Jump to content

MBAM not responding


Recommended Posts

mbam is freezing after about 12 - 14 secs. Spybot S&D removed 4 critical probems & two subsequent S&D scans are clean. Help would be much appreciated. Thank you.

Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 1:50:13 PM, on 10/31/2010

Platform: Windows 2000 SP4 (WinNT 5.00.2195)

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Boot mode: Normal

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\System32\ibmpmsvc.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\Explorer.EXE

C:\WINNT\system32\tp4mon.exe

C:\WINNT\System32\ibmpmsvc.exe

C:\WINNT\system32\ltmsg.exe

C:\WINNT\system32\RunDll32.exe

C:\WINNT\system32\RunDll32.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\PDirect.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\TP98.EXE

C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe

C:\WINNT\system32\PRPCUI.exe

C:\Program files\ThinkPad\Utilities\tponscr.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\Administrator\Desktop\HijackThis\HijackThis.exe

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing)

O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx

O4 - HKLM\..\Run: [TrackPointSrv] tp4mon.exe

O4 - HKLM\..\Run: [synchronization Manager] mobsync.exe /logon

O4 - HKLM\..\Run: [iBMPMSVC] %SystemRoot%\System32\ibmpmsvc.exe -helper

O4 - HKLM\..\Run: [LTWinModem1] ltmsg.exe 9

O4 - HKLM\..\Run: [soundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd

O4 - HKLM\..\Run: [bMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor

O4 - HKLM\..\Run: [PDIRECT] C:\PROGRA~1\ThinkPad\UTILIT~1\PDirect.exe

O4 - HKLM\..\Run: [TP98UTIL] C:\PROGRA~1\ThinkPad\UTILIT~1\TP98.EXE /s

O4 - HKLM\..\Run: [TpHotkey] C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe

O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

O4 - HKUS\.DEFAULT\..\RunOnce: [^SetupICWDesktop] C:\Program Files\Internet Explorer\Connection Wizard\icwconn1.exe /desktop (User 'Default user')

O4 - Global Startup: ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe

O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/...b?1151876503681

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdat...b?1151874634693

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINNT\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINNT\system32\browseui.dll

O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: IBM PM Service (IBMPMSVC) - IBM Corp. - C:\WINNT\System32\ibmpmsvc.exe

--

End of file - 4694 bytes

StartupList report, 10/31/2010, 1:52:15 PM

StartupList version: 1.52.2

Started from : C:\Documents and Settings\Administrator\Desktop\HijackThis\HijackThis.EXE

Detected: Windows 2000 SP4 (WinNT 5.00.2195)

Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)

* Using default options

==================================================

Running processes:

C:\WINNT\System32\smss.exe

C:\WINNT\system32\winlogon.exe

C:\WINNT\system32\services.exe

C:\WINNT\system32\lsass.exe

C:\WINNT\System32\ibmpmsvc.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\System32\svchost.exe

C:\WINNT\system32\spoolsv.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\system32\svchost.exe

C:\WINNT\Explorer.EXE

C:\WINNT\system32\tp4mon.exe

C:\WINNT\System32\ibmpmsvc.exe

C:\WINNT\system32\ltmsg.exe

C:\WINNT\system32\RunDll32.exe

C:\WINNT\system32\RunDll32.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\PDirect.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\TP98.EXE

C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe

C:\WINNT\system32\PRPCUI.exe

C:\Program files\ThinkPad\Utilities\tponscr.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\Administrator\Desktop\HijackThis\HijackThis.exe

C:\WINNT\system32\NOTEPAD.EXE

--------------------------------------------------

Listing of startup folders:

Shell folders Common Startup:

[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]

ZDWLan Utility.lnk = C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe

--------------------------------------------------

Checking Windows NT UserInit:

[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]

UserInit = C:\WINNT\system32\userinit.exe,

--------------------------------------------------

Autorun entries from Registry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

TrackPointSrv = tp4mon.exe

Synchronization Manager = mobsync.exe /logon

LTWinModem1 = ltmsg.exe 9

SoundFusion = RunDll32 cwcprops.cpl,CrystalControlWnd

BMMGAG = RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor

PDIRECT = C:\PROGRA~1\ThinkPad\UTILIT~1\PDirect.exe

TP98UTIL = C:\PROGRA~1\ThinkPad\UTILIT~1\TP98.EXE /s

TpHotkey = C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe

PRPCMonitor = PRPCUI.exe

QuickTime Task = "C:\Program Files\QuickTime\qttask.exe" -atboottime

Adobe Reader Speed Launcher = "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"

--------------------------------------------------

Autorun entries from Registry:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

swg = C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

SpybotSD TeaTimer = C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

--------------------------------------------------

Autorun entries in Registry subkeys of:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

[OptionalComponents]

=

--------------------------------------------------

Shell & screensaver key from C:\WINNT\SYSTEM.INI:

Shell=*INI section not found*

SCRNSAVE.EXE=*INI section not found*

drivers=*INI section not found*

Shell & screensaver key from Registry:

Shell=Explorer.exe

SCRNSAVE.EXE=*Registry value not found*

drivers=*Registry value not found*

Policies Shell key:

HKCU\..\Policies: Shell=*Registry key not found*

HKLM\..\Policies: Shell=*Registry value not found*

--------------------------------------------------

Enumerating Browser Helper Objects:

(no name) - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}

(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}

(no name) - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dll (file missing) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}

--------------------------------------------------

Enumerating Download Program Files:

[QuickTime Plugin Control]

InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx

CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab

[shockwave ActiveX Control]

InProcServer32 = C:\WINNT\system32\macromed\Director\SwDir.dll

CODEBASE = http://download.macromedia.com/pub/shockwa...director/sw.cab

[Windows Genuine Advantage Validation Tool]

InProcServer32 = C:\WINNT\system32\LegitCheckControl.DLL

CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204

[shockwave ActiveX Control]

CODEBASE = http://fpdownload.macromedia.com/pub/shock...director/sw.cab

[WUWebControl Class]

InProcServer32 = C:\WINNT\system32\wuweb.dll

CODEBASE = http://update.microsoft.com/windowsupdate/...b?1151876503681

[MUWebControl Class]

InProcServer32 = C:\WINNT\system32\muweb.dll

CODEBASE = http://update.microsoft.com/microsoftupdat...b?1151874634693

--------------------------------------------------

Enumerating ShellServiceObjectDelayLoad items:

Network.ConnectionTray: C:\WINNT\system32\NETSHELL.dll

WebCheck: C:\WINNT\system32\webcheck.dll

SysTray: stobject.dll

--------------------------------------------------

End of report, 6,050 bytes

Report generated in 0.060 seconds

Command line options:

/verbose - to add additional info on each section

/complete - to include empty sections and unsuspicious data

/full - to include several rarely-important sections

/force9x - to include Win9x-only startups even if running on WinNT

/forcent - to include WinNT-only startups even if running on Win9x

/forceall - to include all Win9x and WinNT startups, regardless of platform

/history - to list version history only

Link to post
Share on other sites

Hi and welcome to Malwarebytes.

Download DDS by sUBs and save it to your Desktop.

Double-click on the DDS icon and let the scan run. When it has run two logs will be produced, please post DDS.txt directly into your reply.

Thank you for your help.

DDS (Ver_10-11-03.01) - FAT32x86

Run by Administrator at 10:10:34.61 on Wed 11/03/2010

Internet Explorer: 6.0.2800.1106

Microsoft Windows 2000 Professional 5.0.2195.4.1252.1.1033.18.511.280 [GMT -5:00]

============== Running Processes ===============

C:\WINNT\System32\ibmpmsvc.exe

C:\WINNT\system32\spoolsv.exe

C:\WINNT\system32\regsvc.exe

C:\WINNT\system32\MSTask.exe

C:\WINNT\system32\stisvc.exe

C:\WINNT\System32\WBEM\WinMgmt.exe

C:\WINNT\Explorer.EXE

C:\WINNT\system32\tp4mon.exe

C:\WINNT\System32\ibmpmsvc.exe

C:\WINNT\system32\ltmsg.exe

C:\WINNT\system32\RunDll32.exe

C:\WINNT\system32\RunDll32.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\PDirect.exe

C:\PROGRA~1\ThinkPad\UTILIT~1\TP98.EXE

C:\PROGRA~1\ThinkPad\UTILIT~1\tphkmgr.exe

C:\WINNT\system32\PRPCUI.exe

C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe

C:\Program files\ThinkPad\Utilities\tponscr.exe

C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe

C:\Program Files\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Documents and Settings\Administrator\Desktop\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.google.com/

uSearch Page = hxxp://www.google.com

uSearch Bar = hxxp://www.google.com/ie

mDefault_Search_URL = hxxp://www.google.com/ie

uSearchAssistant = hxxp://www.google.com/ie

uSearchURL,(Default) = hxxp://www.google.com/search?q=%s

mSearchAssistant = hxxp://www.google.com/ie

BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll

BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll

BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\program files\google\googletoolbarnotifier\2.0.301.7164\swg.dll

EB: Media Band: {32683183-48a0-441b-a342-7c2a440a9478} - %SystemRoot%\system32\browseui.dll

uRun: [swg] c:\program files\google\googletoolbarnotifier\GoogleToolbarNotifier.exe

uRun: [spybotSD TeaTimer] c:\program files\spybot - search & destroy\TeaTimer.exe

mRun: [TrackPointSrv] tp4mon.exe

mRun: [synchronization Manager] mobsync.exe /logon

mRun: [iBMPMSVC] %SystemRoot%\System32\ibmpmsvc.exe -helper

mRun: [LTWinModem1] ltmsg.exe 9

mRun: [soundFusion] RunDll32 cwcprops.cpl,CrystalControlWnd

mRun: [bMMGAG] RunDll32 c:\progra~1\thinkpad\utilit~1\pwrmonit.dll,StartPwrMonitor

mRun: [PDIRECT] c:\progra~1\thinkpad\utilit~1\PDirect.exe

mRun: [TP98UTIL] c:\progra~1\thinkpad\utilit~1\TP98.EXE /s

mRun: [TpHotkey] c:\progra~1\thinkpad\utilit~1\tphkmgr.exe

mRun: [PRPCMonitor] PRPCUI.exe

mRun: [QuickTime Task] "c:\program files\quicktime\qttask.exe" -atboottime

mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe"

dRunOnce: [^SetupICWDesktop] c:\program files\internet explorer\connection wizard\icwconn1.exe /desktop

StartupFolder: c:\docume~1\alluse~1\startm~1\programs\startup\zdwlan~1.lnk - c:\program files\zydas technology corporation\zydas_802.11g_utility\ZDWlan.exe

IE: {c95fe080-8f5d-11d2-a20b-00aa003c157a} - %SystemRoot%\web\related.htm

IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll

DPF: DirectAnimation Java Classes - file://c:\winnt\java\classes\dajava.cab

DPF: Microsoft XML Parser for Java - file://c:\winnt\java\classes\xmldso.cab

DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://www.apple.com/qtactivex/qtplugin.cab

DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://go.microsoft.com/fwlink/?linkid=39204

DPF: {233C1507-6A77-46A4-9443-F871F945D258} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/director/sw.cab

DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1151876503681

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1151874634693

============= SERVICES / DRIVERS ===============

R1 TPPWR;TPPWR;c:\winnt\system32\drivers\TPPWR.SYS [2006-6-29 11776]

R2 PRPC;PRPC;c:\winnt\system32\drivers\prpc.sys [2006-6-29 12182]

R2 V7;V7;c:\winnt\system32\drivers\V7.SYS [2006-6-29 5536]

R3 S3GSavageMX;S3GSavageMX;c:\winnt\system32\drivers\s3gsavm.sys [2002-11-28 88576]

S3 BRGSp50;BRGSp50 NDIS Protocol Driver;c:\winnt\system32\drivers\BRGSp50.sys [2007-1-23 20608]

S3 cwcspud3;Crystal SoundFusion SPuD3 Driver;c:\winnt\system32\drivers\cwcspud3.sys [2000-3-2 19056]

S3 LSWPCv4;Wireless-B Notebook Adapter Driver;c:\winnt\system32\drivers\rtl8180.sys --> c:\winnt\system32\drivers\rtl8180.sys [?]

S3 MBAMSwissArmy;MBAMSwissArmy;c:\winnt\system32\drivers\mbamswissarmy.sys [2010-10-31 38224]

S3 neo20xx;neo20xx;c:\winnt\system32\drivers\neo20xx.sys [2000-3-2 39888]

S3 pc100;Linksys EtherFast 10/100 PC Card NT Driver;c:\winnt\system32\drivers\pc100nd5.sys [2000-10-4 29049]

S3 RTLWUSB;NETGEAR WG111v2 54Mbps Wireless USB 2.0 Adapter NT Driver;c:\winnt\system32\drivers\wg111v2.sys --> c:\winnt\system32\drivers\wg111v2.sys [?]

S3 WPC11;Instant Wireless Network PC Card V2.0 Driver;c:\winnt\system32\drivers\lswlnds.sys --> c:\winnt\system32\drivers\LSWLNDS.sys [?]

=============== Created Last 30 ================

2010-10-31 06:45:26 38224 ----a-w- c:\winnt\system32\drivers\mbamswissarmy.sys

2010-10-31 06:45:20 19288 ----a-w- c:\winnt\system32\drivers\mbam.sys

2010-10-31 05:23:28 -------- d-----w- C:\e25896478ffe63433f4dfc

2010-10-31 02:28:34 -------- d-----w- C:\237a2cb5a023eb4e8c0706d1

2010-10-30 08:41:23 -------- d-----w- c:\program files\Spybot - Search & Destroy

2010-10-30 08:41:23 -------- d-----w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy

2010-10-30 07:57:19 -------- d-----w- C:\688cac224c3a491fa8

2010-10-30 07:33:46 -------- d-----w- c:\docume~1\admini~1\applic~1\Malwarebytes

2010-10-30 07:33:28 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware

2010-10-30 07:33:28 -------- d-----w- c:\docume~1\alluse~1\applic~1\Malwarebytes

2010-10-30 06:57:09 -------- d-----w- C:\5a9b490a3647f2d57438dd

2010-10-29 20:08:14 80848 ----a-w- c:\winnt\system32\dllcache\ipsec.sys

2010-10-29 20:04:14 1715264 ----a-w- c:\winnt\system32\dllcache\NTKRNLMP.EXE

2010-10-29 20:04:13 1736576 ----a-w- c:\winnt\system32\dllcache\NTKRPAMP.EXE

==================== Find3M ====================

============= FINISH: 10:12:01.37 ===============

Link to post
Share on other sites

  • Staff

Hi,

1. Uninstall Malwarebytes' Anti-Malware using Add or Remove programs in the Control Panel.

2. Restart your computer (very important).

3. Download and run this utility.

4. It will ask to restart your computer (please allow it to).

5. After the computer restarts, install the latest version from here.

Note: You will need to reactivate the program using the license you were sent via e-mail if you purchased it.

Try updating and running a Quick Scan. If it stops again, let me know on what file it crashes.

Link to post
Share on other sites

Hi,

1. Uninstall Malwarebytes' Anti-Malware using Add or Remove programs in the Control Panel.

2. Restart your computer (very important).

3. Download and run this utility.

4. It will ask to restart your computer (please allow it to).

5. After the computer restarts, install the latest version from here.

Note: You will need to reactivate the program using the license you were sent via e-mail if you purchased it.

Try updating and running a Quick Scan. If it stops again, let me know on what file it crashes.

It crashed at:

c:\WINNT\system32\SHLWAPI.dll

Link to post
Share on other sites

  • Staff

Hi,

Please zip up a copy of that file and attach it in your next reply.

What security programs are you currently running? Does the crash occur during a Full Scan only or during a Quick Scan as well?

Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).

Try a Full and Quick scan from there and see if it still hangs.

-screen317

Link to post
Share on other sites

Hi,

Please zip up a copy of that file and attach it in your next reply.

What security programs are you currently running? Does the crash occur during a Full Scan only or during a Quick Scan as well?

Please reboot to Safe Mode (tap the F8 key just before Windows starts to load and select the Safe Mode option from the menu).

Try a Full and Quick scan from there and see if it still hangs.

-screen317

Hi & thank you for your assistance. The zipped file is attached. I successfully ran a Quick and Full Scan while in Safe Mode. Then, I downloaded and ran MCPR.exe just to make sure that any traces of McAfee were gone as it had been installed in the past. Rebooted and ran a Quick Scan. It hung up on the same file that I have attached as a zip.

SHLWAPI.zip

Link to post
Share on other sites

Hi,

Under Scanner Settings in MBAM, uncheck Enable advanced heuristics engine. (Heuristics.Shuriken); then try running a Quick Scan. See if it still freezes.

Hi,

I unchecked the box, ran a Quick Scan and MBAM froze at the following file location. I was "not permitted to upload this type of file".

C:\WINNT\system32\cwcprops.cpl

Link to post
Share on other sites

  • 4 weeks later...
  • Staff

Glad we could help. :)

If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.