Problem with Lavasoft's Ad-Aware

M

Mahler

I have run Lavasoft's Ad-Aware Personal several times and
it always stops when it gets to a specific CLSID in the
registry (it contains a InProcServer32, of which there
are several in the registry). Does anybody knows what is
happening and why Ad-Aware stops?

Thanks for your help.
 
M

Mahler

Andre:

Tried your suggestion but it did not work. Ad-Aware stops
at the same CLSID always even in safe mode. MS AntSpy did
not detect anything new in safe mode either.

I am at lost with this problem, as Ad-Aware shows several
suspects in the report window but I can not know what
they are as it stops working at the CLSID mentioned.
 
P

plun

After serious thinking Mahler wrote :
I am at lost with this problem, as Ad-Aware shows several
suspects in the report window but I can not know what
they are as it stops working at the CLSID mentioned.

Hi

Try adaware again with these settings in safe mode:

1: Run the WebUpdate feature. (Click on the Globe icon, Click connect,
Click OK, Click Finish.)

2: Set up the Configurations (Gear wheel at the top) as follows:

General Button => Safety & Settings: Check (Green) all three.
Advanced Button => Logfile Detail Level: All options under this should
be checked (Green).
Tweak Button
==> Scanning Options: Check "Obtain command line of scanned processes"
==> Log Files: Please check only:

* "Include basic Ad-Aware settings in logfile"
* "Include additional Ad-Aware settings in logfile"

Click on "Proceed"

3: Click on "Scan Now"

4: Please deselect "Search for negligible risk entries" as negligible
risk entries (MRU's) are not considered to be a threat. (If MRU's are
included in your logfile they may be removed. Advice will not be
provided on MRU's as they are the user's choice.)

5: Run the scanner using the Full System Scan (Perform Full System
Scan) mode. A full scan is the in-depth scan mode that scans your whole
computer for Spyware infections. When performing a full scan the
following scan settings are used:

* Full Memory Scan is performed
* Registry Scan is performed
* Deep Registry scan is performed
* Cookie-Scan is performed
* Favorites are scanned
* Hosts file is scanned
* Conditional scans are performed
* Archive files are scaned
* All fixed drives are scanned
 
M

Mahler

Tried your suggestion. It did not work either. I ran the
regedit to see what is in the registry.

I found that the specific CLSID is identified as
Microsoft PhotoDraw Event Manager. The InProcServer32 is
identified as C:\Program Files\Common Files\Microsoft
Shared\Grphflt\fpx32.flt.

This CLSID appears 12 consecutive times in the registry.

Any additional suggestions?
 
A

Andre Da Costa

Get HijackThis.exe from
http://tomcoyote.org/hjt/hjt199//HijackThis.exe

Save it to C:\hjt (new folder) then Open it and select
Scan and Save Log. Note where you saved the log then send
it to Ron Kinner as an attachment. He can probably
identify the problem and tell you how to get rid of it for
good.

Ron email address. (e-mail address removed)
He will tell you what to do next. Put Hijack in the
subject so he will know it's not spam.

For information
HijackThis tutorial:
http://www.bleepingcomputer.com/forums/index.php?
showtutorial=42

If the malware problem comes back further specialised
assistance is available via the Hijackthis forum at
http://forum.aumha.org - make sure you read the top
announcements about pre-post steps you should take before
generating a hijackthis log.

http://www.bleepingcomputer.com/files/killbox.php

Here's a few of the reputable spyware forums where you'll
be able to find assistance. Please read the guidelines of
the one you choose prior to posting there :

http://www.bleepingcomputer.com/forums/forum22.html
http://forums.net-integration.net/index.php?showforum=32
http://forum.aumha.org/viewforum.php?f=30
http://spywarewarrior.com/viewforum.php?
f=2&sid=3ce3e4c9a40b25268d1bac3189d22184
http://computercops.biz/forum67.html
 
P

plun

It happens that Mahler formulated :
Tried your suggestion. It did not work either. I ran the
regedit to see what is in the registry.

I found that the specific CLSID is identified as
Microsoft PhotoDraw Event Manager. The InProcServer32 is
identified as C:\Program Files\Common Files\Microsoft
Shared\Grphflt\fpx32.flt.

This CLSID appears 12 consecutive times in the registry.

Any additional suggestions?

Strange... ? Try CCleaner, the third tab cleans registry.
Run all tabs for total removal of all junk.

www.ccleaner.com
 
M

Mahler

Thanks Andre. I have already done the scan with HJT.
However, who is Mr. Ron Kinner?
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top