This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Can You Please Look At This Hijackthis Log

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I have Win2k with SP4. All Updates for Win2k have been installed as of 12/31/04. In addition, I have current updates for these programs. Ad-aware SE Plus Version 1.05 and Spybot 1.3. I also have Spyware Blaster version 3.2 and Norton Internet Security and Have run a complete scan of all my computer. I also have run a complete PandaSoftware Antivirus scan.

In addition, I have completely uninstalled and re-installed Ad-Aware SE Plus.
After all of this, I then "click on Ad-Watch" from Ad-Aware.

Then what happens is that Spybot-SD Resident tells me that it notices that registry entries for the "exe" files of many programs are being deleted. I try to say "deny", but it's too late. After the "clicking" of Ad-Watch, my Norton Internet Security failes to start and is corrupted along with many other programs.

I am able to restore from a backup and duplicate the problem. If I don't click on Ad-Watch, then no problem seems to appear.
I have ran Hijack and am including the file log:
Can you please help?

E-Mail address edited out


// begin of hijack log
Logfile of HijackThis v1.97.7
Scan saved at 10:37:46 AM, on 12/31/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\pctspk.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
C:\Program Files\RAM Idle LE\RAM_XP.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
C:\utility\TOPDESK.EXE
C:\Program Files\One Guy Coding\Automachron\achron.exe
C:\junk\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.weather.com/weather/detail/10021
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [CountrySelection] pctptt.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\Scansoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\Scansoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle LE\RAM_XP.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\pcsync2.exe /NoDialog
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Automachron.lnk = C:\Program Files\One Guy Coding\Automachron\achron.exe
O4 - Startup: Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: TOPDESK.EXE.lnk = C:\utility\TOPDESK.EXE
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/24e4b7f54dfcc9…ip/RdxIE601.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…8070.3936805556




// end of hijack log
I have Win2k with SP4. All Updates for Win2k have been installed as of 12/31/04. In addition, I have current updates for these programs. Ad-aware SE Plus Version 1.05 and Spybot 1.3. I also have Spyware Blaster version 3.2 and Norton Internet Security and Have run a complete scan of all my computer. I also have run a complete PandaSoftware Antivirus scan.

I also have HijackThis version 1.99.0
In addition, I have completely uninstalled and re-installed Ad-Aware SE Plus.
After all of this, I then "click on Ad-Watch" from Ad-Aware.

Then what happens is that Spybot-SD Resident tells me that it notices that registry entries for the "exe" files of many programs are being deleted. I try to say "deny", but it's too late. After the "clicking" of Ad-Watch, my Norton Internet Security failes to start and is corrupted along with many other programs.

I am able to restore from a backup and duplicate the problem. If I don't click on Ad-Watch, then no problem seems to appear.
I have ran Hijack and am including the file log:
Can you please help?

// begin of hijack log

Logfile of HijackThis v1.99.0
Scan saved at 11:28:31 AM, on 1/2/2005
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\system32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
C:\Program Files\Norton Internet Security\NISUM.EXE
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\WINNT\system32\ati2evxx.exe
C:\Program Files\Norton Internet Security\ccPxySvc.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\system32\stisvc.exe
C:\WINNT\wanmpsvc.exe
C:\WINNT\System32\WBEM\WinMgmt.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\Atiptaxx.exe
C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
C:\Program Files\RAM Idle LE\RAM_XP.exe
C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~2\TRAYAP~1.EXE
C:\Program Files\Common Files\Symantec Shared\ccApp.exe
C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe
C:\WINNT\system32\RunDLL32.exe
C:\WINNT\system32\HPJETDSC.EXE
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\COMMON~1\PCSuite\Services\SERVIC~1.EXE
C:\PROGRA~1\COMMON~1\Nokia\MPAPI\MPAPI3s.exe
C:\utility\TOPDESK.EXE
C:\Program Files\One Guy Coding\Automachron\achron.exe
C:\utility\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.weather.com/activities/other/ot…tml?locid=11772
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe
O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Program Files\Roxio\Easy CD Creator 5\DirectCD\DirectCD.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe
O4 - HKLM\..\Run: [IndexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe
O4 - HKLM\..\Run: [RAM Idle Professional] C:\Program Files\RAM Idle LE\RAM_XP.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\COMMON~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~2\TRAYAP~1.EXE
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Program Files\Common Files\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Program Files\Common Files\Symantec Shared\Security Center\UsrPrmpt.exe
O4 - HKCU\..\Run: [PcSync] C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog
O4 - HKCU\..\Run: [OfotoNow USB Detection] C:\WINNT\system32\RunDLL32.exe C:\PROGRA~1\Ofoto\OfotoNow\OFUSBS.DLL,WatchForConnection OfotoNow
O4 - HKCU\..\Run: [HP JetDiscovery] HPJETDSC.EXE
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: Automachron.lnk = C:\Program Files\One Guy Coding\Automachron\achron.exe
O4 - Startup: Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: QuickBooks Update Agent.lnk = C:\Program Files\Common Files\Intuit\QuickBooks\QBUpdate\qbupdate.exe
O4 - Global Startup: TOPDESK.lnk = C:\utility\TOPDESK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINNT\system32\Shdocvw.dll
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O23 - Service: AOL Connectivity Service - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\system32\ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Proxy Service - Symantec Corporation - C:\Program Files\Norton Internet Security\ccPxySvc.exe
O23 - Service: Logical Disk Manager Administrative Service - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Internet Security Accounts Manager - Symantec Corporation - C:\Program Files\Norton Internet Security\NISUM.EXE
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: WAN Miniport (ATW) Service - America Online, Inc. - C:\WINNT\wanmpsvc.exe



// end of hijack log
Not too much in the log, just this one:

O4 - Startup: Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe

It could be:

Checks for updates for Visioneer OneTouch scanners

or

wiseupdt.exe is an updater utility for Grokster file sharing tools. Grokster, has the ability to install AdWare on companies behalf.

or

???????

See if you can find out what it is.


For now, just disable SpybotSD TeaTimer - one of these should work:

Open SpyBot> on its tool-bar > Mode switch to advanced > tools >resident and uncheck tea timer. close SpyBot. in the windows tray (clock area) if tea timer is still visible right click it and chose exit.

Please disable TeaTimer by opening Spybot SD and on the left menu choose Tools and then Resident. In the right hand pane you will see a check box for TeaTimer and for SDHelper . Please uncheck both boxes and then close Spybot.


We can try a couple of things.

Run this trojan scan, see if it finds anything:
Free Online Trojan Scan


You can also run this program that Daemon uses, see if it finds anything:

Click here http://www.mwti.net/antivirus/free_utilities.asp to download mwavscan. Double-click it to run it, select all local drives, scan all files, press 'scan' and when it is completed, (it takes a while) anything found will be displayed in the lower pane. Highlight it, CTRL C and paste it in your next reply.

Let me know, MrC
>>O4 - Startup: Check for TWS Updates.lnk = C:\Jts\WiseUpdt.exe<<


MrC,

That's my broker software, I am a stock trader.


>>For now, just disable SpybotSD TeaTimer - one of these should work:<<

Done.


>>Run this trojan scan, see if it finds anything:
Free Online Trojan Scan<<

Nothing found.


>>Click here http://www.mwti.net/antivirus/free_utilities.asp to download mwavscan. <<

I am including this output. This software has a number of questionable finds. Such as "agent32-17.exe " This is newsgroup software that is several years old.

Thank you for your help.

- Larry



// begin mwave log

File C:\WINNT\system32\pctptt.exe tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File C:\WINNT\system32\pctptt.exe tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File C:\data\choicemail\mailboxes\[removed]\[removed] BB1A89AD-4FAE-43C0-8944-6359651C00FC.lck infected by "Exploit.CodeBaseExec" Virus. Action Taken: No Action Taken.
File C:\data\choicemail\mailboxes\[removed]\Recycle\1FCD43E9-7962-43C4-AF0E-84A38E93DA62.msg infected by "Trojan-Spy.HTML.Bankfraud.br" Virus. Action Taken: No Action Taken.
File C:\data\choicemail\mailboxes\[removed]\Recycle\C847CA72-9202-41E6-B0F3-7BC52DFA9109.msg infected by "Trojan-Spy.HTML.Paylap.bg" Virus. Action Taken: No Action Taken.
File C:\data\choicemail\mailboxes\[removed]\[removed] 19BEA8BD-E441-499B-9615-6BFAABE09ECC-00000C61.lck infected by "I-Worm.MyDoom.m.log" Virus. Action Taken: No Action Taken.
File C:\data\internet\download\agent32-17.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\data\internet\download\df_123.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\data\internet\download\fa32-121.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\data\internet\download\synchro_version_4.0_build_568.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\drivers\modem\PCTPTT.EX_ tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File C:\Program Files\America Online 9.0\Jiti\Jiti_mm.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\Program Files\Common Files\aolback\comp01.000 tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File C:\WINNT\system32\pctptt.exe tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.
File D:\WINNT\system32\pctptt.exe tagged as not-a-virus:Porn-Dialer.Win32.Generic. No Action Taken.

// end mwave log
If you can find these files and see if they belong to:

pctptt.exe is a diagnostic tool for PCTEL modems

C:\WINNT\system32\pctptt.exe
D:\WINNT\system32\pctptt.exe


If not, they should be deleted.


These, see if you can find and delete them - looks like they're files or e-mails.

File C:\data\choicemail\mailboxes\[removed]\[removed] BB1A89AD-4FAE-43C0-8944-6359651C00FC.lck infected by "Exploit.CodeBaseExec" Virus. Action Taken: No Action Taken.

File C:\data\choicemail\mailboxes\[removed]\Recycle\1FCD43E9-7962-43C4-AF0E-84A38E93DA62.msg infected by "Trojan-Spy.HTML.Bankfraud.br" Virus. Action Taken: No Action Taken.

File C:\data\choicemail\mailboxes\[removed]\Recycle\C847CA72-9202-41E6-B0F3-7BC52DFA9109.msg infected by "Trojan-Spy.HTML.Paylap.bg" Virus. Action Taken: No Action Taken.

File C:\data\choicemail\mailboxes\[removed]\[removed] 19BEA8BD-E441-499B-9615-6BFAABE09ECC-00000C61.lck infected by "I-Worm.MyDoom.m.log" Virus. Action Taken: No Action Taken.

Let me know, MrC (I don't know if this is your problem - but??)
MrC, I finally found out the problem and solution. As you know, on a regular basis I already run many of the things to prevent problems. Such as nightly scans for Ad-Aware, Spybot, AntiVirus and I also have FireWall. I had been thinking that I had previoulsy made an Ad-Aware CD that did not change, so obviously my Ad-Watch is somehow corrupted. After I had uninstalled Ad-Aware, I noticed there was still some files left in its directory. I delete them, and made a meticulous search for Ad-Aware stuff. I then re-installed Ad-Aware and everything worked fine. So one of the problems was the the Uninstall from Ad-AWare with automatic uninstall did not remove everything. So please close this case. Thank you for your help and suggestions. I am including your free Spyware and Antivirus utilities in my toolset. Thanks much, - Larry
Glad you found the answer!!

As this problem has been resolved the topic will be closed. If you need this topic reopened, please request this by sending an email to us at the following link
(Click for address)

The subject of the email must be "Reopen". Include your post username and details about why you need it reopened, with a valid link to your post.

Thanks - MrC

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI