Help - Search - Members - Calendar
Full Version: Adware 2008 Free- Removed instead of quarantined
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive General Support Issues
zippy32
I have the Adware 2008 Free version. I ran a full scan last night and found a critical object which was rated 10. I didn't read what the object was- Win32? I clicked too fast and 'removed' the object with the others however, I should have quarantined it. Now that I have removed it there are some files in my 'Windows system 32' that states 'permission denied'. I'm not too sure how to retrieve back the objects that I 'removed' so I could retrieve back the files infected back to my computer and then quarantine it. I tried to do system restore but did not work.


I don't know where to find the log files either perhaps that is where I should look at? Please help!!! ohmy.gif
casey_boy
hi,

Two things I would like you to do:

1. find your scan logs at:

Vista C:\ProgramData\Lavasoft\Ad-Aware\logs
XP C:Documents and Settings\All Users\Application Data\Lavasoft\Ad-Aware\logs

and upload them, so we can see what was removed.

2. Post in the Hijack This forum, but read the "please read this before you post" topic on details on what to do next. Someone should be able to help you remove any malware on your computer.

Casey
zippy32
Hi Casey,

I have managed to find my logs but it wasn't located at the path you've mentioned above. However, I managed to find it else where in the computer but it doesn't have my recent logs only since the beginning of this year. This is weird because I have scanned many times throughout the year so where are my recent logs?
I'm not to sure whether posting the logs for February would help as you would want the most recent one. Would it be any use if I was to post the logs from my antivirus scan?

I only found out I couldn't open some files because I ran the antivirus scan. This is the log from Clamwin antivirus:

Scan Started Sat Sep 13 14:01:24 2008
-------------------------------------------------------------------------------

C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbc2e.ht1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbdam: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbdao: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbeam: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbeao: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbm: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbu2d.ht1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbvm.cf1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\dbvmh.ht1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\fii.cf1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\fiih.ht1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\rpm.cf1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Application Data\Google\Google Desktop Search\rpmh.ht1: Permission denied
C:\Documents and Settings\Khode\Local Settings\Temp\~DF2EA8.tmp: Permission denied
C:\Documents and Settings\Khode\Local Settings\Temp\~DF339E.tmp: Permission denied
C:\Documents and Settings\Khode\Local Settings\Temp\~DF33B4.tmp: Permission denied
C:\Documents and Settings\Khode\Local Settings\Temp\~DF8E3.tmp: Permission denied
C:\Documents and Settings\Khode\Local Settings\Temp\~DFFDA4.tmp: Permission denied
C:\pagefile.sys: Permission denied
C:\Prog\Install\M2NPV-VM-Motherboard\Software\AntiVirus\Support\LUpdate\LUSetup.exe: moved/scheduled to 'C:\Documents and Settings\All Users\.clamwin\quarantine\infected.LUSetup.exe'
C:\WINDOWS\system32\config\default: Permission denied
C:\WINDOWS\system32\config\SAM: Permission denied
C:\WINDOWS\system32\config\SECURITY: Permission denied
C:\WINDOWS\system32\config\software: Permission denied
C:\WINDOWS\system32\config\system: Permission denied

C:\Prog\Install\M2NPV-VM-Motherboard\Software\AntiVirus\Support\LUpdate\LUSetup.exe: Trojan.FakeAlert-632 FOUND
----------- SCAN SUMMARY -----------
Known viruses: 419609
Engine version: 0.94
Scanned directories: 9236
Scanned files: 87993
Infected files: 1

Data scanned: 76814.83 MB
Time: 22589.312 sec (376 m 29 s)
--------------------------------------
Completed
--------------------------------------


Thank you.


casey_boy
hi,

sorry for the late response.

I would recommend posting in the Hijack This forum for help with removing any nasties still left on your computer. It sounds as though, at least in Feb, you had an infection and it may not have been removed properly.

Casey
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.