Author Topic: Self-extracting installation files won't run...  (Read 22237 times)

0 Members and 1 Guest are viewing this topic.

Offline Eddy

  • Avast Evangelist
  • Maybe Bot
  • ***
  • Posts: 31079
  • Watching (over?) you
    • Malware removal, Biljart and other things.
Re:Self-extracting installation files won't run...
« Reply #15 on: January 15, 2004, 11:01:22 AM »
Igor, he did a reinstall of XP. So not likely the issue of the repaired archives.

Jari_ak

  • Guest
Re:Self-extracting installation files won't run...
« Reply #16 on: January 15, 2004, 12:07:27 PM »
Hmm, the file is just a wise installer... it shouldn't perform any special actions.

OK, time for heavy weapons  ;D
Could you try the File Monitor? Start the monitoring before clicking on the SFX file, try to start the SFX file, stop the monitoring, and check for "FILE NOT FOUND" items (they will certainly be many of them, since it's a usual event when searching for a file in multiple directories, such as %PATH% - but some of them may be "suspicious").
If you needed assistance with the FileMon, let us know.

Btw, in the first post you said that a number of files were infected by a virus. What virus was that? I considered the possibility of a corrupted SFX archive (WinZip archives, for example, often give CRC error when they're infected and repaired - since the header has changed a little). I guess it's not the case here, though... I understand that the SFX archives are fresh-downloaded(?)... besides, the error message should certainly be different.

Hmm... I didn't find any FILE NOT FOUND items, but two ACCESS DENIED items... Is my problem related to access permissions?  :-\

The virus was something called "parite", as far as i can recall. yes, the archives are run from a CD provided by the manufacturer.

Hmm... again! When I run the file on my hard drive i see several FILE NOT FOUND items instead.

The output is:

12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:Docf_PebiesnrMkudrfcoIaamtykdDa:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:PebiesnrMkudrfcoIaamtykdDa:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:Docf_PebiesnrMkudrfcoIaamtykdDa:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:PebiesnrMkudrfcoIaamtykdDa:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:Docf_PebiesnrMkudrfcoIaamtykdDa:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:PebiesnrMkudrfcoIaamtykdDa:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:Docf_PebiesnrMkudrfcoIaamtykdDa:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:SummaryInformation:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:Docf_SummaryInformation:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:SummaryInformation:$DATA   FILE NOT FOUND   Options: Open  Access: All   
12:17:48   explorer.exe:1212   OPEN   C:\Documents and Settings\Jari A-K\Mina dokument\Mina Drivrutiner\webxp.EXE\:Docf_SummaryInformation:$DATA   FILE NOT FOUND   Options: Open  Access: All   
« Last Edit: January 15, 2004, 12:21:32 PM by Jari_ak »