cannot install windows updates

Discussion in 'Malware Help (A Specialist Will Reply)' started by Outlawstar15a2, Jan 23, 2007.

  1. Outlawstar15a2

    Outlawstar15a2 Corporal

    I don't really know how to explain this as I wasn't at the computer at the time this happened but. I went to get onto the computer and noticed my wallpaper and IE home page was gone. The home page was replaced by some secure32 address that left it at a blank screen and had locked out my ability to change the homepage. I ran ad-aware, spybot, ccleaner, bitdefender, panda all in that order i also took the advice and did a normal startup in boot mode. I was relieved to notice that I could finally change my IE home page back to it's former setting and that I could finally surf the internet in normal mode again, however there was another problem.

    When I first went to take care of the infestation I also ran Windows Defender it came back with no results. So I went to Windows Update to attempt to install the latest definitions to try again. And it kept rebooting the PC everytime the Windows would go to install the definitions. When I later did my counterspy scan it registered a large reigistry infestation. My current situation is this. Everything is working fine and I can perform normal computer tasks the only thing I cannot do is install Windows Updates because the PC will do a hard re boot. I am getting ready to attach all logs as I've completed all the Read and run me steps. I even included a Hijackthis log if needed.
     

    Attached Files:

  2. Outlawstar15a2

    Outlawstar15a2 Corporal

    ...and the rest of the logs...
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Run this to remove ViewpointKiller Viewpoint Media software because this adware junk from AOL will typical reinstall itself.

    Get updated GetRunKeys and NewFiles (You are using the old version!)



    Run HijackThis and select Do a system scan only. Look for the below lines (you may not always find both of them) and select them but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
    O4 - HKLM\..\Run: [AlcxMonitor] ALCXMNTR.EXE
    O4 - HKLM\..\Run: [AutoSys] C:\WINDOWS\system32\autosys.exe


    After clicking Fix, exit HJT.

    Attach new logs for:
    GetRunKeys
    NewFiles
    HJT
     
  4. Outlawstar15a2

    Outlawstar15a2 Corporal

    ok heres the updated logs. Soory about the getrun and shownew things i didn't realize they had released updated versions...
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Make sure that the below file has been deleted. HijackThis does not always delete them:
    C:\WINDOWS\system32\autosys.exe
     
  6. Outlawstar15a2

    Outlawstar15a2 Corporal

    yep, the file is gone. should i try to download from windows update now?

    ....nevermind i tried to download from windows update and it rebooted saying "the system recovered from a serious error."
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Right click My Computer / properties / advanced / startup and recovery ...and uncheck the box to restart on errors.
    This will give you a BSOD ...please post the error code.

    Also attach new logs:
    GetRun
    ShowNew
    HJT
     
  8. Outlawstar15a2

    Outlawstar15a2 Corporal

    This is the technical information it printed out on the BSOD page.

    ***Stop: 0x0000008E (0xC0000005, 0xF4CFF60A, 0xF1FFDA20, 0x00000000)
    ***system32:lzx32.sys - Address F4CFF60A base at F4CFD000, Datestamp 45b0938b

    Now out of curiosity I looked at the system32 folder in C:\Windows and I couldn't find a lzx32.sys file. I didn't touch anything I merely looked. I thought that might be useful information.
     

    Attached Files:

  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Run this AVG Anti-Rootkit

    You should see a line reporting something like one of the below.

    C:\windows\system32\lzx32.sys
    C:\windows\system32:lzx32.sys

    Yes the colon is correct. This is ADS (Alternate Data Stream) attached to the system32 folder. Have AVG fix this item. If anything else is reported, tell us what but don't fix anything except the reference to lzx32.sys
     
  10. Outlawstar15a2

    Outlawstar15a2 Corporal

    Ok, the definition is installed and Windows Defender should be up to date for now. Looks like it's smooth sailing from here. The Windows Update problem is gone, I was wondering what is a good replacement for Windows Defender? I was looking through some of the threads what about AVG antivirus and how will it interact with Avast antivirus?
     
  11. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is better than nothing, but it is not that good. A better choice would be to buy a commercial program. Even a layered approach of some free tools like the below may be adequate for most people and will be better than Windows Defender:You do not want to run more than one Anti-Virus!!
     
  12. Outlawstar15a2

    Outlawstar15a2 Corporal

    Well heres the complete list of anti malware programs I run. I don't have any set formula or protocol I run most of them when it's time to do a scan and a few are on their way to being phased out.

    Ad Aware
    Spybot - S&D
    Avast Antivirus
    Windows Defender (judgement status pending)
    CCleaner
    CWshredder (being phased out)
    SpywareBlaster
    Windows Malicious Software Removal Tool (no longer used)
    ZoneAlarm (firewall, not Antivirus)
    Panda (online)
    Bitdefender (online)

    in adition to these I have the other tools required by the preliminary Read and run me steps and those recommended to me. However I only use those programs like Hijackthis and Getrun when told to do so otherwise I leave them alone. What I wanted to know was if you had any suggestions for me to improve my list because I was curious if there was anything else I could do to imrpove it.
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are well protected....the Counterspy is a trial version, so you should uninstall it.
    I have only a few of those running and never get infected....the best protection is you.

    How to Protect Yourself[.
     
  14. Outlawstar15a2

    Outlawstar15a2 Corporal

    Just one small question. How come windows security center no longer can see that Zone Alarm is running. ZA is working perfectly but for some reason security center can't see it.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds