Ad-Aware removed tse.dll; comp crashed

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by dolphinocean, Dec 30, 2005.

  1. dolphinocean

    dolphinocean Private E-2

    Tues night I ran Ad-Aware and it reported one critical object known as Spyware AdvancedKeyLogger with a path given as C:\Program Files\Sygate\SPF\tse.dll.

    Others had told me that it could be a false positive. but whether it's false positive or true positive, I didn't know at that time and Ad-Aware had already removed the tse.dll file and caused damage to my system. Right now I need solution.

    I had tried to replace the tse.dll file from my laptop but upon reboot a popup window with a title "Sygate Agent Firewall" stated about something missing in the tfman.dll.

    Well, I copy the tfman.dll from my laptop and replaced the one in the desktop but upon reboot the "Sygate Agent Firewall" popup window stated it has encounter a problem and needs to close. It didn't tell what was the problem. The name "Sygate Agent Firewall" also seems not quite right.

    After futile effort to restore my SPF I went to control panel to remove it. And when I go to the C:\Program Files\ I found two SPF folders. One is SPF the other is SPF 2. I proceeded to delete them.

    Then I thought about system restore and did just that. The firewall still encountered same problem. When I check the C:\Program Files\ it now cpntained 3 SPF subfolders, namely SPF, SPF2, and SPF 3. I delelted them all and proceeded to restore to another point. It didn't help either. So I restored back to the point where I had first removed the firewall but the non-functional firewall was still there cause a freeze on my computer. Upon reboot and checking the hard disk space (total capacity=14.30 GB)
    it now has 5.94 GB, which is 41% free space. Before the problem I usually had 80% to 81% free space. So what happened to the other 40% disk space despite removal of firewall?

    When I rebooted to safe mode and run thru all the cleaning I was able to get the disk space back to 74%.

    Thursday night I tried the winsockxpfix and installed a new firewall from Sunbelt's Kerio PF. I was able to get online but it was slow on load my home page. And I couldn't get further while trying to update Spybot. When I pull up the task mgr it was a nightmare of trying to end the multitude of running or unresponsive task mgr spawning like crazy in the Application tab. And when I managed to end those endless list, anothe batch cme up, and more also in the running processes. The the computer gave a message about running low in visual memory. Finally, the computer just shutdown and rebooted.

    When I checked the system info, my available physical memory was just 3.95MB out of 64 MB, which is only 6% left.

    Now, I have removed Kerio and am wondering what I should do next? I'm thinking of re-installing Sygate from my laptop but I have to find out what was causing my hard disk space and memory to run so low despite removing some programs and the firewall?

    I've been working on this problem till 4 am the night before and I still got nowhere last night and was completely exhausted by 2:30 am.

    Last night, I re-install SPF from a cd but the "Sygate Agent Firewall" gave an error warning but the firewall did appear but not function. I was able to get on-line but there was no firewall protection at all. Eventually the computer shutdown and denied me access bec the page file is too small. This morning I was able to access the comp thru the safe mode.

    Others provided me to a link for help. The link provided was http://www.dslreports.com/remark.15055657 which brought me to a website called BroadBand. I wasn't sure whether it is safe to post there for help. So I came here for help as trusted this site from my past experience.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not really a true malware problem. But rather just a false detection. However your approach to trying to fix it was not the proper approach. System Restore does not backup all files and applications. System Restore actively monitors system file changes and some application file changes to record or store previous versions before the changes occurred.. So it was not going to do anything to help you recover your missing file. Uninstalling Sygate and then reinstalling it would do that.

    Doing all of those System Restore changes more than likely created a bunch of new restore points which will eatup disk space.. How large do you allow System Restore to be? You never provide your OS. Is it WinMe or WinXP? From a previous message thread you had posted I see WinXP but I don't know if this is the same PC. If you are running WinXP on a PC with only 64Mb, it is going to run very slow and will always be low on memory.

    What Ad-Aware SE version do you have and what is the reference file date. A new one just came out that may address the False Positive issue. Ad-aware SE referencefile SE1R84 28.12.2005
     
  3. dolphinocean

    dolphinocean Private E-2

    Thanks for your quick response, Chaslang! I'm glad to hear from you again.
    :)

    OS: Win XP. System is pentium III 550Mhz, 64 MB memory, 15 GB HD.
    Ad-Aware SE Personal, Buid 1.06r1; definition file: SE1R82 19.12.2005.
    System restore: I just checked and the slider was at the max (1757MB).

    Now I'm able to access my computer and thing runs like before after I had deleted the SPF folder from C:\Program Files\ in safe mode and reboot to normal to uninstall SPF from the control panel. But, without any firewall I don't dare to connect to the internet.

    What should I do now? Should I use clear system restore via disable and then enable system restore and use winsockxpfix to fix the registry and then reinstall SPF from my cd?

    BTW, scanning of CCleaner came up with these listed issues which it fixed:

    ActiveX/COM Issue
    HHActiveX.GlossaryPane{959F94FD-DDIE-11D2-B559-00105AD422DF}
    Registry Key: HKCR\HHActiveX.GlossaryPane

    ActiveX/COM Issue
    HHActiveX.GlossaryPane.1{959F94FD-DDIE-11D2-B559-00105AD422DF}
    Registry Key: HKCR\HHActiveX.GlossaryPane.1

    ActiveX/COM Issue
    HHActiveX.HHComponentActivator{399CB6C47312-11D2-B4D9-00105A04DF}
    REgistry Key: HKCR\HHActiveX.HHComponentActivator

    ActiveX/COM Issue
    HHActiveX.HHComponentActivator.1{399CB6C47312-11D2-B4D9-00105A04DF}
    REgistry Key: HKCR\HHActiveX.HHComponentActivator.1

    ActiveX/COM Issue
    Sygate_SSHelper{D59EBAD7-AF87-4A5C-8459-D3F6B918E7C9}
    HKCR\Sygate.SSHelper

    ActiveX/COM Issue
    Sygate_SSHelper.1{D59EBAD7-AF87-4A5C-8459-D3F6B918E7C9}
    HKCR\Sygate.SSHelper.1
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That PC must run like a snail. Rather slow processor with minimal memory for WinXP.

    We don't recommend using Ccleaner's Issues tab. Hope you did a backup first.

    Did you just try re-installing Sygate and doing a full install?
    If that does not work, try one of the others in How to Protect yourself from malware!
     
  5. dolphinocean

    dolphinocean Private E-2

    I did uninstall and re-install twice for SPF and each time upon re-boot this message from "Sygate Agent Firewall" came up:

    "Sygate Agent Firewall encountered a problem and needed to close".

    And then stated also about whether I want to send a report to Miscrsoft. I clicked no because I thought the word "Agent" in "Sygate Agent Firewall" is not how Sygate was known to call itself. I clicked for details and the following was given:

    Error Report:
    szAppName: smc.exe szAppVer: 5.6.0.2808
    szModName: wgman.dll szModVer 1.1.1222.0
    Offset: 00002675
    File included in this report:
    C:\Docume 1\Sh\Locals 1\Temp\WER4.tmp.dir00\smc.exe.mdmp
    C:\Docume 1\Sh\Locals 1\Temp\WER4.tmp.dir00\appcompat.txt
    (There is a worm like sign between Docume and 1 and between Locals and 1 that I couldn't find the button to type it).

    I tried Kerio once and I was able to get online but the memory soon run out. Everything was running like zombie. I guess that was due to system restore taking up the memory space as you explained it. When I pull up the task mgr, it was spawning like crazy.

    At that time I tried CCleaner to clean the system, sometimes I did backup, the last few I didn.t.

    I'm tempted to clear the system restore but was afraid if I want to go back to earlier time point there won't be any. If I set a new restore point can I select earlier time before all these problems occurred? And would that clear up some space for me.

    Even though my system is 64MB Memory with Win XP and dial-up connection, it was running reasonably for me when I surf the web and even working on my word pad program. It was nowhere like snail pace. I had uninstalled MS Office, MS Word in the past to give me more space.

    Now with these problems going on it is more like a zombie and even get worst with each attempt to fix it when I had SPF re-installed.

    Should I take the chance on disabling and enabling system restore and adjust the setting to reduce the disk space usage from 1757MB to something more reasonable for my system?

    Thanks for your dependable help in time my my urgent needs!

    :)
     
  6. dolphinocean

    dolphinocean Private E-2

    Hi Chaslang, Happy New Year!!!

    My computer is now back running like it was before the problem. I did re-set the system restore disk space usage down to 5% (667MB) and then go back to a previous restore point on Dec 25 before the problem started just to make sure those key removed by CCleaner could at least be restored if anything else goes wrong. After that I removed SPF from control panel and installed Kerio PF from cd and rebooted.

    Now I'm on-line surfing without problem. When everything remains fine for a day or 2 I'll disable and enable system restore to set new restore point.

    I think your tip about system restore eating up my disk space is the one that really helped.

    Thank a lot!
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You do not really need to remove your restore points. You did not have any malware to worry about. It's up to you though.
     
  8. dolphinocean

    dolphinocean Private E-2

    In that case I'll leave the system restore as it is until my disk space gets crowded.

    Two questions:

    When I deleted some programs during my initial attempts to fix the problem, those programs showed up again after a system restore to a prior date. When I tried to remove those programs via control panel, they were unable to be removed because some files were missing or some files were protected and access were denied. How do I delete those program manuallY?

    Also, I've heard prefetch function may cause slow system performance due to file location being moved during fragmentation and that clearing the prefetch folders may help the system runs more smooth. Is this true? If so, how to perform a safe prefetch folder cleaning?
     
  9. dolphinocean

    dolphinocean Private E-2

    Another question, upon reboot Kerio firewall icon did not appear on the system tray. I have to manually activate the firewall via START menu/programs and click on firewall engine. Don't they suppose to load automatically at start up?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Reinstall them and then uninstall them otherwise it will take some registry editing on your part (this is not a malware issue). This happened because you restore to a differnet point in time and various registry data was overwritten.

    Again not a malware forum topic. This is a topic that would lead to lot's of discussion and viewpoints. Many people will tell you just clearing the prefetch slows down performance and this is correct initially since the items are no longer in prefetch so you loose the caching. But when you get malware problems you need to empty the prefetch anyway. The prefetch does change periodically anyway because it has a limit of how many items can be stored there. So older items will eventually be removed. If it worries you just do a defrag.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm not sure what you did with all the installing and uninstalling and the System Restore stuff. It should load at startup and this should be the default. Check for options in the program and if not found. Start over (uninstall, reboot, reinstall).
     
  12. dolphinocean

    dolphinocean Private E-2

    The Kerio Firewall icon now appears on systray on startup upon reboot this time. My computer is now running smoothly without anymore problem.

    The false alarm by Ad-Aware can be a pain equivalent to malware attack when removed by ill-informed user like me. Your tip on system restore helped me to understand why my resources were depleted more and more upon each attempted fix with system restore.

    I'm very thankful for all your help on my computer problems!!!

    Thanks again, Chaslang!
    :)
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds