Click here for AnswerPool.com Home page


Google

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    Ad Aware

Moderators: Dwight
Go
Post
Find
Notify
Tools
Reply
  
  Login/Join 
Enthusiast
Picture of luckyladee
Posted
I just downloaded the SP2 for XP and then I did all my weekly chores on my computer.
Stinger, Spy-bot and then adaware. Stinger and Spy-Bot were done all clean files. When I got to adaware it said:
24 running processes
39 objects recognized
0 objects ignored
39 new objects
0 processes identified
16 registry identified
4 registry values identified
17 files identified
2 folders identified
I really did not know what to do about this and by clicking here and there I ended up with 35 objects which I immediately quarantined. After that I redid the adaware scan and all is clean except I still have 35 Objects in quarantine.
This has never happened to me before and I don't really understand adaware at all. All I was told is I should scan once a week which is what I do but never has this happened. What should I do? I sure hope it is not too complicated because I don't have much confidence in myself that I would be able to fix this. Thank you in advance for all you have done for me so far.
 
Posts: 255 | Location: Quebec Canada | Registered: 02-23-04Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Posted Hide Post
Ad-ware should have let you see the objects, most would be mundane things like Tracking Cookies. By right clicking on an object you get many options, one of them is to get a brief description of the object.

However the title will be "tracking Cookie" "Mal ware" "spy ware" etc.

It should also tell you what those folders are, and what the files are.

It is possible that SP2 has files attached which are read a spy or ad ware. However the details will let you know if you should put it on the ignore list or not.

David
 
Posts: 4002 | Location: Leaving land, heading for the ocean | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
There is a log file kept which shows what has been found after scanning Smile
Its a lot easier to read than the main Window Red Face
By the way, there is an update available (2 days old) Press the Globe link with the spy glass on top of the page click the Connect button (to download)then the Configure button(to save) when it's loaded only takes 10 seconds Smile
Worth another scan with this new data? Roll Eyes
 
Posts: 13482 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
I have not D/led SP2 yet
But from early reviews in Computer Mags there are a lot of setup changes to do Frown
For Instance: New Microsoft Firewall settings which is switched on as default besides your own Firewall. 1 has to be switched off or detuned (To avoid conflicts)? ConfusedNew one is a high spec type Smile
So we are all going to be Tiptoeing through this new setup minefield till at least the New Year? Frown
 
Posts: 13482 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Gold Enthusiast
Posted Hide Post
I have ordered the SP2 disc from MS, and plan to scan it with AdAware and AVg when I get it, (paranoid anymore). LOL Your Adaware scan as said in the posts above should tell you what those objects are.

chris
 
Posts: 822 | Location: Wytheville, va. USA | Registered: 09-03-02Reply With QuoteEdit or Delete MessageReport This Post
Enthusiast
Picture of luckyladee
Posted Hide Post
I copied what is quarantined could someone tell me what I should do with this:

======================================================

IBIS TOOLBAR
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[0]=RegKey : CLSID\{339BB23F-A864-48C0-A59F-29EA915965EC}
obj[1]=RegKey : CLSID\{8952A998-1E7E-4716-B23D-3DBE03910972}
obj[2]=RegKey : CLSID\{F1616B86-9288-489D-B71A-0CCF2F1A89DA}
obj[3]=RegKey : CLSID\{FF76A5DA-6158-4439-99FF-EDC1B3FE100C}
obj[4]=RegKey : PROTOCOLS\Handler\tpro
obj[5]=RegKey : PROTOCOLS\Name-Space Handler\res\toolbar.ResProtocol
obj[6]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{8952A998-1E7E-4716-B23D-3DBE03910972}
obj[7]=RegKey : toolbar.ResProtocol
obj[10]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\STO
obj[11]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\TTOOL_UNINSTALL
obj[12]=RegKey : Software\Toolbar
obj[13]=RegKey : SOFTWARE\Toolbar
obj[14]=RegKey : SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\WinTools
obj[15]=RegKey : SOFTWARE\WinTools
obj[16]=RegKey : SYSTEM\ControlSet001\Services\WinToolsSvc
obj[17]=RegKey : SYSTEM\ControlSet002\Services\WinToolsSvc
obj[18]=RegKey : SYSTEM\CurrentControlSet\Services\WinToolsSvc
obj[19]=RegValue : SOFTWARE\Microsoft\Windows\CurrentVersion\Run
obj[20]=Folder : c:\program files\common files\WinTools
obj[21]=Folder : c:\program files\Toolbar
obj[22]=File : c:\program files\common files\wintools\wtoolsa.exe
obj[23]=File : c:\program files\common files\wintools\wtoolsb.dll
obj[24]=File : c:\program files\common files\wintools\wsup.exe
obj[25]=File : c:\program files\common files\wintools\wtoolss.exe
obj[26]=File : c:\program files\common files\wintools\wtoolsc.cfg
obj[27]=File : c:\program files\common files\wintools\wtoolsd.cfg
obj[28]=File : c:\program files\common files\wintools\wtoolsp.cfg
obj[29]=File : c:\program files\common files\wintools\rmhgxlmu.wzg
obj[30]=File : c:\program files\toolbar\toolbar.dll
obj[31]=File : c:\program files\toolbar\iexploreskins.exe
obj[32]=File : c:\program files\toolbar\xzxsv.wzg
obj[33]=File : c:\program files\toolbar\yildhvi.olt
obj[34]=File : c:\program files\toolbar\cursors

POSSIBLE BROWSER HIJACK ATTEMPT
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
obj[8]=RegData : Software\Microsoft\Internet Explorer\Main
obj[9]=RegData : Software\Microsoft\Internet Explorer\Search
 
Posts: 255 | Location: Quebec Canada | Registered: 02-23-04Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
LL
From what I see especially the bottom 2 items
I get the feeling that there is nothing here Confused
The new configuration makes it look like Internet Explorer is being a piece of spyware Confused
My advice? Don't touch it until we have a think about it.

To confirm this I would need to see the log from the scan of HiJackThis a small free program download from www.spychecker.com/program/hijackthis.html
 
Posts: 13482 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
Also download run this free Virus checker Cool
http://housecall.trendmicro.com/housecall/start_corp.asp
And see if anything is produced? ...hopefully nothing Roll Eyes
Admin! All I can see here, is the Quote button.
Means NO edits are possible Frown Cannot report this either as the "Alert" Button missing also Frown
 
Posts: 13482 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Gold Enthusiast
Picture of Ewood27
Posted Hide Post
I downloaded SP2 a couple of days ago (to XP Home) and have just run Spybot, which turned up one registry entry; McAfee VirusScan, which came up clean; and AdAware, which produced the usual number of running processes, and just one hit:

Possible browser hijack attempt : Software\Microsoft\Internet Explorer\MainStart Pageabout:blank

Possible Browser Hijack attempt Object recognized!
Type : RegData
Data : "about:blank"
Rootkey : HKEY_CURRENT_USER
Object : Software\Microsoft\Internet Explorer\Main
Value : Start Page
Data : "about:blank"

My home page is "about: blank".

Agnitum Outpost firewall then warned me that my home page had been changed, and did I want to undo the change? This time I said No, keep the change, and it turned out to be MSN Messenger on the new home page.

SP2 seems to have added about 2 Gb to the contents of my hard disk. It also slows down the boot-up sequence. Furthermore, it took a LOT longer than the 30 minutes they said to download and install it.
 
Posts: 744 | Location: Surrey, England | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Enthusiast
Picture of luckyladee
Posted Hide Post
quote:
Originally posted by bedstor:
There is a log file kept which shows what has been found after scanning Smile
Its a lot easier to read than the main Window Red Face
By the way, there is an update available (2 days old) Press the Globe link with the spy glass on top of the page click the Connect button (to download)then the Configure button(to save) when it's loaded only takes 10 seconds Smile
Worth another scan with this new data? Roll Eyes


Did that and my files are still quarantined
 
Posts: 255 | Location: Quebec Canada | Registered: 02-23-04Reply With QuoteEdit or Delete MessageReport This Post
Diamond Enthusiast

Picture of bedstor
Posted Hide Post
Hi LL
As I said earlier I think the Adaware program picked up a Legit Internet Explorer system file and decided it was suspect Frown
To double check and then delete the quarantined file do this:
Have you updated Adaware to the latest Version?
01R339 26.08.2004 build 273
Signatures total:28779
If that is correct? Simply open the quarantined file hit the blue "Restore" button. Then run the Adaware scan again .
This time there may be a different number found? Hopefully less Roll Eyes Quarantine the findings and whatever the outcome I think it will be safe to delete this file. Smile
Before you do this and stop your IE browser going wrong Go to the Control Panel Press Start and it should be seen On the Menu In here locate and open the Add /Remove Program Folder
Open the window look to the side of the list and click the button "Add Remove Windows components" button on the list
From here its risky (Could do with Dwights Input Roll Eyes) I do know there is a file repair option included in the Uninstall procedure But.. is there an easier way of accessing this without going via the Control Panel?

My answer has brought up a question which I am not sure of the answer Confused
If you are willing to delete that Adaware Quarantine file and nothing happens We can breath easy Razz Otherwise have a Windows CD on standby if it goes wrong! Roll Eyes
Keep us informed on this Thanks.
 
Posts: 13482 | Location: 6 miles west of Wigan UK | Registered: 06-05-02Reply With QuoteEdit or Delete MessageReport This Post
Gold Enthusiast
Posted Hide Post
AdAware's quarantined items can be safely deleted. While in quarantine, they are already out of the equation as far as the computer is concerned.
 
Posts: 530 | Location: Mississauga, Ontario, Canada | Registered: 06-03-02Reply With QuoteEdit or Delete MessageReport This Post
Enthusiast
Picture of luckyladee
Posted Hide Post
quote:
Originally posted by bedstor:
Also download run this free Virus checker Cool
http://housecall.trendmicro.com/housecall/start_corp.asp
And see if anything is produced? ...hopefully nothing Roll Eyes
Admin! All I can see here, is the Quote button.

I did and nothing showed up. I then purchased Norton SystemsWorks and installed that on my machine, scanned all the files ans nothing showed up. I dis installed adaware, reinstalled it and scanned anow nothing shows up. I will keep my fingers crossed but all seems OK now.
Means NO edits are possible Frown Cannot report this either as the "Alert" Button missing also Frown
 
Posts: 255 | Location: Quebec Canada | Registered: 02-23-04Reply With QuoteEdit or Delete MessageReport This Post
 Previous Topic | Next Topic powered by eve community  
 

    AnswerPool.com  Hop To Forum Categories  Computers  Hop To Forums  Security Issues    Ad Aware

© 2002-2008 AnswerPool.com



Visit DiscussionPool.com!