Cannot install any security software or update windows

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by introublesos, Jul 8, 2011.

  1. introublesos

    introublesos Private E-2

    Hi

    I was away from my computer for several months and my family were using my lap top.

    Now when I returned I have several problems.

    I cannot install any security software or update windows (error 80070422)

    Yesterday I installed spybot and it found and removed some infections, or so I thought. When i powered up my lap top today spybot was gone as was an install of google chrome.

    I now tried to save malwarebytes and created a folder on my desktop, changed the name of the exe to explorer.exe, it will download but near the end it will open the folder I created and it will be empty. I also tried to install security essentials but it also cannot be found.

    I know there are a lot of microsoft updates to be installed , I think around 0.5GB but I cannot install them.

    Please help me if you can to resolve this problem.

    Windows vista SP1 (I know it should be at least SP2?)
    No security software on laptop working.

    Thank you for any help and your time.

    edit: I also removed an older version of java but now when i downloaded a new version it too is missing and will not install
     
    Last edited: Jul 8, 2011
  2. introublesos

    introublesos Private E-2

    I wanted to edit my post below but left it for too long.
    When I download anything now on explorer 8 all downloads are going to a temp folder which I cannot find. I also do not know how to change the download location because when I download a file it does not prompt for a location to save it to.

    I have set my laptop to show hidden folders and used MSCONFIG to boot from normal start up mode. I have some files from AVG left over but cannot download the removal tool due to the temp download folder problem.

    Im sorry if my information posted is confusing but I know very little about my problems or how to fix them, sorry if this is annoying for you more advanced users.

    I will wait for further instructions, thank you.
     
  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks, introublesos

    ** DO NOT RUN ANY TEMP FILE CLEANER PROGRAMS unless instructed **

    Please download and save the below tool from Grinler @ bleepingcomputer to your Desktop or anywhere else you can find it ( if the Desktop is not showing )

    http://download.bleepingcomputer.com/grinler/unhide.exe

    Now run it. Now see if you can find your icons, Desktop, Programs,...etc?

    Then run the below:
    TDSSkiller - How to run

    ..and continue on with these instructions

    Try running the AVG Removal Tool now.

    Please follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and then attach the requested logs to your next reply when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.
    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes, you could use a flash drive too, but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    * Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated - our system works the oldest threads FIRST.
     
  4. introublesos

    introublesos Private E-2

    Hello dr.moriarty Thank you for your response and help.

    I have already made a mistake regarding temp file cleaner. I downloaded ccleaner along with spybot yesterday before coming to this form. I ran ccleaner and deleted the files at the time but when i turned lap top on today ccleaner, spybot and chrome had vanished so im not sure if the infection used system restore :(

    After my post today I done some research on here and went and downloaded SUPERantispyware portable onto a cd and managed to run it on this laptop. It found and removed threats as you will see in my attached .txt files.

    After running SAS I was able to download Malwarebytes and sucessfully renamed and opened it from my desktop. I then ran a quick scan and fixed 3 more Issues as you will see in my attached file.

    That is where my good luck ended though and im not sure why.

    Could not and still can't download combofix , RootRepeal, MG Tools , AVG removal tool, TDS Killer, unhide desktop.

    The files are no longer downloading to a temp folder but they do not show up in the path a specify either :confused
    Files will download to 99% and then a explorer pop up will say "copying 0 bytes" and the download just dissapears

    This series of infections has also disabled windows security centre and I cant switch it on, I am also concerned that some links I click in my browser redirect through api.viglink

    I will wait for further instructions. Sorry also for bumping my OP, I should have read the stickies beforehand but at least now I know.

    Thanks again dr.moriarty
     

    Attached Files:

  5. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, introublesos.

    *Do you have access to another pc (Friends, neighbors, co-workers) by which you download the tools and save them to CD/DVD/SD memory card, then transfer them to the infected machine?
     
  6. introublesos

    introublesos Private E-2

    Hi again.

    Yes I have access to another lap top which I can use.
    I will be online most of the day so I will wait for your guidance.

    Thank you.
     
  7. introublesos

    introublesos Private E-2

    Hi again.
    I know this post is a bump and I will be at the bottom of the list but I am providing the logs of the other tools which had to be transferred via cd to infected machine. If it takes a few days to reply thats fine because you are busy here.

    ComboFix>> See log below that I will attach to this post.
    TDSSKiller>> See log below that I will attach to this post.
    MGtools>> See log below that I will attach to this post.
    RootRepeal>> Failed, will describe problem below

    After running combofix I got an error message every time I tried to open a programme or file, the error read as follows "Illegal operation attempted on a registry key that has been marked for deletion"
    After reading about the error I saw it was ok to try and reboot laptop. After reboot the error was gone and I could open files and programmes. Also after running combofix I could download and run programmes such as java from the internet so I updated it.

    All tools ran fairly sommthly except ROOTREPEAL >> When I ran rootrepeal I disabled my firewall etc for it to run smoothly. It scanned some files but then became stuck on C:\Windows\winsxs\manifests\ While it was scanning up to that file it was using 16,000 memory but once it got to the file above the memory usage jumped up and up until it was using nearly 2GB of memory, at that point I ended the scan and had to end the process in task manager. I also tried this scan in Safe Mode but it had the same result.

    Laptop is running a lot smoother after combofix so that is brillant but I still think there maybe some threats because sometimes it becomes un responsive and also there seems to be 2 transpearent files on my desktop and I dont know how they got there, I cannot remove them because It says other programmes may need them, the file is >> Desktop.ini >> [.ShellClassInfo]
    LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
    IconResource=%SystemRoot%\system32\imageres.dll,-183


    Also I would like to know if it is safe to download and install the 650MB of microsoft updates that are in a queue to be downloaded?

    Thanks for helping.
     

    Attached Files:

  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome - you made good progress .

    Problems with running ROOTREPEAL are common. The "Desktop.ini" files are normally hidden until systems are set to show hidden files, folders, and file extensions as instructed in the READ & RUN ME First Guide - Step 4.

    EDIT: *I still need to see the logs from running SUPERAntiSpyware and Malwarebytes.

    Attach those logs, then wait for my further instructions.

    dr.m
     
    Last edited: Jul 9, 2011
  9. introublesos

    introublesos Private E-2

    Hello again.

    I just want to inform you that I preformed step4 before running any of the scans.

    Right Click Start
    Select Explore
    Select Organize
    Select Folder and Search Options
    Select the View tab
    Under the Hidden files and folders heading select Show hidden files and folders.
    Uncheck the Hide extensions for known file types option.
    Uncheck the Hide protected operating system files (recommended) option.
    Click yes to confirm that you really want to do this.
    Click Apply
    Click OK



    It still shows that hidden files are shown and both boxes that have to be unticked are unticked :confused

    Regarding the updates from microsoft, they are taking over and downloading in the background themselves..I will not reboot laptop until further instruction

    Thanks
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Ok

    Then after the updates complete, please re-boot and attach the remaining logs requested logs. *Please remember to run those tools only once.

    dr.m
     
    Last edited: Jul 9, 2011
  11. introublesos

    introublesos Private E-2

    Ok I will wait for updates to be finished>> reboot.

    Sorry but im not sure which other logs you are looking for :confused

    I thought I had uploaded all except rootrepeal?

    "edit" I see you are looking for Malwarebytes and superantispyware logs...You will find them attached to my 3rd post ITT.. I posted them before I managed to transfer the other tools onto this laptop today
     
    Last edited: Jul 9, 2011
  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :)

    Yes, you've already attached them.

    *Please be patient while I go over all the logs.
    dr.m
     
  13. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    introublesos

    *Once Windows has completed updating, please do the following steps

    This installed version is outdated -> Adobe Reader 8.1.3. The current version is 10.0.1.

    Question - what is this? C:\Users\jer\Desktop\756yy.com.exe. *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Users\jer\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 1:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      [​IMG]
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    Step 3:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    *If you don't know what they are, delete these folders :
    c:\users\jer\{b14cbc0a-f646-49d0-bccb-f6c3e95b576b}
    c:\users\jer\AppData\Local\{8E7E61FA-3ECB-42E9-B640-9C50AE76B9D0}

    Step 4:
    Now install the latest Sun Java Runtime Environment

    Step 5:
    Please run the below scanner.
    Using ESET's Online Scanner

    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the new C:\MGlogs.zip and the ESETScan.txt files to your next reply.

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  14. introublesos

    introublesos Private E-2

    Hello again dr M.

    It has taken me a while to reply due to microsoft updates taking about 15hrs to install. So many restarts but at least it is done now :)

    Adobe reader outdated>> Ununstalled and downloaded new version Reader X
    Question - what is this? C:\Users\jer\Desktop\756yy.com.exe
    That file was TDSSkiller which I renamed when transferring to this laptop.
    I have also removed all .exe, zip etc from desktop and have put them in downloads folder.

    When I ran C:\MGtools\analyse.exe it scaned no problem however when I checked the results there was no such entry that you requested I delete >> O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) does not exist :confused

    Anyway I continued on to use combofix and that ran smoothly.

    I have deleted the temp folders as you requested and also updated Java
    Also I did the esets scanner and ran MGtools >> see both attached logs below.

    Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    The only problem I had while running the scans was the entry you asked me to delete does not appear to be there anymore, or at least it is not showing up in the results.

    The laptop seems to be running a LOT smoother after following the steps that you instructed me to do :)

    The only concern I have atm is when I insert my USB broadband/midband dongle into the machine windows reads it as a CD ask asks if I want to view the files? This problem wasn't happening yesterday? I can run the modem by clicking start>computer>CD DriveF>autorun.exe but beforehand it has always run itself when inserted into the usb slot. I think that this is not a problem caused by the scans or malware but probably caused by the windows updates that have been installed> would you say that is the case?

    BTW do you know what I should do with the 2 desktop.ini files that are on my desktop? I dont want to delete them as a warning pops up and says other programmes may not function without them.

    Thank you again for helping and I await final instruction providing my logs are clean (fingers crossed ;))
     

    Attached Files:

  15. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome.

    Your new logs look good! I'm conferring with my colleagues about your modem, although I don't think its malware related.
    *No action is required - those files are legit but only seen when we enable "show hidden files, folders, and file extensions" as part of our cleaning procedures. In my final steps they will become hidden again.

    dr.m
     
  16. introublesos

    introublesos Private E-2

    Im delighted the logs look clean! Computer seems to be running well all day :)

    Thanks for looking into my modem issue. Im nearly positive its related to updates :confused

    Also sorry you had to repeat yourself about the desktop icons. I noticed after posting that today that you had already answered it in another post :-o
     
  17. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, introuboesos

    It is possible that a scanner at some point removed the autorun.inf from the storage area of the dongle.

    Please refer to this link for a downloadable fix to "Enable Autoruns".
    http://support.microsoft.com/kb/967715

    [​IMG]

    NOTE: Resolving this issue would be more properly addressed in our Software Forum.


    * If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them,
      they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed
      ComboFix on your Desktop like we requested.
      )
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! [​IMG]
     
  18. introublesos

    introublesos Private E-2

    Hello again Dr M.

    Yes indeed that microsoft article seems to have resolved my issues :guitar

    Have also preformed all of the final steps.
    Lap top is running better than ever before, on the internet also.

    Ill be sure to keep everything up to date in future and I think the next time I am leaving my lap top at home I will create a guest acc for the others that will be using it.

    Thanks for everything Dr M, I appreciate your time and patience.
    See you around the forums :major
     
  19. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    I'm glad to hear that, introublesos.

    You're very welcome, and that's a good idea on creating an account with limited privileges for when you're away.

    Hope to see you around the forums, also!
    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds