spapps Posted January 3, 2006 Posted January 3, 2006 (edited) Hi I am new here.Just spent about 10 minutes writing up this thread, then deleted the text and restarted lol.To the main point:my WS2003EE with SP1 got infected, for the first time ever, by a trojan/spyware. Anti spyware didnt pick it up unfortunatly, even though i ran an update earlier. My router firewall seemed to have not responded for some reason - whatever. I got hit bad.I didnt wanna have to format and re-install as I have alot of stuff on there, programs, documents, projects, other backups - you name it.Tried several ways of removing it, couldnt.I then got Norton Corporate anti virus 10.0, installed perfect, picked up the devil and removed it. cool, was on the role!However the virus still existed some place, even after removing it and following instructions from symantecs website on where it would place it self etc..The virus infected explorer.exe - not a good thing of course.so, ended up formatting and re-installing.The 2nd thing I decided to do was to install NAV Corp 10.0 after installing anti spyware, and no drivers (the only drivers left were to update the gfx card and capture card). NAV failed to install. I thought ok, perhaps I need to install the rest of the drivers, and software and the system will be updated etc... (after installing updates) and it would all be well.nope.I tried re-doing the installation of NAV Corp v10.0 - still failed. Was really getting annoyed.Did everything I could think of, but it still failed to install and still is failing.I googled the issue but there was no set cure. Been on symantec's website - any suggestions posted did not help.I do not understand what the problem is! Norton Anti Virus Corp edition v10.0 installed fine when i had been infected but not after reformatting and re-installing the computer. I do not understand.I looked at the event logs and found this:The description for Event ID ( 7 ) in Source ( Symantec AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer.The description for Event ID ( 14 ) in Source ( Symantec AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer. The description for Event ID ( 13 ) in Source ( Symantec AntiVirus ) cannot be found. The local computer may not have the necessary registry information or message DLL files to display messages from a remote computer.Also just found a new one:Product: Symantec AntiVirus -- Installation operation failed.well duh! lol.I dont know what the problem is! Does anyone know? I am really stuck and would really want to install this.if anyone has any suggestions or a solution, please post. Would greatly appreciate it!I am usually pretty darn good at this stuff but cannot figure out what the problem is. The virus is completly removed as I had scanned it on another OS on a different computer. Edited January 3, 2006 by spapps
gamehead200 Posted January 3, 2006 Posted January 3, 2006 Not sure what the problem might be, but my guess is that the install just failed because of a corrupt file. But that wouldn't make much sense because as you said, it worked before you formatted. Did you do a quick format or a full format when reinstalling Windows? Also, did you install anything before installing NAV?
spapps Posted January 3, 2006 Author Posted January 3, 2006 (edited) hey thanks for the speedy response! I did reextract the file but that made no use so it is not corruptedI did a full format, I always do.The only thing I installed before NAV was Anti spyware software. Even if i disable that to make sure it wasnt blocking the installation did not help. Even if I disabled the firewall on the computer - that did not help.When I was infected, I of course had the full works of software installed (Office, dev tools, SQL Server etc...) and it installed fine but now before installing all that, and after, it does not install. It just "failed" and has no errors to give me.The interesting thing is - if I run the msi installer from a folder, which I think gets executed in the background if i install it the normal way - it almost completes installation then rolls back saying that the setup was interrupted before it could finish - but no idea what interrupted it. The errors in the event log are also the same from this.Oh - I am sorry if i have posted in the wrong forum Edited January 3, 2006 by spapps
gamehead200 Posted January 3, 2006 Posted January 3, 2006 Don't worry about it...Ummm... Let's see... You say the installation rolls back? What other processes are running when you're installing NAV? I suggest getting HijackThis! and posting what processes you're computer has running on startup. Save the log and post it here.[ Moved. ]
spapps Posted January 3, 2006 Author Posted January 3, 2006 (edited) hehe ive heard about that tool on forums from googling yesterday about this issue.Ive tried to install in safe mode without much success either.here is the file attachment or if you prefer a cleaner look:http://www.spapps.co.uk/personal/hijackthis.txthijackthis.txt Edited January 3, 2006 by spapps
gamehead200 Posted January 3, 2006 Posted January 3, 2006 Is this from before formatting, because it looks like you've got W32/Deloder.worm?
spapps Posted January 3, 2006 Author Posted January 3, 2006 (edited) no this is AFTER formatting - I cannot install NAV Corp after formatting - and how do you know/find out if i got that virus from the tool? I have googled the W32/Deloder.worm and found out its characteristics but i can confirm that there is no virus on the system and that the W32/Deloder.worm is not on the system Edited January 3, 2006 by spapps
gamehead200 Posted January 3, 2006 Posted January 3, 2006 If I were you, I'd visit this page right now and let it scan your computer. You've definitely got a worm on your computer according to your HijackThis log. This will scan your computer and remove anything that's unwanted. Also, do you have a firewall on?http://www.trendmicro.com/hc_intro/default.asp
spapps Posted January 3, 2006 Author Posted January 3, 2006 (edited) that sucks! Already I have a worm? no way! I scanned the system using a different OS/HDD and had the firewall on (in Windows) and on the router as always!the firewall is enabled by default when you install WS2003EE with SP1 - firewalls are always on. but please tell me for my reference, how do you know I have a worm? *scanning from link as requested*it says it will take 10 hours to scan :-/ I have a 10MB connection lol Edited January 3, 2006 by spapps
gamehead200 Posted January 3, 2006 Posted January 3, 2006 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/hardAdmin.htmR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://shdoclc.dll/hardAdmin.htmA quick search on Google shows that res://shdoclc.dll/hardAdmin.htm refers to a worm. If you open Internet explorer, you should be automatically brought to some kind of a search page, with or without pop-ups. If this is not the case, this is probably a leftover from something else, but I highly doubt it.
spapps Posted January 3, 2006 Author Posted January 3, 2006 (edited) ah!that is NOT a worm. that is the DEFAULT web page for WS2003 with SP1. Trust me, thats not a worm I have also asked my colleagues and they confirm this. that page is the default page which tells you that IE is on the "high lock" security settingwe also deploy tons of computers and that is the default page for WS200, but the computer that NAV is installing on, that is my own personal computer at home. Edited January 3, 2006 by spapps
gamehead200 Posted January 3, 2006 Posted January 3, 2006 ah!that is NOT a worm. that is the DEFAULT web page for WS2003 with SP1. Trust me, thats not a worm I have also asked my colleagues and they confirm this. that page is the default page which tells you that IE is on the "high lock" security settingAh, OK. At least we're clear now. Have you tried booting into safe mode and tried to install NAV?
spapps Posted January 3, 2006 Author Posted January 3, 2006 hehe btw - hope you didnt feel offended when i screamed NOT - did not mean it in that sense That was just to make sure... yes I have tried to install NAV corp in safe mode without much success - same issuestop scaring me when you came to the conclusion I have a worm! almost collapsed reading lol
gamehead200 Posted January 3, 2006 Posted January 3, 2006 No offense taken! We all make mistakes.As to NAV, I have no other idea what it may be. If it installed before, it should install now. I don't see what the problem may be. Anyone?
spapps Posted January 3, 2006 Author Posted January 3, 2006 I agree totally - if it installed in the first place, why not now? It's a "baffler"apperently symantec ARE aware of the issue and working on it - but the point is - they should have tested properly first then releasing it, or at least providing a work around for someone in this situation.
Recommended Posts
Please sign in to comment
You will be able to leave a comment after signing in
Sign In Now