Help - Search - Members - Calendar
Full Version: Computer crashes when updating Ad-Aware v1.06
Lavasoft Support Forums > Archived Topics > Archives: Resolved/Inactive Topics > Resolved/Inactive General Support Issues
duchesne
Hi,

I have recently attempted to update Ad-Aware se personal from V1.05 to the new build 1.06. However, I am now unable to have any updates without my computer crashing. A scan works ok (it seems), but when I go to update my definitions (when I push connect), my computer instantly pops a blue screen with some writing for 1 sec then reboots. I tried the 3 suggested solutions at:

http://www.lavasoftsupport.com/index.php?showtopic=2244

However, none of these work. Disabling the auto-restart function on my computer only allows me to see the end of the message on the blue screen, i.e. my computer doesn't shut down, but I am stuck seeing a blue screen with a warning on it. The warning is preventive measures to avoid this problem in the future if this problem persists (see system adminstrator or something). I cannot say what error has occured, since I am unable to scroll upwards in this message, and only see the end part about if the problem persists.

I also cannot run the shutdown -a as an execute, since the program crashes my computer instantly. Does anyone know a solution to this?

Thank you

David
spike-nz
David,

Try the fixes suggested by LS SteveJ here: I Cannot Perform Web Update Of The Definition File After Upgrading To Build 1.06 (error Retrieving Update)

If you are successful, post a then do a "Full Scan"
and then post your logfile here by using the Add-Reply Feature .
As Logs are stored in :
C:\Documents and Settings\USERNAME\Application Data\Lavasoft\Ad-aware\Logs\.
An easy way to get there is to
click Start,
click Run
And type in and press ENTER: %appdata%
then click Lavasoft
then Ad-Aware
and then Logs.
scroll down to find the latest one that you have
(by date & time)
and open it right Click select all
copy and then paste the contents of it here.
(Make sure that all of your Logfile has been posted, sometimes it will require two post's to get it all)

If you persist in having problems, there are other tools that the experts can use to diagnose any other (possibly malware) problems smile.gif

Spike
duchesne
Thank you Spike for helping. Unfortunately, none of the suggestions worked; I still cannot use the "check now for updates" feature (causes PC to instantly restart). I have downloaded the new defs.ref, and Ad-Aware no longer says my definitions are 432 days old.

I have performed a full system scan, which I have posted below.

Thank you,

David
duchesne
Ad-Aware SE Build 1.06r1
Logfile Created on:August 1, 2006 2:13:24 PM
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R116 24.07.2006
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):35 total references
Tracking Cookie(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Search for low-risk threats
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


01-08-2006 2:13:24 PM - Scan started. (Full System Scan)

MRU List Object Recognized!
Location: : E:\Documents and Settings\Administrateur\Application Data\microsoft\office\recent
Description : list of recently opened documents using microsoft office


MRU List Object Recognized!
Location: : E:\Documents and Settings\Administrateur\recent
Description : list of recently opened documents


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct3d


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\direct3d\mostrecentapplication
Description : most recent application to use microsoft direct X


MRU List Object Recognized!
Location: : software\microsoft\directdraw\mostrecentapplication
Description : most recent application to use microsoft directdraw


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\directinput\mostrecentapplication
Description : most recent application to use microsoft directinput


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\internet explorer
Description : last download directory used in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\internet explorer\main
Description : last save directory used in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\internet explorer\typedurls
Description : list of recently entered addresses in microsoft internet explorer


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\mediaplayer\player\recentfilelist
Description : list of recently used files in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\mediaplayer\preferences
Description : last playlist index loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\mediaplayer\preferences
Description : last playlist loaded in microsoft windows media player


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\microsoft management console\recent file list
Description : list of recent snap-ins used in the microsoft management console


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\common\general
Description : list of recently used symbols in microsoft office


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\common\open find\microsoft office powerpoint\settings\insert picture\file name mru
Description : list of recent pictured inserted in microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\common\open find\microsoft office powerpoint\settings\save as\file name mru
Description : list of recent documents saved by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\common\open find\microsoft office word\settings\open\file name mru
Description : list of recent documents opened by microsoft word


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\common\open find\microsoft office word\settings\save as\file name mru
Description : list of recent documents saved by microsoft word


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\powerpoint\recent file list
Description : list of recent files used by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\powerpoint\recent templates
Description : list of recent templates used by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\powerpoint\recent typeface list
Description : list of recently used typefaces in microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\powerpoint\recentfolderlist
Description : list of recent folders used by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\office\11.0\powerpoint\recenttemplatelist
Description : list of recent templates used by microsoft powerpoint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\search assistant\acmru
Description : list of recent search terms used with the search assistant


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\windows\currentversion\applets\paint\recent file list
Description : list of files recently opened using microsoft paint


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\windows\currentversion\applets\wordpad\recent file list
Description : list of recent files opened using wordpad


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru
Description : list of recently saved files, stored according to file extension


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\windows\currentversion\explorer\recentdocs
Description : list of recent documents opened


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\windows\currentversion\explorer\runmru
Description : mru list for items opened in start | run


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\microsoft\windows media\wmsdk\general
Description : windows media sdk


MRU List Object Recognized!
Location: : S-1-5-21-1390067357-113007714-854245398-500\software\winrar\dialogedithistory\extrpath
Description : winrar "extract-to" history


Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 416
ThreadCreationTime : 01-08-2006 6:07:28 PM
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 464
ThreadCreationTime : 01-08-2006 6:07:30 PM
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 488
ThreadCreationTime : 01-08-2006 6:07:31 PM
BasePriority : High


#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 532
ThreadCreationTime : 01-08-2006 6:07:31 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Applications Services et Contrôleur
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 552
ThreadCreationTime : 01-08-2006 6:07:31 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 696
ThreadCreationTime : 01-08-2006 6:07:32 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 760
ThreadCreationTime : 01-08-2006 6:07:32 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [msmpeng.exe]
FilePath : D:\Program Files\Windows Defender\
ProcessID : 800
ThreadCreationTime : 01-08-2006 6:07:32 PM
BasePriority : Normal
FileVersion : 1.1.1347.0
ProductVersion : 1.1.1347.0
ProductName : Windows Defender
CompanyName : Microsoft Corporation
FileDescription : Service Executable
InternalName : MsMpEng.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : MsMpEng.exe

#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 840
ThreadCreationTime : 01-08-2006 6:07:32 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 888
ThreadCreationTime : 01-08-2006 6:07:32 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:11 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 940
ThreadCreationTime : 01-08-2006 6:07:33 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:12 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1200
ThreadCreationTime : 01-08-2006 6:07:33 PM
BasePriority : Normal
FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519)
ProductVersion : 5.1.2600.2696
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:13 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 1388
ThreadCreationTime : 01-08-2006 6:07:34 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Explorateur Windows
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : EXPLORER.EXE

#:14 [ctfmon.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1420
ThreadCreationTime : 01-08-2006 6:07:34 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : CTF Loader
InternalName : CTFMON
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : CTFMON.EXE

#:15 [vptray.exe]
FilePath : D:\PROGRA~1\SYMANT~1\SYMANT~1\
ProcessID : 1656
ThreadCreationTime : 01-08-2006 6:07:39 PM
BasePriority : Normal
FileVersion : 8.1.0.821
ProductVersion : 8.1.0.821
ProductName : Symantec AntiVirus
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus
LegalCopyright : Copyright © Symantec Corporation 1991-2003

#:16 [indicatoruty.exe]
FilePath : D:\Program Files\Fujitsu\Fujitsu Hotkey Utility\
ProcessID : 1664
ThreadCreationTime : 01-08-2006 6:07:39 PM
BasePriority : Normal
FileVersion : 2, 2, 0, 0
ProductVersion : 2, 2, 0, 0
ProductName : Fujitsu Hotkey Utility
CompanyName : FUJITSU LIMITED
FileDescription : Fujitsu Hotkey Utility
InternalName : Fujitsu Hotkey Utility
LegalCopyright : Copyright © FUJITSU LIMITED 2001-2003.
OriginalFilename : IndicatorUty.exe

#:17 [quicktouch.exe]
FilePath : D:\Program Files\Fujitsu\Application Panel\
ProcessID : 1672
ThreadCreationTime : 01-08-2006 6:07:39 PM
BasePriority : Normal
FileVersion : 4, 3, 0, 0
ProductVersion : 4, 3, 0, 0
ProductName : LifeBook Application Panel
CompanyName : FUJITSU LIMITED
FileDescription : LifeBook Application Panel / Core
InternalName : Fujitsu->AUV->QuickTouch.exe
LegalCopyright : Copyright © FUJITSU LIMITED 1998-2002.
OriginalFilename : QuickTouch.exe

#:18 [btnhnd.exe]
FilePath : D:\Program Files\Fujitsu\BtnHnd\
ProcessID : 1680
ThreadCreationTime : 01-08-2006 6:07:39 PM
BasePriority : Normal
FileVersion : 2, 5, 0, 1
ProductVersion : 2, 5, 0, 0
ProductName : Button handler
CompanyName : FUJITSU LIMITED
FileDescription : Button handler
InternalName : Fujitsu->BtnHnd->BtnHnd.exe
LegalCopyright : Copyright © FUJITSU LIMITED 1998-2001.
OriginalFilename : BtnHnd.exe

#:19 [apoint.exe]
FilePath : D:\Program Files\Apoint2K\
ProcessID : 1696
ThreadCreationTime : 01-08-2006 6:07:40 PM
BasePriority : Normal
FileVersion : 5.3.10.174
ProductVersion : 5.3.10.174
ProductName : Alps Pointing-device Driver
CompanyName : Alps Electric Co., Ltd.
FileDescription : Alps Pointing-device Driver
InternalName : Alps Pointing-device Driver
LegalCopyright : Copyright © 1999-2003 Alps Electric Co., Ltd.
OriginalFilename : Apoint.exe

#:20 [jusched.exe]
FilePath : D:\Program Files\Java\jre1.5.0_06\bin\
ProcessID : 1728
ThreadCreationTime : 01-08-2006 6:07:40 PM
BasePriority : Normal


#:21 [agrsmmsg.exe]
FilePath : C:\WINDOWS\
ProcessID : 1752
ThreadCreationTime : 01-08-2006 6:07:40 PM
BasePriority : Normal
FileVersion : 2.1.34 2.1.34 09/23/2003 17:06:56
ProductVersion : 2.1.34 2.1.34 09/23/2003 17:06:56
ProductName : Agere SoftModem Messaging Applet
CompanyName : Agere Systems
FileDescription : SoftModem Messaging Applet
InternalName : smdmstat.exe
LegalCopyright : Copyright © Agere Systems 1998-2000
OriginalFilename : smdmstat.exe

#:22 [statusclient.exe]
FilePath : D:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\
ProcessID : 1760
ThreadCreationTime : 01-08-2006 6:07:40 PM
BasePriority : Normal
FileVersion : 00.00.13
ProductVersion : 00.00.13
ProductName : Hewlett-Packard T-TR Status Client
CompanyName : Hewlett-Packard
FileDescription : Hewlett-Packard T-TR Status Client
InternalName : StatusClient.exe
LegalCopyright : Copyright © 2002 Hewlett-Packard Company
LegalTrademarks : All Rights Reserved.
OriginalFilename : StatusClient.exe

#:23 [msascui.exe]
FilePath : D:\Program Files\Windows Defender\
ProcessID : 1816
ThreadCreationTime : 01-08-2006 6:07:41 PM
BasePriority : Normal
FileVersion : 1.1.1347.0
ProductVersion : 1.1.1347.0
ProductName : Windows Defender
CompanyName : Microsoft Corporation
FileDescription : Windows Defender User Interface
InternalName : MSASCUI
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : MSASCUI.exe

#:24 [hidfind.exe]
FilePath : D:\Program Files\Apoint2K\
ProcessID : 1904
ThreadCreationTime : 01-08-2006 6:07:42 PM
BasePriority : Normal


#:25 [apntex.exe]
FilePath : D:\Program Files\Apoint2K\
ProcessID : 1908
ThreadCreationTime : 01-08-2006 6:07:42 PM
BasePriority : Normal
FileVersion : 5.0.1.15
ProductVersion : 5.0.1.15
ProductName : Alps Pointing-device Driver for Windows NT/2000/XP
CompanyName : Alps Electric Co., Ltd.
FileDescription : Alps Pointing-device Driver for Windows NT/2000/XP
InternalName : Alps Pointing-device Driver for Windows NT/2000/XP
LegalCopyright : Copyright © 1998-2003 Alps Electric Co., Ltd.
OriginalFilename : ApntEx.exe

#:26 [javaw.exe]
FilePath : D:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\
ProcessID : 304
ThreadCreationTime : 01-08-2006 6:07:47 PM
BasePriority : Normal


#:27 [defwatch.exe]
FilePath : D:\PROGRA~1\SYMANT~1\SYMANT~1\
ProcessID : 1084
ThreadCreationTime : 01-08-2006 6:07:50 PM
BasePriority : Normal
FileVersion : 8.1.0.821
ProductVersion : 8.1.0.821
ProductName : Norton AntiVirus
CompanyName : Symantec Corporation
FileDescription : Virus Definition Daemon
InternalName : DefWatch
LegalCopyright : Copyright © 1998 Symantec Corporation
OriginalFilename : DefWatch.exe

#:28 [mdm.exe]
FilePath : D:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\
ProcessID : 1012
ThreadCreationTime : 01-08-2006 6:07:51 PM
BasePriority : Normal
FileVersion : 7.00.9466
ProductVersion : 7.00.9466
ProductName : Microsoft® Visual Studio .NET
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : mdm.exe

#:29 [lmgrd.exe]
FilePath : D:\Program Files\National Instruments\Shared\License Manager\Bin\
ProcessID : 1300
ThreadCreationTime : 01-08-2006 6:07:54 PM
BasePriority : Normal
FileVersion : 7, 2, 6, 0
ProductVersion : 7, 2, 6, 0
CompanyName : GLOBEtrotter Software Inc.
InternalName : LMGRD
LegalCopyright : Copyright © 2000, 1997
OriginalFilename : LMGRD.EXE

#:30 [rtvscan.exe]
FilePath : D:\PROGRA~1\SYMANT~1\SYMANT~1\
ProcessID : 1308
ThreadCreationTime : 01-08-2006 6:07:54 PM
BasePriority : Normal
FileVersion : 8.1.0.821
ProductVersion : 8.1.0.821
ProductName : Symantec AntiVirus
CompanyName : Symantec Corporation
FileDescription : Symantec AntiVirus
LegalCopyright : Copyright © Symantec Corporation 1991-2003

#:31 [nilm.exe]
FilePath : D:\Program Files\National Instruments\Shared\License Manager\Bin\
ProcessID : 1512
ThreadCreationTime : 01-08-2006 6:07:54 PM
BasePriority : Normal


#:32 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1612
ThreadCreationTime : 01-08-2006 6:07:54 PM
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe

#:33 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2368
ThreadCreationTime : 01-08-2006 6:07:55 PM
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe

#:34 [wuauclt.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3968
ThreadCreationTime : 01-08-2006 6:08:40 PM
BasePriority : Normal
FileVersion : 5.8.0.2469 built by: lab01_n(wmbla)
ProductVersion : 5.8.0.2469
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Mises à jour automatiques
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : wuauclt.exe

#:35 [iexplore.exe]
FilePath : D:\Program Files\Internet Explorer\
ProcessID : 1228
ThreadCreationTime : 01-08-2006 6:08:49 PM
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Système d'exploitation Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Internet Explorer
InternalName : iexplore
LegalCopyright : © Microsoft Corporation. Tous droits réservés.
OriginalFilename : IEXPLORE.EXE

#:36 [ad-aware.exe]
FilePath : D:\Program Files\Lavasoft\Ad-Aware SE Personal\
ProcessID : 2668
ThreadCreationTime : 01-08-2006 6:13:11 PM
BasePriority : Normal
FileVersion : 6.2.0.236
ProductVersion : SE 106
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft AB Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 35


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 35


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 35


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : angelika@247realmedia[1].txt
TAC Rating : 3
Category : Data Miner
Comment : Hits:1
Value : Cookie:angelika@247realmedia.com/
Expires : 31-12-2020 8:00:00 PM
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 36



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 36


Deep scanning and examining files (D:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for D:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 36


Deep scanning and examining files (E:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for E:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 36


Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 36




Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 36

2:24:16 PM Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:10:52.809
Objects scanned:219661
Objects identified:1
Objects ignored:0
New critical objects:1
SkittlesPC
Hi!

I see you have done several things to try and figure this out, but I think it is time to rule out any malware in play.

1. Post a HiJack This log for the Malware Experts to review.

Normally we would have one post their log in the hjt forum BUT LS_CalamityJane is going to help you with this one, as I have already talked to her and she has subscribed to this thread, so she can watch it in this thread.

Instructions on creating a HijackThis Log, as well as the download link is provided below, after the steps I am providing.
.....................................................
In addition, in order to rule out any stealth malware (which has been the cause in a few cases)
Please post with your HJT log, the reports from the following two free tools

[the following instructions provided by CalamityJane]
QUOTE
2. Please download Rootkit Revealer
http://www.sysinternals.com/utilities/rootkitrevealer.html
(link is at the very bottom of the page)

Unzip it to your desktop.
Open the rootkitrevealer folder and double-click rootkitrevealer.exe
Click the Scan button (bottom right)
It may take a while to scan (don't do anything while it's running - leave the PC idle during the scan!)
When it's done, go up to File > Save. Choose to save it to your desktop.
Open rootkitrevealer.txt on your desktop and copy the entire contents and paste them here

3. Post a report from this tool

Download the free beta trial of this tool from F-Secure called Blacklight
F-Secure Blacklight: http://www.f-secure.com/blacklight/try.shtml
Doubleclick on bibeta.exe to run it.
Click the *I accept* button near the bottom of that page.
Download and run blacklite click > scan then > next, next again then exit
there will be a new text file near blacklite.Post it please. The text file is named:
fsbl.xxxxxxx.log (the xxxxxxx stand for numbers)
!!Do not rename any files yet

4. After posting those logs in the HijackThis logs section, it might help to see the most current scan log from Adaware that you have? Post that here in this thread.

Logs are stored in :
C:\Documents and Settings\USERNAME\Application Data\Lavasoft\Ad-aware\Logs\.
An easy way to get there is to
click Start,
click Run
And type in and press ENTER: %appdata%
then click Lavasoft
then Ad-Aware
and then Logs.
scroll down to find the latest one that you have
(by date & time)
and open it right Click select all
copy and then paste the contents of it here.
(Make sure that all of your Logfile has been posted, sometimes it will require two post's to get it all)


Here are my instructions on posting your HJT log if you need help with that.

Download HijackThis.exe To your desk top.


Now Click start then my computer, then local disk Which is usually c:/
Now click file > new folder > name it hijackthis or hjt anything you like;)
You should get this.


Now right click on HijackThis.exe which you just downloaded.
It will look like this chose cut
Open the folder right click and chose paste.


After which you should get some thing like this.



Now start hijackthis. Do a system scan and save logfile, the saved the log file
will be in the folder you just created. Open the file click edit then select all click edit again then copy.
Return to the forum and this thread, then click edit then paste.

Now the fun begins. wink.gif
Tutorial written by Little Eagle of Security Central and Revised by SkittlesPC
duchesne
Thanks for helping,

I have copied down the error message I obtain when trying to update; perhaps this will make sense to you. Bear in mind that I cannot see the beginning of this message, only the end.

--------------------------------------------------------------------------------------------

Error

DRIVER_IRQL_NOT_LESS_OR_EQUAL

%then we have a bunch of text on if this problems persists to removal all recently installed software and stuff%

Technical info:

***STOP: 0x000000D1 (0x82400000,0x00000002,0x00000000,0xF8029A98)

***w22n.51.sys - Adress F8029A98 base at F7FB6000, Date Stamp 3ff54d71

Start of physical memory removal
end of physical memory removal

%then some more text about contacting your system administrator%

-----------------------------------------------------------------------------------------------

So I hope this makes sense to anyone. I will proceed with SkittlesPC advice today.

Thanks,

David
duchesne
Hi,

here is the HiJackThis log, the f-secure blacklite log and the rootkitReveal log.
Please update me,

Thank you,

David
duchesne
Logfile of HijackThis v1.99.1
Scan saved at 2:46:03 PM, on 02/08/2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
D:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
D:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
D:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
D:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
D:\Program Files\Apoint2K\Apoint.exe
D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\AGRSMMSG.exe
D:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe
D:\Program Files\Windows Defender\MSASCui.exe
D:\Program Files\Apoint2K\Apntex.exe
D:\Program Files\Apoint2K\HidFind.exe
D:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
D:\Program Files\Fichiers communs\Microsoft Shared\VS7DEBUG\MDM.EXE
D:\Program Files\Internet Explorer\IEXPLORE.EXE
D:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
D:\Program Files\National Instruments\Shared\License Manager\Bin\nilm.exe
D:\Program Files\MSN Messenger\msnmsgr.exe
C:\WINDOWS\system32\svchost.exe
C:\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.inrs.uquebec.ca/Francais/index.jsp
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.inrs.ca/Francais/index.jsp
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Favoris
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Program Files\Fichiers communs\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [vptray] D:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [IndicatorUtility] D:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [LoadFujitsuQuickTouch] D:\Program Files\Fujitsu\Application Panel\QuickTouch.exe
O4 - HKLM\..\Run: [LoadBtnHnd] D:\Program Files\Fujitsu\BtnHnd\BtnHnd.exe
O4 - HKLM\..\Run: [Apoint] D:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] D:\Program Files\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [StatusClient] D:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe /auto
O4 - HKLM\..\Run: [TomcatStartup] D:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe
O4 - HKLM\..\Run: [HPLJ Config] D:\Program Files\Hewlett-Packard\hp LaserJet 1150_1300\SetConfig.exe -c Network -p hpLaserJet1300n -pn "hp LaserJet 1300n PCL 6" -n 0 -l 1036 -sl 120000
O4 - HKLM\..\Run: [IMAQBoot] D:\Program Files\National Instruments\NI-IMAQ\bin\ImaqBoot.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [Windows Defender] "D:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [NIRegistrationWizard] D:\Program Files\National Instruments\Shared\RegistrationWizard\Bin\RegistrationWizard.exe -autoDiscover 1 -displayIfNoneFound 0 -displayRegisterOptions 1 -locale 3084 -checkDate true
O4 - Global Startup: Lancement rapide d'Adobe Reader.lnk = D:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Console Java (Sun) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\Program Files\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O12 - Plugin for .csm: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .csml: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cub: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .cube: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .dx: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .emb: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .embl: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .gau: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .jdx: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mol: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .mop: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .pdb: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .rxn: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .scr: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .skc: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .spt: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .tgf: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O12 - Plugin for .xyz: D:\Program Files\Internet Explorer\Plugins\npchime.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.inrs.ca
O16 - DPF: {01010E00-5E80-11D8-9E86-0007E96C65AE} (SupportSoft SmartIssue) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsi.cab
O16 - DPF: {01012101-5E80-11D8-9E86-0007E96C65AE} (SupportSoft Script Runner Class) - http://www.symantec.com/techsupp/asa/ctrl/tgctlsr.cab
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - http://www.symantec.com/techsupp/asa/ctrl/LSSupCtl.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMesse...pDownloader.cab
O16 - DPF: {BE833F39-1E0C-468C-BA70-25AAEE55775E} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - http://www.symantec.com/techsupp/asa/ctrl/SymAData.cab
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) - http://by106fd.bay106.hotmail.msn.com/activex/HMAtchmt.ocx
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - D:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: DefWatch - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Fichiers communs\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: MATLAB Server (matlabserver) - Unknown owner - D:\Matlab7\webserver\bin\win32\matlabserver.exe
O23 - Service: NILM License manager - GLOBEtrotter Software Inc. - D:\Program Files\National Instruments\Shared\License Manager\Bin\lmgrd.exe
O23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - D:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
duchesne
BlackLigt (F-Secure):

08/02/06 15:15:16 [Info]: BlackLight Engine 1.0.42 initialized
08/02/06 15:15:16 [Info]: OS: 5.1 build 2600 (Service Pack 2)
08/02/06 15:15:16 [Note]: 7019 4
08/02/06 15:15:16 [Note]: 7005 0
08/02/06 15:15:27 [Note]: 7006 0
08/02/06 15:15:27 [Note]: 7011 1420
08/02/06 15:15:27 [Note]: 7026 0
08/02/06 15:15:27 [Note]: 7026 0
08/02/06 15:15:32 [Note]: FSRAW library version 1.7.1019
08/02/06 15:17:09 [Note]: 7007 0



RootkitReveal:

HKLM\SOFTWARE\Microsoft\Cryptography\RNG\Seed 2006-08-02 14:48 80 bytes Data mismatch between Windows API and raw hive data.
C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf 2006-08-02 14:49 20.74 KB Hidden from Windows API.
LS CalamityJane
Ok, those logs are all clean, but the error message indicates a driver problem I think.

This is one article I found.
http://support.microsoft.com/default.aspx?...kb;en-us;293077

To check for updates on software drivers:
http://go.microsoft.com/fwlink/?LinkId=50993

Also look in your Event Viewer for any errors
Go to Start > Run and type in the box: eventvwr.msc
Look under System and Application errors. If you see any red ones, you can click on it to view, then use the button that looks like notepaper to copy it to clipboard and save it in Notepad. There should also be links provided in those reports that may provide clues or even solutions if one has been found.
duchesne
Thank you for your reply,

You are correct, and it is a driver issue. Specifically, I found that it is related to my wireless card (Intel® PRO/wireless 2200BG network connection; the driver causing the crash is w22n51.sys). Although it seems only updating the driver would fix the problem, unfortunately it doesnt appear to work. Instead I can connect by cable connection, and the problem goes away smile.gif. I do find it intriguing that the problem only arises when I try updating with Ad-Aware after V1.06 however; I have never run into this problem elsewhere and have been using the same computer for 1.5 years with the same settings.

Thanks again for your help,

David
LS CalamityJane
Well, I wasn't much help then, darn it. I don't know what to tell you. Perhaps when version 2007 comes out, you may find it works again? Or if you find the problem and the solution, please let know.

Did you find the errors in the Event viewer? Did those reports help at all or just points to a problem with the driver?

Ok, wait. We had a thread in here about Intel wireless drivers and there was a solution found. Let me see if I can find that thread and I'll come back with the link.
LS CalamityJane
Sure enough, same one. Look at this post:

http://www.lavasoftsupport.com/index.php?s...post&p=3229
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2010 Invision Power Services, Inc.