Thứ Năm, 28 tháng 7, 2016

Cannot receive any Window Updates part 2


zarnic

It may be malware (that's another problem) but regardless, I can NOT download any, that's any, Windows Updates... instead I read " error code 80072EE2



techmonkey74

Why do you think it's Malware? You might be ok, wait a while and try again.

You may encounter temporary connection-related errors when you use Windows Update or Microsoft Update to install updates

Devux

Windows Update error 80072ee2

That should fix your problem. Let us know the results.

zarnic

I have tried for at least a year and still no luck. I feel it may be malware because my browser (IE8) can't access most Microwave pages and without Updates I can forget about IE9. I've done a Recovery but still no change.Is there a soution?

techmonkey74

Quote�� Quote: Originally Posted by zarnic View Post
I have tried for at least a year and still no luck. I feel it may be malware because my browser (IE8) can't access most Microwave pages and without Updates I can forget about IE9. I've done a Recovery but still no change.Is there a soution?
One of Security Experts might chime in here. A full year without any updates?
Are you able to access other websites? Are you experiencing any other Malware related problems? What do you have in the way of security software?? (anti virus, anti malware, firewall).

Anak

Hi! zarnic, welcome to 7F

When was the last time you ran any malware scans? No matter, from your posts I would guess about a year. Let us start there first.

If you are able to download at all go here: Malicious Software Removal Tool | Protect Your Computer Download and run the tool.
Then a little further down you will see a link for Live One Care, download and run that also.

Post back any results, good or bad.
You need to get rid of / make sure you do not have the nasties before you can get anything else to work properly.

zarnic

Wow! I didn't expect this level of interest. Been living too long with the no-update problem that I've become complacent.

Techmonkey74:
Yes I can see other web sites and some Microsoft, as long as I don't download.

The Anti-(whatever) that I have used, or do, includes Malware Bytes, Norton, Antivira, and McAfee but little has changed. Maybe my problem is not a malware issue but it does seem strange that Windows is the only victum and sites that offer malware products can not usually be accessed.

Anak:
I tried to download the Malicious Software Tool and got " Internet Explorer cannot display the webpage" in a seperate window... typical response.

As for ' Live One Care ', went there but read "As of October 2009, Windows Live OneCare sales were discontinued in all markets. Product support ended on April 11, 2011.As of October 2009, Windows Live OneCare sales were discontinued in all markets. Product support ended on April 11, 2011...."

techmonkey74

Quote�� Quote: Originally Posted by zarnic View Post
Wow! I didn't expect this level of interest. Been living too long with the no-update problem that I've become complacent.

The Anti-(whatever) that I have used, or do, includes Malware Bytes, Norton, Antivira, and McAfee but little has changed. Maybe my problem is not a malware issue but it does seem strange that Windows is the only victum and sites that offer malware products can not usually be accessed.

As for ' Live One Care ', went there but read "As of October 2009, Windows Live OneCare sales were discontinued in all markets. Product support ended on April 11, 2011.As of October 2009, Windows Live OneCare sales were discontinued in all markets. Product support ended on April 11, 2011...."
Again I think one of our Security Experts needs to chime in but I believe Antivira is a FAKE (rouge) Anti Virus nasty. Also I would not recommend running more than one Anti Virus program at once, Norton and Mcafee don't play well with each other.

zarnic

TY techmonkey74, have to agree about the multiple Anti-Virus programs and I stay away from doing that. McAfee was a one time deal and is gone now. As for Antivira, am happy with it and the controversey continues ... we'll see.

Jacee

  • Please download Dial-A-Fix from one of the following mirrors:
  • Extract the zip file to your desktop.
  • Double click Dial-a-Fix.exe to start the program.
  • Press the green double checkmark box (Looks like this: )
  • UNcheck Empty Temp Folders, as well as Adjust Time/Date in the prep section. The prep section should then look like this:

  • Click on go
  • Exit/Close Dial-A-Fix
Next please go to windows update and install all critical updates
http://windows.microsoft.com/en-US/w...windows-update
Reboot, and see if that solves your update issues

Anak

Quote�� Quote: Originally Posted by zarnic View Post
Wow! I didn't expect this level of interest. Been living too long with the no-update problem that I've become complacent.

Techmonkey74:
Yes I can see other web sites and some Microsoft, as long as I don't download.

The Anti-(whatever) that I have used, or do, includes Malware Bytes, Norton, Antivira, and McAfee but little has changed. Maybe my problem is not a malware issue but it does seem strange that Windows is the only victum and sites that offer malware products can not usually be accessed.
After being beat 'bout the head and shoulders from what a user sees everyday, it is easy to become complacent.
Quote:
The folks at the independent anti-virus testing body AV-Test.org have been in touch with some interesting statistics.
They are finding more than one million unique malware samples a month, and presently the total amount of unique samples in their malware collection exceeds 22 million.
Source: AV-Test.org�s malware count exceeds 22 million | Naked Security

Quote�� Quote: Originally Posted by zarnic View Post
Anak:
I tried to download the Malicious Software Tool and got " Internet Explorer cannot display the webpage" in a seperate window... typical response.

As for ' Live One Care ', went there but read "As of October 2009, Windows Live OneCare sales were discontinued in all markets. Product support ended on April 11, 2011.As of October 2009, Windows Live OneCare sales were discontinued in all markets. Product support ended on April 11, 2011...."
Darn! Missed it by 3days!

As far as Malicious:

  • Restart your machine and try to get into Safe Mode with networking.
  • Usually the user has to tap the F8 key while the machine is booting up.

  • Go to this site to start: SuperAntiSpyware
  • Click on the Red Button to download the free version.
  • When it asks you to save the file, click save file, then save it to your Desktop under an assumed name like mydoghasfleas, do not forget we are trying to fool any nasties that this is a harmless file.
  • Right click the file and click on Run As Administrator if it asks to update say okay.
  • Then let it run.

This trick should also work with the Malicious tool. But, you have to be in Safe Mode!

Any Antimalware tool that is downloaded has to saved under a fictitious name in order to fool the nasties!


If you are happy with Avira Okay, but get rid of all the other extra programs. If you need help because some do not want to be un-installed we will get it figured out, there are tools.

For Starters: McAfee removal tool
Scroll down to Windows Vista \ 7 to start that process.
Do not forget to rename the file before you save it!

I can even show you how to remove any errant entries that were missed in the registry.

I am doing chores outside today so I am not able to stay nearby to see your responses, but I will check back at least once every hour.

Anak

Ahhh...I see Jacee has arrived. Follow her advice, she will be able to help you quicker than I can with a more aggressive approach. As I tend to take a more cautious approach.



Jacee

Once again looking around ... Windows Update error 80072ee2

techmonkey74

Quote�� Quote: Originally Posted by zarnic View Post

The Anti-(whatever) that I have used, or do, includes Malware Bytes, Norton, Antivira, and McAfee but little has changed. Maybe my problem is not a malware issue but it does seem strange that Windows is the only victum and sites that offer malware products can not usually be accessed.

Do you have Antivira: Remove AntiVira Av (Uninstall Guide) -THIS ONE IS A FAKE AV PROGRAM

OR

Avira

Avira anti-virus for home and for business

EDIT: IF YOU DO HAVE THE FAKE AV WAIT FOR JACEE OR SOMEONE ELSE TO HELP YOU OUT. I AM NOT SURE IF THE LINK I PROVIDED ABOVE IS THE BEST SOLUTION

Anak

Quote�� Quote: Originally Posted by zarnic View Post
Maybe my problem is not a malware issue but it does seem strange that Windows is the only victum and sites that offer malware products can not usually be accessed.
Not maybe, but a definite yes that you are infected.
Your statement contains the two prime examples of malware behaviour especially the last one.

techmonkey that bleepingcomputer link you provided would be a good place to start, and either mbam or SuperAS would work.

The fact that it is suggested there could mean that the antivira malware might not be too hard to eradicate, but zarnic is going to have to make the effort to scan his machine first to make sure it is not infected, otherwise any effort to fix his update problem will be futile.

It would not surprise me that once zarnic cleaned up his machine his update problem would disappear.

zarnic

Jacee posted:
Quote:


Please download Dial-A-Fix from one of the following mirrors:
No good, Jacee... keeps referring to Vista! But thanks for the thought.

I'll try the various suggestions but I have to admit... I'm not very hopeful.

Great forum!!

zarnic

Just as I suspected... still no updates, oh well. Sorry that I waited until today, when you all responded yesterday, but after it being over a year without having this ability waiting one day isn't hard to do. At first I thought it was just an IE browser problem but while using Firefox may have allowed me to visit some pages that I couldn't in IE all Anti-(whatever) and Microsoft downloads still would not happen. It may be that I'll have to purchase a new system, tho that is not a good solution... a bit spendy. There is always coffee. Again, thank you all.

techmonkey74

Please refer to post# 13 above. IF you have Antivira AV, THAT is most likely your problem. If you do not want to try to rid the system of the fake AV program AND you are planning to buy a new system instead why not just reformat and reload Windows on this system?

zarnic

Quote�� Quote: Originally Posted by techmonkey74 View Post
Please refer to post# 13 above. IF you have Antivira AV, THAT is most likely your problem. If you do not want to try to rid the system of the fake AV program AND you are planning to buy a new system instead why not just reformat and reload Windows on this system?
First: I do NOT have Antivira AV and, as far as that goes, my problem occurred before I even heard of Antivira.
Second: I have NO plans on purchasing a new system... the need isn't great enough.

I have used System Restore many times and even Recovery, which puts the s/w back to factory specs and guess what... no change. It appears that someone simply dislikes Microsoft products and doesn't want us to use them.

TCG

So I've been fighting with this same windows update error all day today. I've tried every fix I could find out there for this including ones mentioned in this thread. I removed all AV/AS, toggled off/on firewall, etc.... to no avail. As a last ditch effort I decided to unjoin this system from the domain and then rejoin. Much to my surprise, when the machine is off the domain here, windows update works perfectly. If I join to the domain again, the error repeats itself and I cannot do windows updates again(even from the local Admin account while still joined).

Now I assume that you're not running a domain at home so this kinda doesn't apply to you directly, but what it tells me is that this is related to a group policy setting of some sort that's being pushed to my machine when joined (I'm thinking firewall/defender). So I'd think that your problem is related to your Firewall settings or any settings that an AV/AS might apply similar to a firewall.

I could be wrong here, but I'd scrutinize those items on your computer to the best of your ability, I suspect one of them is blocking updates in some way. Sorry I have not discovered a fix yet, I'll keep at the machine I have here though and post any updates I have on this for you.

techmonkey74

Quote�� Quote: Originally Posted by zarnic View Post

First: I do NOT have Antivira AV and, as far as that goes, my problem occurred before I even heard of Antivira.

Second: I have NO plans on purchasing a new system... the need isn't great enough.
Quote�� Quote: Originally Posted by zarnic View Post
Just as I suspected... still no updates, oh well. Sorry that I waited until today, when you all responded yesterday, but after it being over a year without having this ability waiting one day isn't hard to do. At first I thought it was just an IE browser problem but while using Firefox may have allowed me to visit some pages that I couldn't in IE all Anti-(whatever) and Microsoft downloads still would not happen. It may be that I'll have to purchase a new system, tho that is not a good solution... a bit spendy. There is always coffee. Again, thank you all.
Quote�� Quote: Originally Posted by zarnic View Post

Techmonkey74:
Yes I can see other web sites and some Microsoft, as long as I don't download.

The Anti-(whatever) that I have used, or do, includes Malware Bytes, Norton, Antivira, and McAfee but little has changed. Maybe my problem is not a malware issue but it does seem strange that Windows is the only victum and sites that offer malware products can not usually be accessed.

Anak:
Quote�� Quote: Originally Posted by zarnic View Post
TY techmonkey74, have to agree about the multiple Anti-Virus programs and I stay away from doing that. McAfee was a one time deal and is gone now. As for Antivira, am happy with it and the controversey continues ... we'll see.

Sorry for the confusion Your prior posts were a bit confusing at least to me
I hope you get this worked out

TCG

UPDATE:

It appears I have discovered what the issue was with my problem machine here. Our System Essentials VM was off and our GP pushes windows update settings to use it. Interesting that other machines on the domain aren't showing the same issue but this computer is definitely not doing updates as a result of this. If I turn on the VM, windows update works, if I pause/turn off the VM, update fails.

So what does this mean for the OP? Not quite sure at this point. My issue was surely GP/Domain related so it doesn't really apply to the OP. To throw it out there because I didn't see it posted in this thread, have you tried running the FixIT utility from Microsoft yet? Although it says Vista on it, it is the correct tool for Win7 as well. Check your proxy settings in IE, reset IE to default settings to be sure. Check your hosts file for any entries. Make SURE your computer is clean of infection/malware. Also remove your AV/AS if necessary once you're sure it is clean(you can always reinstall), disable windows firewall and defender and try the update again. At this point that's all I can think of for you to try. If anything else comes to mind I'll surely post it.

Good luck, if you do resolve things please let us know what did it, I'd be very interested to hear the resolution for this.



zarnic

Quote�� Quote: Originally Posted by TCG View Post
"... I'd scrutinize those items on your computer to the best of your ability, I suspect one of them is blocking updates in some way...."
I think your ability far exceeds mine so I 'll be interested in anything you find.

TCG

Zarnic check your profile page, I just sent you a message but I'll post it here for you too....

Quote:
If you have a min, I don't mind taking a look via teamviewer for you. I'll need your teamviewer connection ID and password to connect though. You will be able to see everything I'm doing while I'm connected and are able to end the connection at any time you'd like.

zarnic

Er... teamviewer? Huh?

Jacee

zarnic, Copy and paste these lines in Note pad.

@Echo on
pushd\windows\system32\drivers\etc
attrib -h -s -r hosts
echo 127.0.0.1 localhost>HOSTS
attrib +r +h +s hosts
popd
ipconfig /release
ipconfig /renew
ipconfig /flushdns
netsh winsock reset all
netsh int ip reset all
shutdown -r -t 1
del %0


Save as flush.bat to your desktop. Right click to run as Administrator. Your computer will reboot itself.

Next, download Malwarebytes' Anti-Malware, but before saving to your desktop re-name it to zarnic.exe |MG| Malwarebytes Anti-Malware 1.50.1.1100 Download
* Double-click zarnic/mbam-setup.exe and follow the prompts to install the program.
* At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.

Anak

Quote�� Quote: Originally Posted by TCG View Post
Zarnic check your profile page, I just sent you a message but I'll post it here for you too....

Quote:
If you have a min, I don't mind taking a look via teamviewer for you. I'll need your teamviewer connection ID and password to connect though. You will be able to see everything I'm doing while I'm connected and are able to end the connection at any time you'd like.
Quote�� Quote: Originally Posted by zarnic View Post
Er... teamviewer? Huh?
No worries zarnic, teamviewer is user friendly.

zarnic

The following is in response to the last post by Jacee, anyone else can ignore this if they want.

Step 1.
Quote�� Quote: Originally Posted by Jacee View Post
zarnic, Copy and paste these lines in Note pad. On Desktop SaveAs Flush.bat
Did This.

Step2:
Quote:
Next, download Malwarebytes' Anti-Malware, but before saving to your desktop re-name it to zarnic.exe |MG| Malwarebytes Anti-Malware 1.50.1.1100 Download
Tried but got error msg saying "... could not open the Internet site" so used my copy of Malwarebytes. Looked for update but got error msg "PROGRAM_ERROR_UPDATING (12007,0,WinHttpSendRequest) "
But ran my copy.

Step3:
Quote:
* Double-click zarnic/mbam-setup.exe and follow the prompts to install the program.
* Once the program has loaded, select Perform full scan, then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected.
* When completed, a log will open in Notepad. Please save it to a convenient location. Copy and Paste that log into your next reply.
Ok, here is that log report:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5363
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
4/16/2011 7:41:18 AM
mbam-log-2011-04-16 (07-41-18).txt
Scan type: Full scan (C:\|)
Objects scanned: 277445
Time elapsed: 18 minute(s), 0 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 4
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.166.105) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.161.105) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C975BB2F-86FA-49E7-80D7-90F3971561FB}\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.166.105) Good: () -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{C975BB2F-86FA-49E7-80D7-90F3971561FB}\DhcpNameServer (Trojan.DNSChanger) -> Bad: (93.188.161.105) Good: () -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)

Tried Windows Update again but still no change. Next?

(the attachment relates to my attempt to follow your link to the Malware Bytes site)

Jacee

This IP --> 93.188.166.105 is from Ukraine Promnet Ltd
Not a WA IP#

Download DDS from one of these links:
Mirror 1 Mirror 2 Mirror 3
  • Disable any script blocking protection
  • Double click the dds icon to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt <--- will be minimized in the task tray
  • Save both reports to your desktop.
Include the contents of both logs in your next post.

Anak

Quote�� Quote: Originally Posted by zarnic View Post
The following is in response to the last post by Jacee, anyone else can ignore this if they want.
I do not know about "anyone else", but for me this is reading better than any "suspense novel" I have ever read.

zarnic

Quote�� Quote: Originally Posted by Anak View Post
... I do not know about "anyone else", but for me this is reading better than any "suspense novel" I have ever read.
Anak, glad to be of service but you need to read more suspense novels.

Jacee, who you writing to, or want a log from?

Jacee

Quote:
Jacee, who you writing to, or want a log from?
My post above for the two DDS logs is to you, zarnic



zarnic

Quote�� Quote: Originally Posted by Jacee View Post
My post above for the two DDS logs is to you, zarnic
OH! Okay, will get right on it.

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
This IP --> 93.188.166.105 is from Ukraine Promnet Ltd
Not a WA IP#

Download DDS from one of these links:

Mirror 1 Mirror 2 Mirror 3
  • Disable any script blocking protection
  • Double click the dds icon to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt <--- will be minimized in the task tray
  • Save both reports to your desktop.
Include the contents of both logs in your next post.
Done
Here is DDS.txt :

zarnic

Quote�� Quote: Originally Posted by zarnic View Post
Quote�� Quote: Originally Posted by Jacee View Post
This IP --> 93.188.166.105 is from Ukraine Promnet Ltd
Not a WA IP#

Download DDS from one of these links:


Mirror 1 Mirror 2 Mirror 3
  • Disable any script blocking protection
  • Double click the dds icon to run the tool.
  • When done, DDS will open two (2) logs:
    1. DDS.txt
    2. Attach.txt <--- will be minimized in the task tray
  • Save both reports to your desktop.
Include the contents of both logs in your next post.
Done
Here is DDS.txt :
Opps, forgot one
Here is Attach.txt:

Jacee

You have a few problems! Is Win7 an upgrade from Vista? Did you do a "Clean install"?

Roxio could be causing problems ... (not unheard of )
Take a look at the Attach.txt. Scroll to the ==== Event Viewer Messages From Past Week ========
And see the errors.

I think if this was my computer, I'd do a clean install and not fight the same problems over and over again.

zarnic

Thanks... Hummm, here are asnswers in the order you asked.
1. My Win 7 is not an upgrade but came with the machine. I recently did a 'Recovery' using the Dell OS disk sent to me for that purpose.
2. Doubt that Roxio is the culpert in that the program was purchased long after. Roxio is for burning CDs and DVDs.

I'll review the Attach.txt as you suggested now you go enjoy your weekend, I will too. It's too sunny to be at this machine. Ciao

Jacee

Well, it's still early here and my Husband is going to make dinner (read: fast food) tonight, so please do this...

Download Combofix from any of the links below, and save it to your desktop.<--Important
Link 1
Link 2
Link 3

Click on this link Here to see a list of programs that should be disabled.
The list is not all inclusive. If yours is not listed and you don't know how to disable it, please ask.
If your anti-virus or firewall complains, please allow this script to run as it is not malicious.
Next: Disconnect from the internet. If you are on Cable or DSL, unplug your computer from the modem.
Next: Please disable all onboard security programs (all running with back ground protection) as it may hinder the scanner from working.
This includes Antivirus, Firewall, and any Spyware scanners that run in the background.
  • Double click combofix.exe and follow the prompts.
  • When finished, it will produce a log for you. Post that log and a HiJackthis log in your next reply
Note: Do not mouseclick combofix's window while its running. That may cause it to stall
Please be patient while the scan runs, at times it may appear to stall.
When finished and after reboot (in case it asks to reboot), it should open a log, combofix.txt.
Post this log in your next reply together with a new hijackthislog.
After rebooting ensure your Security applications have been re-enabled.

In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run

***A guide and tutorial on "How to use Combofix" can be found here:
A guide and tutorial on using ComboFix

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Post this log in your next reply together with a new hijackthislog.


In your next reply post:
ComboFix.txt
New HJT log taken after the above scan has run
Ran ComboFix and here is its' log:
(what is HiJackThis no log was created)

Jacee

Navigate to c:\windows\msdownld.tmp <-- and delete this file

Next, from the control panel, click on Action Center. Set Windows to notify you before downloading and installing updates.

If UAC is turned off, turn it back on and set it to medium. Give the computer a day or two to see if you are offered updates, then let me know.

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Navigate to c:\windows\msdownld.tmp <-- and delete this file

Next, from the control panel, click on Action Center. Set Windows to notify you before downloading and installing updates.

If UAC is turned off, turn it back on and set it to medium. Give the computer a day or two to see if you are offered updates, then let me know.
Sorry for the delay, was working outside.

Looked for msdownld.tmp but never found it. Did make that change in the Action Center and had the UAC on and as specified. See ya in a couple days. Enjoy yours, and thanks.

Jacee

okay



zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Give the computer a day or two to see if you are offered updates, then let me know.
That quote was Sunday and today is Wednesday so... I'm back.

Little has changed. Still no
? Windows updates (Error code: 0x800072EE2) or
? Defender updates (still get "the program can't check for definition update. Error found (attempt #1- 0x80072efb, attempt #2- 0x80072ee7, attempt #3- 0x80072efd) A connection with server could not be established" )

One good thing came from these few days - got my lawn mowed.

Jacee

You have a third party program that is interfering with your updates.

error 0x80072efb has to do with ActiveSync (mobile device/smartphone, sync partnership between the storage card and Windows Media Player)

error 0x80072EE7
error 0x80072EFD
You may encounter temporary connection-related errors when you use Windows Update or Microsoft Update to install updates

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
You have a third party program that is interfering with your updates.
OK, what do I do about it?

Jacee

Stop it from running in 'services' or startup (msconfig) .... unplug any USB devices other than your mouse and keyboard.

Temporarily disable Norton and turn Windows firewall on.

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Stop it from running in 'services' or startup (msconfig) .... unplug any USB devices other than your mouse and keyboard.

Temporarily disable Norton and turn Windows firewall on.
OK, I can do all this but I doubt it will make any difference. Why? Because I have had this machine for more than a year, with no USB devices, and have never been able to receive any Windows updates. Norton is gone but it was only a recent trial, and short at that. The Firewall has always been on.

As an aside, I've used most Windows' versions, since Windows 3, and have never expierenced this. Perhaps... just perhaps, it is a OS problem. Or maybe the Explorer... I definitely see an infection in IE8, and redirects (Google is bad for that) and popups are constantly appearing, even though pop-up blocker is used.

Isn't life grand!

Jacee

Did you flush the DNS cache and restore Ms's Hosts file using the batch file I gave you in a previous post?


Download TDSSkiller http://support.kaspersky.com/downloa...tdsskiller.zip and save it to your Desktop.
  • Extract the file and run it.
  • Once completed it will create a log in the root directory (usually C:\).
  • Please post the contents of that log in your next reply.

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Did you flush the DNS cache and restore Ms's Hosts file using the batch file I gave you in a previous post?



Download TDSSkiller http://support.kaspersky.com/downloa...tdsskiller.zip and save it to your Desktop.
  • Extract the file and run it.
  • Once completed it will create a log in the root directory (usually C:\).
  • Please post the contents of that log in your next reply.
Alright, sure hope I'm not wasting your time, Jacee. Log attached.

Jacee

You said you bought the computer with Windows 7 already installed, these two items have me curious
C:\Windows.old
C:\$UPGRADE.~OS

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
You said you bought the computer with Windows 7 already installed, these two items have me curious
C:\Windows.old
C:\$UPGRADE.~OS
My IE8 will no longer allow me to access this Forum, in fact I'm using Firefox (V.4) now to do this. I have a Facebook page (Jacques Levieux), Jacee, if you need to reach me because I don't plan to keep using Firefox.

BTW, the directory \Windows.old was created by the machine when I did a 'Recovery'. I reloaded the OS last month, using a mfg disk, and put everything at factory level. I have no idea about the directory \$UPGRADE.~OS.

Needed to get coffee anyway.

Jacee

No Facebook membership, zarnic.

Have you thought about backing up your data and doing a 'clean install'?



Layback Bear

Try this in the Start/search/ type or paste.
hh Microsoft Corporation: Software, Smartphones, Online, Games, Cloud Computing, IT Business Technology, Downloads Hit Enter.
It should take you to Microsoft site and you can go any where from their.
hh http://www.microsoft.com/ Start/past in search.

Jacee

It could be related to all software/programs for itunes and syncing ... I'm at a loss, but I would try uninstalling all of that nonsense , cleaning all temp files, defragging, shut down, restart normally, and then try Windows updates again.
Totally frustrating to me!!

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Totally frustrating to me!!
I Know how you feel... especially when my IE8 wouldn't allow access to this Forum but Firefox does (so now I use Firefox).

Update
Have since noticed Malwarebytes always finds a Registry error called Trojan: DNS Changer by 93.188.166.105 whenever the Internet is used. Months ago someone else had this trojan and also couldn't get Updates. Even though Malwarebytes cleans up my Registry it always reappears and just may be the culprit behind me never being able to update Windows.

Have a nice Easter!

Jacee

Disable the proxy settings in Internet Explorer:

1) Under �Tools� in the browser tool bar select �Internet Options�.
2) In the �Internet Options� window that pops up, click the �Connections� tab at the top.
3) Click �LAN Settings� near the bottom of the �Connections� section.
4) If the �Proxy server� checkbox is marked with a check, click it to deselect/uncheck it.
5) Click �Ok� to close the �Local Area Network (LAN) Settings� window.
6) Click �Ok� to close the �Internet Options� window.

Reboot. Test whether internet connectivity is restored to IE.

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
4) If the �Proxy server� checkbox is marked with a check, click it to deselect/uncheck it.
No check in checkbox.

I know you saw this DNS before (pg 3) and id'd it as coming from Ukraine Promnet Ltd and
not a WA IP#, Jacee, is there a work-around?

Jacee

Go into programs and features ... uninstall BitTorrent

Next, unhide hidden files and folders. Control panel > Folder Options > View tab. Tick to show hidden files and folds, uncheck hide extensions for known file types.

Now, go to C:\Program Files (x86)\BitTorrent <-- delete this folder
C:\Users\Ron\AppData\Roaming\BitTorrent <-- delete this folder

Reboot.

Download CKScanner by askey127 from HERE
Important - Save it to your desktop.
Doubleclick CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify the file saved.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Go into programs and features ... uninstall BitTorrent
OK, but use it for P2P downloading of torrents so may have to reload the exe.

BTW for your info, that Urkraine company, Promnet Ltd, has the IP address which is 85.255.112.121.

Wet outside, huh!

Jacee

Quote:
BTW for your info, that Urkraine company, Promnet Ltd, has the IP address which is 85.255.112.121.
Yes, I know that ... the IP is a known Domain Hijacker. They have control over your computer.

If you don't want to follow my instructions, then do a clean/custom install, or a repair install.

zarnic

Jacee, did all that you just asked and attached the log. Good luck.

Jacee

Uninstall corel videostudio pro

Delete c:\users\ron\documents\corel videostudio pro <--folder
keygen.rar <--- delete this file.

Reboot.
  • Download http://oldtimer.geekstogo.com/OTL.exe to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
      Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.




zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Uninstall corel videostudio pro

Delete c:\users\ron\documents\corel videostudio pro <--folder
keygen.rar <--- delete this file.
OK, Jacee, have deleted the first file and the folder is gone however I don't have the keygen.rar file.

ran OTL and its' logs are attached ( or I can post the full contents if preferred).

I notice the name SteelWerx and its' SWXCACLS.exe . What is this? Is it a threat?

Jacee

SteelWerx and its' SWXCACLS.exe is okay.

Run OTL
Under the Custom Scans/Fixes box at the bottom, paste in the following

:OTL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 93.188.166.105 93.188.161.105 1.2.3.4
O28 - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - Reg Error: Key error. File not found

:Services

:Reg

:Files
ipconfig /flushdns /c

:Commands
[purity]
[emptytemp]
[Reboot]

Then click the Run Fix button at the top
Let the program run unhindered, reboot the PC when it is done

Copy and paste the log back here.
Also, please post the content of C:\qoobox\ComboFix.txt

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
...
Also, please post the content of C:\qoobox\ComboFix.txt
Good Morning!
- I neither have the quoted directory nor fileto post.
- As for the rest of your instructions, done and attached... next?

Oh, and have a Good Day!

Jacee

The OTL Extras.txt is incomplete .... what did you take out of it?

Layback Bear

I sure I'm waiting for the answer to that question.

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
The OTL Extras.txt is incomplete .... what did you take out of it?
Nothing... want me to run OTL again?

Jacee

I just want to see the entire Extras.txt

zarnic

Jacee, I just noticed that I have two OTL-generated Extra files but different sizes so I'll attach them both and if you want me to run OTL again I will.

Here they are: (those two files should be yr 2011 not 2001)

Jacee

I'd like you to scan your machine with ESET OnlineScan
  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the icon on your desktop.
  4. Check
  5. Click the button.
  6. Accept any security warnings from your browser.
  7. Check
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
  11. Push , and save the file to your desktop using a unique name, such as ESETScan. Include the entire contents of this report in your next reply.
  12. Push the button.
  13. Push

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
I'd like you to scan your machine with ESET OnlineScan ....
Can't access the link with either IE8, Firefox (get the msg "Firefox can't establish a connection to the server at eset.com"), or Google Chrome.

Plan B?



Jacee

Plan B .... Clean install!

zarnic

Quote�� Quote: Originally Posted by Jacee View Post
Plan B .... Clean install!
Well... so much for Plan B. Using a Dell disk, I reloaded the Win 7 OS ( which puts everything to factory level ) got back here... went to that link again, and my IE8 gives me "Internet Explorer cannot display the webpage".

Do you still want the file ComboFix.txt (?)... cus I have a directory, now, labeled Qoobox with that file included.


Perhaps I should first try to fix my IE8. Perhaps I should just forget about windows Updates and go on with my life. The sun is out, perhaps I should just go outside.

Layback Bear

Just a thought. Some how some bad thing is hanging in there. If it was my computer and I went through what all you folks have I would wipe my drive with one of many 3rd party programs like Drive Scrubber at least 4 times Remove anything that is plugged into the computer that you don't need to do a clean install. For sure the printer because some of them have memory. Notice I did not tell you to save anything. Do a clean install with a legal Windows 7 disc. Once everything is working properly check to make sure it's activated with Microsoft. Then don't install all those p2p and torrents ect. They are probably where you got what ever this thing is you got. I don't care what security is on a computer if the owner/operator let those types of things by the security this whole mess starts again. There is more than enough information on the net to keep a person reading for days about the bad things that happen with p2p and torrents.

techmonkey74

Adding to what Layback Bear said could something be hiding on the partition? Like myself Zarnic has a OEM Installed OS and like most OEM OS's the Operation system is on a Partition in my case it's the "D" drive. I did not even get any OS discs with my system HP includes a tool that lets you burn a set of your own. CAN a virus creep on to the partition?

zarnic

Thank You All for your thoughts and suggestions. It may very well be that P2P and torrents are the culprit. However, where I got it really means little, how to get rid of whatever-it-is means more.

Perhaps I misunderstood what is ment by a 'clean' install... isn't a manufacturers' disc, an OEM Win 7 OS disc, considered 'clean'? If not then I need educating.

Jacee has spent a lot of her spare time trying to work this out and to her I owe a lot.

I think that after so many years of being infection-free it is probably fitting that now I'm not. Sort of a payback thing.

zarnic

Reset Router and re-installed.
Malwarebytes updated , finally. Yay!
DNSChanger gone. Yay!
Windows updated, first time in year-and-a-half... yay, Yay!! And on a Monday, too.

Thank You, Jacee... I owe ya!

Jacee

w00t!!

techmonkey74

Just curious for my own education HOW was the router affected?

Jacee

See here! DNSCHANGER
DNSChanger

Layback Bear

The reason for knowing where and how you get something like that is so you can try not going to that site again. Knowing how you get a bad thing is a good thing.



zarnic

So true, LB, but... if I had never had this bad thing I never would have heard from such good people, would have never visited this forum, would have never experienced what I did. Sometimes having a bad thing is a good thing.

Không có nhận xét nào:

Đăng nhận xét