Unable to update Windows and others

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Sandytech, Jan 4, 2015.

  1. Sandytech

    Sandytech Private E-2

    I can no longer update Windows 7 automatically or manually. It was originally set to update automatically. Malware Bytes and Spy Hunter also are no longer allowed updates. My authority also has been changed from Administrator to user and cannot be changed back. I ran all the programs in your malware removal process and have attached the logs. I can't upload the Hitman Pro log or the TDSSKiller log because they exceed the .txt size. Let me know what I need to do to get them to you.
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the log from Hitman Pro that was requested!

    Also you need to uninstall both of the below

    AVG 2015
    Norton Internet Security


    You should never have more than one antivirus installed at any given time! We are uninstalling both right now because they may have caused some problems and will also get in the way of cleanup.


    Also uninstall SpyHunter which is very strongly not recommended!!!

    Once you have uninstalled all of the above, continue with the below.

    Run RogueKiller and run a scan. After it finishes the scan, select the Registry tab and then select any of the below that exist and then click the Delete button.

    Then immediately reboot your PC.

    After reboot, run a new scan with RogueKiller and save a log as in original instructions and attach the new log.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the new RogueKiller log
    • C:\MGlogs.zip
     
  3. Sandytech

    Sandytech Private E-2

    I was able to delete the AVG and the Spy Hunter but could not delete Norton either through the control panel or through just trying to delete the file folders themselves in Program files. I remember I tried to uninstall it months ago when I used it a short time and it slowed my system to a crawl. I ran RogueKiller twice with a reboot in between and then ran the MGTools. The new logs are attached. Thanks for your speedy reply. I don't know how you do it. You are amazing in your knowledge.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Download and run the below:

    http://www.majorgeeks.com/files/details/norton_removal_tool.html

    Reboot after running the above and then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below log:
    C:\MGlogs.zip

    Also I still need to see the log from Hitman Pro that was requested.

    After ru
     
  5. Sandytech

    Sandytech Private E-2

    I ran the programs you requested. Attached are the log files. Thanks
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista or Win 7, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines if it still exists but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now. If you do not find this line then close HijackThis and continue.


    O4 - HKLM\..\Run: [OpenSoftwareUpdater] C:\Program Files (x86)\OpenSoftwareUpdater\OpenSoftwareUpdater.exe


    After clicking Fix, exit HJT.


    Please download OTM by Old Timer and save it to your Desktop.
    • Run OTM.exe by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).
    • Copy the lines from the below codebox to the clipboard by highlighting ALL of them and pressing CTRL + C
      (or, after highlighting, right-click and choose Copy): Do not include the word Code: which is just a title line of
      the code box
    Code:
    :Processes
    explorer.exe
    
    
    :Files
    C:\Users\Kathy.HP_PC\Downloads\PCFixSpeedSetup.exe
    C:\Program Files (x86)\AVG
    C:\Program Files (x86)\OpenSoftwareUpdater
    C:\Program Files\Reimage
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
    C:\ProgramData\AVG2014
    C:\ProgramData\AVG2015
    C:\ProgramData\Norton
    C:\ProgramData\NortonInstaller
    C:\ProgramData\Reimage Protector
    C:\$AVG
    C:\rei
    C:\Program Files\Reimage
    C:\Windows\Reimage.ini
    C:\ProgramData\Avg_Update_0614a
    C:\Windows\system32\tasks\Norton Internet Security
    C:\Windows\system32\tasks\Norton WSC Integration
    C:\Windows\system32\tasks\Reimage Reminder
    C:\Windows\system32\tasks\ReimageUpdater
    C:\Windows\TEMP\*.
    C:\Users\Kathy.HP_PC\AppData\Local\Temp\*.*
    
    
    :Reg
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\rlvknlg_RASAPI32]
    [-HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\rlvknlg_RASMANCS]
    [-HKEY_USERS\S-1-5-21-3104320512-218712501-4244557028-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_USERS\S-1-5-21-3104320512-218712501-4244557028-1002\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [HKEY_LOCAL_MACHINE\software\Wow6432Node\microsoft\windows\currentVersion\Run]
    "OpenSoftwareUpdater"=-
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{74EE911A-ACDE-44EC-94ED-31E57B8E09A1}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{74EE911A-ACDE-44EC-94ED-31E57B8E09A1}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}]
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}]
    :Commands
    [purity]
    [EmptyTemp]
    [start explorer]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar
      ) and choose Paste.
    • Now click the large [​IMG] button.
    • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
    • Close OTM.
    Now navigate to the C:\_OTM\MovedFiles folder ( assuming your Windows drive is C). This is where your log will be
    saved in the form of Date and Time mmddyyyy_hhmmss.log. Just look for the most recent .log file. Attach
    this log file to your next message.

    Now please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Note: That JRT may reset your home page to a google default so you will need to restore your home page setting if this happens.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, Win7 or Win8, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • the C:\_OTM\MovedFiles log
    • the JRT.TXT log
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Jan 5, 2015
  7. Sandytech

    Sandytech Private E-2

    Apparently this little bugger is not allowing me to run OTM in Administrator mode. All I get is empty results. Where do I go from here?
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You don't really show any serious infections that would cause a problem like that. Seems more likely to be a Windows problem. Did you disable UAC as requested in the READ & RUN ME? It should still be disabled. You can try booting in safe mode just to run OTM.
     
  9. Sandytech

    Sandytech Private E-2

    UAC was disabled and I ran OTM in both Safe mode and in regular mode. Both gave me blank outputs. However, I am now listed as administrator (yea!) but I can still not access Windows 7 Updates through the control panel or the start up icon.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You probably messed up your PC by running that Reimage junk program which we are also trying to delete. Just continue on with instructions that come after OTM and we will figure out what to do next.
     
  11. Sandytech

    Sandytech Private E-2

    I continued running the process you sent and have attached the logs. I am still listed as Administrator, so that is good. I this some updates to Windows 7 did run but I still cannot do that from the control panel. When I try to do that, I get this error message:
    Windows cannot find '::{26EE0668-A00A-44D7-9371-BEB064C98683}\5\::{36EEF7DB-88AD-4E81-AD49-0E313F0C35F8}\pageSettings'. Make sure you typed the name correctly, and then try again.
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This also is not a malware issue but rather a problem with Windows. You may need to discuss this and any other Windows related problems in the Software Forum once we finish here. And we don't have too much to do. I just want to try and clean up the left overs from AVG and Norton since you could not run OTM properly. So let's run a few more tools.


    Be patient while doing the below. The fixes can sometimes take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Repair MSI (Windows Installer)
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.


    Now please do the below so that we can boot to System Recovery Options to run a scan.

    For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.


    Plug the flashdrive into the infected PC.

    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.


    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  13. Sandytech

    Sandytech Private E-2

    OK I was just able to run the Farber Recovery tool. A touch of the flu has slowed my progress here. I've attached the log file. I can't update Windows yet but I am still administrator. I'll check that odd message with the software folks as you suggested once we finish here. It is frustrating that programs that seem to be safe and have good reviews (bogus, perhaps?) are "crapware" that screw up systems. Norton even did a job on my system - slowed it to a crawl. Firing squad it is!!! lol
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.



    Download this >> View attachment fixlist.txt

    Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.
    Now reboot back into the System Recovery Options as you did previously.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (See how to attach)

    Now boot into normal Windows and continue with the below.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • Fixlog.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  15. Sandytech

    Sandytech Private E-2

    There hasn't been any change since the last time. Still can't run Windows 7 updates and get that strange message each time, but everything else seems stable. I've attached the files requested.
     

    Attached Files:

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    As stated previously, this is not a malware problem. This typcial means Windows is broken. Sometimes running a fix with sfc /scannow can correct this but many times it requires a reinstall. You can try posting in the Software Forum, but you should start backing up important files now since you may be reinstalling.

    Your PC may have been broken due to installing/running Reimage!

    You need to attach the correct log from running the fix with FRST. You just reattached the fix file I gave you. Based on what I saw in MGlogs.zip it does not look like you even ran the fix.
     
  17. Sandytech

    Sandytech Private E-2

    Sorry, I guess my brain is still filled with flu! I did run the fix and have attached the files. View attachment 217932
     

    Attached Files:

  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I need the fixlog.txt file from running the fix with FRST. It still looks like the fix was not run.
     
  19. Sandytech

    Sandytech Private E-2

    Ok - got it now. Attached are both files you requested. You can lead a user to directions but you can't make them follow them correctly! rolleyes
     

    Attached Files:

  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah yes! Finally you have drunk the water. ;)

    We are done other than the below final cleanup.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others) and running MGclean.bat did not remove them, you can delete these files now.
    7. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    8. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your WIndows version in this link: Disable And Enable System Restore
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     
  21. Sandytech

    Sandytech Private E-2

    Thanks so much for all your help. Now I just have that one little software problem to fix and I will be at 100%. I wish I had checked your page first before installing Reimage - no matter what their bogus "recommendations" and "glowing reviews" were. But it did reimage my PC. Just not with programs and files that worked. You guys are a lifesaver and I truly admire what you do. I dealt with systems and software throughout my career but never had to deal with things at the level that you do. Kudos to all of you.:)
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    The below may or may not help with the Windows Update issue. As I stated earlier, many times the only fix is resinstall.
    • Now please click Start, and type cmd into the search box.
    • You should see a cmd.exe and icon appear in the Programs area of the Start Menu.
    • Right click on cmd.exe and select Run As Administrator
    • Then in the black Command Prompt window that opens, type sfc /scannow and hit enter.
    • This runs System File Checker which looks for missing or corrupted system files and attempts to replace/repair them from files on your hard disk or from the CD if necessary. So it will ask for the Windows CD if it needs it.
    Now reboot your PC if it repaired anything. If it needs to repair anything and you do not have a CD then you need a CD in order to repair it.
     
  23. Sandytech

    Sandytech Private E-2

    I ran the scan and it said there were corrupt files it could not fix. A logfile was created but now I am no longer administrator and can't open the log file nor attach it to see if you can read it. :cry
     
  24. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You have been a member of the Administrator user group since you first posted here so I'm not sure what you mean. Your first log and all subsequent logs always showed the below
    Code:
    ******************************************************************************
                                    USER INFORMATION     
    ******************************************************************************
     
    Users on this computer:
    Is Admin? | Username
    ------------------
       Yes    | Administrator (Disabled)
              | Guest (Disabled)
       Yes    | HP
       Yes    | Kathy
              | UpdatusUser
     

    Also I don't need the log. The problems are withing Windows as I was saying and you probably need a Windows DVD to fix or it could require a reinstall.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds