PDA

View Full Version : Avira AntiVir



spy2008
2008-02-08, 22:00
I can not up date the Avira AntiVir scanner,the main reason is the master MDX file has changed:

09.02.2008 03:13:18 - Avira AntiVir PersonalEdition Classic

09.02.2008 03:13:47 - Connection failed while downloading the file http://dl5.avgate.net/upd/idx/master.idx.
09.02.2008 03:13:47 - Switching to next update server
09.02.2008 03:14:09 - Connection failed while downloading the file http://dl6.avgate.net/upd/idx/master.idx.
09.02.2008 03:14:09 - Switching to next update server
09.02.2008 03:14:16 - Master IDX file has changed
09.02.2008 03:14:23 - Keyfile: OK [FULL Mode]

09.02.2008 03:14:27 - File basic-nt/2k/avgntflt.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/avadmin.exe's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/avgio64.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/imp64b.exe's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/psapi.dll's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/shlext64.dll's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/vista64/avgntflt.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/wsctool.exe's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/xp64/avgntflt.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/2k/avgntdd.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/2k/avgntmgr.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/nt/avgntdd.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/nt/avgntmgr.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - File basic-nt/vista64/avgntflt.sys's operating system doesn't match the current one. File ignored.
09.02.2008 03:14:27 - Downloading the product.info file from http://dl4.avgate.net/upd/idx/vdf.info.gz
09.02.2008 03:14:49 - There was a problem updating from the specified server: Connection failed while downloading the file http://dl4.avgate.net/upd/idx/vdf.info.gz.
09.02.2008 03:14:49 - Switching to next update server
09.02.2008 03:15:15 - Master IDX file has changed
09.02.2008 03:15:36 - The following file could not be downloaded: http://dl1.avgate.net/idx/message.idx

09.02.2008 03:15:41 - Keyfile: OK [FULL Mode]

09.02.2008 03:15:41 - Downloading the product.info file from http://dl6.avgate.net/upd/idx/vdf.info.gz
09.02.2008 03:16:03 - There was a problem updating from the specified server: Connection failed while downloading the file http://dl6.avgate.net/upd/idx/vdf.info.gz.
09.02.2008 03:16:03 - Switching to next update server
09.02.2008 03:16:07 - Master IDX file has changed
09.02.2008 03:16:08 - Downloading the product.info file from http://dl7.avgate.net/upd/idx/vdf.info.gz
09.02.2008 03:16:30 - There was a problem updating from the specified server: Connection failed while downloading the file http://dl7.avgate.net/upd/idx/vdf.info.gz.
09.02.2008 03:16:30 - Switching to next update server
09.02.2008 03:16:57 - Connection failed while downloading the file http://dl1.avgate.net/upd/idx/master.idx.
09.02.2008 03:16:57 - Switching to next update server
09.02.2008 03:17:18 - Connection failed while downloading the file http://dl2.avgate.net/upd/idx/master.idx.
09.02.2008 03:17:18 - Switching to next update server
09.02.2008 03:17:32 - Master IDX file has changed
09.02.2008 03:17:59 - The following file could not be downloaded: http://dl3.avgate.net/idx/message.idx

09.02.2008 03:18:04 - Keyfile: OK [FULL Mode]

09.02.2008 03:18:04 - Downloading the product.info file from http://dl1.avgate.net/upd/idx/vdf.info.gz
09.02.2008 03:18:25 - There was a problem updating from the specified server: Connection failed while downloading the file http://dl1.avgate.net/upd/idx/vdf.info.gz.
09.02.2008 03:18:25 - Switching to next update server
09.02.2008 03:18:32 - Master IDX file has changed
09.02.2008 03:18:37 - Downloading the product.info file from http://dl2.avgate.net/upd/idx/vdf.info.gz
09.02.2008 03:18:44 - Keyfile: OK [FULL Mode]

09.02.2008 03:18:44 - Downloading the product.info file from http://dl2.avgate.net/upd/idx/specvir-nt.info.gz
09.02.2008 03:18:45 - Downloading the product.info file from http://dl2.avgate.net/upd/idx/engine.info.gz
09.02.2008 03:18:45 - Downloading the product.info file from http://dl2.avgate.net/upd/idx/engine-nt-en.info.gz
09.02.2008 03:18:49 - Module: SELFUPDATE Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 15
09.02.2008 03:18:49 - Module: MAIN Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 75
09.02.2008 03:18:52 - Module: COMMAPPDATA Source: winwks\en\ Destination: C:\Documents and Settings\All Users\Application Data\ Files: 1
09.02.2008 03:18:52 - Module: TEXT Source: winwks\en\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 3
09.02.2008 03:18:53 - Module: VDF Source: vdf\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 4
09.02.2008 03:18:53 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir2.vdf 7.0.2.49 < 7.0.2.113
09.02.2008 03:18:53 - C:\Program Files\Avira\AntiVir PersonalEdition Classic\antivir3.vdf 7.0.2.107 < 7.0.2.114
09.02.2008 03:18:53 - Module: AVREP_NT Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
09.02.2008 03:18:53 - Module: ENGINE Source: engine\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 2
09.02.2008 03:18:53 - Module: ENGINE_NT_EN Source: engine\nt\ Destination: C:\Program Files\Avira\AntiVir PersonalEdition Classic\ Files: 1
09.02.2008 03:18:53 - Module: DRV Source: winwks\en\ Destination: C:\WINDOWS\SYSTEM32\drivers\ Files: 4
09.02.2008 03:18:53 - Minifilter is installed

09.02.2008 03:18:53 - Minifilter is possible

09.02.2008 03:18:53 - Reading registry value successful: Software\Avira\AntiVir PersonalEdition Classic | FilterType

09.02.2008 03:18:53 - Initialize avnotify.exe

09.02.2008 03:18:53 - Starting avnotify.exe successful

09.02.2008 03:18:53 - Preparing to download files
09.02.2008 03:18:53 - 2 files need to be downloaded / copied from http://dl2.avgate.net/upd/
09.02.2008 03:18:53 - #1: Downloading and extracting http://dl2.avgate.net/upd/vdf/antivir2.vdf.gz to C:\Documents and Settings\All Users\Application Data\Avira\AntiVir PersonalEdition Classic\Update\AVUPDATE_47aca9cb\vdf\antivir2.vdf
09.02.2008 03:19:15 - There was a problem updating from the specified server: Connection failed while downloading the file http://dl2.avgate.net/upd/vdf/antivir2.vdf.gz.
09.02.2008 03:19:15 - Switching to next update server
09.02.2008 03:19:37 - There was a problem updating from the specified server: Connection failed while downloading the file http://dl3.avgate.net/upd/idx/master.idx.
09.02.2008 03:19:37 - Switching to next update server
09.02.2008 03:19:58 - There was a problem updating from the specified server: Connection failed while downloading the file http://dl3.avgate.net/upd/idx/master.idx.
09.02.2008 03:19:58 - Switching to next update server
09.02.2008 03:20:31 - Registry entry created successfully: Software\Avira\AntiVir PersonalEdition Classic |UpdateInProgress

09.02.2008 03:20:31 - Critical error: Connection failed while downloading the file http://dl3.avgate.net/upd/idx/master.idx.



I tried few times, but the result is the same. anybody know why ?

Also, in my scan result, it mentioned can not open below file :

system volume information\_restore45B27768-AF09-4DBF-98OA-RP34\A0013867.dll.

information\restore-45B27768-AF-09-4DBF-9BOA-A0016693.exe

Is it from a virus called "W95/Blumblebee.1738 " ?

Thanks.

spy2008
2008-02-09, 10:47
Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
C:\Documents and Settings\li\Local Settings\Temp\ISSCAN\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was deleted!
C:\Documents and Settings\li\Local Settings\Temp\{842FC730-641C-42CC-8765-5FE37F05AA6F}\{EEBA9416-3207-47E0-9022-116440599DBC}\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '4814f9d5.qua'!
C:\Documents and Settings\li\Local Settings\Temp\{9625F136-84C2-4358-A781-0E19BD15903D}\{98032D6F-3EE6-4646-B68C-40BF012AC89B}\pskavs.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '4814fa0c.qua'!
C:\Documents and Settings\li\My Documents\nmchat.dll
[WARNING] The file could not be opened!
C:\Documents and Settings\li\My Documents\新資料夾 (2)\miniremoval_coolwebsearch_smartkiller.exe
[WARNING] The file could not be opened!
C:\Documents and Settings\li\My Documents\新資料夾 (3)\adsdir.exe
[WARNING] The file could not be opened!
C:\Documents and Settings\li\My Documents\新資料夾 (3)\ADSLocator.exe
[WARNING] The file could not be opened!
C:\Documents and Settings\li\My Documents\新資料夾 (3)\sfl.exe
[WARNING] The file could not be opened!
C:\Documents and Settings\li\My Documents\新資料夾 (3)\sfp.exe
[WARNING] The file could not be opened!
C:\System Volume Information\_restore{45B27768-AF09-4DBF-9B0A-AC5C75A98CA0}\RP18\A0009170.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47d9fe5b.qua'!
C:\System Volume Information\_restore{45B27768-AF09-4DBF-9B0A-AC5C75A98CA0}\RP33\A0012692.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47d9fea1.qua'!
C:\System Volume Information\_restore{45B27768-AF09-4DBF-9B0A-AC5C75A98CA0}\RP34\A0013760.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47d9feb1.qua'!
C:\System Volume Information\_restore{45B27768-AF09-4DBF-9B0A-AC5C75A98CA0}\RP34\A0013867.dll
[WARNING] The file could not be opened!C:\System Volume Information\_restore{45B27768-AF09-4DBF-9B0A-AC5C75A98CA0}\RP38\A0015422.dll
[DETECTION] Contains detection pattern of the Windows virus W95/Blumblebee.1738
[INFO] The file was moved to '47d9fee9.qua'!
C:\System Volume Information\_restore{45B27768-AF09-4DBF-9B0A-AC5C75A98CA0}\RP45\A0016693.exe
[WARNING] The file could not be opened!


Now i can update the Antivir. However, i believe the virus is still detected in below file, pls advise how can i clean it ?

C:\System Volume Information\_restore{45B27768-AF09-4DBF-9B0A-AC5C75A98CA0}\RP34\A0013867.dll
[WARNING] The file could not be opened!

Thanks...

tashi
2008-02-10, 11:36
Hello.

Please see the stickied procedure for this forum: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288)

Then start a new topic, I will close this one as helpers look for zero response. ;)

Regards.