Windows Update / services on XP

Discussion in 'Malware Help (A Specialist Will Reply)' started by TheRealStig, Aug 13, 2012.

  1. TheRealStig

    TheRealStig Private E-2

    Hi, I have a computer running XP.
    Had an issue with Trojans but managed to remove with Malwarebytes + SuperAntiSpyware. Also ran RogueKiller + HitmanPro + TDSKiller without detecting anything. But Windows Update is not running (settings = AUTO) and when clicking on the link to Win Update, the IE just freezes.
    Ran the Windows Repair (Tweaking.com) and also
    wscsvc.reg
    wuauserv.reg
    BITS.reg
    WinDefend.reg
    - apparently without resolving it.
    Finally done the Farbar service scanner - find log attached.

    Thanks

    Stig
     

    Attached Files:

    • FSS.txt
      File size:
      4.2 KB
      Views:
      8
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please provide us with logs from the below tools per our cleaning process:
    • Malwarebytes
    • RogueKiller
    • Hitman
    • MGtools
     
  3. TheRealStig

    TheRealStig Private E-2

    Thanks chaslang, please find RogueKiller and AMB - for AMB both the first one WITH detection and from scan today.

    Thanks

    Stig
     

    Attached Files:

  4. TheRealStig

    TheRealStig Private E-2

    HitmanPro + MGTools
     

    Attached Files:

  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Now download and save a copy of combofix.exe and save it directly onto your Desktop folder. Then double click on it to run it. Do not disturb it by clicking in the window that opens or it may stall. After it finishes, it may reboot your PC. Attach the C:\combofix.txt log that it creates.

    If after running Combofix you discover none of your programs will open up because you receive the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.
     
  6. TheRealStig

    TheRealStig Private E-2

    Thanks!
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Other than Babylon Toolbar ( which you have not even complained about ) I'm not seeing any malware in your logs, but it is a quite hard to follow all of the date because your Windows version is a Spanish version which makes it hard for us to find expected information in your logs.

    When you connect to Windows Update, try shutting down your protection software and tell me what happens. Provide exact word for word error messages if there are any.

    Also since this is a laptop, are you using Wireless to connect or a wired connection? Try wired if that is not what you are using.



    Also let's try updating the BITS registry entry with ComboFix because you may have use a registry key for Vista or Win7 not XP
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it has expired or need to be updated to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box into it:
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    If after running Combofix you discover none of your programs will open up because you recieve the following error: Illegal operation attempted on a registry key that has been marked for deletion then you will need to reboot your computer which will normally fix this problem.

    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )

    Now attach the below log:
    • C:\ComboFix.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Aug 20, 2012
  8. TheRealStig

    TheRealStig Private E-2

    Hi chaslang,

    Let me know to remove BABYLON (just so I don't mess around makes life harder for you ;) )

    If there're anything you need me to translate from Brazilian-Portuguese, please just let me know!!

    Tried Win Update again (wired): Clicked START and then the icon - IE starts and shortly after pops up a window asking me to allow installing the following software:
    Name: Windows Update
    Editor: Microsoft Windows Component Publisher
    - I clicked INSTALL but shortly after a window popped up saying that

    Shortly after the IE showed the error that the malicious software tool had found a problem and is to shut down the process.

    BITS reg / Combofix:
    Ran without problems though during a windows popped up saying PEV.exe found a problem and will need to close down. Do you want to send error report to Microsoft? Combofix continued to run apparently not affected by this.

    Thanks

    Stig
     

    Attached Files:

  9. TheRealStig

    TheRealStig Private E-2

    Hi Chaslang,

    I should state that I get same error running Windows Update both with and without AV running. The exact translation is "A defect or malicious component made Internet Explorer close this website"
    - then it gives me 3 options to 1) go to my home page, 2) return to Microsoft.com 3) more info.

    I also tried to start Windows Defender: Get the error window "Error when initializing the application: 0x800106ba. The service of this program was interrupted due to a problem. To initiate the service, restart the computer or search in Help how to initiate a service manually".

    Thanks

    Stig
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay the BITS service was added to the registry okay ( it was missing before ) but it did not start.
    Also I see your Windows Update service is not running. Have you tried to enable automatic updates?

    See >>http://windows.microsoft.com/en-US/windows-vista/Turn-automatic-updating-on-or-off

    Also try doing the below.

    Be patient while doing the below. The fixes can take quite awhile to run. Especially the permissions repairs. It may be best to kick it off and goto bed or do something else. It is better not to run anything while the repairs are going on.


    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the Start Repairs tab.
    • The click the Start button.
    • Create a System Restore point if prompted.
    • On the next screen, click the Unselect All button to first deselect all repairs.
    • Now select the following repair options:
      • Reset Registry Permissions
      • Reset File Permissions
      • Register System Files
      • Repair WMI
      • Repair Windows Firewall
      • Remove Policies Set By Infections
      • Repair Winsock & DNS Cache
      • Repair Proxy Settings
      • Repair Windows Updates
      • Set Windows Services To Default Startup
    • Now on the lower right side check the box to Restart/Shutdown System When Finished
    • Then make sure the Restart System radio button is enabled.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished.
    Now download the current version of MGtools and save it to your root folder. Overwrite your previous MGtools.exe file with this one.

    Run MGtools.exe ( Note: If using Vista or Win7, make sure UAC is still disabled. Also don't double click on it, use right click and select Run As Administrator )


    Now attach the below log:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  11. TheRealStig

    TheRealStig Private E-2

    Hi chaslang,

    Win Updates IS set to recommended settings = automatic updates. I've also tried to alter the time for checking for updates, to see if that could trigger anything, but no....

    The Windows Repais didn't take that long - even for XP ;)

    MGtools: Had forgotten to disable AVAST and got a sandbox warning, but managed to disable and it appears it didn't affect the MGtools scan - but if you want to I can re-run?
    Please find attached log.

    Thanks

    Stig
     

    Attached Files:

  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay then let's see what happens if you try starting the service since it is stopped.

    Click Start and type services.msc in the Run box and click OK.

    On the Services form scroll down to Automatic Update and double click on it. Set the Startup Type to Automatic ( if not already set that way ) and change the Service Status to Started ( by clicking the Start button). Tell me if it Starts and remains started. If you receive any error messages, provide the EXACT details.

    Try the same to start the Backgound Intelligent Transfer Service. Again tell me what happens.
     
    Last edited: Aug 22, 2012
  13. TheRealStig

    TheRealStig Private E-2

    Hi chaslang,

    Win Update WAS set to automatic, but not started - when I tried to start I got a pop-up window saying "It's not possible to start the service AUTOMATIC UPDATES. Error 1290: 0x50a

    For BITS exactly the same - automatic, but not started. When starting exactly same error message.

    Cheers

    Stig
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is not due to malware. You have a problem with Windows. Information on this error states

    You may want to try performing a System Restore to a point before where your problems began.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Wait a second. Where did you get the patches you said you used in message #1 for the below?
    wscsvc.reg
    wuauserv.reg
    BITS.reg
    WinDefend.reg
     
  16. TheRealStig

    TheRealStig Private E-2

    Hi chaslang,

    I had searched for same issue/trojan on the majorgeeks forum and found one thread treating what appeared to be same problem. Followed the advice given there (though can't remember exactly where).

    Thanks

    Stig
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This is a dangerous thing to do. All fixes are taylor to the particular operating system a user is running and what problems they are having. You may have installed registry patches that are not correct for your version of Windows. Are those the only registry patches you applied or did you use more than those? We may not be able to easily fix this.

    Let's see if we can apply a couple new patches.


    Copy the bold text below to notepad. Save it as fixWU.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now Copy the bold text below to notepad. Save it as fixBITS.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your PC and after reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
    Last edited: Sep 10, 2012
  18. TheRealStig

    TheRealStig Private E-2

    Hi chaslang,

    OK, understood reg. the danger :-o

    I have Win XP and I only ran the scans/patches mentioned:
    Malwarebytes
    SuperAntiSpyware
    Roguekiller
    Hitmanpro
    TDSKiller
    WindowsRepair (Tweaking.com)
    - then the 4 patches wscsvc.reg/wuauserv.reg/bits.reg/windefend.reg
    Finally Farbar.

    Now (following your latest post) ran both patches fixWU.reg and fixBITS.reg exactly as requested and with success message :)

    After reboot, ran MGtools/getLogs.bat - please find attached:

    Afterwards, entered start -> Windows Update
    I get a pop-up window, asking to install Windows Update - I click OK, but then nothing more happens (though no error messages either)

    Thanks

    Stig
     

    Attached Files:

  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well although it said the patches worked, they do not appear to have worked correctly. Thus I'm going to modify them with the below fix. Overwrite the previous patch files with these new ones. Also, I'm adding one new patch file.​

    Copy the bold text below to notepad. Save it as fixWU.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. ​

    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Now Copy the bold text below to notepad. Save it as fixBITS.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry. ​


    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Copy the bold text below to notepad. Save it as fixWSCxp.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.



    Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it definitely did not work.

    Now reboot your PC and after reboot, run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator). ​

    Then attach the below logs:

    • C:\MGlogs.zip
    Make sure you tell me how things are working now!







     
    Last edited: Sep 12, 2012
  20. TheRealStig

    TheRealStig Private E-2

    Thanks chaslang,

    Ran all 3 patches with success message!
    Please find logs.
    Clicked on WINDOWS UPDATE - after "thinking" for about 30 seconds IE stated something like "searching for latest software".
    Shortly after popped up the window asking me to allow installing the Windows Update software.
    While I was typing, suddenly the IE changed, now stating that "IE closed this site to help protect the computer", with sub-text stating "a malfunctioning or malicious add-on caused Internet Explorer to close this webpage".

    res://ieframe.dll/acr_depnx_error.htm#microsoft.com,http://www.update.microsoft.com/microsoftupdate/v6/default.aspx?ln=pt-br

    Nevertheless the Windows Update icon appeared in the taskbar, stating that there are 12 updates available (for me to choose recommended or personal installation) - appears I'll be able to install.
    Do you want me to?

    Thanks a lot

    Stig
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Yes, see if you can install all of the recommended updates. Let me know what happens and if any of them do install, be sure to reboot afterwards. Then attach a new log from MGtools after running the C:\MGtools\GetLogs.bat program.
     
  22. TheRealStig

    TheRealStig Private E-2

    Installed OK, but when I click on WINDOWS UPDATE (from START) I still get the same issue: Searching for updates, then asking to install the WINDOWS UPDATE software, then the "a malfunctioning or malicious add-on caused Internet Explorer to close this webpage".
    Attached logs.
     

    Attached Files:

  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Try running IE without add-ons. Right click your IE icon on your Desktop and select the option Start Without Add-ons

    See how it works this way. You will have to continue in the Software Forum soon as you are not having malware problems. You have Windows problems now. Also since you had and may still have many services broken ( again not a malware forum issue ) this may make it necessary to reinstall to get your PC into a stabile and reliable state.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds