Twain tech BHO problem

L

Lon

I am using Windows XP Pro with IE6.0. I ran Yahoo anti-
spy program and it said I had Twain tech BHO on my
computer. I hope I am in right newsgroup. Steps I have
taken so far:
1. Ran scan and did not remove it so I could find it.
2. Said twain tech was located in
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer\activex compatability {000020dd-c72e-4113-af77-
dd56626c6c42}
3. went to add/remove programs - no twain tech found
4. went to start/run/typed regsvr32 /u c:windows
waintec.dll - no file found
5. went to my computer/tools/folder options/view
tab/selected hidden files and folders to show hidden
files and folder and it was checked.
6. still in my computer/documents and settings/default
user/local settings/temp/temp folder and folder was empty.
7. last went to start/run/type regedit/enter and went to
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer/activex compatibility (000020dd-c72e-4113-af77-
dd56626c6c42} and found the 000020dd-c72e under activex
compatibility.
8. On the right screen are listed two items: (Name)
Default (Type) REG SZ (Data) Value not set
and (Name) Compatibility flags (type) REG_DWORD (Data)
0x00000400 (1024)
8. Exited regedit and did nothing.
My question is this: Are either of the two items I found
the twain tech BHO and if so which one and can it be
deleted? If neither are the twain tech then I don't know
what else to do to find it and get rid of it. Any help
or advice?
 
A

Alan

-----Original Message-----
I am using Windows XP Pro with IE6.0. I ran Yahoo anti-
spy program and it said I had Twain tech BHO on my
computer. I hope I am in right newsgroup. Steps I have
taken so far:
1. Ran scan and did not remove it so I could find it.
2. Said twain tech was located in
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer\activex compatability {000020dd-c72e-4113-af77-
dd56626c6c42}
3. went to add/remove programs - no twain tech found
4. went to start/run/typed regsvr32 /u c:windows
waintec.dll - no file found
5. went to my computer/tools/folder options/view
tab/selected hidden files and folders to show hidden
files and folder and it was checked.
6. still in my computer/documents and settings/default
user/local settings/temp/temp folder and folder was empty.
7. last went to start/run/type regedit/enter and went to
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer/activex compatibility (000020dd-c72e-4113-af77-
dd56626c6c42} and found the 000020dd-c72e under activex
compatibility.
8. On the right screen are listed two items: (Name)
Default (Type) REG SZ (Data) Value not set
and (Name) Compatibility flags (type) REG_DWORD (Data)
0x00000400 (1024)
8. Exited regedit and did nothing.
My question is this: Are either of the two items I found
the twain tech BHO and if so which one and can it be
deleted? If neither are the twain tech then I don't know
what else to do to find it and get rid of it. Any help
or advice?
.
A Yahoo Anti Spy scan showed Twain-Tech on my computer
too. I went to Protonics.com for advise on removing it.The
instructions for removing it are as follows Thank you for
visiting protonic.com! My name is Jake and I will be
assisting you with your question.

Please follow the instructions below if you would like to
remove Twaintech manually. Please notice that you must
follow the instructions very carefully and delete
everything that is mentioned. In most cases the removal
will fail if one single item is not deleted. If Twaintech
remains on your system after stepping through the removal
instructions, please double-check by stepping through them
again.

Start the registry editor. This is done by clicking Start
then Run. (The Run dialog will appear.) Type regedit and
click OK. (The registry editor will open.)

Delete 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Classes \ CLSID \
{000020DD-C72E-4113-AF77-DD56626C6C42}', if it exists.

Delete 'HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \
Windows \ CurrentVersion \ Explorer \ Browser Helper
Objects \ {000020DD-C72E-4113-AF77-DD56626C6C42}', if it
exists.

Exit the registry editor.

Restart your computer.

Start Windows Explorer and delete:
%WinDir%\twaintec.dll

Note: %WinDir% is a variable (?). By default, this is
C:\Windows (Windows 95/98/Me/XP) or C:\WINNT (Windows
NT/2000).

Start Microsoft Internet Explorer.

In Internet Explorer, click Tools -> Internet Options.
Click the Programs tab -> Reset Web Settings.
 
L

Lon

I already have spybot S&D installed as well as ad-aware
se, spywareblaster, spywareguard and spyblocker from
Webroot. None of the others found this Twain tech except
for Yahoo anti-spy. I need to know how I can get rid of
it. Any help or advice?
 
G

Guest

Lon said:
I am using Windows XP Pro with IE6.0. I ran Yahoo anti-
spy program and it said I had Twain tech BHO on my
computer. I hope I am in right newsgroup. Steps I have
taken so far:
1. Ran scan and did not remove it so I could find it.
2. Said twain tech was located in
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer\activex compatability {000020dd-c72e-4113-af77-
dd56626c6c42}
3. went to add/remove programs - no twain tech found
4. went to start/run/typed regsvr32 /u c:windows
waintec.dll - no file found
5. went to my computer/tools/folder options/view
tab/selected hidden files and folders to show hidden
files and folder and it was checked.
6. still in my computer/documents and settings/default
user/local settings/temp/temp folder and folder was empty.
7. last went to start/run/type regedit/enter and went to
HKEY_LOCAL_MACHINE\software\microsoft\internet
explorer/activex compatibility (000020dd-c72e-4113-af77-
dd56626c6c42} and found the 000020dd-c72e under activex
compatibility.
8. On the right screen are listed two items: (Name)
Default (Type) REG SZ (Data) Value not set
and (Name) Compatibility flags (type) REG_DWORD (Data)
0x00000400 (1024)
8. Exited regedit and did nothing.
My question is this: Are either of the two items I found
the twain tech BHO and if so which one and can it be
deleted? If neither are the twain tech then I don't know
what else to do to find it and get rid of it. Any help
or advice?

It is a browser helper object (BHO) use BHODemon to disable it.
Some anti-spyware tools do make false positives,Never tried Yahoo so I
don't know how good it is.You say that you have Spybot S&D, in the advance
mode it will show you all BHO's,have you tried looking there to see what it
says?.
You can find BHODemon at the link below.

Sometimes,when you remove malware it will stop your TCP/IP
stack from working (Internet connection).
Winsock or LSP-fix will correct the problem,Download first.
Note to anyone using NOD32 Anti-Virus software,Do Not delete the
"imon.dll" this fix reports,That is your e/mail scanning engine.

LSP-fix- http://www.cexx.org/lspfix.htm
Spybot S&D - http://www.safer-networking.org/en/index.html
CWS Smart Killer- http://www.safer-networking.org/minifiles.html

About Buster- http://www.spychecker.com/program/aboutbuster.html
Ad-Aware SE - http://www.lavasoftusa.com/software/adaware/
CWShredder - http://www.majorgeeks.com/download4086.html
Hijack this - http://www.majorgeeks.com/download3155.html
SpywareBlaster - http://www.javacoolsoftware.com/spywareblaster.html
SpywareGuard - http://www.javacoolsoftware.com/spywareguard.html
WinPatrol - http://winpatrol.com
BHODemon - http://pcworld.com/downloads/file_download.asp?fid=23611&fileidx=1
Bazooka -http://www.kephyr.com/spywarescanner/index.html
asquared2 "Trojan Remover" - http://www.emsisoft.com/en/
Sygate Firewall- http://smb.sygate.com/download_buy.htm
NOD32Anti-Virus Free 30 day trial
http://nod32.com/download/trial.htm

A link for free online virus and trojan scanners.
http://virusall.com/downscan.html

A listing of BHO's
http://www.spywaredata.com/bho.php?current_page=0

To see if that freeware program you are about to inststall
is infested with spyware check it out first at this link.
http://www.spychecker.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top