Vista32 help

Discussion in 'Malware Help (A Specialist Will Reply)' started by axlmastr, Aug 1, 2012.

  1. axlmastr

    axlmastr Private E-2

    Relative's Vista32 SP2 has not been updating through Microsoft in about 4 months. AVG 2012 has not updated or run a full scan in the same time (approx March 12 2012) also Antivirus shows "not active" in User Interface & "fix" option will not correct. Was given machine to remove a non-Adobe PDF reader and decided to check out the AVG warning in the systray and Event Viewer. AVG will not manually update and Event Viewer/Application shows multiple ESENT Event: 412 errors with the following "wuaueng.dll (1200) SUS20ClientDataStore: Unable to read the header of logfile C:\Windows\SoftwareDistribution\DataStore\Logs\edb.log. Error -546." I followed MG Vista instructions. Roguekiller would hang but managed to get finished. HitmanPro ran but cannot find log. Attached are RK and MGTools logs. Thanks
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you attach the RogueKiller log please, and what happened with MalwareBytes log?
     
  3. axlmastr

    axlmastr Private E-2

    Yeah sorry about that. I had trouble running the RK and Hitman but now have found the solution for that issue and will post logs along with Malwarebytes. Apparently my relative missed the install on the Zonealarm Free firewall and installed both the AV and firewall though AVG Free AV was already installed. We know that two AV at the same time is disaster but they didn't know it. I uninstalled the ZA AV and left the AVG installed and disabled then ran the scans. When running RK I didn't delete the keys it found just saved the report. I managed to get AVG to update and scan after going through Programs & Features to have it repair itself and after a reboot it is functioning correctly. I still cannot get Windows Update to work as I manually initiate it and the browser opens and stays blank infinitely.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Not seeing any malware.


    Delete these folders:
    • C:\Users\Bud\AppData\Roaming\Babylon
    • C:\ProgramData\Babylon

    Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    I want you to run TDSSKiller so refer to the below for how to do so.

    TDSSkiller - How to run
     
  5. axlmastr

    axlmastr Private E-2

    I removed the folders as asked.

    I copied the registry fix and ran with a "success" message.

    I ran tdsskiller with "0 threats" result. log posted

    I still can't get windows update to run. When clicking from start menu the window "system maintenance > windows update" pops up with a message/prompt "check for updates for your computer". If I click "check for updates" button a message pops up "Windows update cannot currently check for updates, because the service is not running. You may need to restart your computer." with the option to click "OK" and the message goes away. It's as if something has blocked access to Windows Update. I did mention to you in previous post that I had not deleted anything when RK was finished scanning and only save the report. I saw in the report that the hosts file had trash in it and some keys in registry were changed, one concerning policy. Any possibility of those items affecting or is it worse than that? I had done research before posting this thread and some solutions were to re-register Windows Update related files. Is this a viable solution or is something rogue still here to reverse those changes? Just thoughts...
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    The roguekiller log is fine, nothing to worry about in there. I suggest you ask about this in the software forum. :) Best of luck.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  7. axlmastr

    axlmastr Private E-2

    Sorry about the delayed reply. I did the post scan cleanup/removal steps as usual and the machine does run better than before both with your help and the removal of the extra AV program. The user is prone to doing things on the web that defies the malware prevention guide and I'm breathless with the reinforcement of such ideas. I did correct the issue with Microsoft Update not functioning either manually or automatically by following a post on another forum written by a MSVP. It stated to delete the contents of the Software Distribution folder and reboot. It stated that some previous updates may have to be reinstalled upon reboot but that Microsoft Update would indeed begin to function once again. I tried this method and it worked. Thanks again for your help Kestrel13!. This thread is considered closed :)

    I will be posting a new thread for a friend's XP machine just to have one of you look at it and see if there is anything in the logs.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds