1
   

Error message when running Spybot, Ad-Aware, etc.

 
 
merstar
 
Reply Sun 21 Nov, 2004 02:31 pm
I posted this awhile ago, but received no responses, so I'm trying again. For the past few months, I can't run Ad-Aware or Spybot. Just before the scan ends I get the following error message. HELP!

"This program has performed an illegal operation and will be shut down. If the problem persists, contact the program vendor.

DETAILS:

AD-AWARE (or Spybot) caused an invalid page fault in
module KERNEL32.DLL at 0167:bff72872.
Registers:
EAX=00010000 CS=0167 EIP=bff72872 EFLGS=00010246
EBX=00000176 SS=4397 ESP=0092a604 EBP=00006764
ECX=0000ffff DS=016f ESI=0000570f FS=0000
EDX=00005f07 ES=016f EDI=0000016f GS=0000
Bytes at CS:EIP:
8b 4d e0 03 e9 0f b7 dc 8e d7 8d 24 19 33 ff 8e
Stack dump:
00402509 005a65c8 00402511 00000034 00000034 bff7b9b6 81783784 bff9ad1b 00923000 005a65c8 00404456 004022e2 0092d690 00000000 00000545 0270a588"
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 3,488 • Replies: 41
No top replies

 
Don77
 
  1  
Reply Sun 21 Nov, 2004 02:36 pm
Hi merstar
A few questions for you,
Are you only having this problem with these 2 programs ?
What version of Ad-aware, what version of Spybot?
Have you tried downloading HijackThis?
If you have it already post a log, If not let me know and I will give you a link

Have you tried running them in safe mode,
0 Replies
 
shewolfnm
 
  1  
Reply Sun 21 Nov, 2004 02:36 pm
Maybe one of these web sites might have a FAQ section that could help you.
I had a similar problem a few months back , though not the same error message..end result I had to remove/reinstall.

http://spybot.safer-networking.de/en/tutorial/index.html

http://www.majorgeeks.com/

http://www.javacoolsoftware.com/support.html


I dont know if these will help , but it is a variety.. maybe one of them has some info you could use.
0 Replies
 
shewolfnm
 
  1  
Reply Sun 21 Nov, 2004 02:38 pm
Don77 wrote:

Have you tried downloading HijackThis?



Hi don.

I have been looking for the prog. hijack this and I have not found anything on it. Do you have a link?
I would appreciate it!
Thanks !
0 Replies
 
Don77
 
  1  
Reply Sun 21 Nov, 2004 02:43 pm
Sure can shewolfnm, will give the usual speech with it as well Very Happy

Please go Here and unzip the newest version of HJT into a new dedicated folder,
Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it hjt.
Unzip HijackThis into this folder. Launch Hijack This, then press Scan, and press Save Log
This will generate a text file that will list all running processes, all applications that are loaded automatically when you start Windows, and more.
Most things are harmless and needed so don't make any changes.
post a log here please.

You having any problems in particualr ?
0 Replies
 
shewolfnm
 
  1  
Reply Sun 21 Nov, 2004 02:48 pm
No problems. I have just been reading alot of the threads about computer problems and have wanted to install this on my computer to assist with the hundreds of pop up adds.
Thanks for the info.
0 Replies
 
Don77
 
  1  
Reply Sun 21 Nov, 2004 03:02 pm
Quote:
No problems. I have just been reading alot of the threads about computer problems and have wanted to install this on my computer to assist with the hundreds of pop up adds.


HijackThis will not make them go away, You have to be carefull using it, Removing the wrong items could do some major damage,

Why don't you post a log and lets have a look at it,
Your choice,
0 Replies
 
shewolfnm
 
  1  
Reply Sun 21 Nov, 2004 03:03 pm
Wow.....
I have alot more on my plate then I can handle. Are you willing to help me sort through this Don?
It would be appreciated beyond belief!!!! Very Happy

Here is my hijak report..


Logfile of HijackThis v1.98.2
Scan saved at 3:01:14 PM, on 11/21/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\McAfee\McAfee VirusScan\Avsynmgr.exe
C:\WINDOWS\system32\cisvc.exe
C:\Program Files\McAfee\McAfee VirusScan\VsStat.exe
C:\Program Files\McAfee\McAfee VirusScan\Vshwin32.exe
C:\WINDOWS\System32\igfxtray.exe
C:\WINDOWS\System32\hkcmd.exe
C:\WINDOWS\BCMSMMSG.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe
C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Dell\EUSW\Support.exe
C:\WINDOWS\System32\CDDBCont.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\WINDOWS\System32\rundll32.exe
C:\Program Files\QuickTime\qttask.exe
C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
C:\Program Files\AutoUpdate\AutoUpdate.exe
C:\WINDOWS\System32\davache.exe
C:\Program Files\McAfee\McAfee Firewall\CPD.EXE
C:\Program Files\McAfee\McAfee VirusScan\Avconsol.exe
C:\Program Files\McAfee\McAfee VirusScan\Webscanx.exe
C:\Program Files\McAfee\McAfee Firewall\CPDCLNT.EXE
C:\Program Files\Common Files\Network Associates\McShield\Mcshield.exe
C:\WINDOWS\System32\NuzK60.exe
C:\WINDOWS\System32\JgvW.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Program Files\CxtPls\CxtPls.exe
C:\WINDOWS\System32\a2b7.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\cidaemon.exe
C:\America Online 5.0\waol.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\CHJT\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.able2know.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.dellnet.com
R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
R3 - URLSearchHook: IncrediFindBHO Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL
O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Program Files\CxtPls\cxtpls.dll
O2 - BHO: NavErrRedir Class - {0199DF25-9820-4bd5-9FEE-5A765AB4371E} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~2.DLL
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: (no name) - {7B55BB05-0B4D-44fd-81A6-B136188F5DEB} - C:\WINDOWS\questmod.dll
O2 - BHO: (no name) - {A78860C8-EE1A-46DF-A97F-E3E6D433E80B} - C:\WINDOWS\SYSTEM32\f0aiai3.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: (no name) - {12EE7A5E-0674-42f9-A76B-000000004D00} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM\..\Run: [BCMSMMSG] BCMSMMSG.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [Alogserv] C:\Program Files\McAfee\McAfee VirusScan\alogserv.exe
O4 - HKLM\..\Run: [McAfee Guardian] "C:\Program Files\McAfee\McAfee Shared Components\Guardian\CMGrdian.exe" /SU
O4 - HKLM\..\Run: [MMTray] C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mm_tray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [2LRX2W83X2T3MQ] C:\WINDOWS\System32\Vju9.exe
O4 - HKLM\..\Run: [fee68778c4c6] C:\WINDOWS\System32\CDDBCont.exe
O4 - HKLM\..\Run: [A70F6A1D-0195-42a2-934C-D8AC0F7C08EB] rundll32.exe E6F1873B.DLL,D9EBC318C
O4 - HKLM\..\Run: [98D0CE0C16B1] rundll32.exe D0CE0C16B1,D0CE0C16B1
O4 - HKLM\..\Run: [{12EE7A5E-0674-42f9-A76B-000000004D00}] rundll32.exe stlb2.dll,DllRunMain
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe"
O4 - HKLM\..\Run: [t7tf36R] davache.exe
O4 - HKLM\..\RunOnce: [0arlmb.exe] C:\WINDOWS\System32\0arlmb.exe /k
O4 - HKCU\..\Run: [McAfee.InstantUpdate.Monitor] "C:\Program Files\McAfee\McAfee Shared Components\Instant Updater\RuLaunch.exe" /startmonitor
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exe
O4 - Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O4 - Global Startup: America Online Tray Icon.lnk = C:\America Online 5.0\aoltray.exe
O4 - Global Startup: MyWebSearch Email Plugin.lnk = C:\Program Files\MyWebSearch\bar\1.bin\MWSOEMON.EXE
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\googletoolbar.dll/cmsearch.html
O8 - Extra context menu item: &Search - http://bar.mywebsearch.com/menusearch.html?p=ZNxdm006XXUS
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\googletoolbar.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\googletoolbar.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\googletoolbar.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\googletoolbar.dll/cmtrans.html
O9 - Extra button: (no name) - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\TD.exe
O9 - Extra 'Tools' menuitem: Turbo Download - {1A00C40B-DA85-4aa3-A67F-582D9347EECD} - C:\WINDOWS\System32\TD.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
O9 - Extra button: (no name) - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Program Files\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O17 - HKLM\System\CCS\Services\Tcpip\..\{A2717D41-700E-4FC8-A6B9-F3B9367D7D55}: NameServer = 205.188.146.146
0 Replies
 
Don77
 
  1  
Reply Sun 21 Nov, 2004 03:17 pm
Quote:
Wow.....
I have alot more on my plate then I can handle. Are you willing to help me sort through this Don?
It would be appreciated beyond belief!!!!

Wow is right, I'll be glad to,

A few things to do here,
First
You have a Peper Trojan
Go here and run the The Removal Tool
. You must be connected to the internet for it to work.
Close all open windows then run it. It will run in a flash so don't think it hasn't worked!
Reboot

Next

Click on Start.
Click on Settings.
Click on Control Panel.
From the Control Panel, double-click on Add/Remove Programs.
Click on the Install/Uninstall tab in the Add/Remove Programs Properties window.
Locate the following programs MyWebSearch, 'My Search Bar', 'MyWay Speed Bar' or 'My Web Search Bar'.
Ebates_MoeMoneyMaker
and if found select it.
Click on the Add/Remove button.
After removal of software, you may be prompted to reboot.

Do so.
Then reboot


Next
Follow the steps outlined in this Post

Ignore the section about HJT, Also Empty your Recycle bin after you clean out your temp Folders,


Post back afresh log when your done please,
We will have a bit more to clean up
0 Replies
 
shewolfnm
 
  1  
Reply Mon 22 Nov, 2004 05:01 pm
Don,

hi there . I am sorry I have not posted a new report. My daughter recieved her shots yesterday and has been feeling truly awful all day. I have not been able to sit down and do everything step by step. Though I am almost through with the reccomendations you gave on the information thread, it probally wont be until tonight when I can give you a new hijak report.
Thanks again though for taking the time to help me with this. I cant tell you how much I appreciate it!!!
:-)
0 Replies
 
Don77
 
  1  
Reply Mon 22 Nov, 2004 07:08 pm
No problem shewolfnm,
Take care of the little one,
I will be popping in and out, I will keep an eye out for your reply,
0 Replies
 
shewolfnm
 
  1  
Reply Tue 23 Nov, 2004 08:18 am
I have started my own thread so that I dont flood this one with my information.

:-)

http://www.able2know.com/forums/viewtopic.php?p=1032787#1032787
0 Replies
 
merstar
 
  1  
Reply Tue 23 Nov, 2004 04:28 pm
Don77 wrote:
Hi merstar
A few questions for you,
Are you only having this problem with these 2 programs ?
What version of Ad-aware, what version of Spybot?
Have you tried downloading HijackThis?
If you have it already post a log, If not let me know and I will give you a link

Have you tried running them in safe mode,


Hello Don,
Yes, I only have problems with these two programs. Haven't tried HijackThis. The versions are: AdAwareSEPersonal and Spybot Search and Destroy 1.3. I have uninstalled and reinstalled, but to no avail. They did work a few months ago, so I don't understand it. Could my ISP have anything to do with it? It has some kind of anti-virus anti-parasite program included in its software package. I have Earthlink Total Access 2004, although I've had it for awhile, way before the problems started with the AdAware and Spybot. FYI, I have no anti-spyware running at Start-up, though I noticed something in my Start-up configuration, called SpySweeper, but it's unchecked so doesn't run at start-up. I never downloaded this program, so I'm wondering if it's connected to the Earthlink software - it doesn't show up on "AddRemove" programs.

No, I haven't tried running them in safe mode. How do I do that, and afterward how do I get the computer back to "normal" mode?

Thanks for your help!
0 Replies
 
merstar
 
  1  
Reply Tue 23 Nov, 2004 04:32 pm
shewolfnm wrote:
Maybe one of these web sites might have a FAQ section that could help you.
I had a similar problem a few months back , though not the same error message..end result I had to remove/reinstall.

http://spybot.safer-networking.de/en/tutorial/index.html

http://www.majorgeeks.com/

http://www.javacoolsoftware.com/support.html


I dont know if these will help , but it is a variety.. maybe one of them has some info you could use.


Thanks for the links - will check them out.
0 Replies
 
Don77
 
  1  
Reply Tue 23 Nov, 2004 04:49 pm
Hi merstar,
Spysweeper probably was a part of Earthlink, I m not possitive about that, but it is a legit program,

You can get to safe mode, by tapping the F8 key as your computer is starting up, it will bring ytou to a screen look for Safe Mode highlight it hit enter,
To return to normal mode, Restart the computer normally.

Post a highjackthis log and lets take a look
0 Replies
 
merstar
 
  1  
Reply Wed 24 Nov, 2004 11:51 am
Don77 wrote:
Hi merstar,
Spysweeper probably was a part of Earthlink, I m not possitive about that, but it is a legit program,

You can get to safe mode, by tapping the F8 key as your computer is starting up, it will bring ytou to a screen look for Safe Mode highlight it hit enter,
To return to normal mode, Restart the computer normally.

Post a highjackthis log and lets take a look


Hi Don,

If Spysweeper is running in the background, could that interfere with running AdAware and Spybot? I can't find it, however, in "Add/Remove" programs - it's only listed in the start-up, but unchecked.

I tried doing the safe-mode routine, and still got the same error message, so I'm back to square one. I don't understand this -it's sooooo frustrating.

What exactly should I be downloading at highjackthis.com?

Thanks for your help!
0 Replies
 
Don77
 
  1  
Reply Wed 24 Nov, 2004 05:03 pm
Hi merstar
It shouldn't affect it,

Here is a direct link for HJT From here
unzip the newest version of HJT into a new dedicated folder,
Create a folder on the C: drive called C:\HJT.
You can do this by going to My Computer (Windows key+e) then double click on C: then right click and select New then Folder and name it hjt.
Unzip HijackThis into this folder. Launch Hijack This, then press Scan, and press Save Log

This will generate a text file that will list all running processes, all applications that are loaded automatically when you start Windows, and more.
Most things are harmless and needed so don't make any changes.
post a log here please.
0 Replies
 
merstar
 
  1  
Reply Thu 25 Nov, 2004 11:32 pm
Hello Don,
Here's the logfile:

Logfile of HijackThis v1.97.7
Scan saved at 12:22:31 AM, on 11/26/04
Platform: Windows 98 Gold (Win9x 4.10.1998)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE
C:\WINDOWS\SYSTEM\MSTASK.EXE
C:\WINDOWS\EXPLORER.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
C:\CSAFE\AUTOCHK.EXE
C:\PROGRAM FILES\ZONE LABS\ZONEALARM\ZLCLIENT.EXE
C:\PROGRAM FILES\EARTHLINK 5.0\CONMGR.EXE
C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE
C:\PROGRAM FILES\EARTHLINK TOTALACCESS\TASKPANL.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\PROGRAM FILES\EARTHLINK TOTALACCESS\FASTLANE\IPCLIENT.EXE
C:\PROGRAM FILES\INTERNET EXPLORER\IEXPLORE.EXE
C:\WINDOWS\SYSTEM\PSTORES.EXE
C:\WINDOWS\SYSTEM\DDHELP.EXE
C:\PROGRAM FILES\ACCESSORIES\WORDPAD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
C:\HJT - HIJACK THIS\HIJACKTHIS.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http:///
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://start.earthlink.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.earthlink.net/partner/more/msie/button/search.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.earthlink.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://websearch.drsnsrch.com/sidesearch.cgi?id=
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAM FILES\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL
O2 - BHO: EarthLink Popup Blocker - {4B5F2E08-6F39-479a-B547-B2026E4C7EDF} - c:\Program Files\EarthLink TotalAccess\PnEL.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O3 - Toolbar: Pop-Up Blocker - {D7F30B62-8269-41AF-9539-B2697FA7D77E} - c:\Program Files\EarthLink TotalAccess\PnEL.dll
O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [ConfigSafe] C:\CSAFE\AUTOCHK.EXE
O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER\DPPS2.EXE"
O4 - HKLM\..\Run: [vrjilthwnlhx] C:\WINDOWS\SYSTEM\ukgftg.exe
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [ConMgr.exe] "C:\PROGRAM FILES\EARTHLINK 5.0\CONMGR.EXE"
O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKCU\..\Run: [PopUpStopperFreeEdition] "C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER FREE EDITION\PSFREE.EXE"
O4 - HKCU\..\Run: [E6TaskPanel] "C:\PROGRAM FILES\EARTHLINK TOTALACCESS\TASKPANL.EXE" -winstart
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O12 - Plugin for .pcm: C:\PROGRA~1\INTERN~1\PLUGINS\NpCurMem.dll
O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/ansi/iuctl.CAB?37876.3487152778
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
0 Replies
 
timberlandko
 
  1  
Reply Fri 26 Nov, 2004 12:19 am
nevermind - I screwed up one of the links Embarrassed - I'll get back to you real quick Rolling Eyes

Second Edit - OK - now all the links work - sorry for any confusion my clumsy typing caused


merstar, you're Don's patient, and I haven't looked over your log real well yet - there does appear to be a problem or two there in your R1 and your O2 sections, but if you and he don't mind a second opinion, I'd recommend you uninstall both AdAware and Spybot, then search-for-and delete all files and folders named or containing "AdAware", "LavaSoft", "Spybot", and "PepiMK". Then empty your Temp folder (usually C:\Temp), your Windows Temp folder (usually C:\WINDOWS\TEMP), and your Temporary Internet Files (usually C:\WINDOWS\Temporary Internet Files) - just empty those 3 folders, don't delete them. Then, empty your recycle bin and reboot. Next, go to Windows Update and be certain yor Windows and your IE are fully updated. When that is all good, go to LavaSoft, and follow the instructions to download AdAware SE. As soon as you've downloaded it, update it and configure it for full system scan, and run it, letting it fix whatever it finds, then reboot. Now go to Safer Networking and likewise download, update, configure, and run the latest version of SpyBot Search and Destroy V (1.3.1).
0 Replies
 
Don77
 
  1  
Reply Fri 26 Nov, 2004 07:15 am
Don't mind at all Timber,

In fact merstar after you have finsihed with the instructions Timber has spelled out above,
Please go Here and unzip the newest version of HJT
Scoll down the page and find HJT. Download it same way you did before and save it to the same folder,
Remove the older version first please,

After you have finshed all of the above
Post back a fresh log please
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Error message when running Spybot, Ad-Aware, etc.
Copyright © 2025 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.03 seconds on 05/03/2025 at 11:09:30