Programs including McAfee cannot update.

Discussion in 'Malware Help (A Specialist Will Reply)' started by Agent00111, Dec 17, 2010.

  1. Agent00111

    Agent00111 Private E-2

    I have a Toshiba Satellite A500 laptop running Windows Home Premium 64-bit (6.1, build 7600) with an Intel i7 processor, 4 GB of RAM and 325 GB of free hard drive space.

    For some reason, most of my programs cannot download updates, citing internet connection problems. I have a good connection to the internet, however, and while many of the affected programs are game patchers and the like, neither McAfee Total Protection nor windows itself can get updates either. I made sure that none of the affected programs were being blocked by McAfee's firewall first (despite the fact that I didn't think an antivirus program would firewall itself), and they were not. This led me to believe I had some malware.

    The first place I turned to for help was McAfee itself, and I found this page and followed all instructions within: https://community.mcafee.com/message/130658. MBAM found four trojans and some other piece of malware (see attached log) and deleted them. This changed absolutely nothing. I had the exact same problems as before. So, I found this website and followed all the instructions from "READ & RUN ME FIRST" that I could (had a problem with combofix, see below) and none of the scans found anything. I still have the same problems. I have attached the requested logs.

    Problems encountered in READ & RUN ME FIRST
    When I tried downloading the latest version of Java after deleting my older version, it gave me the same sort of "Can't connect to the internet" problem that my other programs are having.
    When I tried to download combofix.exe, the download failed after a second and McAfee instantly sprang up with an ARTEMIS error saying it detected a trojan and automatically removed it. So, I disabled realtime scanning, tried to download again, and never even got to my download window. Firefox brought up a tab saying: Firefox can't find the file at http://download.bleepingcomputer.com/sUBs/ComboFix.exe. * Check the file name for capitalization or other typing errors. * Check to see if the file was moved, renamed or deleted.

    The first mbam log is the one from before i tried READ & RUN ME FIRST. The other three ARE from READ & RUN ME FIRST.

    Thank you in advance for reading this and spending your time fixing my problem. :D
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Go to TDSSKiller and Download TDSSKiller.zip to your Desktop

    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Now double click the TDSSkiller.exe file to run it ( if using Vista or Windows 7 do not double click on it but rather, right click and select Run As Administrartor.
    • Allow the application to run and a window will open showing that it is TDSSkiller from Kaspersky
    • Click Start scan
    • It will run rather quickly and will notify you of whether anything is found or not.
    • Follow the instructions to delete/quarantine if asks you what to do when if finds something.
    Whether an infection is found or not, a log file should be created on your C: drive ( or whatever drive you boot from) in the root folder named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply. (See: HOW TO: Attach Items To Your Post )

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.

    Tell me how things are running for you now?
     
  3. Agent00111

    Agent00111 Private E-2

    It seems partially fixed.
    *Steam browser now works
    *Steam games will update
    *Java was downloadable
    *Windows update seems to work (it can search out new updates, but there are not any essential ones for me to try downloading right now, just optional ones)

    However, McAfee still can't update. Go figure.
    I did receive a success message from fixME.reg.
    TDSSKiller turned up nothing, thank god. Imagine if I had a rootkit. T_T

    Unfortunately, I saw that TF2 got a massive update with new weps so now I am tempted to just go slobber over those. :drool Fixing my AV is way more important though. So I will wait.

    Definitely better now, but McAfee doesn't want to collaborate. Attached are TDSSKiller and MG logs. (Are there supposed to be 2 TDSS logs? I only ran it once...) Thanks!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    What errors do you recieve when trying?

    C:\ProgramData\ParetoLogic <--- delete this folder.
     
  5. Agent00111

    Agent00111 Private E-2

    ParetoLogic folder deleted. (uninstalled it a couple of days ago mere minutes after installing it and figuring out that it wasn't legit, guess it didn't want to leave, eh?)

    McAfee problem (as detailed as I can get it) is as follows:
    These are my actions:
    1. Double click McAfee Total Protection to open the program
    2. Observe the top 4 categories:
    (Green check mark) Scan: Complete
    (Red x) Updates: Available
    (Green Check Mark) Firewall: On
    (Green check mark) Subscription: Active
    3. Click on "Updates: Available"
    4. Click the first bullet "Check for Updates"
    5. Wait while it checks for updates.
    6. Scoff as the computer status bar turns green and states "Your computer is secure (no action required)"
    7. Observe the "checking for updates" sequence ending successfully.
    8. Sigh inwardly as is moves on to download the updates, remaining at 0%
    10. "Downloading updates" changes to "Update problem" and green bar changes to red "Your computer is at risk"
    11. Message is displayed: "McAfee cannot update your software. Please check your Internet connection. If the problem continues, please contact Technical Support."
    12. Not check my internet connection, knowing that the simple act of writing this response renders the suggestion moot.

    So pretty much it just won't download the updates despite the fact that it recognizes them as being available. Should I try uninstall/redownloading it?
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes, I would. Let me know how it goes.
     
  7. Agent00111

    Agent00111 Private E-2

    After a reboot everything seems to work just fine. Did not have to redownload McAfee. Problems solved, as far as I can tell.

    Thanks a bunch Kestrel. Say hi to Mingy Jongo for me! ;)
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Ahhh that's great!
    You're most welcome!
    ...LOL I had to google that!

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds