Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Can't Install Any Antivirus Program


  • Please log in to reply
1 reply to this topic

#1 juliaintrouble

juliaintrouble

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:10:04 PM

Posted 12 April 2008 - 04:37 PM

Hello,

I had loads of problems with a virus
(BDS/IRCBot, BDS/Small, TR/Agent55296.1,...)
which caused me to eventually re-install Windows after having desperately tried everything to get rid of it.

Now the first thing I did was try to install an antivirus program, which failed for AntiVir receiving the message "the CRC of ... was altered. This could be due to a virus". Installation also failed for Kaspersky that did not respond to the installation in the first place; and then for AVG receiving the message "action failed for avgamsvr.exe: starting service - access denied".

I have run HijackThis and ComboFix, but don't know how to analyse the results.

In case this should help I'll post both of them here.

I would be very grateful for any kind of help!

---------

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 19:28:15, on 10.04.2008
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\logonui.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\antiv.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\WINDOWS\ISW\alice\signup\AliceCnn.exe
C:\Programme\Windows NT\Zubehör\WORDPAD.EXE
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
C:\Programme\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice-dsl.de
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.alice-dsl.de
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice-dsl.de
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [Windows Mod Verifier] upfdve.exe
O4 - HKLM\..\Run: [runner1] C:\WINDOWS\mrofinu1001186.exe 61A847B5BBF72813329B39577AFF01F0B3E35B6638993F4661AA4EBD86D67C56389B284534F310
O4 - HKLM\..\Run: [Microsoft Anivirus Monitor Process] antiv.exe
O4 - HKLM\..\RunServices: [Windows Mod Verifier] upfdve.exe
O4 - HKLM\..\RunServices: [Microsoft Anivirus Monitor Process] antiv.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O17 - HKLM\System\CCS\Services\Tcpip\..\{A2F72BAA-E605-4CC4-83B4-19745E3EB97D}: NameServer = 62.109.123.6 213.191.92.87

--
End of file - 2416 bytes

-------

COMBOFIX:

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
TimedOut: progfile.dat

((((((((((((((((((((((( Dateien erstellt von 2008-03-12 bis 2008-04-12 ))))))))))))))))))))))))))))))
.

2008-04-11 00:12 . 2008-04-11 00:12 81,465 --a------ C:\WINDOWS\system32\drivers\klif.cab
2008-04-11 00:04 . 2008-04-11 00:13 <DIR> d-------- C:\Programme\Kaspersky Lab
2008-04-11 00:04 . 2008-04-11 00:22 53,280 --ahs---- C:\WINDOWS\system32\drivers\fidbox.dat
2008-04-11 00:04 . 2008-04-11 00:22 3,360 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.dat
2008-04-11 00:04 . 2008-04-11 00:22 1,676 --ahs---- C:\WINDOWS\system32\drivers\fidbox.idx
2008-04-11 00:04 . 2008-04-11 00:22 1,388 --ahs---- C:\WINDOWS\system32\drivers\fidbox2.idx
2008-04-11 00:01 . 2008-04-11 00:01 <DIR> d-------- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab Setup Files
2008-04-10 19:27 . 2008-04-10 19:27 <DIR> d-------- C:\Programme\Trend Micro
2008-04-10 18:56 . 2008-04-10 18:56 0 --a------ C:\WINDOWS\nsreg.dat
2008-04-09 23:59 . 2001-08-17 13:50 181,632 --a------ C:\WINDOWS\system32\drivers\rdpdr.sys
2008-04-09 23:59 . 2001-08-17 22:38 37,896 --a------ C:\WINDOWS\system32\drivers\termdd.sys

.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-04-09 22:58 73,216 ----a-r C:\WINDOWS\system32\antiv.exe
2008-04-09 22:46 170,496 --sh--r C:\WINDOWS\wiadss.exe
2008-04-09 22:43 114,176 ---ha-w C:\WINDOWS\system32\bueyctqo.exe
2008-04-09 22:40 634,086 ----a-r C:\WINDOWS\system32\runvsc.exe
2008-04-09 22:13 --------- d-----w C:\Programme\microsoft frontpage
2008-04-09 22:07 --------- d-----w C:\Programme\Online-Dienste
2008-04-09 22:05 --------- d-----w C:\Programme\Gemeinsame Dateien\Dienste
.

------- Sigcheck -------

2001-08-23 14:00 430080 2b0e480e975ee51f2d5ce5f068fed6e2 C:\WINDOWS\system32\winlogon.exe

2001-08-18 14:00 1013760 4269b4e94d9ac439758745cdbc41f713 C:\WINDOWS\explorer.exe
2001-08-18 14:00 1013760 da3a0c946f290cea2a42884b439e0486 C:\WINDOWS\system32\dllcache\explorer.exe
.
(((((((((((((((((((((((((((( Autostart Punkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
REGEDIT4
*Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [2001-08-18 14:00 23040]
"MSMSGS"="C:\Programme\Messenger\msmsgs.exe" [2001-08-02 07:14 1089565]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Windows Mod Verifier"="upfdve.exe" []
"Microsoft Anivirus Monitor Process"="antiv.exe" [2008-04-10 00:58 73216 C:\WINDOWS\system32\antiv.exe]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Windows Mod Verifier"="upfdve.exe" []
"Microsoft Anivirus Monitor Process"="antiv.exe" [2008-04-10 00:58 73216 C:\WINDOWS\system32\antiv.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="C:\WINDOWS\System32\CTFMON.EXE" [2001-08-18 14:00 23040]

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
"AntiVirusOverride"=dword:00000001
"UpdatesDisableNotify"=dword:00000001
"FirewallOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableNotifications"= 1 (0x1)

R0 PDDSLHND;PDDSLHND;C:\WINDOWS\System32\drivers\PDDSLHND.sys [2005-10-09 16:13]
R2 MS NET Service;MS NET Service;"C:\WINDOWS\wiadss.exe" [2008-04-10 00:46]
R3 PDDSLADP;ProDyne DSL Adapter;C:\WINDOWS\System32\DRIVERS\PDDSLADP.SYS [2005-10-09 16:13]
S3 NtApm;Herkömmlicher NT APM-Schnittstellentreiber;C:\WINDOWS\System32\DRIVERS\NtApm.sys [2001-08-18 05:27]

*Newly Created Service* - AVG7CORE
*Newly Created Service* - AVG7RSW
*Newly Created Service* - AVG7RSXP
*Newly Created Service* - AVGCLEAN
*Newly Created Service* - AVGTDI
*Newly Created Service* - CATCHME
.
**************************************************************************

catchme 0.3.1351 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-04-12 21:05:56
Windows 5.1.2600 NTFS

detected NTDLL code modification:
ZwOpenFile

Scanne versteckte Prozesse...

C:\WINDOWS\wiadss.exe [884] 0x826E03D0

Scanne versteckte Autostart Einträge...

Scanne versteckte Dateien...

Scan erfolgreich abgeschlossen
versteckte Dateien: 0

**************************************************************************
.
Zeit der Fertigstellung: 2008-04-12 21:07:14
ComboFix-quarantined-files.txt 2008-04-12 19:06:54
5 Verzeichnis(se), 7,486,455,808 Bytes frei
7 Verzeichnis(se), 7,434,084,352 Bytes frei

BC AdBot (Login to Remove)

 


#2 Starbuck

Starbuck

    'r Brudiwr


  • Malware Response Team
  • 4,150 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Midlands, UK
  • Local time:09:04 PM

Posted 24 April 2008 - 08:54 AM

Hi juliaintrouble

I apologize for the delay in response to your thread. We get overwhelmed at times but we are trying our best to keep up.
If you have since resolved the original problem you were having, I would appreciate you letting us know.. If not please perform the following below so I can have a look at the current condition of your machine.

Thanks and again sorry for the delay.

Step 1
Your system is very out of date..... you have no service packs installed.
The minimum requirement for a log reading is SP1.
It is important that you visit:
http://www.microsoft.com/windowsxp/downloa...p1/default.mspx
and then click on 'Express installation'.

Once you have installed SP1 please carry with the rest of these instructions.

Step 2
Please download Deckard's System Scanner (DSS) and save to your Desktop.
alternate download site

DSS will do the following:
  • Create a new System Restore point in Windows XP and Vista.
  • Clean your Temporary Files, Downloaded Program Files, Internet Cache Files, and empty the Recycle Bin on all drives.
  • Check some important areas of your system and produce a report for me to analyze.
  • Automatically run HijackThis. It will also install and place a shortcut to HijackThis on your desktop if you do not already have it installed. So if HijackThis is not installed and DSS prompts you to download it, please answer yes.
You must be logged onto an account with administrator privileges when using.
  • Close all applications and windows.
  • Double-click on dss.exe to run it and follow the prompts.
  • If your anti-virus or firewall complains, please allow this script to run as it is not
    malicious.
  • When the scan is complete, two text files will open in Notepad:
    • main.txt <- this one will be maximized
    • extra.txt <- this one will be minimized
  • If not, they both can be found in the C:\Deckard\System Scanner folder.
  • Please copy (Ctrl+C) and paste (Ctrl+V) the contents of main.txt and extra.txt in your next reply.
-- When running DSS, some firewalls may warn that it is trying to access the Internet especially if your asked to download the most current version of HijackThis. Please ensure that you allow it permission to do so.
-- If you get a warning from your anti-virus while DSS is scanning, please allow DSS to continue as the scan is not harmful.


Step 3
Please do an online scan with Kaspersky WebScanner

Click on Accept Button

You will be promted to install an ActiveX component from Kaspersky, Click Yes.
  • The program will launch and then begin downloading the latest definition files:
  • Once the files have been downloaded click on NEXT
  • Now click on Scan Settings
  • In the scan settings make that the following are selected:
    • Scan using the following Anti-Virus database:
    Extended (if available otherwise Standard)
    • Scan Options:
    Scan Archives
    Scan Mail Bases
  • Click OK
  • Now under select a target to scan:Select My Computer
  • This will program will start and scan your system.
  • The scan will take a while so be patient and let it run.
  • Once the scan is complete it will display if your system has been infected.
    • Now click on the Save as Text button:
  • Save the file to your desktop.
  • Copy and paste that information in your next post.
Many thanks.

BBPP6nz.png





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users