BleepingComputer.com: odbc_set

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

odbc_set Reg entry keeps reappearing

#1 User is offline   _aleph_ 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-March 10

Posted 01 March 2010 - 02:05 PM

I have a user who keeps getting an odbc_set entry in her registry at
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad.

I've deleted it repeatedly, but something keeps rewriting it. After I delete the entry, she gets one clean boot-up, then she gets 2 odbcmr32.dll related errors at each subsequent reboot until I delete the entry again.

I have looked in Administrative Tools/Data Sources (ODBC), but I'm not sure what I should be seeing/not seeing there, it just looks like some file associations for Excel, SQL, etc.

She isn't running any software that dozens of other of my users aren't running, but she's the only one getting the registry value rewritten. If anybody has a clue, I sure could use some help with this.

Thanks,

_aleph_

#2 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,334
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 01 March 2010 - 02:23 PM

Then its probably needed, what issues are trying to resolve? If you are getting errors then you need to update Windows or another application.




Mod edit: removed quote of entire previous thread for ease of reading,already read it once.

This post has been edited by boopme: 01 March 2010 - 03:03 PM


My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#3 User is offline   hamluis 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 31,433
  • Joined: 03-September 05
  • Gender:Male
  • Location:Killeen, TX

Posted 01 March 2010 - 02:38 PM

I guess that I'd like to know...what the actual error message is.

I guess that I'm also curious what made you focus on registry values?

Louis

#4 User is offline   _aleph_ 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-March 10

Posted 01 March 2010 - 04:24 PM

I'll have to get the wording of the error msgs tomorrow when I'm on-site. As for looking in the registry, several other computers had a similar value in the HKLM Run key. When I deleted those, the error msgs disappeared and the entry stayed gone. Why did I look in the registry in the first place? It was obvious that some process was trying to run (now that I think about it, I believe one of the errors was that the file is not a valid image file) and the All Users and user profile didn't have anything suspicious in the Startup folder, so I checked the HKLM Run key. When that was deleted but the errors still apeared, I did Google & forum searches for other places in the registry where commands to start programs can be found.
_aleph_

#5 User is offline   _aleph_ 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-March 10

Posted 01 March 2010 - 04:34 PM

Cryptodan,

Sorry, I scrolled to the bottom and completely missed your reply. I'm just trying to get 2 error messages from popping up every time my user boots-up. She just has to acknowledge them and her system works fine, but it's a bother to her and makes her feel like there's something wrong with her computer. She's a library department manager, so the last thing she needs is an annoyance to start her work day every day.

If you come up with any ideas, speak up!

Thanks,

_aleph_

#6 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,334
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 01 March 2010 - 04:57 PM

Is the computer fully updated?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#7 User is offline   hamluis 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 31,433
  • Joined: 03-September 05
  • Gender:Male
  • Location:Killeen, TX

Posted 01 March 2010 - 05:37 PM

FWIW: I think that a number of "bad image" errors result from malware, IIRC.

Lots of guessing on these, from what I see.

Louis

#8 User is offline   _aleph_ 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-March 10

Posted 02 March 2010 - 09:31 AM

cyrptodan,

Systemwide (library system), a WSUS server does the updates for us. I can't see this being an update issue. That reg value is being rewritten, but since the process can't start, the error msgs pop up. Since she has a roaming profile, she gets the errors on every machine she logs into. I'm beginning to wonder if there is a particular computer in the department that she uses that may actually be trying to run something corrupt or unauthorized from Startup, placing the reg value which copies her profile to the server, from which it propogates to all other machines when she logs in, and makes my live adventurous. Everyone else on the domain enjoys error-free boot-ups. There's something wrong in her profile that I can't identify, and my network admin is loath to delete her profile in AD so that I could delete her local profiles to keep them from overwriting the server copy and them maybe move on with my life. Anybody got any extra straw? I believe I'm grasping at my last piece.

She'll be in around lunchtime (we're in EST) and I'll get the error msgs and any other thing I can stumble upon that might be a clue to this mystery, and I'll post it all here.
_aleph_

#9 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,334
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 02 March 2010 - 11:24 AM

Delete her profile and have it recreated.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#10 User is offline   _aleph_ 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-March 10

Posted 22 March 2010 - 01:53 PM

I believe that the IT powers that be are finally ready to recreate her profile on the server so we can delete locally cached copies and get her logging on in a trouble-free fashion again. It seems most likely that this was an infection with Win32/Cemgar. Unfortunately, I found no silver bullet and we have to use the shotgun approach.

Thanks, for the help.
_aleph_

#11 User is offline   _aleph_ 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 01-March 10

Posted 23 March 2010 - 11:02 AM

HA! I spoke too soon. A co-worker forund the silver bullet!

What had to be done was go to each of the affected computers (we have roaming profiles) and do the following:
• Boot into Safe Mode
• Delete C:\WINDOWS\system32\odbcmr32.dll (a hidden file)
• Delete the registry entry called odb_set under HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
• Search and delete any registry entry containing the string odbcmr32
• Reboot into normal mode

I hope this info helps future generations...
_aleph_

#12 User is offline   hamluis 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Moderator
  • Posts: 31,433
  • Joined: 03-September 05
  • Gender:Male
  • Location:Killeen, TX

Posted 23 March 2010 - 11:37 AM


#13 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,334
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 23 March 2010 - 12:30 PM

For what its worth:

Win32/Cemgar

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users