From: Robert Aldwinckle on


"Bruce Parent" <BruceParent(a)discussions.microsoft.com> wrote in message
news:EE0D1516-678B-4C2E-A915-9614E3A68CA9(a)microsoft.com...
> I tried to use windows updates to check if there were any additional
> updates
> after I had applied the Apr 2010 updates ending with KB980302 and after a
> reboot. Every time that I do this

> I receive a message Windows could not search for new updates with error
> code 80070005.


My approach to that symptom is to run ProcMon to supplement whatever other
diagnostics you are getting. Typically it can uncover a permissions
problem.


Good luck

Robert Aldwinckle
---


> Biographical: I am a retired
> networking tech and a mainframe systems programmer. I have auto updates
> turned off because I like to do it myself. I applied the updates after
> returning from a week's vacation.
> --
> Bruce Parent

From: MowGreen on
Bruce Parent wrote:

> and ran avast scan (deleted 3 viruses and then reboot

Time Out !!! * Which 3 viruses* were detected and do you have any idea
how they were able to get onto your system ?
This is not a trivial matter, Bruce and would explain why the system can
no longer update. The Kernel update may have exposed hidden malware. May
have, not definitively did expose.

Strongly suggest that you download a copy of Malwarebytes anti-malware
(MBAM), install and update it, and then run a Quick scan (it's Default
scan option)- http://www.malwarebytes.org/

Click the Download free version button.
Please post the names of the 3 detected viruses and if anything was
detected by MBAM scan.

Since you state Trend was never present in the clean install of Vista
then there's no sense in running AppRemover.

> I have only one userid: bapa... which is administrator (unless vista gets its
> own ideas) the os is vista home premium so ms fixit to reset security
> settings has some risks. I will back up files same as prior to rebuild or win
> 7 upgrade before attempting this. I have much mail in windows mail. Unless I
> can save the mail file (location ?) I would lose any mail I did not save as a
> text file. Any advice?

Let's hold off on any Perms changes until we find out what's up with the
malware. And, upgrading with a possibly infected OS is never a sound
practice.
Can't you export the emails in Windows Mail as one would with Outlook
Express ... File > Export > Messages ?


MowGreen
================
*-343-* FDNY
Never Forgotten
================

banthecheck.com
"Security updates should *never* have *non-security content* prechecked
From: Bruce Parent on
I attempted windows update from brueggers bagels with no success.
I ran malwarebytes 3 registry
rogue antivirus suite registry key hkey current user software avsuite
rogue antivirus suite.gen registry value hkey current user software
microsoft current version run jxfuvxik value jxfuvxik
trojan fraudpak registry key hkey current user software avsoft
all of these may have occured last night. I noticed a fake antivirus and
quickly closed the window but may have been too late
removed middle item 1 & 3 might be avast
I deleted the 3 earlier viruses from the avast virus chesst so no names left

I see file export messages - thanks

I will not run system without windows update
I built servers installings windows os's
I consider my system a "data server"
I don't like restrictions of windows HOME premium
I am willing to upgrade to windows 7 something (which?? cost is issue)
upgrade issues through dec 09 I am used to 2 - 4 reboots during build
I want 3+ logical drives on 1 physical drive os - data - linux? - ??
I back up data drive - lax on backups of C drive
would I have to upgrade to vista sp 2 (I have early vista disk)
could I just build windows 7 directly from upgrade package

i have good speed and memory duo t7500 2.2 ghz 4gb mem 32bit os
--
Bruce Parent


"MowGreen" wrote:

> Bruce Parent wrote:
>
> > and ran avast scan (deleted 3 viruses and then reboot
>
> Time Out !!! * Which 3 viruses* were detected and do you have any idea
> how they were able to get onto your system ?
> This is not a trivial matter, Bruce and would explain why the system can
> no longer update. The Kernel update may have exposed hidden malware. May
> have, not definitively did expose.
>
> Strongly suggest that you download a copy of Malwarebytes anti-malware
> (MBAM), install and update it, and then run a Quick scan (it's Default
> scan option)- http://www.malwarebytes.org/
>
> Click the Download free version button.
> Please post the names of the 3 detected viruses and if anything was
> detected by MBAM scan.
>
> Since you state Trend was never present in the clean install of Vista
> then there's no sense in running AppRemover.
>
> > I have only one userid: bapa... which is administrator (unless vista gets its
> > own ideas) the os is vista home premium so ms fixit to reset security
> > settings has some risks. I will back up files same as prior to rebuild or win
> > 7 upgrade before attempting this. I have much mail in windows mail. Unless I
> > can save the mail file (location ?) I would lose any mail I did not save as a
> > text file. Any advice?
>
> Let's hold off on any Perms changes until we find out what's up with the
> malware. And, upgrading with a possibly infected OS is never a sound
> practice.
> Can't you export the emails in Windows Mail as one would with Outlook
> Express ... File > Export > Messages ?
>
>
> MowGreen
> ================
> *-343-* FDNY
> Never Forgotten
> ================
>
> banthecheck.com
> "Security updates should *never* have *non-security content* prechecked
> .
>
From: MowGreen on
Comments inline:

Bruce Parent wrote:
> I attempted windows update from brueggers bagels with no success.
> I ran malwarebytes 3 registry
> rogue antivirus suite registry key hkey current user software avsuite
> rogue antivirus suite.gen registry value hkey current user software
> microsoft current version run jxfuvxik value jxfuvxik
> trojan fraudpak registry key hkey current user software avsoft
> all of these may have occured last night. I noticed a fake antivirus and
> quickly closed the window but may have been too late
> removed middle item 1& 3 might be avast
> I deleted the 3 earlier viruses from the avast virus chesst so no names left

So, I assume that MBAM does not detect anymore items after removing the
items that Avast quarantined, correct ?

Using Internet Explore, suggest you have the system scanned by the
OneCare Online Safety scanner as it sometimes resolves updating
Permissions issues:
http://onecare.live.com/site/en-us/center/howsafe.htm


> I see file export messages - thanks

YW.


> I will not run system without windows update
> I built servers installings windows os's
> I consider my system a "data server"
> I don't like restrictions of windows HOME premium

Have you disabled User Account Control (UAC) ?

BTW, you *can* enable the built in Admin account and use that account to
configure the system as *you* see fit. However, using it for day to day
use is *not* recommended as it drastically lowers the native Security of
Vista.
Suggest you create a Standard User account and, if you so desire, I'll
give you instructions on how to enable the hidden, built in Admin
account so that you can configure the system as you see fit, not MS.

The steps for creating a a Standard User account in Vista are
essentially the same as for Windows 7-

http://unixwiz.net/techtips/win7-limited-user.html


> I am willing to upgrade to windows 7 something (which?? cost is issue)
> upgrade issues through dec 09 I am used to 2 - 4 reboots during build
> I want 3+ logical drives on 1 physical drive os - data - linux? - ??
> I back up data drive - lax on backups of C drive
> would I have to upgrade to vista sp 2 (I have early vista disk)
> could I just build windows 7 directly from upgrade package
>
> i have good speed and memory duo t7500 2.2 ghz 4gb mem 32bit os
> -- Bruce Parent

Let's hold off on any Win 7 discussion until we can determine, as best
as possible, that the system is free of malware.


MowGreen
================
*-343-* FDNY
Never Forgotten
================

banthecheck.com
"Security updates should *never* have *non-security content* prechecked
From: Bruce Parent on
1. I found upgrade to avast 5.0 occured just after 3/15 mar windows updates.
So I agree that this points to avast as the culprit. I opened ticket: avast
causes error 80070005 in windows update (cmt-252920) if you wish to view it.
I see you have found other avast 80070005 errors in the past.

2. I am impressed with the tools you have had me use (I hope these pages
stay available after I am fixed so I can make them available to me) are there
other tools available that unknowledgable users such as me can safely use to
protect their systems?

3. I reran malwarebytes and only found the 2 avast (?) entries. I ran
onecare but still cannot search windows updates (I did have to convince email
I knew my password)

4. I may still wish to be windows 7 something if no problems since december.
Especially if I have to rebuild. I had 3 userids on original vista. non admin
pain if I wish to install software like readerworks. I have many clever
passord schemes. rembering which clever password after 6 months of non-use
became an issue. I went back to one id before I had to rebuild last time. UAC
is on.
I will be unavailable on Tuesday. I will be waiting awhile for possible
avast solution.

--
Bruce Parent


"MowGreen" wrote:

> Comments inline:
>
> Bruce Parent wrote:
> > I attempted windows update from brueggers bagels with no success.
> > I ran malwarebytes 3 registry
> > rogue antivirus suite registry key hkey current user software avsuite
> > rogue antivirus suite.gen registry value hkey current user software
> > microsoft current version run jxfuvxik value jxfuvxik
> > trojan fraudpak registry key hkey current user software avsoft
> > all of these may have occured last night. I noticed a fake antivirus and
> > quickly closed the window but may have been too late
> > removed middle item 1& 3 might be avast
> > I deleted the 3 earlier viruses from the avast virus chesst so no names left
>
> So, I assume that MBAM does not detect anymore items after removing the
> items that Avast quarantined, correct ?
>
> Using Internet Explore, suggest you have the system scanned by the
> OneCare Online Safety scanner as it sometimes resolves updating
> Permissions issues:
> http://onecare.live.com/site/en-us/center/howsafe.htm
>
>
> > I see file export messages - thanks
>
> YW.
>
>
> > I will not run system without windows update
> > I built servers installings windows os's
> > I consider my system a "data server"
> > I don't like restrictions of windows HOME premium
>
> Have you disabled User Account Control (UAC) ?
>
> BTW, you *can* enable the built in Admin account and use that account to
> configure the system as *you* see fit. However, using it for day to day
> use is *not* recommended as it drastically lowers the native Security of
> Vista.
> Suggest you create a Standard User account and, if you so desire, I'll
> give you instructions on how to enable the hidden, built in Admin
> account so that you can configure the system as you see fit, not MS.
>
> The steps for creating a a Standard User account in Vista are
> essentially the same as for Windows 7-
>
> http://unixwiz.net/techtips/win7-limited-user.html
>
>
> > I am willing to upgrade to windows 7 something (which?? cost is issue)
> > upgrade issues through dec 09 I am used to 2 - 4 reboots during build
> > I want 3+ logical drives on 1 physical drive os - data - linux? - ??
> > I back up data drive - lax on backups of C drive
> > would I have to upgrade to vista sp 2 (I have early vista disk)
> > could I just build windows 7 directly from upgrade package
> >
> > i have good speed and memory duo t7500 2.2 ghz 4gb mem 32bit os
> > -- Bruce Parent
>
> Let's hold off on any Win 7 discussion until we can determine, as best
> as possible, that the system is free of malware.
>
>
> MowGreen
> ================
> *-343-* FDNY
> Never Forgotten
> ================
>
> banthecheck.com
> "Security updates should *never* have *non-security content* prechecked
> .
>