Jump to content

unable to connect to update server 3.0.6.1469-10103


Recommended Posts

Just renewed got a key, installed 3.0.6.1469-10103 and it wont update, Sometimes it even disconnects the network, Checked hosts. One entry 127.0.0.1       localhost

Couldn't see any rules in the firewall setup with XP sp3. Only a list of programs. Added malwarebytes to the list but still no luck. Attached are the 3 logs

mbamlogs.zip

Link to post
Share on other sites

  • Replies 58
  • Created
  • Last Reply

Top Posters In This Topic

WITH CHROME AND FIREFOX I got:

This site can’t be reached

sirius.malwarebytes.com’s server DNS address could not be found.

DNS_PROBE_FINISHED_NXDOMAIN

 I deactivated the license and it seemed to update but now it won't. Even after clicking deactivate it still says premium. I don't think it deactivated.

I watch the network status for packets received. When I click deactivate or update I get a few packets and after a delay a few more then none.

I am afraid the remove and reinstall because my key might be black listed. I am also afraid to go back to the older version for the same reason and the key for that is expired.

 
Edited by Fosdick
Link to post
Share on other sites

12 hours ago, dcollins said:

Can you try going to https://sirius.malwarebytes.com in your web browser? If the page opens and says Ok, then try getting updates again. if the page gives you an error, try with a browser like Chrome or Firefox

Your link is not working correctly... that being said, I am curious about it https://sirius.malwarebytes.com/ you want it tested or to see if the OP can go to that page.  I tried that on multiple computers where I am not having issues updating like the OP, and I too get This Page Can't Be Displayed...

Link to post
Share on other sites

  • Root Admin

Hello @Fosdick

The logs indicate that your computer is infected. I've moved your topic into the Malware Removal forum where I can assist you one-on-one with cleaning the computer.

 

Please restart the computer first and then run the following steps and post back the logs as attachments when ready.

STEP 01
Please download Junkware Removal Tool to your desktop.

  • Shutdown your antivirus to avoid any conflicts.
  • Right click over JRT.exe and select Run as administrator on Windows Vista or Windows 7, double-click on XP.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next reply message
  • When completed make sure to re-enable your antivirus

STEP 02

adwcleaner_new.png Fix with AdwCleaner

Please download AdwCleaner by Xplode and save the file to your Desktop.

  • Right-click on adwcleaner_new.png icon and select RunAsAdmin.jpg Run as Administrator to start the tool.
  • Accept the Terms of use.
  • Wait until the database is updated.
  • Click Scan.
  • When finished, please click Clean.
  • Your PC should reboot now.
  • After reboot, logfile will be opened. Copy its content into your next reply.

Note: Reports will be saved in your system partition, usually at C:\Adwcleaner

STEP 03
Download Sophos Free Virus Removal Tool and save it to your desktop.
 

  • Double click the icon and select Run
  • Click Next
  • Select I accept the terms in this license agreement, then click Next twice
  • Click Install
  • Click Finish to launch the program
  • Once the virus database has been updated click Start Scanning
  • If any threats are found click Details, then View Log file (bottom left-hand corner)
  • Copy and paste the results in your reply
  • Close the Notepad document, close the Threat Details screen, then click Start cleanup
  • Click Exit to close the program
  • If no threats were found, please confirm that result.

STEP 04
Please download the Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatible with your system. You can check here if you're not sure if your computer is 32-bit or 64-bit

  • Double-click to run it. When the tool opens, click Yes to disclaimer.
  • Press the Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it also makes another log (Addition.txt). If you've, run the tool before you need to place a check mark here.
  • Please attach the Additions.txt log to your reply as well.

 

Thank you

Ron

 

Link to post
Share on other sites

  • Root Admin

Let me have you run the following and we'll continue to review the system and get it working.

Please visit this web page and read the ComboFix User's Guide:

  • Once you've read the article and are ready to use the program you can download it directly from the link below.
  • Important! - Please make sure you save combofix to your desktop and do not run it from your browser
  • Direct download link for: ComboFix.exe
  • Please make sure you disable your security applications before running ComboFix.
  • Once Combofix has completed it will produce and open a log file.  Please be patient as it can take some time to load.
  • Please attach that log file to your next reply.
  • If needed the file can be located here:  C:\combofix.txt
  • NOTE: If you receive the message "illegal operation has been attempted on a registry key that has been marked for deletion", just reboot the computer.
Link to post
Share on other sites

Combofix would not run unless malwarebyte is disabled. I disabled protection and start with windows.  Then combofix needed to install the restore console but it said there was no internet connection. There was no connection until I re enabled malwarebytes. Even if I get restore console working, combofix said it needed an internet connection to run.

 

Edited by Fosdick
Link to post
Share on other sites

This may be extremely stupid assumption buuuut, when I view my modem's web activity log, I see nothing from my machine. I see my wife's activity and my Dish receiver's activity but nothing from my activity. I was trying to see exactly what happens when I click the update button. I receive a few packets but the update button reappears and nothing happens. Is there a way that the activity log can be bypassed by using different ports?

After installing 3.0.6 last Wednesday, I could not update. I clicked the deactivate license button and MWB updated or at least started to update once. Since then it will not update.

When I click deactivate now, I receive a few packets but it still says premium 3.0. I don't believe it is deactivating.

The modem firewall is in NAT mode and there is no firewall log. There is a system log showing things.  Actiontec GT784Wn

 

Link to post
Share on other sites

  • Root Admin

The issue is certainly different with other programs reporting no connection as well. Let me have you run the following please and we'll see what it says about your connection.

Please download MiniToolBox save it to your desktop and run it.

Checkmark the following check-boxes:

  • Flush DNS
  • Report IE Proxy Settings
  • Reset IE Proxy Settings
  • Report FF Proxy Settings
  • Reset FF Proxy Settings
  • List content of Hosts
  • List IP configuration
  • List Winsock Entries
  • List last 10 Event Viewer log
  • List Installed Programs
  • List Devices
  • List Users, Partitions and Memory size.
  • List Minidump Files


Click Go and post the result (Result.txt). A copy of Result.txt will be saved in the same directory the tool is run.

Note: When using Reset FF Proxy Settings option Firefox should be closed.

 

Link to post
Share on other sites

This sounds weird like a conspiracy theory buuuut, I used netsh -n 5 >scan.txt and found all kinds of TCP going on with weird ports being used. I reset my modem and suddenly I could see activity in the modem log and every site in my personal bookmark page was coming up.

I immediately shut down and switched to another computer that I haven't used in years with W7. I sat up until 2 AM changing the passwords on every account I have.

My not well educated theory is

1. TCP was being used somehow and it was invisible to the modem activity log.

2. Somehow my personal bookmarks were hacked and visited.

3. I am suspicious that It may have been facilitated by the logs I posted here.

I used free malwarebytes for years but a year ago I bought MWB 2 on a CD. It expired and I bought a renewal, got a key and downloaded 3.0 and applied the key.

4. Evidently there were things that slipped through 2.0 that screwed up 3.0

Am I nuts?

I am hesitant to download and run any more of the fixits and post the log. But he old machine is roached anyway so if necessary i can reconnect it and run that minitoolbox. I am using chrome now and I am not going back to firefox.

Right now I am using MWB 3.0 free on my W7 machine but I am afraid to apply the key because the same thing might happen.

Edited by Fosdick
Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.