BleepingComputer.com: antivirus not working

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 11 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

antivirus not working antivirus

#31 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 18 September 2011 - 08:16 AM

i have it in my download files and in the desktop too ....

#32 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,005
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 18 September 2011 - 09:40 AM

Right click on the desktop file combofix.exe and select Properties. On the first tab, do you see a Target or Location? If so can you tell me what is shown there?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#33 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 18 September 2011 - 10:10 AM

what i have in my desktop is SHORTCUT TO COMBOFIX
and theres no target or location, it only says FIND TARGET.
Did I do it all wrong? perhaps we need to start all over again?
I'm really sorry Elise.

#34 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,005
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 18 September 2011 - 02:34 PM

No problem. Right click on combofix.exe there and click Cut, now right click on your desktop and click Paste.
You should now have combofix.exe on your desktop. Double click on this and see if it will run.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#35 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 23 September 2011 - 11:49 AM

Hi Elise, thank you for being patient. But can I just download combofix.exe again?
please tell me how to do it, cause i tried this cut and paste thing but still it didn't run.

josh

#36 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,005
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 23 September 2011 - 12:02 PM

In that case, right click on the following link: http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Select "Save link/target as"
Save the file as combofix.exe to your desktop (click the Desktop button in the left panel, click Save).

The file should now be downloaded directly to your desktop.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#37 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 23 September 2011 - 12:23 PM

Okay, I'm really having a headache now... I'm really, really lost.
I have downloaded combofix again so now its the combofix(3) in my file.
I have tried to delete the other two but it didn't allow me to delete it.
I have saved the combofix that I have just downloaded now but it went directly to
my DOWNLOADS folder, not in my desktop. I went to the DOWNLOADS folder and click
CUT and went to my desktop and click PASTE. For some reasons, it didn't allow me
to perform the said action and it said that "make sure that the dick is not full
or protected" something like that...
Elise... still got patience for me?
Is there anyway that we could chat or we can only talk here? I mean, just trying to find
a faster way to communicate.

#38 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,005
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 23 September 2011 - 12:46 PM

We can chat using IRC if you'd like that.

You can use the Web client: http://www.bleepingcomputer.com/webchat/

My IRC nick is Elise, feel free to give me a nudge. :)
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#39 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 30 September 2011 - 12:16 PM

hi Elise, how are you?
can we talk in the chatroom?

#40 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,005
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 30 September 2011 - 12:56 PM

Hi Josh, how are things running now? Have you been able to run Junction as discussed?
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#41 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 01 October 2011 - 03:47 AM

Hi Elise, this is the yext that I got:

Junction v1.06 - Windows junction creator and reparse point viewer
Copyright © 2000-2010 Mark Russinovich
Sysinternals - www.sysinternals.com


Failed to open \\?\c:\\hiberfil.sys: The process cannot access the file because it is being used by another process.



Failed to open \\?\c:\\pagefile.sys: The process cannot access the file because it is being used by another process.



Failed to open \\?\c:\\System Volume Information: Access is denied.


...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...

...


Failed to open \\?\c:\\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix(1).exe: Access is denied.



Failed to open \\?\c:\\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix(2).exe: Access is denied.



Failed to open \\?\c:\\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix(3).exe: Access is denied.



Failed to open \\?\c:\\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix.exe: Access is denied.


...

...

...

...

...

...

...

.
Failed to open \\?\c:\\Program Files\Avira\AntiVir Desktop\avscan.exe: Access is denied.


..

...

...

...

...
Failed to open \\?\c:\\Program Files\Google\Chrome\Application\chrome.exe: Access is denied.




...

...

...

...

...

...

...

...

...

...

...

...


Failed to open \\?\c:\\WINDOWS\$NtUninstallKB37241$: Access is denied.


...

...

...

...

...

...

\\?\c:\\WINDOWS\assembly\GAC_32\System.EnterpriseServices\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790
Substitute Name: C:\WINDOWS\WinSxS\x86_System.EnterpriseServices_b03f5f7f11d50a3a_2.0.0.0_x-ww_7d5f3790


Failed to open \\?\c:\\WINDOWS\assembly\GAC_MSIL\Desktop(2).ini: Access is denied.



Failed to open \\?\c:\\WINDOWS\assembly\GAC_MSIL\Desktop.ini: Access is denied.


\\?\c:\\WINDOWS\assembly\GAC_MSIL\IEExecRemote\2.0.0.0__b03f5f7f11d50a3a: JUNCTION
Print Name : C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e
Substitute Name: C:\WINDOWS\WinSxS\MSIL_IEExecRemote_b03f5f7f11d50a3a_2.0.0.0_x-ww_6e57c34e

...

...

...

...

...

...

...


Failed to open \\?\c:\\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\enterprisesec.config.cch.536.2117093: Access is denied.



Failed to open \\?\c:\\WINDOWS\Microsoft.NET\Framework\v2.0.50727\CONFIG\security.config.cch.536.2117093: Access is denied.


...

...

...


Failed to open \\?\c:\\WINDOWS\system32\MRT.exe: Access is denied.


...

...

...

..

#42 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,005
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 01 October 2011 - 04:31 AM

Please go to your Downloads folder and double click on GrantPerms.exe or GrantPerms64.exe
Copy and paste the following in the edit box:

c:\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix(1).exe
c:\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix(2).exe
c:\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix(3).exe
c:\Documents and Settings\Dewagede\My Documents\Downloads\ComboFix.exe
c:\Program Files\Avira\AntiVir Desktop\avscan.exe
c:\Program Files\Google\Chrome\Application\chrome.exe
c:\WINDOWS\$NtUninstallKB37241$
c:\WINDOWS\system32\MRT.exe

Click Unlock. When it is done click "OK".
Click List Permissions and post the result (Perms.txt) that pops up. A copy of Perms.txt will be saved in the same directory the tool is run.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#43 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 01 October 2011 - 06:25 AM

i did what u tell me, i posted the text in the edit box and clicked unlock...after that it disappears and no pop-ups appeared. :(

#44 User is offline   Elise 

  • Bleepin' Blonde
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Study Hall Admin
  • Posts: 39,005
  • Joined: 05-October 07
  • Gender:Female
  • Location:Romania

Posted 01 October 2011 - 08:06 AM

How are things running at this moment?

Can you please rerun Combofix (just double click on it to run it). If it asks you to update, click Yes.
regards, Elise

"The mind is its own place, and in itself can make a heaven of hell, a hell of heaven." ~ John Milton
Posted Image Follow BleepingComputer on: Facebook | Twitter | Google+

#45 User is offline   josh@bcn 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 105
  • Joined: 14-July 11

Posted 01 October 2011 - 08:10 AM

still no pop up.... for this Grantperms.
I rerun combofix and it did run... a black box appeared with some green text running, but it
didn't ask me to update.

Share this topic:


  • 11 Pages +
  • 1
  • 2
  • 3
  • 4
  • 5
  • Last »
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users