Can't turn on Windows updates

Discussion in 'Malware Help (A Specialist Will Reply)' started by csebasti, Mar 30, 2011.

  1. csebasti

    csebasti Private E-2

    I had some malware on my computer, but went through the read and run me first topic, and it seems to be gone now. I'm running Win XP SP3. The malware was one that runs a fake virus scan and comes up with a ton of bogus hits.

    My windows autoupdate is now turned off, and I can't turn it back on.

    My .exe file association was lost and I couldn't run any programs, but I've fixed that now.

    I'd like someone to take a look at my log files and see if everything looks ok. I had some trouble running RootRepeal. It crashed a couple times when my computer's screensaver came on. In the multiple times I ran it trying to get it to finish, it seemed to be picking up different items on C: each time. Not sure what that was all about.

    Thanks for the help.

    Chris
     

    Attached Files:

  2. csebasti

    csebasti Private E-2

    Here's the 5th log file.

    Chris
     

    Attached Files:

  3. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, csebasti

    I am reviewing your logs and will get back to you with instructions as needed. Please be patient!

    dr.m
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Hello, csebasti

    *Other than the tools our guide instructed you to save there, I strongly recommend that you clean up this account's Desktop immediately leaving only shortcut links. [ C:\Documents and Settings\Chris\Desktop ] Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least - it can have an effect on your PCs performance.

    Step 1:
    Please look in Add/Remove Programs (Programs and Features if using Vista or Windows 7) for the following and uninstall if found. If you get any errors just make a note and continue on.
    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Step 2:
    Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Make sure you have shut down all protection software (antivirus, antispyware, firewall...etc) programs so they do not interfere with the running of ComboFix. *Remember to re-start them before coming back online.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text inside of the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
      If it asks you to overide the previous file with the same name, click YES.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    Note:
    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    NOTE: If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion"... the answer is to REBOOT the machine, and all will be corrected.

    Step 3:
    Delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    Step 4:
    Open CCleaner - select "Cleaner" > "Run Cleaner" <---use this function ONLY!

    Step 5:
    Please go to VirusTotal.com and upload each of the following files for analysis.
    Step 6:
    Then run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Windows 7, use right click and select Run As Administrator).

    Please attach the below logs to your next reply:
    • C:\MGlogs.zip
    • VirusTotal.txt

    * Make sure you tell me if you had any problems running this procedure; and answer this - "What malware problems are you still experiencing?"

    dr.m
     
  5. csebasti

    csebasti Private E-2

    dr. m,

    I ran through your list of instructions.

    1. I found and removed Java 2 Runtime Environment, SE v1.4.2_03

    2. I ran Combofix with the CFscript file you posted. I left the room, and came back and the computer was restarting. I assume it was supposed to do that. The ComboFix window said it was generating logs. When the computer restarted, my AV and firewall restarted as well. I got a popup from the firewall saying PEV.cfxxe was trying to access the internet. Since this was in the ComboFix folder, and ComboFix seemed to be hung up waiting on it, I allowed it. Was this OK?

    3. CCleaner ran fine.

    4. I scanned the 3 files at VirusTotal.com, but didn't see any way to get the VirusTotal.txt file you requested. The first and 3rd file were identified as the same file, and both returned 0/43 for result. The middle one was 0/42.

    5. MGTools ran fine.



    I'm still getting popups telling me windows autoupdates are turned off, and I can't turn it back on. Can you help me get it turned back on?

    Also, I'm curious why running ComboFix put an IE icon on my desktop? I don't use IE, so I don't normally have it on my desktop. I noticed it after running through the run and read me first instructions, but hadn't noticed when it appeared. This time I know it appeared sometime while ComboFix was running.

    Thanks for the help.

    Chris
     

    Attached Files:

  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Part of the ComboFix process puts a shortcut for Internet Explorer on the Desktop... you may delete it if you wish.

    You can try the below tips but this is a topic better suited for our Software Forum.

    Things to do when Window's Update doesn't work
    1. Make sure time and date and TimeZone are correct
    2. See if it works in safe boot mode
    3. Reset HOSTS file

    Download HostsXpert and then follow the below steps.
    Unzip HostsXpert.zip
    It will create a folder named HostsXpert in whatever folder you extract it to.
    Run HostsXpert.exe by double clicking on it.
    Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    Click Restore Microsoft's Hosts File and then click OK.
    Click the X to exit the program

    4. Flush DNS server

    Right-click on the Command Prompt icon and select
    "Run as administrator". Then type in: ipconfig/flushdns
    and press the Enter key on your keyboard.

    5. add Microsoft URLs to the Trusted Zone (see below)
    6. shutdown firewall and retry
    7. shutdown AntiVirus and try

    MS URLs

    http://*.update.microsoft.com
    http://download.windowsupdate.com
    http://genuine.microsoft.com
    http://go.microsoft.com
    http://support.microsoft.com
    http://update.microsoft.com
    https://*.update.microsoft.com <--Notice the https designation.

    The first thing to always check for Windows Update problems! Make sure that Automatic Updates is not turned off. It needs to be on and the service status needs to be Started and the Service type needs to be Automatic.

    Your logs look good! If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and re-enable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have re-enabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds