First off Mow, thank you for your help.
My answers are based on the first computer I was dealing with. The guy from the second computer is probably no more a concern of mine. I was originally helping him get the Enterprise version of Office 2007 to install correctly, but he has been evasive in answers
to several important questions (mainly where he got it, key code, ect) and I am beginning to think he has either a cracked copy or or is using some other method to steal the software. I don't steal and I won't help other to steal. I have steered him to a part
of the website I'm helping him at populated by UNITE and ASAP certified malware experts to clean his computer of said malware. I'm still learning malware and am not qualified to clean any computer but my own, but I know enough to look at his logs for the
info I want for evidence of stealing. So do they. If he's stealing, they will get him clean, remove his P2p and send him on his way with his stolen software uninstalled and a warning that they will NOT help him get rid of malware if he comes back with his
P2P software theft program on his computer.
Did you go over the CheckSUR.log and CheckSUR.persist.log of the Vista system after running the System Update Readiness Tool [CheckSUR]? They're located in WINDOWS\Logs\CBS The SUR tool did not install with a message it was not needed so I assume it left no CheckSur.log or persist.log. If I am wrong, let me know and I will go to my friends house and take a look at it. If so what am I looking for?Are both systems running Vista ?
yes, 32 bit.
What is the installed antivirus/security suite on these systems ?
The first computer had that 90 trial version of Norton Security 2008 that Acer bundles along with other assorted crapware on their machines. By the time I got to the machine, it had long expired and the definition data base was out dated. I removed it with
the Norton Removal Tool (NRT). I had to use it twice and didn't get the last bits off until we nuked them with ComboFix. After the computer was clean I installed Avast! (free edition), Spybot, SAS, Winpatrol and MBRAM. All were disabled during any attempts
to fix the 80072efd problem.
**Is a 3rd party firewall used or the native Vista firewall ?**As I stated above **** he originally had Norton on but I removed it now it is the native Vista firewall. We disabled it, updated it removed it, re installed it, checked the oil and rotated the tires on it. Seriously, I can't remember all
the steps I took on the MS firewall, but I can go back to the threads I requested help on and check if you need to know. I remember we changed the values so it wouldn't start (using Combofix) and I had to go to a KB (I forget which one but again I can find
out) to reset the firewall and get it working again.
Have you tried Clean booting the systems and then run the Fixit to rule out interference by 3rd party software ?
It never occured to me to do so as I had the anti malware, AV and firewall turned off. I didn't think more than briefly in terms of other programs. The update history showed the specific date ( around May 17th I believe) when it quit working. I had set it for
him to automatic when I set his computer up for him. On checking the OTList It log I was able to see what folders and files were changed/added between the time of his last successful update and his first unsuccessful one. I think that all that was there was
the adware/spyware (the spyware they ad to that stupid coupon download crapware) and the accompanying browser jacker that I had removed iTunes software. Are there known issues with iTunes software? I googled but didn't see anything.
For the purportedly infected system, you can get no-charge assistance from MS for the installation issue of SP2 or,contact MS for no-charge assistance in getting the system cleaned up.
Is that the the Onecare site? I actually did go there on his computer and did the download and the free scan. I was a bit put off by the bait and switch type tactics used with the "you have 6 million problems"
yet they would never list them for me. Besides, and I say this with no criticism intended and it is probably as irrational a bias as my dislike of Auborn University (Go Dawgs) but...........
I have a hard time having faith in the removal of malware by the same company that wrote the code that contained the original vulnerabilities. I feel that sometimes a big corporation is exposed to so much (and often frivolous) liability that they will often
spend more time trying to dodge "blame" than in finding a solution. I know, it's silly, but isn't any irrational bias?
Anyways, thank you again for your help and I look forward to the answers to my questions.