Results 1 to 10 of 41

Thread: I can't update windows. I may have an infection.

Hybrid View

Previous Post Previous Post   Next Post Next Post
  1. #1
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Did you allow it to quarantine what it found?


    How's the computer now?


    What we can do now is run an online scan with Eset, for the time being it is our most trusted scanner.
    Most reliable and thorough.
    The settings I suggest will show us items located in quarantine folders so don't be alarmed with this, also, in case of a false positive I ask that you not allow it to delete what it does find.
    This scanner can take quite a bit of time to run, depending of course how full your computer is.


    Go here to run an online scannner from ESET. Windows Vista/Windows 7/Windows 8 users will need to right click on their Internet Explorer shortcut, and select Run as Administrator
    • Note:
      For browsers other than Internet Explorer, you will be prompted to download and install esetsmartinstaller_enu.exe. Click on the link and save the file to a convenient location. Double click on it to install and a new window will open. Follow the prompts.
    • Turn off the real time scanner of any existing antivirus program while performing the online scan. Here's how.
    • Click the blue Run ESET Online Scanner button
    • Tick the box next to YES, I accept the Terms of Use.
    • Click Start
    • When asked, allow the program to install the "OnlineScanner.cab" activex control by clicking the Install button
    • Once the activex control is installed, on the next screen click on Enable detection of potentially unwanted applications
    • Click on Advanced Settings
    • Make sure that the option Remove found threats is unticked.
    • Ensure these options are ticked
      • Scan archives
      • Scan for potentially unsafe applications
      • Enable Anti-Stealth technology

    • Click Start
    • Wait for the scan to finish
    • When the scan is done, if it shows a screen that says "Threats found!", then click "List of found threats", and then click "Export to text file..."
    • Save that text file on your desktop. Copy and paste the contents of that log as a reply to this topic.
    • Close the ESET online scan.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  2. #2
    Member
    Join Date
    Jun 2008
    Location
    UK
    Posts
    68

    Default

    ESET SCAN RESULTS

    C:\AdwCleaner\Quarantine\C\Windows\System32\drivers\{8ce1c375-1e13-43f7-a4fd-6530f47c4fde}Gw64.sys.vir a variant of Win64/BrowseFox.J potentially unwanted application
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\12\3f6d7f0c-41f1ebcb multiple threats
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\17\14287991-5af0df3f multiple threats
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\25\372af719-1e113e30 multiple threats
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\WINDOWSold\Downloaded Installations\{610AA503-16B3-4D15-87DF-8E6B91402299}\PC MightyMax v9.msi a variant of Win32/Adware.PCMightyMax.A application
    C:\Users\Crosshair\Downloads\spsetup117.exe Win32/Bundled.Toolbar.Google.E potentially unsafe application
    F:\Games\LFS\lfs_s2z_keyfilegen.exe a variant of Win32/Keygen.BQ potentially unsafe application
    F:\Games\LFS\download\lfs_s2z_keyfilegen.exe a variant of Win32/Keygen.BQ potentially unsafe application
    F:\Program Files\Cute PDF\CuteWriter.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application
    F:\Program Files\Cute PDF\CuteWriter.zip a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application

  3. #3
    Member
    Join Date
    Jun 2008
    Location
    UK
    Posts
    68

    Default

    I deleted the last four items:

    F:\Games\LFS\lfs_s2z_keyfilegen.exe a variant of Win32/Keygen.BQ potentially unsafe application
    F:\Games\LFS\download\lfs_s2z_keyfilegen.exe a variant of Win32/Keygen.BQ potentially unsafe application
    F:\Program Files\Cute PDF\CuteWriter.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application
    F:\Program Files\Cute PDF\CuteWriter.zip a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application

    Is this OK?

  4. #4
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    Quote Originally Posted by sufferinginsilence View Post
    I deleted the last four items:

    F:\Games\LFS\lfs_s2z_keyfilegen.exe a variant of Win32/Keygen.BQ potentially unsafe application
    F:\Games\LFS\download\lfs_s2z_keyfilegen.exe a variant of Win32/Keygen.BQ potentially unsafe application
    F:\Program Files\Cute PDF\CuteWriter.exe a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application
    F:\Program Files\Cute PDF\CuteWriter.zip a variant of Win32/Bundled.Toolbar.Ask.D potentially unsafe application

    Is this OK?
    Be fine

    Torrents and cracks always come bundled with things behind the scenes that can render a computer useless.

    Open notepad. Please copy the contents of the quote box below. To do this highlight the contents of the box and right click on it and select copy.
    Paste this into the open notepad. save it to the Desktop as fixlist.txt
    NOTE. It's important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
    It needs to be saved Next to the "Farbar Recovery Scan Tool" (If asked to overwrite existing one please allow)

    start
    CloseProcesses:
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\12\3f6d7f0c-41f1ebcb
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\17\14287991-5af0df3f
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\25\372af719-1e113e30
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\WINDOWSold\Downloaded Installations\{610AA503-16B3-4D15-87DF-8E6B91402299}\PC MightyMax v9.msi
    C:\Users\Crosshair\Downloads\spsetup117.exe
    EmptyTemp:
    End
    Open FRST/FRST64 and press the Fix button just once and wait.
    If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run.
    When finished FRST will generate a log on the Desktop (Fixlog.txt). Please post it to your reply.


    How's the computer now?
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  5. #5
    Member
    Join Date
    Jun 2008
    Location
    UK
    Posts
    68

    Default

    After my last reply, Windows closed down and automatically downloaded the update. When it rebooted the update installation failled.



    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-10-2014 02
    Ran by Crosshair at 2014-10-13 09:37:46 Run:3
    Running from C:\Users\Crosshair\Desktop
    Loaded Profile: Crosshair (Available profiles: Crosshair)
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    start
    CloseProcesses:
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\12\3f6d7f0c-41f1ebcb
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\17\14287991-5af0df3f
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\25\372af719-1e113e30
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\WINDOWSold\Downloaded Installations\{610AA503-16B3-4D15-87DF-8E6B91402299}\PC MightyMax v9.msi
    C:\Users\Crosshair\Downloads\spsetup117.exe
    EmptyTemp:
    End
    *****************

    Processes closed successfully.
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\12\3f6d7f0c-41f1ebcb => Moved successfully.
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\17\14287991-5af0df3f => Moved successfully.
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\Documents and Settings\Brian.old\Application Data\Sun\Java\Deployment\cache\6.0\25\372af719-1e113e30 => Moved successfully.
    C:\MaxtorExtHD\Siemens Scaleo\copy of C Drive\WINDOWSold\Downloaded Installations\{610AA503-16B3-4D15-87DF-8E6B91402299}\PC MightyMax v9.msi => Moved successfully.
    C:\Users\Crosshair\Downloads\spsetup117.exe => Moved successfully.
    EmptyTemp: => Removed 60.1 MB temporary data.


    The system needed a reboot.

    ==== End of Fixlog ====



    Computer seems to reboot quicker than before.

  6. #6
    Security Expert-emeritus Juliet's Avatar
    Join Date
    Feb 2007
    Location
    Deep South
    Posts
    4,084

    Default

    After my last reply, Windows closed down and automatically downloaded the update. When it rebooted the update installation failled.
    Which update?, windows update?

    Computer seems to reboot quicker than before.
    Good deal. I need to know what issues remain.
    Windows Insider MVP Consumer Security 2009 - 2017
    Please do not PM me for Malware help, we all benefit from posting on the open board.

  7. #7
    Member
    Join Date
    Jun 2008
    Location
    UK
    Posts
    68

    Default

    Yes, the windows update. It failled.

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •