I was handed a friend's laptop that was experiencing very strange virus-like symptoms. He could log in, but there'd be warnings about un-associated .lnk shortcuts, and the icons showed as generic windows icons. Then nothing would run: trying to start any program would result in a window asking the user to choose a program to associate .exe with. Looked like a virus to me.
I rebooted into Safe Mode, logged in as administrator, chose a Restore point prior to this problem appearing. Then rebooted, logged in as adminstrator, and everything was fine. Updated Windows to the new SP3 service pack. Then, when he logged into his account, no warnings and the icons were fine, but then Ad-Aware popped-up and warned about a bunch (50 or so) registry association changes. After that -- same symptoms as before.
So, after a little Internet search, I repeated the Restore exercise, loaded his registry hive (ntusers) into regedt32, and removed the software\microsoft\windows\currentversion\Run entry for Ad-Aware. Then unloaded the hive, logged out, and he logged into his account. Voila... worked fine. So I uninstalled Ad-Aware 2007 and Ad-Aware SE Professional. (For some reason both were installed.) Now he's in great shape.
Has anyone run into this before? I know I took a brute-force approach to Ad-Aware: but I haven't worked with it before and he didn't know why he needed it. But it leaves me thinking I should tell all my clients and friends to avoid Ad-Aware.
Was it just that he had outdated definitions, or that he had set up Ad-Aware to have too much control?
Thanks... Ken.