microsoft security essentials error code: 0x80070424

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by denver_fox, Jan 15, 2013.

  1. denver_fox

    denver_fox Private E-2

    Hi all. First time here. Thanks for your help.

    So it seems I am having the exact same problem a fellow user was a while back.
    http://forums.majorgeeks.com/showthread.php?t=261126

    MSE just recently started to not work.

    I have read the read-me and run-me faq, to no evail. My OS is XP.

    Here are the logs I'm supposed to give you guys. Many thanks in advance, cool forum you guys have here!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can I see the Mglogs.zip from running MGTools.exe please?
     
  3. denver_fox

    denver_fox Private E-2

    Sorry about that. Here it is.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you do not use Windows Messenger Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Re scan with Hitman and have it delete Potential Unwanted Programs


    [​IMG] Fix items using RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Scan button
    Now click the Registry tab and locate these 3 detections:

    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-21-1715567821-606747145-725345543-1003\$cb07297d4d8007fdf7f5584d4e1b9b2b\n.) -> FOUND
    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-18\$cb07297d4d8007fdf7f5584d4e1b9b2b\n.) -> FOUND
    • [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-18\$cb07297d4d8007fdf7f5584d4e1b9b2b\n.) -> FOUND

    Place a checkmark each of these items, leave the others unchecked.
    Now press the Delete button.

    ...Same for entries on file/folder tab...

    • [ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-18\$cb07297d4d8007fdf7f5584d4e1b9b2b\@ --> FOUND
    • [ZeroAccess][FILE] @ : C:\RECYCLER\S-1-5-21-1715567821-606747145-725345543-1003\$cb07297d4d8007fdf7f5584d4e1b9b2b\@ --> FOUND
    • [ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-18\$cb07297d4d8007fdf7f5584d4e1b9b2b\U --> FOUND
    • [ZeroAccess][FOLDER] U : C:\RECYCLER\S-1-5-21-1715567821-606747145-725345543-1003\$cb07297d4d8007fdf7f5584d4e1b9b2b\U --> FOUND
    • [ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-18\$cb07297d4d8007fdf7f5584d4e1b9b2b\L --> FOUND
    • [ZeroAccess][FOLDER] L : C:\RECYCLER\S-1-5-21-1715567821-606747145-725345543-1003\$cb07297d4d8007fdf7f5584d4e1b9b2b\L --> FOUND

    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[2].txt to your next message. (How to attach)
    Reboot the machine.



    Please give Ccleaner a run, not the registry scanner, just the cleaner itself to be rid of many temp files.

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.

    After reboot, check to see if your firewall is working.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. denver_fox

    denver_fox Private E-2

    I uninstalled windows messenger. No problem there.

    I re-scanned with hitman and program remnants of something called softonic showed up. I've never heard of it so I googled it. It said it was spanish software downloading or something, so I deleted it. Don't know why that was there.

    Now I'm kinda stuck with roguekiller. It works fine and scans, I am just having trouble locating the files you mentioned under "registry."

    Heres what I see when I scan and go to the registry tab.
    [​IMG]


    So which of these files am I supposed to delete? Don't wanna delete the wrong thing and mess something up.

    And thanks for your help so far, man!
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go to the FILES tab and look for entries I highlighted.
     
  7. denver_fox

    denver_fox Private E-2

    So.... I don't have to delete anything under the registry tab?
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Well, yea...these should be showing, but obviously they are not now:

    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-21-1715567821-606747145-725345543-1003\$cb07297d4d8007fdf7f5584d4e1b9b2b\n.) -> FOUND
    • [HJ INPROC][ZeroAccess] HKCR\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-18\$cb07297d4d8007fdf7f5584d4e1b9b2b\n.) -> FOUND
    • [HJ INPROC][ZeroAccess] HKLM\[...]\InprocServer32 : (C:\RECYCLER\S-1-5-18\$cb07297d4d8007fdf7f5584d4e1b9b2b\n.) -> FOUND

    ...so just move on, and fix what you can see. ;)
     
  9. denver_fox

    denver_fox Private E-2

    O.k, so I went ahead and unchecked and ignored everything under the registry tab. I did remove the six files you mentioned under the files tab.

    I'll post two reports. One's from before I deleted files(from scan) and the other is from removal success.
     

    Attached Files:

  10. denver_fox

    denver_fox Private E-2

    O.k, so now I just finished with windows repair.

    I forgot to mention earlier, but windows security alerts wasnt working at all either. Now it's working fine after running windows repair!

    My firewall is working now as well.:highfive

    MSE is still NOT working, unfortunatly. Same error.

    Here's the new MGLog.
     

    Attached Files:

  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please uninstall MSSE using Revo uninstaller and then after rebooting, reinstall and let me know if it works okay. :)
     
  12. denver_fox

    denver_fox Private E-2

    Everything is working now!!

    Thanks for all your help, Kestrel. I truly appreciate it.

    Now what can I do to protect myself from this happening again?
     
  13. denver_fox

    denver_fox Private E-2

    O.k, so I have one small problem still bothering me.

    MSE is working, but windows security alerts isn't detecting it anymore. It says it is off.

    When I turned my computer on this morning it was like it was frozen. My mouse cursor moved freely, but I couldnt select anything. I couldnt even open the start menu.

    I thought this was really strange. I rebooted several times and it kept doing the same thing. So I rebooted again and just let it sit for a couple hours while I did some chores, now it's working fine.... weird.

    So heres what I see regarding MSE and security alerts.

    As you can see, MSE is working.
    [​IMG]


    But windows security alerts isn't detecting it...
    [​IMG]

    What do you think?
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It's a common problem, you can ask about it in the software forum. :)

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Press and hold the Windows key [​IMG] and then press the letter R on your keyboard. This opens the Run dialog box.
      • Copy and paste the below into the Run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 4 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    7. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove, you can delete these files now.
    8. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds