Author Topic: Vista Antimalware 2010 help?  (Read 4391 times)

0 Members and 1 Guest are viewing this topic.

MyHatBarks

  • Guest
Vista Antimalware 2010 help?
« on: March 27, 2010, 09:11:36 PM »
So I've been trying to get rid of this whatever-it-is for the past three days with no luck. I've run Malwarebytes, Avast, Spybot S&D and tried to run a fix in OTL. I have run all of them in safe mode with them ending up being clear. Only to try and restart in regular mode and have Vista Antimalware start up again. I run the rkill.exe, so it shuts down. I try to run the antivirus/malware programs and they always find things the next time. OTL gives me a Range Check error when I try to run a fix found on another website. Then I ran a scan with OTL and I'll paste the log in the next post, as it said this post was too long.


I'm stuck in the same situation. I run all the programs in safemode, things show up clear, I restart in regular mode and the whole thing starts over again. I keep getting popups for different antivirus programs and random .exe's keep saying they need to shut down. Any ideas or help would be so much appreciated. I know there's another thread floating around on this forum, but I've tried most of the stuff in there with no luck.

MyHatBarks

  • Guest
Re: Vista Antimalware 2010 help?
« Reply #1 on: March 27, 2010, 09:12:12 PM »
Log from OTL:

All processes killed
Error: Unable to interpret <helper32.dll /lsp> in the current context!
Error: Unable to interpret <winhelper86.dll /lsp> in the current context!
Error: Unable to interpret <%HOMEDRIVE%\Internet Security 2010.lnk /s> in the current context!
Error: Unable to interpret <%systemroot%\System32\winlogon32.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\smss32.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\AVR10.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\helper32.dll> in the current context!
Error: Unable to interpret <%systemroot%\System32\winlogon32.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\smss32.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\warning.html> in the current context!
Error: Unable to interpret <%systemroot%\system32\IS15.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\winhelper86.dll> in the current context!
Error: Unable to interpret <%HOMEDRIVE%\trhh.exe> in the current context!
Error: Unable to interpret <%HOMEDRIVE%\sdigdvmg.exe> in the current context!
Error: Unable to interpret <%HOMEDRIVE%\wgqi.exe> in the current context!
Error: Unable to interpret <%HOMEDRIVE%\byyk.exe> in the current context!
Error: Unable to interpret <%systemroot%\lsass.exe > in the current context!
Error: Unable to interpret <%systemroot%\odbn0.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\sdra64.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\41.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\153.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\292.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\491.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\1869.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\2876.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\2995.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\3902.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\4827.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\5436.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\5447.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\5705.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\6334.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\7376.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\9961.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\11478.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\11538.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\11942.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\12382.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\12662.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\13931.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\14070.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\14604.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\14771.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\15724.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\16827.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\16944.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\17125.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\17421.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\18467.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\18716.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\19169.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\19718.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\19895.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\19905.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\19912.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\21386.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\21726.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\22934.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\23281.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\24242.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\24464.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\24478.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\26308.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\26500.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\26962.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\27213.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\28145.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\28466.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\29358.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\32391.exe> in the current context!
Error: Unable to interpret <%systemroot%\System32\32439.exe> in the current context!
Error: Unable to interpret <%systemroot%\system32\ndisdrv.sys> in the current context!
Error: Unable to interpret <%HOMEDRIVE%\s> in the current context!
Error: Unable to interpret <%systemroot%\system32\kbdsock.dll> in the current context!
Error: Unable to interpret <%systemroot%\system32\mshlps.dll > in the current context!
Error: Unable to interpret <%systemroot%\system32\drivers\kdrhkukb.sys > in the current context!
Error: Unable to interpret <%PROGRAMFILES%\InternetSecurity2010> in the current context!
Error: Unable to interpret <%systemroot%\System32\lowsec> in the current context!
========== SERVICES/DRIVERS ==========
Error: No service named lmuytnv was found to stop!
Service\Driver key lmuytnv not found.
Error: No service named ndisdrv was found to stop!
Service\Driver key ndisdrv not found.
Error: No service named qvazdxe was found to stop!
Service\Driver key qvazdxe not found.
========== COMMANDS ==========
OTL cannot create restorepoints on Vista OSs!
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
HOSTS file reset successfully
 
[EMPTYTEMP]
 
User: All Users
 
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Meaghan
->Temp folder emptied: 31832 bytes
->Temporary Internet Files folder emptied: 116237 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 5372183 bytes
->Google Chrome cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
 
User: Public
 
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 2813396 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 0 bytes
 
Total Files Cleaned = 8.00 mb
 
 
OTL by OldTimer - Version 3.1.37.3 log created on 03272010_123732

Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
C:\Users\Meaghan\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZS1GMMZ9\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\SSQIOFV2\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ODNHZWCA\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\GUCM6Y34\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\desktop.ini scheduled to be moved on reboot.
File move failed. C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\desktop.ini scheduled to be moved on reboot.

Registry entries deleted on Reboot...

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog

MyHatBarks

  • Guest
Re: Vista Antimalware 2010 help?
« Reply #3 on: March 28, 2010, 03:41:52 AM »
So I went through that website and tried every solution on there. I've been running Malwarebytes for past few hours or so to get everything out. It asks me to restart to finish deleting some of the bad stuff it got. I do that, and everything comes back, again. This time it also starts pulling up my start bar and acting like someone's holding down spacebar. Even when I open up firefox, it acted like the spacebar was being held down. It stopped once the "antivirus" loaded though. Go figure.

 ??? I'm so very frustrated...any other advise?


** Forgot to add the random sound bites from pop-ups that just randomly play when no ads are open.
« Last Edit: March 28, 2010, 03:44:31 AM by MyHatBarks »

MyHatBarks

  • Guest
Re: Vista Antimalware 2010 help?
« Reply #4 on: March 28, 2010, 03:55:51 AM »
I ran Avast! but it found no threats. I looked into it and my program was out of date and the registration had expired. Oh good. So I am trying Avira AntiVir right now. I just did a scan and it said it removed about 30 items. But the splash screen for the vista antimalware program is still there and the random pop up ads (that can't be seen, just heard) still play. There's a program Avira is trying to block but it says it doesn't have access. I guess back to trying Malwarebytes again?

syngi99

  • Guest
Re: Vista Antimalware 2010 help?
« Reply #5 on: March 29, 2010, 11:49:33 AM »

Offline FreewheelinFrank

  • Avast Evangelist
  • Ultra Poster
  • ***
  • Posts: 4872
  • I'm a GNU
    • Don't Surf in the Nude!
Re: Vista Antimalware 2010 help?
« Reply #6 on: March 29, 2010, 12:12:49 PM »
Can you post the log from MalwareBytes?
     Bambleweeny 57 sub-meson brain     Don't Surf in the Nude Blog