Need help with Ad-Aware SE?

Started by Corrine, July 17, 2005, 02:03:41 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Corrine

Do you need help with Ad-Aware SE? 

We would be happy to assist.  Please post your question(s) or a logfile in a new topic of your own.


Logfile Preparation and Posting Instructions

Download Ad-Aware SE) and install it. If you already have Ad-Aware SE, please configure it as indicated below. (Note that Ad-Aware SE is free for non-commercial, non-governmental, and non-educational use.) If you have a previous version of Ad-Aware, please install Build 1.06r1.

Note:  Some Files and Folders may be Hidden, by design. Please ensure that "Show Hidden Files and Folders" is enabled. (Instructions: How to make Windows show all files).  Reverse this process after your system is clean.

1)  Run the Webupdate feature. (Click on the Globe icon > Click connect > Click OK > Click Finish.)

2)  Set up the Configurations (Click the gear wheel at the top) as follows:

    General Button > Safety & Settings:  Check (Green) all three.
    Advanced Button > Logfile Detail Level:  All options under this should be checked (Green).
    Tweak Button >
      >  Scanning Engine:  Check "Obtain command line of scanned processes"
      >  Log Files:  Please check only
            * "Include basic Ad-Aware settings in logfile"
            * "Include additional Ad-Aware settings in logfile"
            * "Include reference summary in logfile"
      > Click on "Proceed"

3)  To start the scan, Click > "Scan Now"
      >  Deselect "Search for negligible risk entries" as negligible risk entries (MRU's) are not considered to be a threat.
      >  Select "Search for low-risk threats"
      >  Select "Perform full system scan"   
      >  Click Next

          A full scan is the in-depth scan mode that scans your whole computer for Spyware infections.
          When performing a full scan the following scan settings are used:

                * Full Memory Scan is performed
                * Registry Scan is performed
                * Deep Registry scan is performed
                * Cookie-Scan is performed
                * Favorites are scanned
                * Hosts file is scanned
                * Conditional scans are performed
                * Archive files are scaned
                * All fixed drives are scanned

4)  When the scan has completed, click "Show Logfile".  Copy/paste the complete log file in a thread of your own.  Do not quarantine or remove anything at this time, just post a complete logfile. This sometimes takes 2-3 posts to get it all posted. You will know you are at the end when you see the "Summary of this scan" information has been posted.


Thank you, LandzDown Team


Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.

Corrine

    Ad-Aware Freezing/Hanging Help

    Ad-Aware SE freezing, stalling or unable to quarantine can be caused by many different situations.  We have found that almost all freezing issues that are resolved were due to corrupted files or some other machine issue.  That does not mean that Ad-Aware SE will successfully run on all machines, but this is no different than any other software. There are simply too many operating systems and program combinations for any program to run in all possible environments.

    Collected here are solutions that have been found will generally work.  Although I have updated the original document a number of times, thanks go to the following for their contributions, including suggestions, solutions and verbage for the original document:  appetiser, cannymum, EASTER, Eric the Red, IAMSKINZ, Option^Explicit, rmetzger, Sigma and Totro.   

    NOTE:  to receive individual attention, please create a topic of your own, kindly indicating what actions you have taken, including a debugf log if you still cannot complete a scan.

    Launch Ad-Aware SE and check for any Definition File updates.  Click on the gear to access the Configuration Menu.  Click on Tweak > Cleaning Engine > UNcheck "Always try to unload modules before deletion". 

    A.  Manually Clean 'Temporary Internet Files'
    Clean the following directory contents (but not the directory folder). Please disconnect from the Internet (for broadband (DSL/Cable) users, it is recommended that you disconnect the cable connection) and close All open browsers.

    Cleaning 'Temporary Internet Files'

    • C:\Windows\Temp\, C:\WINNT\Temp\, or C:\TEMP\
    • "C:\Documents and Settings\<Your Profile>\Local Settings\Temporary Internet Files\" <=This will delete all your cached Internet content including cookies.
    • "C:\Documents and Settings\<Your Profile>\Local Settings\Temp\"
    • "C:\Documents and Settings\<Your Profile>\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\"
    • "C:\Documents and Settings\<Any other users Profile>\Local Settings\Temporary Internet Files\" <=This will delete all the other users cached Internet content including cookies.
    • "C:\Documents and Settings\<Any other users Profile>\Local Settings\Temp\"
    • "C:\Documents and Settings\<Any other users profile>\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\"
    • Empty your "Recycle Bin," including extended recycle bins, such as "Norton's Protected Recycle Bin"
    • Shutdown/Restart the computer (except when specifically told not to)


      Notes:

    • Some Files and Folders may be Hidden, by design. Please ensure that "Show Hidden Files and Folders" is enabled. How to make Windows show all files
    • Java Cache folders may be named slightly differently depending on version. Locate the lowest lever below 'cache' for deletion.
    • You may have other areas that need to be cleaned as well. Drive C: may not be your %SystemDrive%, substitute accordingly.
    • If having difficulty deleting files, consider rebooting in Safe Mode ( http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001052409420406 )
      and repeating the process.

      B.  Using CCleaner to "Clean TemporaryInternet Files"
      Download CCleaner from this direct link:  http://www.ccleaner.com/downloadbin.asp?f=2 .   

      Instructions for using CCleaner:

      1. Before first use, check under Options > Advanced > UNcheck "Only delete files in Windows Temp folder older than 48 hours".
      2. A pop up box will appear advising this process will permanently delete files from your system.
      3. To protect logon cookies that you wish to retain, under Options > Cookies.  Select and using the arrow move those cookies to the "Cookies to keep" column.
      4. Then select the items you wish to clean up.

      In the Windows Tab:

      Clean all entries in the "Internet Explorer" section.
      Clean all the entries in the "Windows Explorer" section.
      Clean all entries in the "System" section.
      Clean all entries in the "Advanced" section.
      Clean any others that you choose.

      In the Applications Tab:

      Clean all in the Firefox/Mozilla section if you use it.
      Clean all in the Opera section if you use it.
      Clean Sun Java in the Internet Section.
      Clean any others that you choose.

      5. Click the "Run Cleaner" button and it will scan and clean your system.
      6. Click exit. 
      7. Shutdown/restart the computer.

      C.  Conditional Scan -- For Ad-Aware SE Plus and Professional customers experiencing freezing during the conditional scan, please use the following command line option*:

      Click "Start" > select "Run" > type the text shown in bold below (including the quotation marks and with the same spacing as shown) for your version of Ad-Aware SE:

      "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" +procnuke +cskip
      "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" +procnuke +cskip


      D.  Additional Steps:  Please try the following:
    • Disk Defragmentation, followed with a thorough Check or Scan Disk, depending upon your version of Windows

    • Online Scan:  Do an online scan at one or more of the sites listed below and follow any removal instructions. 

      BitDefender
      Panda
      F-Secure
      TrendMicro
      A2 Trojan Scan

      To scan individual files, please go to: http://virusscan.jotti.org/ .  Upload the file in the "File to upload & scan" box at the upper left.  If Jotti reports the file is infected, please provide that information in your post topic.

    • Safe Mode Scan:  ( http://service1.symantec.com/SUPPORT/tsgen...001052409420406 )

    • Real-time AV MonitorsOnly while disconnected from the Internet, try scanning with the AV software shut down.

    • Real-time Monitoring Programs:  See "How to Disable Real Time Monitoring Programs"

    • Command Line Scan:  Click "Start" > select "Run" > type the text shown in bold below (including the quotation marks and with the same spacing as shown) for your version of Ad-Aware SE: 
      "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" /full +procnuke
      "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" /full +procnuke
      "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" +procnuke

    • Stop/Start Method:  Start the scan, however cancel BEFORE the scan reaches the point of stalling -- say after 20 objects are detected.  Then click cancel and click on the logfile.  Remove any objects you choose and rescan.  Again stop the scan before it reaches the point of stalling and remove any addiitonal objects.  For highly infected systems, it may also be necessary to shutdown/restart between scans.

    • Selective Removal:  For severely infected machines, it is not always possible to remove all objects at the same time.  It is necessary to quarantine in smaller groups.  Start with "tracking cookies" and include other families detected, but not removing more than around 60 objects at a time.  If a "family" has 60 or more objects detected, select only that family for removal with that scan.  Shutdown/restart between removals.

    • Malware Shutdown:  Some malware can target programs designed to remove them so if you find Ad-Aware SE is being shutdown during a scan or will not start try using the +immortal option.

      -- Click "Start" > select "Run" > type the appropriate text shown in bold below (including the quotation marks and with the same spacing as shown). Select the Professional, Plus or Personal command depending on the version of Ad-Aware SE you have.

      "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" /full -mru +auto +immortal
      "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" /full -mru +auto +immortal
      "C:\Program Files\Lavasoft\Ad-Aware SE Personal\Ad-Aware.exe" +immortal

      Then click on the OK button to run the command. For Professional and Plus versions the scan will start scanning and automatically remove items found.  For the Personal Edition you need to start the scan manually and you will need to reboot your PC to close Ad-Aware SE.

    • +Debugf Log:  If none of the above works and you are an Ad-Aware SE Plus or Professional license holder and you still can NOT complete a scan, please do the following and submit that log to Lavasoft Research.  For Ad-Aware SE Personal users, with the Lavasoft Support Forums closed, please post the debug log as a reply and I will send it to LS SteveJ at Lavasoft Research.  Although I will do my best, there is no guarantee that your issue will be addressed.

      Launch Ad-Aware SE.  Click on "Preferences" > "Tweak" > "Logfiles".  Check (ON) this tweak:  "Include used command line parameters in logfile".

      Next:, click "Start" > select "Run" > type the text shown in bold below (including the quotation marks and with the same spacing as shown) for your version of Ad-Aware SE:

      "C:\Program Files\Lavasoft\Ad-Aware SE Professional\Ad-Aware.exe" +debugf
      "C:\Program Files\Lavasoft\Ad-Aware SE Plus\Ad-Aware.exe" +debugf

      The +debugf will create a log (debug output) in the Ad-Aware folder if the program freezes.  In a topic of our own, copy the last five lines only of the debuglog-file (NOT closing AAW, or doing any modifications to its current state).  The debuglog will show us at which particular operation it hangs.  We need that information.  Also, post the logfile.  You can close Ad-Aware SE after that.


      *Note: For command line scans, the path shown between the quotes is the default location of Ad-Aware SE, if you installed to a different directory please adjust it to the correct location.  For Ad-Aware SE Personal, when the GUI launches, you will need to click Start > Select Full System Scan > Click Next.


    Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

    Remember - A day without laughter is a day wasted.
    May the wind sing to you and the sun rise in your heart.