removed virus, can't install antivirus

Discussion in 'Malware Help (A Specialist Will Reply)' started by chiepler, Sep 27, 2010.

  1. chiepler

    chiepler Private First Class

    I recently removed a virus for someone & tried installing a free antivirus program. The installation failed because it said the OS is not supported; it needs Windows 2000 or later. The system icon in the contol panel says this OS is Windows XP Home SP3. Do I still have a virus? Here's my logs....

    PS - RootRepeal showed nothing, so I didn't include the log for that.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. I am currently reviewing your logs and will get back to you with a set of instructions in the next post I make to you.
     
  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, there's still some digging to be done.

    Tell me what symantec products you have installed, I am seeing the below in your logs:

    Symantec KB-DocID:2003093015493306 and LiveUpdate 3.0 (Symantec Corporation)

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Folder::
    c:\documents and settings\All Users\Application Data\Viewpoint
    File::
    C:\WINDOWS\system32\ot.ico 
    DirLook::      
    C:\WINDOWS\system32\1024 
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Don't forget to address my question about symantec.
     
  4. chiepler

    chiepler Private First Class

    Thanks for helping!
    The symantec item might be related to a popup I get when I boot Windows. Down by the system tray, a Windows alert balloon shows up saying "Norton Internet Worm protection is turned off." The only item I see in the Add/Remove Programs list is "Live Update 3.0 (symantec corporation)". I think a Norton product was installed on this PC when it was purchased, but was later removed. Should I uninstall the Live Update item? Would that get rid of the popup/balloon?

    Here are the logs...
     

    Attached Files:

  5. chiepler

    chiepler Private First Class

    Are you still able to help me?
    I still can't install an antivirus due to the Windows version error.
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, you have to be patient as I had alot to get through last night. Reviewing your logs now.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Delete the below empty folder:

    Uninstall:

    • Symantec KB-DocID:2003093015493306
    • LiveUpdate 3.0 (Symantec Corporation)

    Then:

    Please give the Norton Removal Tool (SymNRT) a run > reboot your machine and then run it again for good measure.

    Then:

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  8. chiepler

    chiepler Private First Class

    I removed the folder & the LiveUpdate 3.0, but I can't find Symantec KB-DocID:2003093015493306 anywhere in Add/Remove Programs. I searched the c: drive & didn't pull back any results (I'm showing hidden files). Here's the new logs file....
     

    Attached Files:

  9. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    And are you now able to install antivirus?
    If not, tell me which anti virus you are trying to install
    Tell me what errors you are having when trying.
     
  10. chiepler

    chiepler Private First Class

    No. I wasn't able to install any free AV programs from download.com (AVG, Avira, Avast). The owner of the PC needed it back - I was just helping out.

    I can't remember the exact words of the error message, but it said something along the lines of "this program is not compatible with this version of Windows. Please upgrade to Windows 2000 or later...". I checked various places in the PC like the registry & system icon in control panel and they all said the version was XP Home, SP3. Maybe after all this work, it needed an OS repair to restore its version information????

    Thanks for your time & help!
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If he has not deleted all the tools from his PC get him to give combofix a run by double clicking on it, let's just have one more look. Log retrievable @ C:\combofix.txt

    Then he could also run the below scan

    Using ESET's Online Scanner
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds