Code 80072efe error when installing window updates
Every time I try to install a new windows update for my computer I get a code 80072efe error and I try to find help with this error but I can't find anything about this error.
HiJack This log:
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:31:30 PM, on 10/4/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18943) Boot mode: Normal
I'm kevinf80 and I will be helping with any malware issues you may have with your system.
Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Either print or Save to Notepad all instructions and please follow them carefully, if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
If you do not reply within 72 hours the thread will be closed, if you need more time let me know. Likewise if I do not respond within 48 hours feel free to PM me.
If you have any P2P applications installed such as , BitTorrent, uTorrent or Limewire etc etc. Please remove them before we start.
If you have any cracked or illegal software in use the thread will locked and all help will cease.
As follows please :-
Step 1
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
1. Starting with v 1.27.26 (This version no. will differ),
CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it,
REMOVE the checkmark when provided with the option
ORdownload the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use,
select Options > Advanced and UNCHECK "
Only delete files in Windows Temp folder older than 24 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
Clean all the entries in the "Windows Explorer" section.
Clean all entries in the "System" section.
Clean all entries in the "Advanced" section.
Clean any others that you choose.
In the Applications Tab:
Clean all except cookies in the Firefox/Mozilla section if you use it.
Clean all in the Opera section if you use it.
Clean Sun Java in the Internet Section.
Clean any others that you choose.
4. Click the "
Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "
OK" and it will scan and clean your system.
7. Click "
exit" when done.
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
Please save the log to a location you will remember.
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Step 4
Download Security Check by screen317 from
HERE or
HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Sorry I was looking a the current replies to the threads in the malware removal forum and I saw that you responded to most of them so I gave you a message. Thanks for taking your time to help me.
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: (No malicious items detected)
Registry Keys Infected: (No malicious items detected)
Registry Values Infected: (No malicious items detected)
Registry Data Items Infected: (No malicious items detected)
Folders Infected: (No malicious items detected)
Files Infected: (No malicious items detected)
Here is my Security Checks Log:
Results of screen317's Security Check version 0.99.5 Windows Vista Service Pack 2 (UAC is enabled) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! avast! Free Antivirus WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Malwarebytes' Anti-Malware CCleaner Java(TM) 6 Update 21 Java(TM) 6 Update 5 Out of date Java installed! Adobe Flash Player 10.1.85.3 Adobe Reader 8.2.0 Out of date Adobe Reader installed! Mozilla Firefox (3.6.10) Firefox Out of Date! ```````````````````````````````` Process Check: objlist.exe by Laurent Windows Defender MSASCui.exe Spybot Teatimer.exe is disabled! Windows Defender MSASCui.exe Alwil Software Avast5 AvastSvc.exe Alwil Software Avast5 AvastUI.exe ```````````````````````````````` DNS Vulnerability Check: GREAT! (Not vulnerable to DNS cache poisoning)
``````````End of Log````````````
Here is my fresh HJT Log:
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:46:29 PM, on 10/6/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18943) Boot mode: Normal
-- End of file - 7606 bytes ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
I am still getting a code 80072efe error when I try to get my windows updates. I also get a virus warning from my avast anti virus program when I open my firefox browser. Finally, I get a message saying that my host process has been stopped.
Its OK about the the PM, I dont like to take too many threads on together, logs can be complex and take a considerable length of time to research. I only help out here when the site is busy, its not my home site. Helpers are a bit thin on the ground, thats why i`ve taken on more than usual....
Please double-click OTM to run it. (Note: If you are running on Vista, right-click on the file and choose Run As Administrator).
Copy the lines between the dotted lines below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy): ------------------------------------------------------------------------------------------------------------------- :Processes
Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM and reboot your PC.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Step 2
Run ESET Online Scan
Hold down Control and click on the following link to open ESET OnlineScan in a new window.ESET OnlineScan
Click the button.
For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
Click on to download the ESET Smart Installer. Save it to your desktop.
Double click on the icon on your desktop.
Check
Click the button.
Accept any security warnings from your browser.
Check
Push the Start button.
ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
When the scan completes, push
Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
Push the button.
Push
You can refer to this animation by neomage if needed. Frequently asked questions available Here
Step 3
Please download VEW by Vino Rosso from HERE and save it to your Desktop.
Double-click VEW.exe. to start, Vista and Windows 7 users Right Click and select "Run as Administrator"
Under 'Select log to query...check the boxes for both Application and System.
Under 'Select type to list... select both Error and Critical.
Click the radio button for 'Number of events...Type 10 in the 1 to 20 box.
Then click the Run button.
Notepad will open with the output log. It will take a couple of minutes to generate the log, please be patient.
OTM by OldTimer - Version 3.1.16.1 log created on 10072010_013921
Files moved on Reboot... File move failed. C:\Windows\temp\_avast5_\Webshlock.txt scheduled to be moved on reboot.
Registry entries deleted on Reboot...
Log from ESETScan:
C:\Windows.old\ProgramData\Spybot - Search & Destroy\Recovery\DNSFlushcws1.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined C:\Windows.old\ProgramData\Spybot - Search & Destroy\Recovery\SmitfraudCgp1.zip Win32/Bagle.gen.zip worm cleaned by deleting - quarantined C:\Windows.old\Users\Elliot Wasser\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\591ffc59-5545f3b3 a variant of Java/TrojanDownloader.Agent.NAN trojan deleted - quarantined C:\Windows.old\Users\Elliot Wasser\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4\40591084-4fb026c0 probably a variant of Win32/Agent.HRYTTOE trojan deleted - quarantined C:\Windows.old\Users\Elliot Wasser\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53\640c67b5-7fe9a62e probably a variant of Win32/Agent.FPEXZHL trojan deleted - quarantined C:\Windows.old\Users\Elliot Wasser\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8\3f5641c8-14ad839f multiple threats deleted - quarantined C:\Windows.old\Users\Elliot Wasser\AppData\Roaming\scdata\wispex.html Win32/Adware.WinAntiVirus application cleaned by deleting - quarantined C:\Windows.old\Windows\ServiceProfiles\LocalService\AppData\Local\Temp\TfsStore\Tfs_DAV\JnteZcorv10.exeZxHffff3d5cV03003f36002Rf183b3a4108Tb3e9a6bcQ000002fa901801F002d000aJ12000601l0409325 probably a variant of Win32/Agent.DSFIQXJ trojan deleted - quarantined
Log from VEW:
Vino's Event Viewer v01c run on Windows Vista in English Report run at 07/10/2010 10:18:17 AM
Note: All dates below are in the format dd/mm/yyyy
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Critical Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 07/10/2010 2:11:50 PM Type: Error Category: 0 Event: 8210 Source: System Restore The scheduled restore point could not be created. Additional information: (0x800423f4).
Log: 'Application' Date/Time: 07/10/2010 2:11:50 PM Type: Error Category: 0 Event: 8193 Source: System Restore Failed to create restore point on volume (Process = C:\Windows\system32\rundll32.exe /d srrstr.dll,ExecuteScheduledSPPCreation; Descripton = Scheduled Checkpoint; Hr = 0x800423f4).
Log: 'Application' Date/Time: 07/10/2010 2:11:50 PM Type: Error Category: 0 Event: 16387 Source: SPP Shadow copy creation failed because of error reported by ASR Writer. More info: The parameter is incorrect. (0x80070057).
Log: 'Application' Date/Time: 07/10/2010 2:11:20 PM Type: Error Category: 101 Event: 1002 Source: Application Hang The program iexplore.exe version 8.0.6001.18943 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Problem Reports and Solutions control panel. Process ID: 139c Start Time: 01cb66296e1690c0 Termination Time: 16
Log: 'Application' Date/Time: 07/10/2010 8:28:41 AM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Log: 'Application' Date/Time: 07/10/2010 8:27:47 AM Type: Error Category: 100 Event: 1000 Source: Application Error Faulting application svchost.exe, version 6.0.6001.18000, time stamp 0x47918b89, faulting module ntdll.dll, version 6.0.6002.18005, time stamp 0x49e03821, exception code 0xc0000005, fault offset 0x0004714e, process id 0x4c8, application start time 0x01cb65e242499d7f.
Log: 'Application' Date/Time: 07/10/2010 5:41:38 AM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Log: 'Application' Date/Time: 07/10/2010 5:39:57 AM Type: Error Category: 0 Event: 8193 Source: System Restore Failed to create restore point on volume (Process = C:\Windows\system32\wbem\wmiprvse.exe; Descripton = OTM Restore Point; Hr = 0x800423f4).
Log: 'Application' Date/Time: 07/10/2010 5:39:57 AM Type: Error Category: 0 Event: 16387 Source: SPP Shadow copy creation failed because of error reported by ASR Writer. More info: The parameter is incorrect. (0x80070057).
Log: 'Application' Date/Time: 07/10/2010 5:23:05 AM Type: Error Category: 0 Event: 10 Source: Microsoft-Windows-WMI Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'System' Log - Critical Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'System' Date/Time: 19/09/2010 10:13:07 PM Type: Critical Category: 0 Event: 41 Source: Microsoft-Windows-Kernel-Power The last sleep transition was unsuccessful. This error could be caused if the system stopped responding, failed, or lost power during the sleep transition.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'System' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'System' Date/Time: 07/10/2010 2:10:09 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 2:10:08 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 2:10:07 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 2:10:07 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 2:10:06 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 2:10:06 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 2:10:05 PM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 8:29:57 AM Type: Error Category: 0 Event: 7032 Source: Service Control Manager The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running.
Log: 'System' Date/Time: 07/10/2010 5:41:59 AM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
Log: 'System' Date/Time: 07/10/2010 5:41:59 AM Type: Error Category: 0 Event: 7000 Source: Service Control Manager The BCM42RLY service failed to start due to the following error: The system cannot find the file specified.
I am still getting the code 80072efe error and the host process stopping message. I am not seeing the message from avast anymore when I open my mozilla firefox browser.
Don`t forget
Combofix must be saved to your desktop.
<--Very important
Ensure you have
disabledyour Firewall and all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
<---Very important
Please include the
C:\ComboFix.txt in your next reply for further review.
Examples of how to disable realtime protection available at the following link :-
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
*EXTRA NOTES*
If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)
ComboFix 10-10-07.01 - Elliot 10/07/2010 16:59:40.1.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.3061.1907 [GMT -4:00] Running from: c:\users\Elliot\Desktop\ComboFix.exe SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9} SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Created a new restore point .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) .
C:\Launcher.exe
Infected copy of c:\windows\system32\DRIVERS\RDPCDD.sys was found and disinfected Restored copy from - Kitty ate it :p . ((((((((((((((((((((((((( Files Created from 2010-09-07 to 2010-10-07 ))))))))))))))))))))))))))))))) .
Try turning UAC (user access control) to off and try updates again:
Start.
Control Panel.
User Accounts
User Accounts (in the new window)
Turn User Account Control (UAC) on or off.
check the box to turn off UAC.
click "OK".
restart computer.
run Microsoft updates.
reverse procedure to turn UAC back on.
If that doesn`t help go
Here and run
Microsoft Fixit. 646 error is apparently related to MS office, quite a common problem from what i`ve found using Google.
kevinf80_1d0ac6
2 Intern
•
1131 Posts
897
0
Posted October 6th, 2010 13:00
I'm kevinf80 and I will be helping with any malware issues you may have with your system.
As follows please :-
Step 1
Please re-open HiJackThis and scan only. Check the boxes next to all the entries listed below.
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:6092
Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot
Step 2
Download and scan with CCleaner
1. Starting with v 1.27.26 (This version no. will differ), CCleaner installs the Yahoo Toolbar as an option which IS checkmarked by default during the installation. IF you do NOT want it, REMOVE the checkmark when provided with the option OR download the toolbar-free or Slim versions instead of the Standard Build.
2. Before first use, select Options > Advanced and UNCHECK " Only delete files in Windows Temp folder older than 24 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:
In the Applications Tab:
4. Click the " Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click " OK" and it will scan and clean your system.
7. Click " exit" when done.
Step 3
Alernative D/L mirror
Alternative D/L mirror
Double Click mbam-setup.exe to install the application.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Step 4
Download Security Check by screen317 from HERE or HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
What i`d like in your reply :-
Kevin