I think this is Vista related rather than AV related.
I use Steganos AV 2007 (the same as Kapersky but just re-badged) and installed the same program on my wife's machine.
The machine came up with a warning which unfortunately I did not see or record.
The antivirus software reported some corrupt files, but appears to be generally working, the File, Mail and Proactive Defense modules are working but when I try to access the web antivirus the program locks. Also, Vista does not recognise the program as working (it used to).
I tried to repair the progrm but it did not improve so I thought I would uninstall the whole programme and start again. Unfortunately I now have a catch 22 as the program will not uninstal - see attachment.
I do not know enough about Vista to be able to change the privileges and I find the MS help files most unhelpful! I tried right clicking and choosing the assume privileges option but this had no effect at all.
I add a HijackThis fle in case this will help.
What I would like to do is to delete the Steganos Program and start again (I cannot delete the program folder).
Kind regards
Martin
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18:50:47, on 29/01/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16575)
Boot mode: Normal
I have been struggling to solve this problem since your last message.
I tried using Autoruns, however I found this a rather complex interface and was cautious about being too aggressive with what is obviously a powerful tool.
I deselected everything I could to do with Steganos and Kapersky (Steganos use the Kapersky core program) this had no effect at all and I was still unable to delete the program to re-install.
I had a long dialogue with Steganos who are no help at all as they keep telling me to unistall the original program and start again and I keep telling them that every time I try to uninstall, the uninstallation goes as far as telling me it is about to 'stop utilities' when I get the error message saying
"Error 1921 Service Steganos Antivirus could not be stopped. Verify that you have sufficient privileges to stop system services" at that point I am completely scuppered!
I am even more desperate now as the licence is about to expire and I purchased a new licence hoping that I could continue with what I have. Guess what???!!! When I tried to load the upgrade it told me to delete the old program first!!! So I am completely up a gum tree with this catch 22.
Any ideas? Presumably if I had full administrator privileges that might help. Unfortunately this problem is on my wifes machine and I don't recall setting any privileges when we first purchased the machine. Also, of course somehow this has now become all my fault!
Kind regards
Martin
I attach another copy of the Hijackthis log in case this is needed:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 08:47:34, on 15/02/2008
Platform: Windows Vista (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16609)
Boot mode: Normal
Autoruns is not a "deleter". You can always go back and recheck an item if you make a mistake. The listed items are not deleted. They are just stopped from starting automatically.
I tried several things none of which worked. I received a reply from Steganos and apparently the 1921 error is there deliberately by Steganos to prevent malicious software switching off the AV system.
Steganos said to simply switch off the sytem by clicking exit in the system tray - if only! No good whatsoever.
I even went so far as not only deselecting items in "Autoruns" but actually deleting them. I then re-started and checked in HJT that Steganos AV was not working - confirmed. Even so exactly the same result:- it uninstals as far as 'stopping utilities' and then comes up with error 1921.
See attached image.
I now feel like the ancient Mariner with an albatross around my neck.
Martin
PS What would happen if I went to C:\Program Files\Steganos AntiVirus 2007\avp.exe and simply deleted the .exe file?
M
Last edited by Riftvalley; 16-02-2008 at 12:06 PM.
Reason: added PS
I still have a couple of days before the licence runs out.
I will wait to see if Steganos come up with a less drastic action,and then I will simply pull the plug (assuming the computer lets me delete the .exe file) and then take it from there.
I have everthing well backed up on an external drive plus DVD's so at worst it is just a complete reinstallation.
A shame really; as I have deliberatly kept my wife's machine simple, neat and tidy with the minimum of software (in direct contrast to my desktop which is a disgusting heap and full of really flaky stuff).
Just for information I received an answer from Steganos (which I will paste below) I was able to remove the software and instal Steganos AV 2008. However, what might be of interest to DAL was that during the installation it appeared that Kapersky, Steganos and AVG all seem to use common files. Possibly they all use the same AV threat library etc.
Anyway this is what I got from Steganos:
We are sorry about your experience with installing this Steganos product. Please try the following:
* Start your PC in the so called windows 'safe mode' (press permanently keyboard's "F8" while your PC is starting and before Windows boot logo comes, up to open Windows start menu, then select 'safe mode').
* run Windows RegistryEditor (Start => run => /ENTER/ regedit => OK).
* Find the key: HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\ (take care and doublecheck the path!).
* rightclick the key and select 'Permission'.
* Make sure that for all displayed user-groups full access is already enabled. If not please do so and confirm all upcoming messages with 'OK'.
* You should now see the key HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\ again. Please rightclick on the(!) key and 'remove' it together with all sub keys. In case of upcoming errormessages, you need to follow the same procedure for the sub key 'Components' beneath HKEY_LOCAL_MACHINE\SOFTWARE\KasperskyLab\ again.
* After successfully removing all keys, close the RegistryEditor and re-boot your PC as usual.
* Now try again to install your copy of Steganos.
If you are still experiencing difficulties, please feel free to write back.
When answering to this e-mail please leave the subject line unchanged. This is to ensure the mail returns directly to my inbox. Thank you.