Another victim of the Network Shield/Malicious Malware warning

I am new to this forum so bear with me, but I have been having similar problems to what was posted earleir, but from viewing different threads in the forums I understand that it is best to start a new thread rather than hop on an existing one because of the uniqueness of each person’s computer and system. I will say that recently I have been bombarded by the network shield pop ups coming up from avast. I have run avast, but it isn’t coming up with anything and now the problem seems to have worsened, I no longer have access to my homepage (which is set to my iGoogle page) and my automatic updates for windows has shut down and can’t be restarted, even though it says it is set to be on in the Control Panel. Any assistance you could offer would be greatly appreciated.

You would be wanting to start by following this guide>>http://forum.avast.com/index.php?topic=53253.msg451454#msg451454

Post the logs as attachments back here.

I believe I am supposed to submit these with my query.

And here is the mbam log

Malwarebytes’ Anti-Malware 1.51.1.1800
www.malwarebytes.org

Database version: 7482

Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702

8/16/2011 11:52:09 PM
mbam-log-2011-08-16 (23-52-09).txt

Scan type: Quick scan
Objects scanned: 168553
Time elapsed: 17 minute(s), 3 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

Ok, now you just wait for essexboy to review them. Hes here most days afternoon/evening, UK time.

Thanks for the tips, I also got the aswMBR log which I think I also needed.

The aswMBR log appears to be clear, default MBR and no unknown items reported.

Disk 0 Windows XP default MBR code

I take it that none of the entry lines in your aswMBR display window were coloured, Red or Yellow ?

No, I don’t recall anything being colored red or yellow after the scan.

OK, that is in itself good, given the rest basically says the MBR hasn’t been modified. Unfortunately it will be a few hours before essexboy will be on-line, 4:05pm in the UK right now.

Not a problem, I am at work right now anyway, just messaging between tasks as I get a chance to check for updates to the thread.

Hi there as this fix is quite large I will attach it as a text file at the end

On completion of this run could you check for alerts and let me know what problems remain

Download the text file to your desktop

Run OTL

[*]Then click the Run Fix button at the top
[*]OTL will then ask for the location of the fix, direct it to the fix.txt you have downloaded to your desktop
[*]Once the file is selected press run Fix again
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

First off thank you for taking the time to address my problem. I applied the fix and rebooted nd the first positive sign was that my homepage actually appeared. I also have the OTL file you requested after the running the quick scan.

The only problem I still see is that the automatic updates from Windows still will not turn on. The shield in the task bar is red and if you click on it tells you to access it through the Control Panel. The System tab there will let you change the settings, but they do not apply and visits to the Microsoft update site come up with Error number: 0x80070424. Other than that though everything seems to be running fine at this point.

Could you run the fixit on this page please and let me know the result http://support.microsoft.com/kb/968002 plus any other problems that are apparent

I ran the Fixit from the Microsoft but the issue and error message remain the same. It still will not turn on automatic updates and trying to download them from the Microsoft site, the same error message remains.

Download bitsadmin.exe to your desktop
Run the programmme and reboot on completion

Then dowload the dial-a-fix zip file and extract then run the programme

Select WU/WUAU fix windows update

Downloaded bitsadmin and got an error message when I went to run it (bitsadmin.exe is not a valid Win32 application).

OK mayhap I missed something - lets check

Download and Install CombofixDownload ComboFix from one of the following locations:

Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop *

IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

As far as I can tell, everything seems to be running okay. Combofix addressed the issue with automatic updates, after a reboot after the Combofix scan the updates are now on and running. Here is a log of what Combofix did.

Let it run for a day and if there are still no problems I will remove my tools and tidy you up