This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Closed] www.mcafee.com responds with "The specified method

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here is the scenario: - Kid's computer - they go where they go. - Windows XP Pro - was running SP1 when infected - now is SP3 - Had McAfee AV installed. - Kids reported that web pages in Firefox were being redirected to advertisements. I checked this and found it true. - Attempts to open Command Prompt from Start menu causes explorer.exe to crash and restart. - If I right click on Command Prompt, choose Run As and start it as the currwent user, it opens fine. - Tried to reinstall McAfee without success. - Did a Windows OS repair. Succeeded, but Windows Genuine Advantage processes were running at 100%. - Removed at WGA refwerences in registry and system at least now is responsive. - Most web pages now work. - Attempt to reach www.McAfee.com in Firefox gets reply "The specified method is not supported" - Attempt to reinstall McAfee gets a window that says reboot required before installing McAfee products. - No number of reboots resolves this. - Ran McAfee uninstaller, rebooted and still same results. Today, came to this site: - Ran ATF Cleaner and removed everything but cookies (I will if I have to.) - Ran Malwarebytes' Anti-Malware quick scan. It found and removed several items, but still cannot access www.mcafee.com or install McAfee AV. - Command Prompt also still fails and succeeds as described above. Malwarebytes' Anti-Malware log follows. Thanks in advance, Bill F. Malwarebytes' Anti-Malware 1.36 Database version: 2162 Windows 5.1.2600 Service Pack 3 5/24/2009 1:14:48 PM mbam-log-2009-05-24 (13-14-48).txt Scan type: Quick Scan Objects scanned: 108450 Time elapsed: 32 minute(s), 36 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 10 Registry Values Infected: 5 Registry Data Items Infected: 3 Folders Infected: 1 Files Infected: 5 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0036a69 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\__c0056840 (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\instkey (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Track System (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\cs41275 (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bf (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\bk (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\iu (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Settings\mu (Trojan.Agent) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\sdra64.exe,) Good: (userinit.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\WINDOWS\system32\lowsec (Stolen.Data) -> Quarantined and deleted successfully. Files Infected: C:\WINDOWS\bdwu.oqx (Trojan.Gumblar) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lowsec\local.ds (Stolen.Data) -> Quarantined and deleted successfully. C:\WINDOWS\system32\lowsec\user.ds (Stolen.Data) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Microsoft\bits.dll (Trojan.Agent) -> Quarantined and deleted successfully. C:\Documents and Settings\All Users\Application Data\Microsoft\ipdll.dll (Trojan.Agent) -> Quarantined and deleted successfully.
All right, sorry, competitor's product. I will look elsewhere. Somebody could have mentioned this so I did not wait for an answer all day. Please close this thread. Bill F.
I would love some help. On my own, I have managed to get the McAfee AV and anti-spam enterprise tools reinstalled via sneakernet and run a full scan. I still cannot get to www.mcafee.com. What do I do next? Thanks in advance, Bill F.
Download Combofix from any of the links below. You must rename it before saving it. Save it to your desktop.

Link 1
Link 2

[external image: Posted Image]


[external image: Posted Image]
——————————————————————–

Double click on Combo-Fix.exe & follow the prompts.
  • When finished, it will produce a report for you.
  • Please post the C:\ComboFix.txt along with a HijackThis log so we can continue cleaning the system.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI