problem updating anti virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by beerwolf-crowe, Sep 2, 2009.

  1. beerwolf-crowe

    beerwolf-crowe Private E-2

    Hi all, my problem first stated when i tried to update AVG Free but the server couldn't be found, i found this strange as i was surfing the web at the time. Anyway i downloaded & tried to install Avira, after a recomendation from a friend but this wouldn't install because of the same server error, so i tried to go to the microsoft website for a bit of info and again the same error. i use firefox for my browser of choice but also get the same problems with internet explorer. I then googled the problem & found my way here and The Read & Run Me First Guide. I have followed the guide to the letter but have had a few problems, couldnt run combofix because of the following error messages;
    windows cannot find 32788R22FWJFW\iexplore.exe
    "" "" "" "" \hidec.exe
    "" "" "" "" \n.pif
    "" "" "" "" \nircmd.cfxxe.
    RootRepeal would not start even after i waited over 20 mins for it to initialize.

    Both of these problems occured even in safe mode.
    I have attached log files for the other 3 programs in the hope they may be of some assistance to you & then of course me. sorry for the long post but i wanted to include as much info as possible.
    Many Thanks & looking forward to hearing from you.
     

    Attached Files:

  2. beerwolf-crowe

    beerwolf-crowe Private E-2

    serious problem

    hi again all, yesterday i posted regarding malware problems etc with relevent logs but today things are getting worse. i manually updated avgfree and then resident scan threw up 100's of html/framer threats plus others, firefox & thunderbird just crash on startup & all other problems still exist as per previous post. have included latest logs , can somebody please help & advise. Many Thanks
     

    Attached Files:

  3. beerwolf-crowe

    beerwolf-crowe Private E-2

    please please help

    hi everybody, i fear a re-formatting is inevitable here,things get worse the more i try,html/framer is all i continually get from avg,f/fox & t/bird wont run & IE wont allow logs to be posted, they can be read in prev thread, can somebody please advise me (before i get the chainsaw too it):cry
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Each time you posted and additional message, you bumped yourself to the bottom of the work queue and thus delay getting an answer even longer than normal. You should have read this sticky you were given: Don't Bump! It Only Hurts You!!!

    Before you tried to run ComboFix, did you shutdown your protection software as requested?

    You are EXTREMELY out of date with your version and databases of Malwarebytes. You did not update as requested. Now run Malwarebytes and click the Update tab. Then click the Check for Updates button so you update to the current version of the program and database. Then run a new scan with it too. Attach the new log.

    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.

    Uninstall the below old versions of Sun Java as rquested in the READ & RUN ME:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 5
    J2SE Runtime Environment 5.0 Update 6
    J2SE Runtime Environment 5.0 Update 8
    J2SE Runtime Environment 5.0 Update 9
    Java 2 Runtime Environment, SE v1.4.2_01
    Java(TM) 6 Update 15
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3
    Java(TM) 6 Update 5
    Java(TM) SE Runtime Environment 6 Update 1
    Java(TM) SE Runtime Environment 6

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\vyrwc.dll/sp.html#29126
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O2 - BHO: (no name) - {a786e841-0541-427e-a26a-a5e078bfcd86} - (no file)
    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
    O4 - HKCU\..\Run: [BitTorrent] "C:\Program Files\BitTorrent\bittorrent.exe" --force_start_minimized
    O4 - HKCU\..\Run: [Aida] C:\Documents and Settings\Owner\Application Data\ttuh.exe
    O4 - Startup: BitTorrent.lnk = C:\Program Files\BitTorrent\bittorrent.exe
    O8 - Extra context menu item: &Search - http://ka.bar.need2find.com/KA/menusearch.html?p=KA
    O8 - Extra context menu item: &Search The Internet - res://C:\WINDOWS\Downloaded Program Files\toolbar.dll/SEARCH.HTML
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O15 - Trusted IP range: 206.161.125.149
    O16 - DPF: {92F05779-6D88-4958-8AD3-83C12D855D67} - http://www.activesearch.com/tb/toolbar.cab
    O18 - Protocol: s-http - {D37E6C5F-1C0F-47C0-A3B6-403EEC555402} - (no file)
    O23 - Service: sofatnet Service (sofatnet) - Sigma Designs In - C:\WINDOWS\system32\sofatnet.exe

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.
    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program

    Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\WINDOWS\TEMP
    C:\Documents and Settings\Owner\Local Settings\Temp

    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )



    Then attach the below logs:
    • the updated Malwarebytes log
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 8, 2009
  5. beerwolf-crowe

    beerwolf-crowe Private E-2

    Hi chaslang, many thanks for looking at the logs & apologies for "panicky,unintentional bumps":-o. I have followed your instructions but had a few problems. combofix will not run in any way shape or form. I couldnt update anti-malware bytes(no connection to website) so d/l latest defs(from another pc) and ran them 01/09/09, but got error code 732 on startup. couldnt get avenger to run with full script, had to leave out first 2 commands(drivers to stop & delete sofatnet).have attached the new logs as requested, hope they are more helpful. look forward to hearing from you soon. still having probs with "security" websites. many thanks again.
     
  6. beerwolf-crowe

    beerwolf-crowe Private E-2

    cant attach files at the mo will try another pc or just nip off & rob fort knox(it will be less hassle):-D:banghead
     
  7. beerwolf-crowe

    beerwolf-crowe Private E-2

    here are the logs
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your infection keeps spreading/respawning. So I dug a little deeper into your logs and I'm sorry but I have to give you bad news. You will have to do a total clean reinstall.


    I can see the reason for your problems and also why ComboFix will not run. Your logs show that your Windows Operating system files have become infected by a Virut infection and there is no known reliable fix for this. In addition there are many many other infected files. We could spend a lot of time trying to remove this infection, but odds are that it will not work because the nature of the infection has so many executable system files infected that as soon as we fix one file, other files that are infected will almost immediately or upon the next reboot, just reinfect the files. In addition, your PC would still basically be unreliable/untrustworthy even if we manage to fix the infected files that we can see since there could be many more that we are not seeing.

    The safest thing for you to do is backup your personal data immediately since your PC could possibly become unbootable at any point in time. Do not back up any executable files. This includes programs that you have downloaded since any of them could be infected. Anything you may have already backed up that is an executable type file (things you downloaded to install programs....etc) are most likely infected and will cause you to be reinfected if you reuse these files.

    Once you backup, you need to format partitions and reinstall Windows and all other software especially your protection software. Then install all updates for all software. DO NOT reinstall from any executable file backups you made while this PC was infected or you will just be reinstalling the infection.
     
  9. beerwolf-crowe

    beerwolf-crowe Private E-2

    Hi Chaslang, many thanks for the time & effort, but i had feared this news for a while.:cry. so i will get down to the dreaded task at hand & also take the recomendations on this website & "invest" in some good software for the future, even though the freebies have done well for a while, & hopefully i wont be needing your services again ;)
    Many Thanks again & keep up the great work you guys do here.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds