antivirus unable to update

Discussion in 'Malware Help (A Specialist Will Reply)' started by johny3, Jul 28, 2010.

  1. johny3

    johny3 Private E-2

    good evening. I started having redirects on IE about 2 weeks ago. Since then I have also been unable to update any antivirus software, either manually or using the update. I have tried avira and avast. Of note, malwarebytes updates fine. I think this all started when I went to piratebay to download some ringtones off of a recommendation from a friend. I ran all the scans and you will see some items were detected and taken care of but I still cannot update avast, the current AV installed.
    any help would be wonderful. Please let me know if I need to correct the posts or forgot something.
     

    Attached Files:

  2. johny3

    johny3 Private E-2

    :cool
    thanks for reading
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    Please also download MBRCheck to your desktop

    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...

    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:

    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message.
     
  4. johny3

    johny3 Private E-2

    thank you :)

    HJ done

    I had to run mbr from the download window in IE, just double clicking the downloaded file would not launch anything, but I made sure the other browser window was closed.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What is your F drive? A usb backup drive?
     
  6. johny3

    johny3 Private E-2

    yes
    blacx thermaltake with a WD 1tb
    sorry i had to run out
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How are things running now? What issues do you still have, if any?
     
  8. johny3

    johny3 Private E-2

    hi
    i worked 24 hrs yesterday so was not able to check. The computer does not seem slow and I can update AV but when I went to dell.com I got a popup window for registry defender. I closed both and then went back to dell.com and did not get it again. Is this likely a redirect type program or you think I am good? I figure there is something directing me there since registry defender is malware.
    thanks!
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    If your external drive is still connected, run MBAM and do a deep scan ( which will allow you to include the external). Also re-run SAS and be sure to include the external when doing that scan as well.
     
  10. johny3

    johny3 Private E-2

    I am unsure how to make mbam scan both drives I will look into it a bit more later.
     

    Attached Files:

  11. johny3

    johny3 Private E-2

    woops had to do a full scan.
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    They came up clean. What issues are you having, if any?

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  13. johny3

    johny3 Private E-2

    thanks for all of your help. I appreciate it.


    after doing all of the steps below I went to windows update and got a popup for registry defender again. looks like I am not out of the woods :(
    or do you think it is harmless?

    http://www....com/l/indexsg.asp?utm...gn=mg1&utm_source=ron3594&utm_term=ron_113594

    I took out "registrydefender" from the web site so no one can click it. i added the link b/c i was unsure if that would help. please remove it if it needs to be

    also
    when i went to look at my popup blocker settings in IE this was under the allowed sites "Popupmgr" and I did not allow it.

    edit again:
    just got this at the windows update page after allowing the active x install.

    [Error number: 0x80072EFF]

    The website has encountered a problem and cannot display the page you are trying to view. The options provided below might help you solve the problem.
    For self-help options:

    Frequently Asked Questions

    Find Solutions

    Windows Update Newsgroup
    For assisted support options:

    Microsoft Online Assisted Support (no-cost for Windows Update issues)
     
    Last edited: Aug 1, 2010
  14. johny3

    johny3 Private E-2

    also
    (sorry to post again)
    I am getting redirects like crazy again. specifically when trying to read about that error message from the windows site - every click after a google search lands me a redirect in IE
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Well, that's not good.

    Download TDSSKiller from Kaspersky to your directly onto your Desktop

    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor. )
    • Allow the application to run if prompted by Windows or any security programs you have installed
    • It will start the scan and run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    • Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )
     
  16. johny3

    johny3 Private E-2

    no objects found but log posted. also it seems my windows automatic updates are working (but not if I go to the site manually).
    strange.

    here is the log thanks :)
     

    Attached Files:

  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Does this happen in every browser? Does it happen in safe mode? Which version of IE are you running?
     
  18. johny3

    johny3 Private E-2

    chrome seems fine. before we started this process it would crash on startup.
    firefox seems fine
    IE version
    8.0.6001.19702
    tried safemode for about 5 minutes. just clicking like crazy and no redirects. yesterday I got them like crazy in regular mode, as you know.
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Interesting. No redirect in safe mode. Go ahead and uninstall IE. Then run CCLeaner ( both the cleaner and the registry ---> make sure you do the backup when prompted). Then reinstall IE8. Tell me if that works.
     
  20. johny3

    johny3 Private E-2

    seems to be good now. I will surf around some more later and let you know if anything happens. figure let us hold off on declaring this clean for a little bit :) until I can surf some more
    thanks again
    also, I can do windows updates at the web site now
     
  21. johny3

    johny3 Private E-2

    my avast did a scheduled scan today and I cannot find the log to attach it but it found this file
    Win32: alureon-fz
    c:\qoobox\32788r22fwjfw\kbdclass.sys

    is this a false + detection of an element of combofix or is this real, I wonder?
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No, it is just a quarantined file in ComboFix's quarantine folder.


    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:




    Support MajorGeeks with Geek Wear!
     
  23. johny3

    johny3 Private E-2

    i thought that was probably the case, thank you.
    MbAm did catch a file after a scan today.
    It took care of it.

    I have not had any redirects today yet, although I have not been using the computer much.
    Let me know if you think the MBAM log below require attention. if not I am game for calling this infection cured. I did change my computer date back to the right day, I noticed from the logs we were creating that the date was wrong.

    thank you again.
     

    Attached Files:

  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good that MBAM caught that. It is important to keep your AV and AS software up to date. I will leave this thread open just in case you need to come back to it later. Otherwise, I think you are good to go. :)
     
  25. johny3

    johny3 Private E-2

    sweet thanks :)
    i will run thru the steps below a little later.
    thank you so much for your help :major
     
  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds