1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Twaintec.dll Removal?

Discussion in 'Security and Privacy' started by Hoya, 2004/05/27.

Thread Status:
Not open for further replies.
  1. 2004/05/27
    Hoya

    Hoya Inactive Thread Starter

    Joined:
    2004/05/27
    Messages:
    4
    Likes Received:
    0
    Does anyone know any method to remove this file. I've tried just about everything and I'm at my wits end right now. I've read to try a number of things (del through safe mode, NAV removal, auto exec., ad-aware, etc.) I'm running windows XP corp. I've also gone to their website and those removal instructions do not work. I didn't install this on my cpu and I want it off :mad: :mad: :mad: :mad: :mad:


    Any help would be greatly appreciated
     
    Hoya,
    #1
  2. 2004/05/27
    sparrow

    sparrow Inactive

    Joined:
    2004/03/21
    Messages:
    2,282
    Likes Received:
    0
    Hoya,

    As you may know, this is adware. There probably are multiple copies of the dll on your computer.

    Suggest you get ad-aware and update and run it.

    Suggest you then get spybot and let it delete all it finds.

    Please tell us the results.
     
    Last edited: 2004/05/28

  3. to hide this advert.

  4. 2004/05/27
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    http://www.snapfiles.com/get/moveonboot.html
    Install MoveOnBoot, then right click on it and select to Delete on Boot, then reboot. After using, please use HijackThis, and post a log on here, I am sure there are some extra things left. The link is below.
     
  5. 2004/05/27
    Hoya

    Hoya Inactive Thread Starter

    Joined:
    2004/05/27
    Messages:
    4
    Likes Received:
    0
    I tried ad-aware again. Normally it would come up and say that it could not remove it but would try at next re-boot. I tried to scan again. There must have been a new update that just came out and I got it. I did a reboot and adaware deleted it...............I think. Should be OK, but I'll keep you posted.

    Thanks
     
    Hoya,
    #4
  6. 2004/05/27
    Newt

    Newt Inactive

    Joined:
    2002/01/07
    Messages:
    10,974
    Likes Received:
    2
    A hijackthis log would still be a good idea. I'm with markp62 that there is likely to be more junk you would be better without.
     
    Newt,
    #5
  7. 2004/05/27
    sarni1000

    sarni1000 Inactive

    Joined:
    2004/05/27
    Messages:
    6
    Likes Received:
    0
    having the same problem ad-aware and those other programs don't seem to help, it tells me its off but and the software tells me there is no other adware on my computer but once i restart it apears again.

    Any suggestians

    -Sarni
     
  8. 2004/05/28
    Triger

    Triger Inactive

    Joined:
    2004/04/21
    Messages:
    174
    Likes Received:
    0
  9. 2004/05/28
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Hoya and sarni1000, welcome to WindowsBBS! :)

    After installing, updating and running both Spybot and Ad-aware (run in full scan mode), please post a HijackThis log, Hoya in this thread and sarni1000 in a new thread, please. :)
     
  10. 2004/05/28
    sarni1000

    sarni1000 Inactive

    Joined:
    2004/05/27
    Messages:
    6
    Likes Received:
    0
    posting my Hijackthis log now in a new post.

    -Sarni
     
  11. 2004/05/29
    Hoya

    Hoya Inactive Thread Starter

    Joined:
    2004/05/27
    Messages:
    4
    Likes Received:
    0
    Sorry I was gone for awhile. Here is my logfile


    Logfile of HijackThis v1.97.7
    Scan saved at 10:10:01 AM, on 5/29/2004
    Platform: Windows XP SP1 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
    C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
    C:\Program Files\Common Files\EPSON\EBAPI\SAgent2.exe
    C:\WINDOWS\runservice.exe
    C:\Program Files\Norton AntiVirus\navapsvc.exe
    C:\WINDOWS\System32\nvsvc32.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\Explorer.EXE
    C:\WINDOWS\SOUNDMAN.EXE
    C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
    C:\Program Files\Common Files\Symantec Shared\ccApp.exe
    C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe
    C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe
    C:\Program Files\Messenger\msmsgs.exe
    C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe
    C:\WINDOWS\System32\WISPTIS.EXE
    C:\Program Files\Outlook Express\msimn.exe
    C:\Program Files\Internet Explorer\iexplore.exe
    C:\Documents and Settings\Matt & Angie Wheeler\Desktop\downloads\HijackThis.exe

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://hispeed.rogers.com
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Rogers Hi-Speed Internet
    R3 - Default URLSearchHook is missing
    O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
    O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
    O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
    O4 - HKLM\..\Run: [EPSON Stylus CX3200] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P19 "EPSON Stylus CX3200" /O6 "USB001" /M "Stylus CX3200 "
    O4 - HKLM\..\Run: [Ink Monitor] C:\Program Files\EPSON\Ink Monitor\InkMonitor.exe
    O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe "
    O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe "
    O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe "
    O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe "
    O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe "
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
    O4 - HKCU\..\Run: [ScanSpyware v3.5] "C:\Program Files\ScanSpyware v3.5\Scanner.exe "
    O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
    O9 - Extra button: Research (HKLM)
    O9 - Extra button: Messenger (HKLM)
    O9 - Extra 'Tools' menuitem: Messenger (HKLM)
    O14 - IERESET.INF: START_PAGE_URL=http://hispeed.rogers.com
    O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
    O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52....apple.com/saba/us/win/QuickTimeInstaller.exe
    O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicode/iuctl.CAB?38104.4713541667
    O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
    O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab
     
  12. 2004/05/29
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Pretty clean log as far as I can tell. Scan again and place a check next to the following. Close all other windows and click fix.

    R3 - Default URLSearchHook is missing
    O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab

    Are you still having problems? Errors?
     
  13. 2004/05/29
    Hoya

    Hoya Inactive Thread Starter

    Joined:
    2004/05/27
    Messages:
    4
    Likes Received:
    0
    no problems. See my previous post. Ad aware was able to delete it, finally! I recommend people with adaware use it to get rid of this. Make sure you have all of the latest updates though
     
  14. 2004/05/29
    noahdfear

    noahdfear Inactive

    Joined:
    2003/04/06
    Messages:
    12,178
    Likes Received:
    15
    Yep, and yep! :D Glad you're rid of it. :) Thanks for posting back!!
     
  15. 2004/05/29
    Lonny Jones

    Lonny Jones Inactive Alumni

    Joined:
    2002/12/16
    Messages:
    2,252
    Likes Received:
    0
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.