Solved

Active X component can't create object - Scode: 800A01AD

Posted on 2008-10-05
14
765 Views
Last Modified: 2013-11-22
I am working on a Sony VAIO model number PCG - R5050GL  The OS is Windows XP service pack two.  The combination above presents me with the following error message every time the computer is started:

Active X component can't create object
SRC: Microsoft VBScript runtime error
Line 6  Error:0 Scode: 800A01AD

At the top of the box where this information is being displayed, it appears to give the name of the application that is generating the error message that being Smartissue. The application appears to be made by Sony(?). The only thing I can find is that it may be related to is SupportSoft.

Any suggestions are welcomed!
Thanks!
0
Comment
Question by:cdplayer
  • 7
  • 6
14 Comments
 
LVL 22

Expert Comment

by:orangutang
ID: 22647098
Is your computer working okay besides the error? Send us your HijackThis (http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php) log.
0
 
LVL 142

Expert Comment

by:Guy Hengel [angelIII / a3]
ID: 22652552
please check out all the applications/services that are started automatically when the computer is starting resp when the user is logging in.
0
 
LVL 1

Author Comment

by:cdplayer
ID: 22656538
orangutang,

Yesterday I ran AVAST's BART software which cleaned off 209 nasties! Very nice software! I was using the trial version.

Attached is the output generated by HiJackThis.
hijackthis.log
0
 
LVL 22

Expert Comment

by:orangutang
ID: 22656554
Your computer still seems infected. Also, try Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam.php) and send us an updated HijackThis log.
0
 
LVL 1

Author Comment

by:cdplayer
ID: 22656722
angelIII - It appears that it does not matter who is logging in they still get the same error message.
0
 
LVL 1

Author Comment

by:cdplayer
ID: 22658991
orangutang - I was surprised to see how many nasties were still on that computer after AVAST BART! Look at the output from Malwarebytes' Anti-Malware. I take it that this scanner also picks up more than just malware.

Attached is the output from HiJackThis
hijackthis.log
mbam-log-2008-10-07--06-44-24-.txt
0
 
LVL 1

Author Comment

by:cdplayer
ID: 22659420
I am currently running Kaspersky's online scanner. Upload the results when scanning completes.
0
What Is Threat Intelligence?

Threat intelligence is often discussed, but rarely understood. Starting with a precise definition, along with clear business goals, is essential.

 
LVL 22

Expert Comment

by:orangutang
ID: 22660761
Hmm, you still seem to be infected. Is that the HijackThis log after you scanned with Malwarebytes' Anti-Malware or before? If it's before, send an updated HijackThis log and use thr latest version of HijackThis (http://www.trendsecure.com/portal/en-US/threat_analytics/hijackthis.php) not 1.99.1
0
 
LVL 1

Author Comment

by:cdplayer
ID: 22664375
Here is the lastest version generated by HiJackThis.
hijackthis.log
0
 
LVL 22

Expert Comment

by:orangutang
ID: 22665234
Wow, it looks like you got a pretty nasty infection. Create a system restore point and remove these from your HijackThis log in safe mode to clean up:
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)
O2 - BHO: (no name) - {1D64A215-EB1C-46DB-81C7-85522BC364D8} - C:\WINDOWS\system32\mscd.dll (file missing)
O2 - BHO: (no name) - {2C043049-77FD-4521-803D-EEDB1020D6FF} - C:\WINDOWS\system32\snnpapi.dll (file missing)
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINDOWS\system32\iecust.dll (file missing)
O3 - Toolbar: SpamBlockerUtility - {74CC49F7-EB32-4A08-B204-948962A6E3DB} - C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbHostIE.dll (file missing)
O4 - HKLM\..\Run: [AQ3HelperStartUp] C:\PROGRA~1\AQUATI~1\AQ3HEL~1.EXE /partner AQ3
O4 - HKLM\..\Run: [taskopen.exe] taskopen.exe
O4 - HKLM\..\Run: [StartCpl] newbreed.exe
O4 - HKLM\..\Run: [newbreed] srbho.exe
O4 - HKLM\..\Run: [SpamBlocker] C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbOEAddOn.exe
O4 - HKLM\..\Run: [Spam Blocker for Outlook Express] C:\PROGRA~1\SPAMBL~1\Bin\484~1.0\SBInst.exe
O4 - HKLM\..\Run: [zoaoojbm] C:\WINDOWS\system32\tcnwjubl.exe
O4 - HKLM\..\Run: [SpySpotter System Defender] C:\Program Files\SpySpotter3\Defender.exe -startup
O4 - HKLM\..\Run: [WeatherOnTray] C:\Program Files\SpamBlockerUtility\Bin\4.8.4.0\SbWeatherOnTray.exe
O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /min
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: PrecisionTime.lnk = C:\Program Files\PrecisionTime\PrecisionTime.exe
O18 - Filter hijack: text/html - {A2073562-07D8-4302-A13F-B5F127FCFA68} - C:\WINDOWS\system32\snnpapi.dll
O18 - Filter: text/plain - {A2073562-07D8-4302-A13F-B5F127FCFA68} - C:\WINDOWS\system32\snnpapi.dll
O20 - Winlogon Notify: mlJAqqRk - mlJAqqRk.dll (file missing)
O23 - Service: SpywareCleanerService - Unknown owner - C:\Program Files\Spyware Cleaner\SCService.exe (file missing)

Also, if you're still having the problem, remove this from your HijackThis log:
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
Also, send another updated HijackThis log.
0
 
LVL 22

Accepted Solution

by:
orangutang earned 500 total points
ID: 22665264
I've requested attention for help from spyware experts. In the meantime, you can also scan with SUPERAntiSpyware (http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE). Also, try removing this:
O4 - HKLM\..\Run: [CleanupProgram] C:\Sonysys\cleanup.exe
Also, try checking Add/Remove Programs for anything related to Support.com and uninstall it before trying to remove:
O4 - HKLM\..\Run: [ZTgServerSwitch] c:\program files\support.com\client\lserver\server.vbs
0
 
LVL 1

Author Comment

by:cdplayer
ID: 22668496
orangutang -

I've just completed running SuperAnitiSpyware. It picked up a LOAD of Trojans and spyware - 41 files detected 8269. You have to remember that this laptop NEVER had any anti anything installed on it. The computer is about 7(?) years old. GOOD GRIEF!
Attached is the latest output from HiJackThis. I also preformed the HiJackThis cleanup you requested.

Thanks orangutang for your continued support!
hijackthis-safemode-after.txt
0
 
LVL 1

Author Comment

by:cdplayer
ID: 22674660
Thanks folks for all of your help! The client wanted his computer today, now. He was having computer withdrawals!
After that last scanning when I started up the computer, I didn't see any error messages during boot time.
For some reason I could not switch from one user to another - had to re-boot.  I found that strange, the client didn't care about that.

Cheers!
0
 
LVL 22

Expert Comment

by:orangutang
ID: 22675109
Well, the latest HijackThis log shows:
O4 - HKCU\..\Run: [WinFixer2006] "C:\Program Files\WinFixer_2006\uwfx6.exe" /min
which is still a sign that it's infected. I would remove that line
0

Featured Post

Why You Should Analyze Threat Actor TTPs

After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

Join & Write a Comment

It started not too long ago. It was at first annoying. My keystrokes seemed to be randomly generated, not the ones I typed on the keyboard. For some reason this only happened in certain applications (especially browsers such as IE11, Firefox and Chr…
Before we dive into the marketing strategies involved with creating an effective homepage, it’s crucial that EE members know what a homepage is. In essence, a homepage is the introductory, or default page, of a website that typically highlights the …
The purpose of this video is to demonstrate how to set up the WordPress backend so that each page automatically generates a Mailchimp signup form in the sidebar. This will be demonstrated using a Windows 8 PC. Tools Used are Photoshop, Awesome…
This video shows how to remove a single email address from the Outlook 2010 Auto Suggestion memory. NOTE: For Outlook 2016 and 2013 perform the exact same steps. Open a new email: Click the New email button in Outlook. Start typing the address: …

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

19 Experts available now in Live!

Get 1:1 Help Now