PDA

View Full Version : [Invalid data type for "MenuText"]



koaaa
2007-08-14, 00:37
Hi,

I have an issue with Spybot S&D version 1.4 and updated today :
When checking the harddrive he finds a list of spyware such as "7FaSSt" but says "Invalid data type for "MenuText"...

I have of course completely removed the software and did a clean install but I still have the same issue :eek:.
I have also launched the software in Windows safe mode but with similar results.

Any idea on what could cause this ?

Thank you.

OS : Windows XP SP2.

koaaa
2007-08-15, 13:22
Hi,

Nobody has experienced the same issue ? :red:

[J4ck]
2008-12-09, 02:17
Hey,
I'm experiencing the exact same thing with Spybot 1.6.0.30
Everytime i do a scan i always get several msgs like the ones in the log below.
I also already did a clean reinstall of the app. It didn't fix it. :sad:

OS : Windows XP SP3


LOG:
Hint of the Day: Click the bar at the right of this to see more information! ()


Error during check!: X-Diver [13 - $D49F6EFE] (Invalid data type for 'MenuText') ()


Error during check!: X-Diver [14 - $FE01B949] (Invalid data type for 'MenuText') ()


Error during check!: 7FaSSt [20 - $BADB843C] (Invalid data type for 'MenuText') ()


Error during check!: 7FaSSt [26 - $83278DE4] (Invalid data type for 'MenuText') ()


Error during check!: AdultLinks.QcBar [21 - $B4972226] (Invalid data type for 'MenuText') ()


Error during check!: MSN Messenger Polygamy [2 - $CA0F06E1] (Invalid data type for 'MenuText') ()


Error during check!: SearchALot [16 - $E38FCEFF] (Invalid data type for 'MenuText') ()

--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---

2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-09-16 TeaTimer.exe (1.6.3.25)
2008-12-09 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-10-22 advcheck.dll (1.6.2.13)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2008-11-04 Includes\Adware.sbi (*)
2008-11-25 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-11-18 Includes\HijackersC.sbi (*)
2008-09-09 Includes\Keyloggers.sbi (*)
2008-11-18 Includes\KeyloggersC.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-03 Includes\MalwareC.sbi (*)
2008-11-03 Includes\PUPS.sbi (*)
2008-12-02 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-12-02 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-11-04 Includes\Spyware.sbi (*)
2008-12-02 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-11-04 Includes\Trojans.sbi (*)
2008-12-02 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Greyfox
2008-12-10, 08:13
koaaa, [J4ck]

I suspect both your PC's may either have infections, or the remnants of same, so I suggest you both start individual topics in the malware removal forum.

Before doing so, please read this

http://forums.spybot.info/showthread.php?t=1266

md usa spybot fan
2008-12-10, 15:21
[J4ck]:

The data type for MenuText items in the registry are normally REG_SZ. I suspect that one of the MenuText entries in your registry has a data type other than REG_SZ affecting the Spybot scan.

When you get the errors, try expanding one of the errors, if possible, by clicking on the + to the left of the error. If a registry key is displayed on the right hand side of the entry, double click on it to see the registry entry.

[J4ck]
2008-12-10, 18:57
[J4ck]:

The data type for MenuText items in the registry are normally REG_SZ. I suspect that one of the MenuText entries in your registry has a data type other than REG_SZ affecting the Spybot scan.

When you get the errors, try expanding one of the errors, if possible, by clicking on the + to the left of the error. If a registry key is displayed on the right hand side of the entry, double click on it to see the registry entry.

Hey md usa spybot fan,

It doesn't give you an option to expand anything mate. I'm sending a printscreen of some of the app results during a scan. There's no '+', just a big red circle with an 'X'. Even when i try the option to right click an item ---> 'More details' ---> 'Jump to location' nothing happens.:sad:
I'm not even sure SpyBot is detecting spyware and is unable to remove ir or if it is just reporting errors while checking for those specific types. I use outpost, nod32, firefox with both no-script and adblock plus addons. Normally i would only run spybot once or twice a month and it would only detect one or two minor threats.
I find it odd that suddenly my computer would get so badly infected.:sad:
But hey if there's such a thing as scientology..anything's possible. Any more hints? Thanks in advance.
Cheers.

[J4ck]
2008-12-10, 19:36
koaaa, [J4ck]

I suspect both your PC's may either have infections, or the remnants of same, so I suggest you both start individual topics in the malware removal forum.

Before doing so, please read this

http://forums.spybot.info/showthread.php?t=1266

Greyfox:

Here's the results log after completing a check:

Hint of the Day: Click the bar at the right of this to see more information! ()


Error during check!: X-Diver [13 - $D49F6EFE] (Invalid data type for 'MenuText') ()


Error during check!: X-Diver [14 - $FE01B949] (Invalid data type for 'MenuText') ()


Error during check!: 7FaSSt [20 - $BADB843C] (Invalid data type for 'MenuText') ()


Error during check!: 7FaSSt [26 - $83278DE4] (Invalid data type for 'MenuText') ()


Error during check!: AdultLinks.QcBar [21 - $B4972226] (Invalid data type for 'MenuText') ()


Error during check!: MSN Messenger Polygamy [2 - $CA0F06E1] (Invalid data type for 'MenuText') ()


Error during check!: SearchALot [16 - $E38FCEFF] (Invalid data type for 'MenuText') ()


Error during check!: Sexy [1 - $1E4024BD] (Invalid data type for 'MenuText') ()


Error during check!: Alexa [35 - $0E864F2C] (Invalid data type for 'MenuText') ()


Error during check!: BonziBuddy [4 - $42EDFD33] (Invalid data type for 'MenuText') ()


Error during check!: BrowserAid.CashToolbar [25 - $41036D78] (Invalid data type for 'MenuText') ()


Error during check!: CommonName [47 - $879EE92B] (Invalid data type for 'MenuText') ()


Error during check!: Flyswat [18 - $1330B06F] (Invalid data type for 'MenuText') ()


Error during check!: Flyswat [19 - $F37BB2B4] (Invalid data type for 'MenuText') ()


Error during check!: Huntbar [49 - $4DB544EC] (Invalid data type for 'MenuText') ()


Error during check!: Huntbar [50 - $D4879DFB] (Invalid data type for 'MenuText') ()


Error during check!: PopUp Notes [57 - $8E60C8C2] (Invalid data type for 'MenuText') ()


Error during check!: PopUp Notes [58 - $98DB60A9] (Invalid data type for 'MenuText') ()


Error during check!: Search-Explorer [11 - $5493C21E] (Invalid data type for 'MenuText') ()


Error during check!: TurboDownload [5 - $6A124B07] (Invalid data type for 'MenuText') ()


Error during check!: Zlob.Downloader.vcd [3 - $00EED593] (Invalid data type for 'MenuText') ()


Congratulations!: No immediate threats were found. ()



--- Spybot - Search & Destroy version: 1.6.0 (build: 20080707) ---

2008-07-07 blindman.exe (1.0.0.8)
2008-07-07 SDFiles.exe (1.6.0.4)
2008-07-07 SDMain.exe (1.0.0.6)
2008-07-07 SDShred.exe (1.0.2.3)
2008-07-07 SDUpdate.exe (1.6.0.8)
2008-07-07 SDWinSec.exe (1.0.0.12)
2008-07-07 SpybotSD.exe (1.6.0.30)
2008-09-16 TeaTimer.exe (1.6.3.25)
2008-12-10 unins000.exe (51.49.0.0)
2008-07-07 Update.exe (1.6.0.7)
2008-10-22 advcheck.dll (1.6.2.13)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2008-09-15 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2008-10-22 Tools.dll (2.1.6.8)
2008-11-04 Includes\Adware.sbi (*)
2008-12-09 Includes\AdwareC.sbi (*)
2008-06-03 Includes\Cookies.sbi (*)
2008-09-02 Includes\Dialer.sbi (*)
2008-09-09 Includes\DialerC.sbi (*)
2008-07-23 Includes\HeavyDuty.sbi (*)
2008-11-18 Includes\Hijackers.sbi (*)
2008-11-18 Includes\HijackersC.sbi (*)
2008-12-09 Includes\Keyloggers.sbi (*)
2008-12-09 Includes\KeyloggersC.sbi (*)
2008-11-18 Includes\Malware.sbi (*)
2008-12-09 Includes\MalwareC.sbi (*)
2008-11-03 Includes\PUPS.sbi (*)
2008-12-09 Includes\PUPSC.sbi (*)
2007-11-07 Includes\Revision.sbi (*)
2008-06-18 Includes\Security.sbi (*)
2008-12-09 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2008-12-10 Includes\Spyware.sbi (*)
2008-12-10 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2008-11-04 Includes\Trojans.sbi (*)
2008-12-10 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

Could it still be malware?
Cheers.

md usa spybot fan
2008-12-10, 22:34
[J4ck]:


;265392']... Could it still be malware? ...
I have contacted a member of "Team Spybot" and asked if someone could take a look at this thread.

I am still under the impression that there is something in your registry or in the way Spybot handles those entries that is causing the problem.

However, in the mean time, feel free to post in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum and have someone take a look at your system as Greyfox (http://forums.spybot.info/member.php?u=34340) suggested.

If you decide to have an experienced malware removal specialist take a look at your system, please follow the procedure in this link to run scans and produce a HijackThis log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) ( http://forums.spybot.info/showthread.php?t=288).
After you have completed the required scans and produced the requested logs, start your own thread in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum, making sure to post the HijackThis log produced from the above instructions.

Yodama
2008-12-11, 07:18
hello,

I am of the same opinion as md usa spybot fan, it is very likely the data type in the registry that causes this issue.

The affected command in this case is documented
here (http://wiki.spybot.info/index.php/IEExtension)
so you can look up the location in the registry.

The most important part is this key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt

Please use regedit and export this key.

Malware could have affected the respective registry entries, but there may also be some tools or addons for the Internet Explorer which could have affected this.

It may be best to create a full Spybot S&D report file and email it to detections-at-spybot.info (replace -at- with @)
Please make a reference (link) to this thread in your email.

To create the full Spybot S&D report, right click the scan results screen and select to save the full Spybot S&D report.

[J4ck]
2008-12-11, 13:29
Hey Yodama


hello,

I am of the same opinion as md usa spybot fan, it is very likely the data type in the registry that causes this issue.

The affected command in this case is documented
here (http://wiki.spybot.info/index.php/IEExtension)
so you can look up the location in the registry.

The most important part is this key:

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt

Please use regedit and export this key.

I checked that registry key and as it turns out it's empty. It displays only the (default) REG_SZ entry with no data. So..No use in exporting it, right? As it would turn out redundant to what you already know..:sad:



Malware could have affected the respective registry entries, but there may also be some tools or addons for the Internet Explorer which could have affected this.

It may be best to create a full Spybot S&D report file and email it to detections-at-spybot.info (replace -at- with @)
Please make a reference (link) to this thread in your email.

To create the full Spybot S&D report, right click the scan results screen and select to save the full Spybot S&D report.

I'm performing a scan right now. I'll email the results in a few minutes.

Cheers mate, and i thank you all for all the help so far.