Problems running AD-Aware SE Personal edition after installation

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by billy9215, Nov 24, 2004.

  1. billy9215

    billy9215 Private E-2

    Downloaded this program to remove spyware.

    I tried running the software after installing it but got this error message:

    This program has performed an illegal operation and will be shut down.

    Details are below:

    AD-AWARE caused an exception eedfadeH in module <unknown> at 0000:00000000.
    Registers:
    EAX=00000000 CS=0000 EIP=00000000 EFLGS=00000000
    EBX=00000000 SS=0000 ESP=00000000 EBP=00000000
    ECX=00000000 DS=0000 ESI=00000000 FS=0000
    EDX=00000000 ES=0000 EDI=00000000 GS=0000
    Bytes at CS:EIP:


    Anyone help?

    Sorry if dumb question.

    Thanks much
     
    Last edited: Nov 24, 2004
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. billy9215

    billy9215 Private E-2

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    OK! Let me know the results.
     
  5. billy9215

    billy9215 Private E-2

    Well, I went to the site, there are 2 riched20.dll and 2 riched32.dll files, which ones do I select?

    Also, do I directly download them into Windows/System32 Folder or do they go in the Drivers Subfolder under System32?

    Thoughts?

    Incidentally, am running on Windows 98 SE.

    Thanks much
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    For Win98, those files belong in c:\windows\system

    First check to see if you have them already.

    I would guess the ones you need are:

    riched20.dll (431376 bytes)
    riched32.dll (183264 bytes)


    You should probably get the below file two. It could be missing too.

    richtx32.ocx (195856 bytes)
     
  7. billy9215

    billy9215 Private E-2

    Hello again, well downloaded both riched.dll and guess what the AD-AWARE SE starting running, you who!!!

    It found several suspect files, put them in quarantine, restarted the computer and guess what...still have the about.blank default homepage on IE. Also still have those annoying popups.

    What to do next?

    Well, I downloaded Spybot, again the freeware version, it found only one suspect file, here is the message it gave me:

    DSO Exploit: Data source object exploit (Registry change, nothing done)
    HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

    What to do?

    Thanks much

    Cheers
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Install this update for Spybot: Spybot - Search and Destroy DSO Exploit Fix

    Have you run ALL the steps from: READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    If so, you should read the tutorial in this Sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis log file as an attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT

    Make sure you have HJT version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment.
     
  9. billy9215

    billy9215 Private E-2

    Hi again, have installed some of the spyware programs you recommend, however, still have adware, spyware problemos..let's just put that aside for now.

    I get the following error messages when I try to open "My computer" or
    "Settings, control panel":

    Here are the messages:

    EXPLORER caused an invalid page fault in
    module JAVAOD32.DLL at 0167:01c5be53.
    Registers:
    EAX=01c72877 CS=0167 EIP=01c5be53 EFLGS=00010202
    EBX=bfe20080 SS=016f ESP=01c2e8c8 EBP=01c2e8d4
    ECX=01c2ee34 DS=016f ESI=01c66aa1 FS=1917
    EDX=000000f8 ES=016f EDI=bfe2ffff GS=0000
    Bytes at CS:EIP:
    8a 27 47 38 c4 74 f2 2c 41 3c 1a 1a c9 80 e1 20
    Stack dump:
    bfe20080 bfe20000 bfe20000 01c66aa0 01c41b7e bfe2ffff 01c66aa0 01c66aac 01c45d40 0000002c 01c66aa0 01c41c4e 6300c36f 01c66aa0 01c66aac 01c45d40

    --------------------------------------------------------------

    EXPLORER caused an invalid page fault in
    module KERNEL32.DLL at 0167:bff8ac13.
    Registers:
    EAX=00000000 CS=0167 EIP=bff8ac13 EFLGS=00000246
    EBX=00000000 SS=016f ESP=01bdeb44 EBP=01bdec7c
    ECX=01c1f2c8 DS=016f ESI=01c1f2e4 FS=2edf
    EDX=c00309cc ES=016f EDI=00000000 GS=0000
    Bytes at CS:EIP:
    a1 10 9d fc bf 50 e8 96 95 fe ff ff 76 04 e8 35
    Stack dump:
    bff8abfa 01bf6366 01c1f2e4 00000000 00000000 01bf0000 6b6a6968 6f6e6d6c 73727170 77767574 7b7a7978 01bdebb0 00000228 01e305d0 00000804 bff7a3a0


    Would you have a solution for these two faults?

    Thanks
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Last edited: Nov 29, 2004
  11. billy9215

    billy9215 Private E-2

    Upon turning on the computer one morning, there was a Windows message
    saying they were restoring the registry using a backup setting (I don't know what was done to deserve this but I accepted). I clicked enter and it removed all traces of the spyware..opened the IE browser and no more about.blank or adware/spyware popups.

    Go figure.

    Cheers
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That's cool! I guess Christmas came early! ;)
     
  13. billy9215

    billy9215 Private E-2

    I'm doing a little reading on the Windows site pertaining to registy backups.

    In Windows 98, Windows creates a backup log each day that can be recovered by booting in safe mode, thus removing any files that were installed recently (spyware included it seems).

    Here is the link for manual restoring in case this happens to anyone.

    http://support.microsoft.com/kb/221512/EN-US/

    Might solve a lot of peoples' problems.

    Cheers
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not typically! These are just copies made at each successful boot of your PC. They are not backup to certain dates in time. Each time you boot up (whether there are malware problems or not) a copy is safed (only 5 copies are saved). So if you have simply booted 5 times since getting the malware problems, the old (good) registry save is already gone.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds