vista can't run windows update and more

Discussion in 'Malware Help (A Specialist Will Reply)' started by whril, Feb 21, 2012.

  1. whril

    whril Private First Class

    I have been fighting with a Dell Inspiron 531 running Vista Home Premium. Trying to update windows, ie, and antivirus with no success. When running the Windows Update it did have an error which pointed me to a time problem. I changed the time to the correct year and ran the program again. Now it hangs with no error codes. When updating IE browser or Avast it returns "can not connect to server".

    Thinking it might be malware I did run all the suggested scans. Attached is the logs. Had to run the MGTools twice as the first time did not find a zip file.

    I did see the post from June 2011 between TimW and thrdegree. None of the posted links are working for me.


    Any help would be greatly appreciated.

    Thank you
    smile
    whril
     

    Attached Files:

  2. whril

    whril Private First Class

    the last scan.
     

    Attached Files:

  3. Goldenskull

    Goldenskull I can't follow the rules

    i would run a malwarebytes scan too check
     
  4. whril

    whril Private First Class

    i thought i did. is the mbam log the malwarebytes?
     
  5. samtal

    samtal Corporal

    I had a similar problem once and it turned out to be a faulty router. Worth checking another router to see if it's the problem.
     
  6. whril

    whril Private First Class

    The computer has been connected to 3 different routers in as many towns. Acts exactly the same in each location. It can access the web, just can't update a thing. downloads don't seem to be an issue.
    :(
     
  7. satrow

    satrow Major Geek Extraordinaire

    I'll get this moved to the Malware forum for you.
     
  8. whril

    whril Private First Class

    Thank you. Wasn't quite sure which category it would fit best in.
     
  9. whril

    whril Private First Class

    This morning I tried once again to install Windows Updates in safe mode. The error code 8000ffff showed. Followed the manual instructions to fix it. Booted back into safe mode. Ran Update again. This time it was error code 80070020. Ran the Microsoft Fix It and it would not complete as I need the power shell. The power shell will not install. How would I get the power shell to install?
    Thank you
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Can you explain why you have files showing as being installed in the year 2013? For example your Avast install and others (see below )
    Code:
    2013-02-20 04:57 . 2011-11-28 17:51 20568 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys
    2013-02-20 04:57 . 2011-11-28 17:53 314456 ----a-w- c:\windows\system32\drivers\aswSP.sys
    2013-02-20 04:57 . 2011-11-28 17:52 34392 ----a-w- c:\windows\system32\drivers\aswRdr.sys
    2013-02-20 04:57 . 2011-11-28 17:52 52952 ----a-w- c:\windows\system32\drivers\aswTdi.sys
    2013-02-20 04:57 . 2011-11-28 17:53 435032 ----a-w- c:\windows\system32\drivers\aswSnx.sys
    2013-02-20 04:57 . 2011-11-28 17:52 55128 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
    2013-02-20 04:50 . 2011-11-28 18:01 41184 ----a-w- c:\windows\avastSS.scr
    2013-02-20 04:50 . 2011-11-28 18:01 199816 ----a-w- c:\windows\system32\aswBoot.exe
    2013-02-20 04:06 . 2013-02-20 04:06 -------- d-----w- c:\program files\AVAST Software
    2013-02-20 03:25 . 2013-02-20 04:49 -------- d-----w- c:\programdata\AVAST Software
    2013-02-20 01:45 . 2013-02-20 01:46 -------- d-----w- C:\richs modem
    2013-02-19 14:17 . 2013-02-20 01:13 -------- d-----w- c:\users\kevin perham\{13fa326b-900a-4229-8d17-50fda9a69d4e}
    2013-02-19 13:35 . 2013-02-20 01:13 -------- d-----w- c:\users\kevin perham\{7b223179-19b8-45a0-b1da-8b92391c5dbf}
    2013-02-19 06:02 . 2013-02-20 01:12 -------- d-----w- c:\program files\Linksys Wireless-G PCI Wireless Network Monitor
    Were these all put on your PC before you fixed the time? Also how did you date get changed to begin with?

    Other than a few items that have already been removed your logs are clean; but let's run a few additional scans to be safe.



    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    • Be sure to attach your log from TDSSKiller
    Now please also download MBRCheck to your desktop.


    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
    Also Please do the below so that we can boot to System Recovery Options to run a scan.

    For x32 (x86) bit systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.


    Enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Select US as the keyboard language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
      Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this file to your next reply. (See: How to attach)
     
  11. whril

    whril Private First Class

    chaslang,
    Thank you for getting back to me. I really can't explain the date issue as it is not my computer, belongs to a friend. Seems she was having quite a few issues with it. I can fix quite a few problems with computers but the downloading and a problem with the start up on this one was losing me. Yes, those installs were done before I changed the time. Truthfully never thought to check the time until an error code pointed me that way. She said the time has been off for years and she has no idea how it was changed to begin with.

    After much research today I have managed to install the files needed in order to update Windows and Avast. That issue seems to be solved, will know for sure when I run it tomorrow.

    I will run the TDSSkiller and MBRCheck in the morning. Do you think it is necessary to run the Farbar Recovery Scan as the problem is solved?

    There is another issue that I don't think is virus related? When starting the computer searches for a diskette. Not found so need to press F1 to continue. Should I post this issue somewhere else?

    Thanks!
    whril
     
  12. whril

    whril Private First Class

    Attached are the files you requested. I sure hope this thing is clean now!
    :)
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Your logs are clean.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  14. whril

    whril Private First Class

    Thank you!

    I really appreciate the time and effort that goes into the aid you provide here on MajorGeeks. Thank you for being here.

    smile
    whril
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds