Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee Flying bat in a marquee

Tuesday, March 3, 2009

Quick Launch settings are not saved; Search Assistant Toolbar in Taskbar

These symptoms are caused by this Malware. This page discusses the preliminary steps required to remove this Desk band object, before running spyware removal tools.
Solution I :- Removing the Search Assistant Toolbar from the Taskbar
Click Start, Run and type this command exactly as given and press Enter:
regsvr32 /u "%Systemroot%\System32\omniband.dll"
This uninstalls the Search Assistant Desk Band settings in the registry. Next, rename the file omniband.dll to old_omniband.dll and reboot Windows.
Note:- The module name was determined by this program named deskbands.exe.This tiny utility which I wrote, enumerates all the Desk Band objects from the registry and just lists them with the corresponding DLL names.
Phase II:- Fixing a registry entry which causes the Quick Launch issue (not retaining the settings)
Click Start, Run and type REGEDIT. Navigate to:
HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ WindowsNT \ CurrentVersion \ Winlogon
In the right-pane, change the value of Userinit to "C:\WINDOWS\system32\userinit.exe,"
Type the above value exactly as given, including the comma - exclude the quotes. Also, change the path to userinit.exe appropriately if Windows is installed in a different drive.
Close Registry Editor and restart Windows. The Quick Launch settings should be retained now.
Phase III:- Removing the Malware from the system

No comments:

Post a Comment