Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
I am having a world of a time removing IBIS Toolbar and Huntbar. Everyone sends me to the registry to remove them. When I try to remove the registry entry, BTIEIN,I get this message,"Cannot delete BTIEIN:Error while deleting key". I have tried ad-aware,spybot and HijackThis. I have no more hair to pull out!! PLEASE help!

Robert
Ad-aware has other settings within it to effect better removal of items detected.
Check the help file here:
http://www.lavahelp.com/howto/fullscan/index.html
Once ad-aware is set up like that...when you do your scan make sure you check the custom scanning options.
Do the scan while offline, all other programs including antivirus closed.There is a new update to ad-aware also..reference file is now at:
01R275 25.03.2004
I had trouble getting the update with the updater within ad-aware...
You can download the update manually from here:http://www.lavasoft.de/update/refs/reflist.zip
To install the update unzip the saved download to:
c:\program files\lavasoft\ad aware 6
Yes to the prompt.
Still no joy...post back.
I never give up!

Blender,
I've already tried all those things. I was at the lavasoft forum. I even used info from you to remove msg121.dll. Those two items are the only things left.

Robert
Ok..Download Hijackthis from here:
http://www.lurkhere.com/~nicefiles/
First in the list.Save the download to it's own permanent directory, unzip, scan, scan button changes to "save log" button. Save the log which auto pops up in notepad, hit ctrl+a to select all, copy/paste results here in reply.
Recommend not fixing anything yet...most of what comes up in scan is safe or even essential.
I will check ack in a bit...
_____________________________________I never give up!

Blender,
Here is the log.Logfile of HijackThis v1.97.7
Scan saved at 11:13:42 AM, on 3/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\WINDOWS\wanmpsvc.exe
D:\WINDOWS\Explorer.exe
D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe
D:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
D:\Program Files\GIANT Company Software\Spam Inspector\siMailProxyServer.exe
D:\Program Files\GIANT Company Software\Spam Inspector\siSpamFilterEngine.exe
D:\Program Files\Internet Explorer\iexplore.exe
D:\Documents and Settings\Robert Johnson\My Documents\HijackThis.exeO3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Hotmail Spam Filter - {58A83E4F-477A-4A3F-BF9B-B65BC2BD5598} - D:\Program Files\GIANT Company Software\Spam Inspector\siClientUIHotmail.dll
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [siService.exe] "D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe"
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe"
O8 - Extra context menu item: &Google Search - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .bcf: D:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/support/chipdetect/SiSAutodetectNT.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {556DDE35-E955-11D0-A707-000000521957} - http://www.xblock.com/download/xclean_micro.exe

Robert
I dont see any sign of IBIS or Huntbar in the log...Have you disabled anything with msconfig?
If so...please recheck what you have disabled and post new logThanks.
I never give up!

here it is in all it's glory.
Logfile of HijackThis v1.97.7
Scan saved at 8:45:01 PM, on 3/25/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
D:\Program Files\Alwil Software\Avast4\ashServ.exe
D:\WINDOWS\System32\nvsvc32.exe
D:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\ZONELABS\vsmon.exe
D:\WINDOWS\wanmpsvc.exe
D:\WINDOWS\Explorer.exe
D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\Winamp\Winampa.exe
D:\Program Files\Common Files\Real\Update_OB\realsched.exe
D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
D:\WINDOWS\SM1BG.exe
D:\Program Files\Common Files\Real\Update_OB\realevent.exe
D:\Program Files\QuickTime\qttask.exe
D:\Program Files\Common Files\Real\Update_OB\realevent.exe
D:\Program Files\GIANT Company Software\Spam Inspector\siMailProxyServer.exe
D:\Program Files\GIANT Company Software\Spam Inspector\siSpamFilterEngine.exe
D:\Program Files\Microsoft IntelliPoint\point32.exe
D:\Program Files\Ahead\InCD\InCD.exe
D:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
D:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.exe
D:\WINDOWS\System32\RUNDLL32.exe
D:\Program Files\Ares\Ares.exe
D:\Corel\Suite8\Programs\DAD8.exe
D:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
D:\Program Files\OpenOffice.org1.1.0\program\soffice.exe
D:\Documents and Settings\Robert Johnson\My Documents\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://msn.com/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - D:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Hotmail Spam Filter - {58A83E4F-477A-4A3F-BF9B-B65BC2BD5598} - D:\Program Files\GIANT Company Software\Spam Inspector\siClientUIHotmail.dll
O4 - HKLM\..\Run: [Zone Labs Client] D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.exe D:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [siService.exe] "D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe"
O4 - HKLM\..\Run: [avast!] D:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [winnet] D:\PROGRA~1\COMMON~2\ADDRES~1\winnet.exe
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\Winampa.exe"
O4 - HKLM\..\Run: [WebInstall2] D:\Documents and Settings\Linda\WebInstall.exe /R
O4 - HKLM\..\Run: [updmgr] D:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [updater] D:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [Trickler] "d:\windows\temp\adware\fsg_4104.exe"
O4 - HKLM\..\Run: [TkBellExe] "D:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\j2re1.4.2_01\bin\jusched.exe
O4 - HKLM\..\Run: [SQInstaller] D:\Documents and Settings\Linda\igetnet_3845_3645.exeSQInstaller.exe
O4 - HKLM\..\Run: [SM1BG] D:\WINDOWS\SM1BG.exe
O4 - HKLM\..\Run: [SiS KHooker] D:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [QuickTime Task] "D:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [PGStub.exe] D:\Documents and Settings\Linda\dp-b23011805.exe
O4 - HKLM\..\Run: [P2P Networking] D:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART
O4 - HKLM\..\Run: [Openwares LiveUpdate] C:\Program Files\LiveUpdate\LiveUpdate.exe
O4 - HKLM\..\Run: [NeroCheck] D:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [LimeShop] javaw -cp "D:\Program Files\LimeShop\System\Code" Main lp: "D:\Program Files\LimeShop"
O4 - HKLM\..\Run: [iTunesHelper] D:\Program Files\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [IntelliPoint] "D:\Program Files\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [InCD] D:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [GroksterSupport] javaw -cp "D:\Program Files\GroksterSupport\System\Code" Main lp: "D:\Program Files\GroksterSupport"
O4 - HKLM\..\Run: [DM_Server] D:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [CMESys] "D:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [AutoLoaderAproposClient] "D:\Documents and Settings\Linda\sys_ai_client_loader.exe" /HideUninstall /PC="AM.NICT" /ShowLegalNote=nonbranded
O4 - HKLM\..\Run: [AST] D:\WINDOWS\AST
O4 - HKLM\..\Run: [ashMaiSv] D:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
O4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "D:\PROGRA~1\PANICW~1\POP-UP~1\PSFREE.exe"
O4 - HKCU\..\Run: [NvMediaCenter] RUNDLL32.exe D:\WINDOWS\System32\NVMCTRAY.DLL,NvTaskbarInit
O4 - HKCU\..\Run: [Yahoo! Pager] D:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - HKCU\..\Run: [MSMSGS] "D:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ares] "D:\Program Files\Ares\Ares.exe" -h
O4 - HKCU\..\Run: [AIM] D:\PROGRA~1\AIM\aim.exe -cnetwait.odl
O4 - Startup: OpenOffice.org 1.1.0.lnk = D:\Program Files\OpenOffice.org1.1.0\program\quickstart.exe
O4 - Global Startup: GStartup.lnk = D:\Program Files\Common Files\GMT\GMT.exe
O4 - Global Startup: Corel Desktop Application Director 8.LNK = D:\Corel\Suite8\Programs\DAD8.exe
O4 - Global Startup: America Online 9.0 Tray Icon.lnk = D:\Program Files\America Online 9.0\aoltray.exe
O8 - Extra context menu item: &Google Search - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://D:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://D:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://D:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://D:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O12 - Plugin for .bcf: D:\Program Files\Internet Explorer\Plugins\NPBelv32.dll
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {16095503-786F-4097-AED6-5D567A26D760} (SiS_OCX Control) - http://www.sis.com/support/chipdetect/SiSAutodetectNT.cab
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

Hi
Sorry I took so long...busy as heck.
First put Hijack in it's own folder...it will make a mess of your documents folder because it makes backups
in case restore is needed.By doing the following...your grokster may not function any more. You can get kazaa lite at oldversion.com. (clean, no spyware)
just dont install the "kazaa super trick" it will mess up your hosts file; there are better programs for working with the hosts file than kazaa.Altnet points manager can be removed through add/remove programs in control panel, it will also remove p2p networking.
Also remove limeshop, comet cursor and GroksterSupport from add/remove prog.Start hijackthis again while offline and check the following to fix: (some may not be present)
O4 - HKLM\..\Run: [WebInstall2] D:\Documents and Settings\Linda\WebInstall.exe /R
O4 - HKLM\..\Run: [updmgr] D:\Program Files\Common files\updmgr\updmgr.exe
O4 - HKLM\..\Run: [updater] D:\Program Files\Common files\updater\wupdater.exe
O4 - HKLM\..\Run: [Trickler] "d:\windows\temp\adware\fsg_4104.exe"O4 - HKLM\..\Run: [SQInstaller] D:\Documents and Settings\Linda\igetnet_3845_3645.exeSQInstaller.exe
O4 - HKLM\..\Run: [PGStub.exe] D:\Documents and Settings\Linda\dp-b23011805.exe
O4 - HKLM\..\Run: [P2P Networking] D:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTARTO4 - HKLM\..\Run: [LimeShop] javaw -cp "D:\Program Files\LimeShop\System\Code" Main lp: "D:\Program Files\LimeShop"
O4 - HKLM\..\Run: [GroksterSupport] javaw -cp "D:\Program Files\GroksterSupport\System\Code" Main lp: "D:\Program Files\GroksterSupport"
O4 - HKLM\..\Run: [DM_Server] D:\PROGRA~1\COMETS~1\DM\bin\dmserver.exe /onreboot
O4 - HKLM\..\Run: [CMESys] "D:\Program Files\Common Files\CMEII\CMESys.exe"
O4 - HKLM\..\Run: [AutoLoaderAproposClient] "D:\Documents and Settings\Linda\sys_ai_client_loader.exe" /HideUninstall /PC="AM.NICT" /ShowLegalNote=nonbranded
O4 - HKLM\..\Run: [AST] D:\WINDOWS\ASTO4 - HKLM\..\Run: [AltnetPointsManager] c:\program files\altnet\points manager\points manager.exe -s
O4 - HKCU\..\Run: [ares] "D:\Program Files\Ares\Ares.exe" -h
O4 - Global Startup: GStartup.lnk = D:\Program Files\Common Files\GMT\GMT.exe
Reboot and delete the following: (some may not be present)
D:\Documents and settings\Linda\Webinstall.exe <-file
D:\Documents and settings\Linda\SQinstaller.exe <-file
D:\Documents and settings\Linda\igetnet_3845.exe <-file
D:\documents and settings\Linda\dp-b23011805.exe <-file
D:\documents and settings\Linda\sys_ai_client_loader.exe <-fileD:\windows\AST.exe <-file
D:\windows\Temp\adware <-folder
D:\windows\system32\p2p networking<-folder
D:\program files\common files\updmgr<-folder
D;\program files\common files\updater<-folder
D:\program files\common files\CMEII <-folder
D:\program files\common files\GMT <-folderD:\program files\ARES <-folder
D:\program files\Limeshop <-folder
D:\program files\GroksterSupport<- folder
D:\program files\Commet Cursor <-folderC:\program files\altnet <-folder...Do you have a program files directory on C:\? it is listed as installed on c:\ but all else is on D:\
You also have common name infection..
Instructions here to remove:
http://www.commonname.com/english/ug/toolbar/default.asp?idx=10#4
You will want to empty out tempory internet files again...by turning on these programs to see what was going on you likely picked up some
updater files for this crapware.Once done reboot once more to remove remanents from memory.
You might want to remove grokster and go with winmx or k-lite...your grokster will just keep on re-infecting you if you keep any of the adware required to make it work.
Post a fresh hijack log for me to check.
I never give up!

Blender,
I am not sure I am understanding. First let me say that all of the stuff you saw is in my msconfig utility. I just put a check in them so that you could see what was there. There are only five things I start auto and they are:
Zonealarm - D:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe
Avast - D:\PROGRA~1\ALWILS~1\Avast4\ashmaisv.exe
Panicware - D:\Program Files\Panicware\Pop-Up Stopper Free Edition\PSFree.exe
Spam Inspector - D:\Program Files\GIANT Company Software\Spam Inspector\siService.exe
Rundll.32
I have already cleaned or uninstalled everything that was on the listaltnet,kazaa,grokster are not running apps. they are just remenet in msconfi along with some other misc. My HijackThis Log is the same as the firt one I posted. I hope I have given you what you need. Once again thanks for your help!

Robert
Ok ...
If you unchecked all those entries before uninstalling those programs...those registry values still remain...just in a different spot. The uninstallers will look in the HKLM\...\run, run services, HKCU\...\run, run services keys to uninstall the program.
Those items you disabled in msconfig go to either of these places in registry:HKEY_LOCAL_MACHINE\software\microsoft\windows\current version\run-, run services-
HKEY_CURRENT_USER\software\microsoft\windows\current version\run-, run services-
HKEY_LOCAL_MACHINE\software\shared tools\MSConfig\startupfolder
HKEY_LOCAL_MACHINE\software\shared tools\MSConfig\startupregBy checking those places and removing the items for disabled programs you have uninstalled....you will clean up your msconfig entries.
Since you rechecked them...now they are where hijack can see them.
Hijack does not scan disabled msconfig items.Here's a couple links to check out...you may have been there..
http://www.pestpatrol.com/PestInfo/i/ibis_toolbar.asp
This one likely is best bet:
http://www.lavahelp.com/articles/v6/04/02/0302.html
__________________________________I never give up!

Blender,
Thanks for all your help. My computer is running at it's best now. I have run ad-aware and spy bot . I still get the IBIS Toolbar but everything else is working fine. I do have one last question for you. Can I change my file system from FAT32 to NTFS without reinstalling XP?

Robert
Apparently you can...I have never tried it tho...always installed NTFS.
http://aroundcny.com/technofile/texts/tec042102.html
http://support.microsoft.com/default.aspx?scid=kb;en-us;307881
As explained on both pages....if you don't like the change you can't switch back...
Good luck
___________________________________I never give up!

Blender,
I am having the same nightmare trying to remove the stupid "Btiein" registry key. I am not turning up any toolbars when i use my various spyware programs, but i have used about 6 different programs and none of them can remove the damn regiistry key. I have tried removing it manually and it wont allow me to, i have even tried to unregister the key then delete and still no luck.
I have had the majority of my startup programs disabled withe the MSconfig utility for several montsh now because it seems to make my computer run faster.
If i re-enable all of my startup programs and posted a "Hijack THis" report like robert did, could you help me out like you did with him?
Many thanks,
-Kyle

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |