You are not logged in.

Wednesday, July 30th 2014, 7:00am

The Avira Forum will be moved to the new platform Avira Answers soon. We'll make the transition of existing user profiles and threads as smooth as possible.
New visitors are able to log in on Avira Answers with the existing Avira account directly or sign up with a new account.

  • "zavclub" started this thread

Date of registration:
Dec 25th 2009

  • Send private message

1

Friday, December 25th 2009, 12:55pm

Installing new files

The problem appears when using Avira Personal 9 on virtual machine (VMWare 6.5.2 with WinXP SP3 as a guest system). Avira starts update, downloads new files without any problems, then reastarts update, downloads all files again, stops the guard and begins installing new files. When progress bars shows ~70% of completion it hangs and there is no possibility to shut it: neither thru task manager, nor by warm turn off (sometimes it shows message that system blocks the process). Reinstallation doesn't help because also hangs while installer stopps running Avira.

Is there any solution for problem?

Date of registration:
Jan 5th 2009

Operating System:
XP

  • Send private message

2

Monday, December 28th 2009, 8:37am

Hi,
Does this command work?
"C:\Program Files\Avira\AntiVir Desktop\update.exe" /DM="0" /NOMESSAGEBOX /receivetimeout=120
Also if this doesn't work please try to make a manual update
Thanks for choosing Avira
Alexandru Manea
Avira Operations GmbH & Co. KG

  • "zavclub" started this thread

Date of registration:
Dec 25th 2009

  • Send private message

3

Monday, December 28th 2009, 2:46pm

There is no problem with downloading updates -- problem appears when it goes about installing new files (system blocks updater)

Date of registration:
Jan 5th 2009

Operating System:
XP

  • Send private message

4

Monday, December 28th 2009, 3:38pm

Hi,

Please also post here a HJT log
Thanks for choosing Avira
Alexandru Manea
Avira Operations GmbH & Co. KG

  • "zavclub" started this thread

Date of registration:
Dec 25th 2009

  • Send private message

5

Tuesday, December 29th 2009, 5:27pm

Here it is:
-----------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:47:17, on 29.12.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\Program Files\VMware\VMware Tools\vmacthlp.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\VMware\VMware Tools\VMwareTray.exe
C:\Program Files\VMware\VMware Tools\VMwareUser.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Ditto\Ditto.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Launchy\Launchy.exe
C:\Program Files\Punto Switcher\punto.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\VMware\VMware Tools\VMwareService.exe
C:\WINDOWS\system32\wscntfy.exe
W:\usr\local\mysql5\bin\mysqld.exe
W:\usr\local\apache\bin\TrayApache.exe
W:\denwer\tools\sendmail\sendmail_daemon_start.exe
W:\usr\local\apache\bin\httpd.exe
W:\usr\local\miniperl\miniperl.exe
W:\usr\local\apache\bin\httpd.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Documents and Settings\All Users\Application Data\Avira\AntiVir Desktop\TEMP\UPDATE\TMP_UPDATE\update.exe
C:\Program Files\Avira\AntiVir Desktop\avguard.exe
C:\Program Files\Ashampoo\UnInstaller Suite\UnInstaller.exe
C:\Program Files\Far\Far.exe
C:\Program Files\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки
O1 - Hosts: 127.0.0.3 b-a-co.com
O1 - Hosts: 127.0.0.4 www.b-a-co.com
O1 - Hosts: 127.0.0.5 locator.b-a-co.com
O1 - Hosts: 127.0.0.6 www.locator.b-a-co.com
O1 - Hosts: 127.0.0.7 i-currency.info
O1 - Hosts: 127.0.0.8 www.i-currency.info
O1 - Hosts: 127.0.0.9 internet-currency.info
O1 - Hosts: 127.0.0.20 www.inscicon.net
O1 - Hosts: 127.0.0.21 inscicon.com
O1 - Hosts: 127.0.0.22 www.inscicon.com
O1 - Hosts: 127.0.0.23 ukrania.info
O1 - Hosts: 127.0.0.24 kentavr
O1 - Hosts: 127.0.0.25 organika.ho.ua
O1 - Hosts: 127.0.0.2 custom-host
O1 - Hosts: 127.0.0.2 www.custom
O1 - Hosts: 127.0.0.2 custom
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [VMware Tools] C:\Program Files\VMware\VMware Tools\VMwareTray.exe
O4 - HKLM\..\Run: [VMware User Process] C:\Program Files\VMware\VMware Tools\VMwareUser.exe
O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Ditto] C:\Program Files\Ditto\Ditto.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Punto Switcher.lnk = C:\Program Files\Punto Switcher\punto.exe
O4 - Startup: Start Denwer.lnk = D:\Webservers\denwer\Run.exe
O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exe
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - Winlogon Notify: TPSvc - C:\WINDOWS\SYSTEM32\TPSvc.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - C:\WINDOWS\system32\imapi.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Корпорация Майкрософт - C:\WINDOWS\system32\mnmsrvc.exe
O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - C:\WINDOWS\system32\services.exe
O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - C:\WINDOWS\system32\sessmgr.exe
O23 - Service: Смарт-карты (SCardSvr) - Корпорация Майкрософт - C:\WINDOWS\System32\SCardSvr.exe
O23 - Service: Журналы и оповещения производительности (SysmonLog) - Корпорация Майкрософт - C:\WINDOWS\system32\smlogsvc.exe
O23 - Service: TP AutoConnect Service (TPAutoConnSvc) - ThinPrint GmbH - C:\Program Files\VMware\VMware Tools\TPAutoConnSvc.exe
O23 - Service: VMware Tools Service (VMTools) - VMware, Inc. - C:\Program Files\VMware\VMware Tools\VMwareService.exe
O23 - Service: VMware Physical Disk Helper Service - VMware, Inc. - C:\Program Files\VMware\VMware Tools\vmacthlp.exe
O23 - Service: Теневое копирование тома (VSS) - Корпорация Майкрософт - C:\WINDOWS\System32\vssvc.exe
O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - C:\WINDOWS\system32\wbem\wmiapsrv.exe

--
End of file - 7165 bytes

avon

Community member

Date of registration:
Apr 15th 2008

Version:
Avira Antivirus Suite

Operating System:
Windows 8.1U1 Pro 32-bit Windows XP Home SP3 32-bit

  • Send private message

6

Tuesday, December 29th 2009, 10:28pm

Quoted

O1 - Hosts: 127.0.0.3 b-a-co.com
O1 - Hosts: 127.0.0.4 www.b-a-co.com
O1 - Hosts: 127.0.0.5 locator.b-a-co.com
O1 - Hosts: 127.0.0.6 www.locator.b-a-co.com
O1 - Hosts: 127.0.0.7 i-currency.info
O1 - Hosts: 127.0.0.8 www.i-currency.info
O1 - Hosts: 127.0.0.9 internet-currency.info
O1 - Hosts: 127.0.0.20 www.inscicon.net
O1 - Hosts: 127.0.0.21 inscicon.com
O1 - Hosts: 127.0.0.22 www.inscicon.com
O1 - Hosts: 127.0.0.23 ukrania.info
O1 - Hosts: 127.0.0.24 kentavr
O1 - Hosts: 127.0.0.25 organika.ho.ua
O1 - Hosts: 127.0.0.2 custom-host
O1 - Hosts: 127.0.0.2 www.custom
O1 - Hosts: 127.0.0.2 custom

Are you aware about those entries?
Unknown entries within the HOSTS-file should be fixed.

avon.

This post has been edited 1 times, last edit by "avon" (Dec 29th 2009, 10:30pm)


  • "zavclub" started this thread

Date of registration:
Dec 25th 2009

  • Send private message

7

Wednesday, December 30th 2009, 1:18pm

Yes, I'm aware of those. Actually the said virtual machine is dedicated for web developments and those hosts are just for testing my scripts.

Farger

Moderator

Date of registration:
Jul 10th 2009

Version:
Avira Free Antivirus
Avira Ultimate Protection Suite
Avira Internet Security

Operating System:
Windows XP/ Windows 7

  • Send private message

8

Wednesday, December 30th 2009, 2:18pm

Hi zavclub,

Maybe your problem is that you have broken LSP?

O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll
O10 - Unknown file in Winsock LSP: c:\program files\vmware\vmware tools\vsock sdk\bin\win32\vsocklib.dll


But lets wait for more suggestions ;)
Scotty is currently on patrol