

    Thanks, Now I need to search the forum and see if there is anything about my AUTOEXEC.NT going away on reboot.
     
  11. 2005/04/13
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    That's great news! :) Take a look at this page and search your computer for the files and registry entries mentioned. Remove if found (I'd like to know what you find) and see if the autoexec.nt problem remains.
     
  12. 2005/04/13
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    My autoexec.nt problem disappeared. It all might have been related, I don't know. I looked for a few of the files on the wind webpage and didn't find anything.

    I think all is good for a while now. Till I load new software. :) :) :cool:
     
  13. 2005/04/13
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Glad to hear it. :)
     
  14. 2005/05/12
    RickinSoCal

    RickinSoCal Inactive

    Joined:
    2005/05/12
    Messages:
    32
    Likes Received:
    0
    Roger. I have discovered why this file (Ladhide5.dll) is constantly showing up in your WINDOWS\TEMP folder.

    I went to Start>Run/msconfig. Then to the StartUp tap and UNSELECTED all programs.

    Rebooted in safe or DOS mode and deleted the offending file.

    Again . . . Start>Run> msconfig StartUp tab and selected one program at a time. If there were multiple file occurances for one program (In my case there were three files listed for KODAK.) I selected them all and rebooted the computer until I found the programs listed in the StartUp tab that loaded this file each time the computer was turned on or rebooted up. KODAK was my offending program.

    If you select the file with your mouse and right click then properties you will find the owner of the file; BackWeb.

    If you look at this site http://www.backweb.com/ (You will see icons for companies that use their services. KODAK is one of them. That's what lead me to discovered which program caused this file to load after deletion.

    I've contacted BackWeb directly to inquire exactly what this file does. I suspect that it has something to do with KODAK's Updater Software. I'm also going to inquire to KODAK on the purposes of this file.

    It also could be a breach supplying personal information to KODAK AND BackWeb.

    If I get a response I'll let you know.

    Rick
     
    Last edited: 2005/05/12
  15. 2005/05/12
    AOPA Roger

    AOPA Roger Inactive Thread Starter

    Joined:
    2005/04/07
    Messages:
    26
    Likes Received:
    0
    Thanks for the info Rick.
     
  16. 2005/05/13
    RickinSoCal

    RickinSoCal Inactive

    Joined:
    2005/05/12
    Messages:
    32
    Likes Received:
    0
    KODAK Response . . .

    Kodak's customer portal offers software updates and downloadable software that allows Kodak's digital camera customers to maximize use of their Kodak products, such as transferring digital photos from their camera to PC. Kodak wanted to ensure efficient access to and delivery of the software's valuable content to as many camera customers as possible. Due to the passive nature of traditional portals, customers were not always aware that new updates existed, requiring them to manually search for content.

    BackWeb enables Kodak to automatically deliver software updates and notifications to millions of customers based on specific user preferences. By moving from a passive approach to a proactive approach, Kodak is maximizing the ROI of its customer portal in two key ways:

    1) decreasing customer and technical support costs by minimizing the volume in customer service inquiries, and
    2) increasing sales of Kodak products and services through improved customer satisfaction and product usage.
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.