View Single Post
  #5  
Old 10-15-2004, 08:59 AM
Brad Brad is offline
 
Join Date: Nov 2001
Posts: 4,765
Благодарил(а): 0 раз(а)
Поблагодарили: 0 раз(а) в 0 сообщениях
Default

Quote:
Originally Posted by Michael Morris
My Google-Fu brought this up among others...

http://www.pestpatrol.com/pest_info/.../clientman.asp
Good page, here is the manual remove instructions from it altho I recomend you read the entire page anyway.

Quote:
If there is an entry for mscman in the Control Panel's Add/Remove Programs list, use it to remove ClientMan.

If that fails, to remove ClientMan, do the following:

1. Right click here, and from the context menu, choose "Save Target As.." Save the file to your hard drive anywhere as remcli.exe.
2. Close all copies of Internet Explorer and other applications.
3. Find remcli.exe (the file you just saved), and doubleclick on it to run it. (If you saved it as remcli.ex, it will not run. Rename it to remcli.exe and then run it.)
4. Immediately reboot your PC.
5. Once you have rebooted, immediately use Windows Explorer or look under "My Computer" and find C:\Program Files\ClientMan\
6. Delete the directory C:\Program Files\ClientMan\.

If that fails, you will learn that the developers of ClientMan have gone out of their way to make automated removal difficult. In the directory \program files\clientman\ or \program files\clientman\run\ you will have some randomly named dlls, such as browserhelperX.dll, trackurlX.dll, or searchrepx.dll, where X is a random eight-digit hexadecimal value.

You will need to unregister each of these dlls before removing them, invoking

regsvr32 /u x

where x is the name of each dll you have found.

Remove these registry entries if found:

HKEY_CLASSES_ROOT\clsid\{00a0a40c-f432-4c59-ba11-b25d142c7ab7}
HKEY_CLASSES_ROOT\clsid\{166348f1-2c41-4c9f-86bb-eb2b8ade030c}
HKEY_CLASSES_ROOT\clsid\{25f7fa20-3fc3-11d7-b487-00d05990014c}
HKEY_CLASSES_ROOT\clsid\{96be1d9a-9e54-4344-a27a-37c088d64fb4}
HKEY_CLASSES_ROOT\clsid\{a097840a-61f8-4b89-8693-f68f641cc838}
HKEY_CLASSES_ROOT\clsid\{cc916b4b-be44-4026-a19d-8c74bbd23361}
HKEY_CLASSES_ROOT\clsid\{f76fda04-87fa-4717-91f6-4bb5be9fd2bb}
HKEY_CLASSES_ROOT\clsid\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb}
HKEY_CURRENT_USER\software\climan
HKEY_CURRENT_USER\software\ipend
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\runclientman1
HKEY_LOCAL_MACHINE\bjects\{00a0a40c-f432-4c59-ba11-b25d142c7ab7}
HKEY_LOCAL_MACHINE\bjects\{166348f1-2c41-4c9f-86bb-eb2b8ade030c}
HKEY_LOCAL_MACHINE\bjects\{25f7fa20-3fc3-11d7-b487-00d05990014c}
HKEY_LOCAL_MACHINE\bjects\{96be1d9a-9e54-4344-a27a-37c088d64fb4}
HKEY_LOCAL_MACHINE\bjects\{a097840a-61f8-4b89-8693-f68f641cc838}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runclientman
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\runclientman1

Stop Running Processes:

Kill these running processes with Task Manager:
ause3-decoded.exe
msdm.exe
msgdmf.exe
msmm.exe
msvc32.exe
programfilesdir+\clientman\run\ause3.exe
programfilesdir+\clientman\run\cmupd.exe
programfilesdir+\clientman\run\fixtitle.exe
programfilesdir+\clientman\run\getbuys.exe
programfilesdir+\clientman\run\infoctl.exe
programfilesdir+\clientman\run\msckin.exe
programfilesdir+\clientman\run\mscman.exe
programfilesdir+\clientman\run\msurlcli1.exe
programfilesdir+\clientman\run\uinfo4.exe
programfilesdir+\clientman\run\uinfo7.exe
svc.exe
systemroot+\system32\msawindows.exe
systemroot+\system32\msccof.exe
uinfo4-decoded.exe
uinfo5.exe
uinfo7-decoded.exe
unpacked-svc.exe

Remove AutoRun Reference:

Go To the key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run.
If you find the value HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run\clientman, delete it and reboot the machine immediately.
If you find the value HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run\clientman1, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\clientman, delete it and reboot the machine immediately.
If you find the value HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\clientman1, delete it and reboot the machine immediately.

Unregister DLLs:

Unregister these DLLs with Regsvr32, then reboot:
browserhelper.dll
browserhelper-decoded.dll
browserhelpere90a5c6.dll
c:\windows\system32\barbho.dll
metahelp60741389.dll
msdpdm.dll
profilepath+\applic~1\iestcrmfrood.dll
profilepath+\locals~1\temp\mskhhe.dll
profilepath+\locals~1\temp\mskpkc.dll
programfilesdir+\clientman\run\2in1fd04f73f.dll
programfilesdir+\clientman\run\browserhelper2db3ad 7a.dll
programfilesdir+\clientman\run\dnsrepa9c22ca5.dll
programfilesdir+\clientman\run\gstylebhob76a4c84.d ll
programfilesdir+\clientman\run\msvrfy804449fd.dll
programfilesdir+\clientman\run\searchrep8181a0e2.d ll
programfilesdir+\clientman\run\trackurl79ad003c.dl l
programfilesdir+\clientman\run\trackurld66084b4.dl l
programfilesdir+\clientman\run\urlcli25e74486.dll
programfilesdir+\clientman\run\urlclia30956de.dll
searchrep6706569a.dll
systemroot+\downloaded program files\disable.dll
systemroot+\downloaded program files\disable1.dll
systemroot+\mscdka.dll
systemroot+\mseclk.dll
systemroot+\mseffm.dll
systemroot+\msncjk.dll
systemroot+\msobfl.dll
systemroot+\system\disable.dll
systemroot+\system\disable1.dll
systemroot+\system\mscdka.dll
systemroot+\system\mseffm.dll
systemroot+\system\msobfl.dll
systemroot+\system32\disable.dll
systemroot+\system32\disable1.dll
systemroot+\system32\mscdka.dll
systemroot+\system32\msdaim.dll
systemroot+\system32\msdlgk.dll
systemroot+\system32\mseclk.dll
systemroot+\system32\msedah.dll
systemroot+\system32\mseffm.dll
systemroot+\system32\msfaol.dll
systemroot+\system32\msibkd.dll
systemroot+\system32\msjfbl.dll
systemroot+\system32\mskceo.dll
systemroot+\system32\mskhhe.dll
systemroot+\system32\mskpkc.dll
systemroot+\system32\msncjk.dll
systemroot+\system32\msnkmi.dll
systemroot+\system32\msobfl.dll
taggerbhoe884facd.dll
trackurl5f9d991e.dll
trackurl7f663945.dll
trackurl7f663945-decoded.dll
unpacked-browserhelper.dll

Clean Registry:

Remove these registry items (if present) with RegEdit:

HKEY_CLASSES_ROOT\appid\{026e4b83-1bf7-41cb-8233-4af35341bc69}
HKEY_CLASSES_ROOT\clsid\{00a0a40c-f432-4c59-ba11-b25d142c7ab7}
HKEY_CLASSES_ROOT\clsid\{0982868c-47f0-4efb-a664-c7b0b1015808}
HKEY_CLASSES_ROOT\clsid\{0ba1c6eb-d062-4e37-9db5-b07743276324}
HKEY_CLASSES_ROOT\clsid\{166348f1-2c41-4c9f-86bb-eb2b8ade030c}
HKEY_CLASSES_ROOT\clsid\{25f7fa20-3fc3-11d7-b487-00d05990014c}
HKEY_CLASSES_ROOT\clsid\{447160cd-ecf5-4ea2-8a8a-1f70ca363f85}
HKEY_CLASSES_ROOT\clsid\{5ed50735-b0d9-47c6-9774-02dd8e6fe053}
HKEY_CLASSES_ROOT\clsid\{94927a13-4aaa-476a-989d-392456427688}
HKEY_CLASSES_ROOT\clsid\{96be1d9a-9e54-4344-a27a-37c088d64fb4}
HKEY_CLASSES_ROOT\clsid\{a097840a-61f8-4b89-8693-f68f641cc838}
HKEY_CLASSES_ROOT\clsid\{ba77911b-a393-4a2e-b5b5-5b8ed17d7b43}
HKEY_CLASSES_ROOT\clsid\{cc916b4b-be44-4026-a19d-8c74bbd23361}
HKEY_CLASSES_ROOT\clsid\{f76fda04-87fa-4717-91f6-4bb5be9fd2bb}
HKEY_CLASSES_ROOT\clsid\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb}
HKEY_CLASSES_ROOT\dnsrep.dnsrepobj
HKEY_CLASSES_ROOT\dnsrep.dnsrepobj.1
HKEY_CLASSES_ROOT\interface\{a7370377-e217-4467-8448-9845270cd4a3}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{00a0a40c-f432-4c59-ba11-b25d142c7ab7}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{0982868c-47f0-4efb-a664-c7b0b1015808}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{0ba1c6eb-d062-4e37-9db5-b07743276324}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{166348f1-2c41-4c9f-86bb-eb2b8ade030c}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{25f7fa20-3fc3-11d7-b487-00d05990014c}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{447160cd-ecf5-4ea2-8a8a-1f70ca363f85}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{5ed50735-b0d9-47c6-9774-02dd8e6fe053}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{94927a13-4aaa-476a-989d-392456427688}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{96be1d9a-9e54-4344-a27a-37c088d64fb4}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{a097840a-61f8-4b89-8693-f68f641cc838}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{ba77911b-a393-4a2e-b5b5-5b8ed17d7b43}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{cc916b4b-be44-4026-a19d-8c74bbd23361}
HKEY_CLASSES_ROOT\software\microsoft\windows\curre ntversion\explorer\browser helper objects\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb}
HKEY_CLASSES_ROOT\typelib\{a1a986e7-7674-4d8b-8081-e422fdb8480b}
HKEY_CLASSES_ROOT\urlcli.urlcliobj
HKEY_CLASSES_ROOT\urlcli.urlcliobj.1
HKEY_CURRENT_USER\software\climan
HKEY_CURRENT_USER\software\ipend
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run\clientman
HKEY_CURRENT_USER\software\microsoft\windows\curre ntversion\run\clientman1
HKEY_LOCAL_MACHINE\clsid\{00a0a40c-f432-4c59-ba11-b25d142c7ab7}
HKEY_LOCAL_MACHINE\clsid\{0982868c-47f0-4efb-a664-c7b0b1015808}
HKEY_LOCAL_MACHINE\clsid\{0ba1c6eb-d062-4e37-9db5-b07743276324}
HKEY_LOCAL_MACHINE\clsid\{166348f1-2c41-4c9f-86bb-eb2b8ade030c}
HKEY_LOCAL_MACHINE\clsid\{25f7fa20-3fc3-11d7-b487-00d05990014c}
HKEY_LOCAL_MACHINE\clsid\{447160cd-ecf5-4ea2-8a8a-1f70ca363f85}
HKEY_LOCAL_MACHINE\clsid\{5ed50735-b0d9-47c6-9774-02dd8e6fe053}
HKEY_LOCAL_MACHINE\clsid\{94927a13-4aaa-476a-989d-392456427688}
HKEY_LOCAL_MACHINE\clsid\{96be1d9a-9e54-4344-a27a-37c088d64fb4}
HKEY_LOCAL_MACHINE\clsid\{a097840a-61f8-4b89-8693-f68f641cc838}
HKEY_LOCAL_MACHINE\clsid\{ba77911b-a393-4a2e-b5b5-5b8ed17d7b43}
HKEY_LOCAL_MACHINE\clsid\{cc916b4b-be44-4026-a19d-8c74bbd23361}
HKEY_LOCAL_MACHINE\clsid\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb}
HKEY_LOCAL_MACHINE\software\classes\clsid\{00a0a40 c-f432-4c59-ba11-b25d142c7ab7}
HKEY_LOCAL_MACHINE\software\classes\clsid\{0982868 c-47f0-4efb-a664-c7b0b1015808}
HKEY_LOCAL_MACHINE\software\classes\clsid\{0ba1c6e b-d062-4e37-9db5-b07743276324}
HKEY_LOCAL_MACHINE\software\classes\clsid\{166348f 1-2c41-4c9f-86bb-eb2b8ade030c}
HKEY_LOCAL_MACHINE\software\classes\clsid\{25f7fa2 0-3fc3-11d7-b487-00d05990014c}
HKEY_LOCAL_MACHINE\software\classes\clsid\{447160c d-ecf5-4ea2-8a8a-1f70ca363f85}
HKEY_LOCAL_MACHINE\software\classes\clsid\{5ed5073 5-b0d9-47c6-9774-02dd8e6fe053}
HKEY_LOCAL_MACHINE\software\classes\clsid\{94927a1 3-4aaa-476a-989d-392456427688}
HKEY_LOCAL_MACHINE\software\classes\clsid\{96be1d9 a-9e54-4344-a27a-37c088d64fb4}
HKEY_LOCAL_MACHINE\software\classes\clsid\{a097840 a-61f8-4b89-8693-f68f641cc838}
HKEY_LOCAL_MACHINE\software\classes\clsid\{ba77911 b-a393-4a2e-b5b5-5b8ed17d7b43}
HKEY_LOCAL_MACHINE\software\classes\clsid\{cc916b4 b-be44-4026-a19d-8c74bbd23361}
HKEY_LOCAL_MACHINE\software\classes\clsid\{fcaddc1 4-bd46-408a-9842-cdbe1c6d37eb}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{00a0a40c-f432-4c59-ba11-b25d142c7ab7}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{0982868c-47f0-4efb-a664-c7b0b1015808}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{0ba1c6eb-d062-4e37-9db5-b07743276324}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{166348f1-2c41-4c9f-86bb-eb2b8ade030c}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{25f7fa20-3fc3-11d7-b487-00d05990014c}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{447160cd-ecf5-4ea2-8a8a-1f70ca363f85}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{5ed50735-b0d9-47c6-9774-02dd8e6fe053}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{94927a13-4aaa-476a-989d-392456427688}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{96be1d9a-9e54-4344-a27a-37c088d64fb4}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{a097840a-61f8-4b89-8693-f68f641cc838}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{ba77911b-a393-4a2e-b5b5-5b8ed17d7b43}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{cc916b4b-be44-4026-a19d-8c74bbd23361}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\explorer\browser helper objects\{fcaddc14-bd46-408a-9842-cdbe1c6d37eb}
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\clientman
HKEY_LOCAL_MACHINE\software\microsoft\windows\curr entversion\run\clientman1

Remove Files:

Remove these files (if present) with Windows Explorer:
app.dat
ause3-decoded.exe
browserhelper.dll
browserhelper-decoded.dll
browserhelpere90a5c6.dll
c:\windows\system32\barbho.dll
clickthru.log
client.cfg
firstrun.log
getall.php
ipend.log
metahelp60741389.dll
msckin.dat
mscman.dat
msdm.exe
msdpdm.dll
msgdmf.exe
msmm.exe
msvc32.exe
mungedpage.html
popup.log
profilepath+\applic~1\iestcrmfrood.dll
profilepath+\locals~1\temp\mskhhe.dll
profilepath+\locals~1\temp\mskpkc.dll
programfilesdir+\clientman\run\2in1fd04f73f.dll
programfilesdir+\clientman\run\ause3.exe
programfilesdir+\clientman\run\browserhelper2db3ad 7a.dll
programfilesdir+\clientman\run\cmupd.exe
programfilesdir+\clientman\run\dnsrepa9c22ca5.dll
programfilesdir+\clientman\run\fixtitle.exe
programfilesdir+\clientman\run\getbuys.exe
programfilesdir+\clientman\run\gstylebhob76a4c84.d ll
programfilesdir+\clientman\run\infoctl.exe
programfilesdir+\clientman\run\msckin.exe
programfilesdir+\clientman\run\mscman.exe
programfilesdir+\clientman\run\msurlcli1.exe
programfilesdir+\clientman\run\msvrfy804449fd.dll
programfilesdir+\clientman\run\searchrep8181a0e2.d ll
programfilesdir+\clientman\run\trackurl79ad003c.dl l
programfilesdir+\clientman\run\trackurld66084b4.dl l
programfilesdir+\clientman\run\uinfo4.exe
programfilesdir+\clientman\run\uinfo7.exe
programfilesdir+\clientman\run\urlcli25e74486.dll
programfilesdir+\clientman\run\urlclia30956de.dll
searchhijack.html
searchrep6706569a.dll
svc.exe
systemroot+\cachelut.dat
systemroot+\downloaded program files\disable.dll
systemroot+\downloaded program files\disable1.dll
systemroot+\mscdka.dll
systemroot+\mseclk.dll
systemroot+\mseffm.dll
systemroot+\msncjk.dll
systemroot+\msobfl.dll
systemroot+\system\disable.dll
systemroot+\system\disable1.dll
systemroot+\system\mscdka.dll
systemroot+\system\mseffm.dll
systemroot+\system\msobfl.dll
systemroot+\system32\disable.dll
systemroot+\system32\disable1.dll
systemroot+\system32\msawindows.exe
systemroot+\system32\msccof.exe
systemroot+\system32\mscdka.dll
systemroot+\system32\msdaim.dll
systemroot+\system32\msdlgk.dll
systemroot+\system32\mseclk.dll
systemroot+\system32\msedah.dll
systemroot+\system32\mseffm.dll
systemroot+\system32\msfaol.dll
systemroot+\system32\msibkd.dll
systemroot+\system32\msjfbl.dll
systemroot+\system32\mskceo.dll
systemroot+\system32\mskhhe.dll
systemroot+\system32\mskpkc.dll
systemroot+\system32\msncjk.dll
systemroot+\system32\msnkmi.dll
systemroot+\system32\msobfl.dll
systemroot+\words.lst
taggerbhoe884facd.dll
trackurl5f9d991e.dll
trackurl7f663945.dll
trackurl7f663945-decoded.dll
uinfo4-decoded.exe
uinfo5.exe
uinfo7-decoded.exe
uninstall.uni
unpacked-browserhelper.dll
unpacked-svc.exe
whois-om.html

Remove Directories:

Remove these directories (if present) with Windows Explorer:
c:\program files\clientman\run
programfilesdir+\clientman
Reply With Quote
 
X vBulletin 3.8.12 by vBS Debug Information
  • Page Generation 0.01355 seconds
  • Memory Usage 1,864KB
  • Queries Executed 11 (?)
More Information
Template Usage:
  • (1)SHOWTHREAD_SHOWPOST
  • (1)ad_footer_end
  • (1)ad_footer_start
  • (1)ad_header_end
  • (1)ad_header_logo
  • (1)ad_navbar_below
  • (2)bbcode_quote
  • (1)footer
  • (1)gobutton
  • (1)header
  • (1)headinclude
  • (6)option
  • (1)post_thanks_box
  • (1)post_thanks_button
  • (1)post_thanks_javascript
  • (1)post_thanks_navbar_search
  • (1)post_thanks_postbit_info
  • (1)postbit
  • (1)postbit_onlinestatus
  • (1)postbit_wrapper
  • (1)spacer_close
  • (1)spacer_open 

Phrase Groups Available:
  • global
  • postbit
  • reputationlevel
  • showthread
Included Files:
  • ./showpost.php
  • ./global.php
  • ./includes/init.php
  • ./includes/class_core.php
  • ./includes/config.php
  • ./includes/functions.php
  • ./includes/class_hook.php
  • ./includes/modsystem_functions.php
  • ./includes/functions_bigthree.php
  • ./includes/class_postbit.php
  • ./includes/class_bbcode.php
  • ./includes/functions_reputation.php
  • ./includes/functions_post_thanks.php 

Hooks Called:
  • init_startup
  • init_startup_session_setup_start
  • init_startup_session_setup_complete
  • cache_permissions
  • fetch_postinfo_query
  • fetch_postinfo
  • fetch_threadinfo_query
  • fetch_threadinfo
  • fetch_foruminfo
  • style_fetch
  • cache_templates
  • global_start
  • parse_templates
  • global_setup_complete
  • showpost_start
  • bbcode_fetch_tags
  • bbcode_create
  • postbit_factory
  • showpost_post
  • postbit_display_start
  • post_thanks_function_post_thanks_off_start
  • post_thanks_function_post_thanks_off_end
  • post_thanks_function_fetch_thanks_start
  • post_thanks_function_fetch_thanks_end
  • post_thanks_function_thanked_already_start
  • post_thanks_function_thanked_already_end
  • fetch_musername
  • postbit_imicons
  • bbcode_parse_start
  • bbcode_parse_complete_precache
  • bbcode_parse_complete
  • postbit_display_complete
  • post_thanks_function_can_thank_this_post_start
  • showpost_complete