Header-Flash

Pages

Showing posts with label Virus. Show all posts
Showing posts with label Virus. Show all posts

Apr 29, 2010

Fix: NOD32 Antivirus "Failed to read firewall configuration" Error

Symptoms:
You install ESET NOD32 antivirus on a Windows system and keep getting 
error messages saying:
 "Failed to read firewall configuration"
Even if you try to uninstall and re-install, the error remains..

How to Fix:
follow these steps for full cleanup of the NOD32 leftovers and a successful installation:

Uninstall ESET and then do the following: (please note: some of these files/folders/drivers/ may not be there, which is OK)

Boot into Safe mode

1. Delete files and folder

Folders:
C:\Program Files\ESET
C:\Documents and Settings\All Users\Application Data\ESET
C:\ProgamData\ESET (vista)

Registry keys:
-HKEY_CURRENT_USER\Software\ESET
-HKEY_LOCAL_MACHINE\Software\ESET

2. Go to Window's Services and disable ESET Services
a. ESET Service
b. ESET Http Server

3. Go to Device Manager and disable drivers for ESET.

a. In Device Manager, go to View on the menu bar and select "Show Hidden devices". This opens up "Non-Pug and Play Drivers" in devices manager .
b. Disable "ehdrv" and "epfwtdir" drivers.

Boot back into normal mode and download "Windows Installer Cleanup Utility":
http://support.microsoft.com/default...b;en-us;290301

Run this program and make sure ESET is gone from the list.

Make sure you have the latest Windows Update and any other anti-virus program removed.

Reinstall ESET.



Note:
It is recommended to install SP1 or SP2 for a Vista system.
Also, always make sure you try to install the latest version of the antivirus from ESET.

Jun 4, 2009

Fix: Unable to Show Hidden Files and Folders in Folder Options

There are some viruses that prevents you from settings the Folder Options to Show Hidden Files and Folders.
The virus use this block as a protection to hide its files and prevents the healing process.
When you try to set the Show Hidden Files and Folders to Enabled it reverts back to Disabled after you click on OK. Sometimes you don't even have access to the Folder Options settings at all.

There are several ways to fix this problem. It depends on the complexity of the virus:

1. Use the tool DiskHeal from Computer-Realm to bypass the blocked Show Hidden Files and Folders.
    install the tool and run it. on the Fix Menu click on the button "Fix Folder Options inaccessibility".

2. Using Safe-Mode and Login as a different Administrator Account
   Most viruses does the blocking by using Windows own Local Group Policy. the policy is applied on the Current User Account and only on some cases on the Local Machine. Therefore by login-in as a different Administrator user you can bypass the block. Using Safe-Mode as a trouble-shooting environments is also wise because most group policy rules are not working in that mode.
you can also do a Virus Scan on Malware scan during the Safe-Mode session.
3. Cleanup using an external Boot CD
   You can use one of those custom Mini-XP boot CD's or Microsoft's ERD Commander to get access to the  system's Registry, Autorun settings and file system. Than you could delete the problematic virus files, either manually or using an anti-virus scanner. One of my favorites boot CD's is the Hiren's  BootCD. the latest 9.8 version includes a custom Mini-XP that runs from your CD and gives you a great Explorer shell to troubleshoot Windows. you can download Hiren's BootCD using this Torrent.