Can't install any anti virus software

Discussion in 'Malware Help (A Specialist Will Reply)' started by parseltongue, Jul 15, 2010.

  1. parseltongue

    parseltongue Private E-2

    Hi, I'm having problems installing an antivirus software. I'm running on windows 7 and I'm trying to install AVG Antivirus Free version. This is the error message:

    Local machine: installation failed
    Installation:
    Error: Action failed for file sc.dat: creating file....
    Access is denied.
    Rollback:
    Error: Action failed for file sc.dat: removing file....
    Access is denied. %PATH% = "C:\Program Files\AVG\AVG9\sc.dat"
    Access is denied.

    I tried everything but to no avail. And also there is also an error message when I'm starting to run rootrepeal:

    18:45:57: FOPS - DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x000000dc)
    18:45:57: DeviceIoControl Error! Error Code = 0x1e7
    18:45:57: FOPS - DeviceIoControl Error! Error Code = 0xc0000024 Extended Info (0x000000dc)

    But the other programs run smoothly. Thanks in advance.
     

    Attached Files:

  2. parseltongue

    parseltongue Private E-2

    also, I don't know if this is related. I'm trying to reformat my PC but it can't read the CD. I tried different versions of windows but still it can't boot.

    I tried putting some discs that is not a windows cd and the DVD Rom can read it so I assume it's not the DVD Rom that is busted.

    I assumed that something is preventing the system to read the boot file.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Don't know if your problems are caused by malware or not. I shall see when I review the logs. But after reading this statement from you I am wondering if it is worth it if you are just going to wipe?

    You sound like you have alot of non malware related issues but as I said, regardless, I'll check your logs out now.
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please go to Add/Remove programs and uninstall the following software:

    • Java(TM) 6 Update 16
    • Java(TM) 6 Update 18

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    c:\programdata\19bc9
    
    Folder::
    c:\program files\Free Offers from Freeze.com
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now delete the below as it is not where we requested it to be anyway.

    C:\Users\cha\Desktop\MGtools.exe

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    I suggest you run the Official AVG Removal Tool

    Make sure you also delete any AVG folders in Program Files and Documents & Settings/Application Data directories.

    Now Run Ccleaner. I certainly do not reccommend programs such as Registry Mechanic which you have installed.

    You should now restart your system and, if you were attempting an installation, then download a new set up file for avg and try again.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  5. parseltongue

    parseltongue Private E-2

    I just don't know what to do coz I've tried everything that's why I decided to reformat.. but if there is a work around I definitely won't wipe. :)
     
  6. parseltongue

    parseltongue Private E-2

    I tried to install AVG again but I got the same error:

    Local machine: installation failed
    Installation:
    Error: Action failed for file sc.dat: creating file....
    Access is denied.
    Rollback:
    Error: Action failed for file sc.dat: removing file....
    Access is denied. %PATH% = "C:\Program Files\AVG\AVG9\sc.dat"
    Access is denied.



    The MGtools.exe file is in the desktop because when i'm installing it, it won't install in the c:, there's an error message that says you can't install in the directory. I just installed it in the desktop coz I've read in your read and run me first that "If for some reason you still have a problem trying to save MGtools.exe properly which can happen with Vista and Win7, you can download and run it from your Desktop as long as your Desktop folder is located on the same drive that you boot Windows from." but I've already deleted it. I'm really sorry.

    Also, for C:\Users\cha\Local Settings\TEMP, I can't access the local setting for some reason, the error message is C:\Users\cha\Local Settings is not accessible, access is denied. Even the documents and settings, I also can't access it. Same error.

    the file for the MGlog is nowhere to be found in the c drive. It says in the scanning complete your log file is c:\MGlogs.zip. But it is not in the c drive.
     

    Attached Files:

  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmmm, well then we'll just have to have you rerun MGTools.exe and see if it creates a log as it should do this time.
     
  8. parseltongue

    parseltongue Private E-2

    I've rerun MGtools 4 times and still the zip file is not in the C:
     
  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Sigh...
    Let's try this then :)

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  10. parseltongue

    parseltongue Private E-2

    I perform the ff actions and these are the logs. there are no errors. :)
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hmm, I'm not seeing anything that stands out malware wise... I really think I will end up referring you to software but firstly let's do the below:

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    DirLook::
    C:\Windows\System32\0F6226
    C:\Windows\System32\5A8DCC
    C:\Windows\System32\76682F
    C:\Windows\System32\0F6226
    C:\Windows\System32\5A8DCC
    C:\Windows\System32\76682F
    C:\Windows\System32\ACF7EF
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  12. parseltongue

    parseltongue Private E-2

    these are the logs. there are no errors. thanks a lot. :)
     

    Attached Files:

  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    C:\Windows\System32\0F6226
    C:\Windows\System32\5A8DCC
    C:\Windows\System32\76682F
    C:\Windows\System32\0F6226
    C:\Windows\System32\5A8DCC
    C:\Windows\System32\76682F
    C:\Windows\System32\ACF7EF
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Try and do this now as I cannot see any reason for a complete zipped log not being created.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    If you REALLY can't find a C:\Mglogs.zip then do this again:

    Please click Start, Run, and enter cmd and click OK. This will open a command prompt window. Enter the below commands at the command prompt each followed by the enter key. The bold black are commands. The purple is merely informational.

    cd \MGtools <-- this changes to the MGtools folder and the prompt should change to C:\MGtools>
    ShowNew <-- this will try to run all another scan from MGtools. Tell me what error messages, if any, you see.
    GetRunKey <-- this will try to run all one scan from MGtools. Tell me what error messages, if any, you see.
     
  14. parseltongue

    parseltongue Private E-2

    Sorry if it's just now that I've done all of these things.. I just came back from my vacation.. thanks for your patience.. these are the logs.:)
     

    Attached Files:

  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Did you run the avg removal tool? If you wish to continue using avg and wish to re-install, then you will be well advised to follow my below instructions and then use the removal tool as I suggested earlier. Then you can attempt reinstallation if that's what you want. Or opt for a different AV. Choice is yours.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    Avgfwfd
    
    DirLook::
    C:\ProgramData\MSCEAJKQBYE
    
    File::
    c:\windows\system32\drivers\avgfwd6x.sys
    C:\Users\cha\desktop\avg9inst.log
    
    Folder::
    c:\program files\AVG
    
    Registry::
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3CA2F312-6F6E-4B53-A66E-4E65E497C8C0}]
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now only attempt reinstallation of avg/or other AV after you have run the avg removal tool.

    Run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know how things are running.
     
  16. parseltongue

    parseltongue Private E-2

    I've tried installing AVG again but still it doesn't install..tried to install kaspersky but it says that there is one software that is not compatible, ESET on access scan but I can't find it in add remove programs. I've also included the errors in the attachment. thanks.
     

    Attached Files:

  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Now we are out of the realm of malware removal. The issues you have should now be worked out in the software forum. I am not seeing any malware in those logs. I can have you run this script to be rid of remnants from symantec/ESET scanner.

    You can use the avg Removal Tool again yourself if you wish, as you have stuff remaining from that too.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    epfwwfp
    File::
    c:\windows\system32\DRIVERS\epfwwfp.sys
    Folder::
    c:\programdata\Norton
    c:\programdata\Symantec
    c:\programdata\NortonInstaller
    c:\programdata\Symantec
    c:\program files\Common Files\Symantec Shared
    c:\programdata\MSCEAJKQBYE
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    You don't need to post back with logs. Just create a fresh thread in software.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds