Adware Keeps Freezing

Discussion in 'Malware Help (A Specialist Will Reply)' started by BerryOnline, Jun 6, 2005.

  1. BerryOnline

    BerryOnline Private E-2

    Every time i run Lavasoft Adware 1.06, its gets to 4400 files and then frezzes and i have to end task, delete. I've done virues scans and found nothing. Can anyone help me? Here is my hijackthis file.


    THANKS

    _________________________________________________________________

    Log file removed
     
    Last edited by a moderator: Jun 6, 2005
  2. Major Attitude

    Major Attitude Co-Owner MajorGeeks.Com Staff Member

  3. BerryOnline

    BerryOnline Private E-2

    Ok. I've done what you said to do here.
    http://forums.majorgeeks.com/showthread.php?t=35407

    i had noproblems only thing was i couldnt complete adware scan, because it froze.

    Heres my new hijack file.

    Edit by bjgarrick: Wrong location, Inline HJT log removed!


    THANKS
     
    Last edited by a moderator: Jun 7, 2005
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First, please look in Add/Remove Programs and uninstall the following program:

    Viewpoint


    Now, please EXTRACT HijackThis from the ZIP File to a Safer location. Here's how:

    To create a new folder:
    Click START > My Computer > Local Disc C: > Program Files
    Now, Right Click on an Empty Area and select New > Folder & name it HijackThis and ENTER

    To Extract HijackThis:
    Now, Right Click your HijackThis ZIP File and select Extract All > Next > and browse to your newly created HijackThis Folder
    (C:\Program Files\HJT) and click Next.

    Now run HJT from there. Please save your HJT Log as a .txt File and attach it via the "Manage Attachments" tool in the Additional Options section when you post.

    The reason HJT needs its own safe folder is so that backups will be safely preserved. That way, if a mistake is made in the removal process, the mistakenly deleted entry can be restored.
     
  5. BerryOnline

    BerryOnline Private E-2

    Sorry for posting wrong, wasnt understanding what you had asked. I uninstalled view point and uploaded my new hijackthis log.


    THanks
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download the following file, after download is complete run the uninstaller. When uninstall is complete reboot and post a new HJT log.

    Download Uninstaller
     
  7. BerryOnline

    BerryOnline Private E-2

    DOne.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First:
    Click Start > Run > type services.msc and Click OK

    Locate System Startup Service (SvcProc) and RightClick on it to bring up the Service Properties Window.
    First: Stop the service by clicking the Stop Button.
    Next: Disable it by changing the Startup Type to Disabled and click Apply

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://hsremove.com/done.htm

    O2 - BHO: CInterfaceObj Object - {58F07DD3-924D-4141-BC74-299F523A95F1} - C:\WINDOWS\pxwma.dll

    O17 - HKLM\System\CCS\Services\Tcpip\..\{FEB7AC2E-C2E4-4463-BA81-6EF214B1FA39}: NameServer = 69.50.184.84,195.225.176.37

    O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Navigate to and DELETE the following if they should remain:

    C:\WINDOWS\svcproc.exe

    C:\WINDOWS\pxwma.dll

    NEXT:
    Run CCleaner and Spybot S&D and have Spybot fix what it finds.
    Note: Dont forget to update Spybot S&D by selecting "Search For Updates"

    Then, as an added precaution, Go to Start > Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.


    Reboot to Normal Windows , Scan with HijackThis and attach the new log.
     
  9. BerryOnline

    BerryOnline Private E-2

    Alright did as i was told here is my new log.
     

    Attached Files:

  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your HJT log is clean, however there is one small issue we need to address.

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    This entry was added from Spybot S&D, this needs to be removed.

    Other than the above, your HJT log is clean. Are you having any further problems?
     
  11. BerryOnline

    BerryOnline Private E-2

    Yea when adware reaches HKCU\Software it freezes. So thats probley the problem causing adware to freeze. How do i remove it, just use regedit and delete it?? or do i have to adjust something??
     
  12. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    If possible attach the log from Ad-Aware. When it freezes during the scan, does it find anything before it freezes?
     
  13. BerryOnline

    BerryOnline Private E-2

    Yes it does find stuff before it freezes. Finds 21 stuff. I've looked for a log but i think think adware saves logs.
     
  14. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Its possible to get a log, first what version of Ad-Aware are you running?
     
  15. BerryOnline

    BerryOnline Private E-2

    Its Ad-Aware SE Personal Version 1.06
     
  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Reboot into Safe Mode and run the scan again. See if it will complete in safe mode.

    Let me know!
     
  17. BerryOnline

    BerryOnline Private E-2

    Still freezes, same spot.
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download Spy Sweeper 4.0.3.363 and install it.

    After you install make sure you get the updated spyware definitions. Then do a full sweep removing all infections. After you remove the infections with SpySweeper, reboot and run Ad Aware again.
     
  19. BerryOnline

    BerryOnline Private E-2

    Scaned, found 49things, but adware still keeps freezing.
     
  20. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Have you tried uninstalling, reboot and reinstalling?
     
  21. BerryOnline

    BerryOnline Private E-2

    Yup tried that too,
     
  22. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Are you doing a "Full System Scan" or "Perform smart system scan" ??
     
  23. BerryOnline

    BerryOnline Private E-2

    Both, and it still freezes
     
  24. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Reboot into Safe Mode, after windows has loaded open Ad Aware but dont start the scan yet. Now press the keys below:

    CONTROL + SHIFT + ESC

    This will open Task Manager, select explorer.exe, right click and END TASK on this process. You desktop will disappear, this is normal.

    Now run a scan with Ad Aware and see if it still freezes.

    After the scan is complete, press the same keys above. In task manager, select the Applications Tab. Click the button "New Task...". Type in explorer.exe.

    Now reboot into normal mode and let me know the results.
     
  25. BerryOnline

    BerryOnline Private E-2

    Still does it.
     
  26. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Go into Control Panel, look in Add/Remove Programs and uninstall Ad Aware.

    Now, download the following version of Ad-Aware.

    Ad-Aware 6.0 Personal (Old Version)

    Get the updates ref file but ignore the product update. Afterwards do another scan and see if the dang thing still freezes.
     
  27. BerryOnline

    BerryOnline Private E-2

    Still freezes but now it tells me exactly were it freezes.

    SOFTWARE\Microsoft\Internet Explorer...
     
  28. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Before we continue, surf in to Windows Updates and install Service Pack 2. Afterwards post a fresh HJT log and we will see how things look.
     
  29. BerryOnline

    BerryOnline Private E-2

    Updated, but still having the same problem.
     

    Attached Files:

  30. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Something I notice in your HJT log that still remains, thats the entry below.

    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present

    This was added from Spybot S&D or Ad-Aware, this could be the cause of it freezing.

    First, update your Ad-Aware back to the current version. Then remove the above restriction. Scan with HJT and fix it, then try another scan.
     
  31. BerryOnline

    BerryOnline Private E-2

    Nope still freezes.
     
  32. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Did you remove the restriction?
     
  33. BerryOnline

    BerryOnline Private E-2

    Yes, updated back to the new version of adware, removed the restriction and then scaned with adware.
     

    Attached Files:

  34. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    -Please download Ewido Security Suite

    - Install and get any updates!
    - Run a full scan on Local Disk C:\
    - Remove ALL found infections
     
  35. BerryOnline

    BerryOnline Private E-2

    Still freezes. I saved a log of the scan. Only had one problem, but i dont think thats the cause. Heres the log.
     

    Attached Files:

  36. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    + Infected files: 93
    + Removed files: 92


    Thats more than ONE problem LOL!

    How come you have all those _RESTORE files infected? Have you had system restore enabled this whole time?
     
  37. BerryOnline

    BerryOnline Private E-2

    Well i meant only one problem wasnt solved.

    C:\Documents and settings\BerryOnline\Cookies\berryonline@network[1].txt -> Spyware.Tracking-Cookie -> Error during cleaning

    System Restore was enabled, i just turned it off. Was i suppose to have it off????
     
  38. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This should have be done back in step # 2! Disabling System Restore is the FIRST step in Malware removal.

    If you had read the READ ME step by step you would have known this.
     
  39. BerryOnline

    BerryOnline Private E-2

    O for real. My bad. i guess i missed that.
     
  40. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    How long do you allow Ad-Aware to scan when it freezes, its not like a brief freeze is it?
     
  41. BerryOnline

    BerryOnline Private E-2

    no its gets to 45,080 objects and then just stops.
     
  42. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Is it still detecting infections after all of the scans?
     
  43. BerryOnline

    BerryOnline Private E-2

    up to that point it found nothing. no infections.
     
  44. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Run CCleaner and see if it still freezes. If it still freezes, then follow the steps below.

    - Run Ad-Aware, at the top of the program in the right corner. Click the second to last button on the left, this will open the Ad-Aware Configuration Window.

    - Click the Startup button

    - Click "Perform Full System Scan"

    After you complete the above, reboot and let Ad-Aware scan, let me know if it still freezes.
     
  45. BerryOnline

    BerryOnline Private E-2

    Did the CCleaner, but it still freezes.
    Then when i try to Click on Perform Full System Scan, it wont let me. I cant click on anything under the start up section.
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I quickly read thru this thread.

    First it is not clear to me that System Restore is now disabled. If it is not disabled, please disable it.

    Now run Ad-Aware and click the Scan Now button but do no scan yet.
    Uncheck (it should become a red circle with an X in it) the option that is labeled "Search for negligible risk entries". Now select Perform smart system scan and click Next

    Does this allow a complete scan?
     
  47. BerryOnline

    BerryOnline Private E-2

    System restore is disabled. I did what you said but still no luck. Still freezes.
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now select Use custom scanning options and click Customize.

    Disable Deep-scan registry

    Now try a scan.

    If that does not work, also disable Scan registry

    And see if that works!
     
  49. BerryOnline

    BerryOnline Private E-2

    Did that and it worked, found no infections.
     
  50. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! It would appear to me that something in your registry is causing a problem for Ad-Aware to complete scanning when in the Deep Scan mode.

    Does it give you the full registry key where it hangs or only a partial key?

    I wonder if your registry has any problems in it.

    This may be a problem that you will have to send to Lavasoft to get resolved but they may not talk to you unless you have a registered version of the software.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds