Avira wont scan or update

Reaction score
0
Location
Canada
I have a customers computer here, and I've scanned it thoroughly with every AV I can think of and ran Combofix and it comes up clean, and I have uninstalled and reinstalled Avira 5 times, however it will not update or scan. If I click "Start Update" from the main window, it does nothing. When I right click the system tray icon and click "Start Update" it does nothing. When I try to run a scan, again it does nothing. the same thing happens in safe mode, absolutely nothing happens. I'm lost, I have never seen anything like this before:confused::confused:
 
Try GMER, Hitman Pro (SAFEMODE)Check process explorer and as suggested the MRB and offline scan. Sounds like a possible rootkit, check host file proxys flush dns ,check TCPIP settings and stack.
 
ran TDSS Killer, nothing
ran Avira Registry cleaner, still not working
Ran offline scans, nothing
Ran Avira rescue disk, nothing
Currently running Dr. Web, found Wild Tangent games, but other than that, nothing.

The interface of GMER confuses me, I've used it before, but I was kinda lost.
I will run Hitman Pro once all the other scans are finished.
 
Have you tried re-downloading the AV program from the Avira website?

Have you tried pinging or tracert the update server?

Have you tried a manual update?

Could another security program be blocking the AV program or conflicting with it?

Have you ran any other AV removal programs? I would run the McAfee and Norton removal programs before installing Avira.

Maybe an image hijack in the registry, something like: Image File Execution Options\AVScanner.exe, debugger=DeletedMalware.exe

Any error messages in the event viewer?

The interface of GMER confuses me, I've used it before, but I was kinda lost.
You could let it do its quick scan it does when it starts up and usually anything that displays in red is going to be bad. I think most people ignore the three arrows tab at the top next to the Rootkit/Malware tab I never hear anybody say anything about the tabs along the top, Gmer can display a lot of info: Processes, Modules, Services, Files, Registry, Rootkit/Malware, Autostart and CMD/Regedit.
 
I am with everyone here. smells of ROOTKIT.

First before anything if the customer paid for the software, then get the tech support onto it whilst you are onsite. Make them work for what customer paid for, sometimes (very occasionally they can offer insight, but don't hold your breath, the only AV company who I have given credit is MCAFEE, they didn't fix issue but the offered more than just reboot-uninstall re-install advice)

Like in "Freddy got fingered" when he gets inside of the roadkill, you have to get inside the mind of the person who created the attack. When hardware of software corrupts it usually stays in one area.

When some malicious is at play there are always multiple signs they usually block multiple things.

An example of this is, you have same problems in normal windows as in safe boot mode, straight away I would bump ROOTKIT or BOOT loader virus up my check list.

ROOTKIT - detectors are different to AV detection. With rootkits scanner like GMER you need to google every result and then make a educated judgement (which can be very hard) whether to kill or let live.

End of the day - sad as it will be customer (should be) paying you by the hour. If the AV company can't work it out and there are no tell tail signs of virus, demand refund and switch AV companies. Sometimes it just is, and if the customer goes onto a successful 3 years with new AV product then job done. You did your initial checks to make sure now widespread virus the troubled product's support team looked into it and couldn't resolve. Move on.
 
Just a thought have you checked the date and time to make sure its correct.

I had a problem on clients PC with Avast, wouldn't update. I ended up checking the date, time was correct but the year was wrong. Updated that and everything worked fine.
 
Dr. Web finished scanning after 12 hours:eek:

Yes I've tried a manual update, that didn't work either,
I didn't run Norton removal tool, but I probably should

I just contacted the client, he said he wants windows reinstalled.
 
It's all good if you just want to reformat, but if you get me an OTL scan I can probably get it fixed for you. :)
 
Back
Top