This post has been edited by hamluis: 06 February 2011 - 11:02 AM
Reason for edit: Moved from Win 7 to AV, Firewall, Privacy Protection.
Mcafee Antivirus will not run scans
#1
Posted 06 February 2011 - 09:24 AM
#2
Posted 06 February 2011 - 09:38 AM
#3
Posted 06 February 2011 - 11:26 AM
#5
Posted 06 February 2011 - 05:45 PM
#6
Posted 06 February 2011 - 06:02 PM
As Allan stated mcafee is not a very respected AV, with Tech support that seems to match.
I would be more inclined to take the word of the MBAM team then of the mcafee tech(?) support.
#7
Posted 06 February 2011 - 06:10 PM
#8
Posted 06 February 2011 - 06:44 PM
#9
Posted 07 February 2011 - 08:06 AM
#10
Posted 07 February 2011 - 08:25 AM
tinkerbellpixie, on 06 February 2011 - 05:45 PM, said:
If you want, there is a way to check if cngaudit.dll is a legitimate Microsoft executable or not.
Download sigcheck from Microsoft: http://technet.microsoft.com/en-us/sysinternals/bb897441
It is a command-line tool. Start it from cmd.exe: sigcheck.exe cngaudit.dll (this example is assuming you've extracted sigcheck.exe in the same directory as cngaudit.dll).
You will see info displayed about cngaudit.dll, the most important needs to be:
Verified: Signed
This will check the digital signature (AuthentiCode) of cngaudit.dll. If it's not from Microsoft, it will not have a Microsoft signature, and if it is infected, the signature will not be valid.
This post has been edited by Didier Stevens: 07 February 2011 - 08:32 AM
#11
Posted 07 February 2011 - 10:52 AM
#12
Posted 07 February 2011 - 03:51 PM
tinkerbellpixie, on 07 February 2011 - 10:52 AM, said:
No problem. Just save the sigcheck file to one of your folders, and unzip it there. Let's say that the folder you choose is c:\temp
From the start menu, type cmd.exe and run it.
In the cmd.exe console, type cd \temp to go to the folder where you saved sigcheck.
Then type: sigcheck c:\windows\system32\cngaudit.dll
Accept the EULA.
On my machine, I get this output:
sigcheck v1.60 - sigcheck
Copyright (C) 2004-2009 Mark Russinovich
Sysinternals - www.sysinternals.com
c:\windows\system32\cngaudit.dll:
Verified: Signed
Signing date: 4:17 14/07/2009
Strong Name: Unsigned
Publisher: Microsoft Corporation
Description: Windows Cryptographic Next Generation audit library
Product: Microsoft« Windows« Operating System
Version: 6.1.7600.16385
File version: 6.1.7600.16385 (win7_rtm.090713-1255)
Your output should be similar, the versions and date may differ, but the file should be signed (Verified: Signed) by Microsoft.
Update:
You can also do this with the live drive, i.e. without downloading sigcheck.
Start cmd.exe, and type the following command:
\\live.sysinternals.com\tools\sigcheck c:\Windows\System32\cngaudit.dll
If this doesn't work, then do has I explained above.
This post has been edited by Didier Stevens: 07 February 2011 - 03:57 PM
#13
Posted 07 February 2011 - 04:10 PM
#14
Posted 07 February 2011 - 11:14 PM
#15
Posted 07 February 2011 - 11:52 PM
It is ment to compliment and work alongside AV`s to catch what they may miss. Not to replace them.

Help

Back to top










