AD-aware not completing.

Discussion in 'Malware Help (A Specialist Will Reply)' started by adjohnson1971, Oct 14, 2006.

  1. adjohnson1971

    adjohnson1971 Private E-2

    Hi. A fewdays ago i was doing my weekly scans and spybot SD was running slower than usual, when it had completed a window popped but the writing inside it was foreign and I couldn't understand it so just closed it down. I then ran ad-aware and it gets about 2/3 the way through and then it freezes. By now i was abit concerned so ran avg anti virus and it found nothing, and also did an online scan with f-secure,which found 2 items and removed? them. I've tried ad-aware again and the same happens. I've followed your read and run first instructions and nothing untowards has appeared so I've posted all logs and would kindly ask for some further advice please.
     
  2. adjohnson1971

    adjohnson1971 Private E-2

    sorry i forgot to add the scan files.
     

    Attached Files:

  3. adjohnson1971

    adjohnson1971 Private E-2

    here is the rest of the scan files.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs do not reveal any major malware issues, but they do show that you did not follow the READ & RUN ME properly.

    You have Kazaa Lite installed which was requested to be uninstalled in step 0 of the READ ME. You should uninstall this now.

    You are also using Spybot - Search & Destroy 1.3 which has not been used in over 2 years. If you follow the directions in the READ ME and verified version numbers, you would have the proper version of Spybot. Uninstall the old version, REBOOT, and then install the correct version.

    Also the READ ME suggested that you install the current version of Sun Java (which is presently 5.0 update 9) you do not have this version but you do have the below 5 outdated versions all installed:

    J2SE Runtime Environment 5.0 Update 1
    J2SE Runtime Environment 5.0 Update 2
    J2SE Runtime Environment 5.0 Update 4
    J2SE Runtime Environment 5.0 Update 6
    Java 2 Runtime Environment Standard Edition v1.3.1_04

    These should all be uninstalled and the current version given in the READ ME should be installed afterwards.


    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://utu.popcap.com/games/popcaploader_v6.cab
    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)
    After clicking Fix, exit HJT.
    Now we need to Reset Web Settings:
    1. If you have an Internet Explorer icon on your Desktop, goto step 2. If not, skip to step 3.
    2. Now right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK. Then skip step 3.
    3. If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.
    Note for IE 7 users: You need to select Internet Options then the Advanced tab and then Reset Internet Explorer Settings!

    Now Copy the bold text below to notepad. Save it as fixWLK.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Now I would suggest you reboot into Safe Mode, and shutdown ALL applications and Windows and only run a scan with Ad-Aware SE (by the way what version do you have and are the referenece files up to date?

    Does is complete a scan in safe mode.
     
  5. adjohnson1971

    adjohnson1971 Private E-2

    I've followed your new instructions exactly, except that when I used HJT I could not find this entry O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - http://utu.popcap.com/games/popcaploader_v6.cab. I therefore carried on exactly as you describe. Everything seems to be running ok now. Many thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds