Windows Update Error Code 80072EFE and IE Redirect
Hi,
Everytime I try a Windows Update I get the error code 80072EFE. Also I have problems when searching on yahoo and sometimes google and I get redirected to websites with ads. Also the host processes on my computer stop working a lot. My hijack log is this:
Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 10:09:53 PM, on 9/26/2010 Platform: Windows Vista SP2 (WinNT 6.00.1906) MSIE: Internet Explorer v8.00 (8.00.6001.18943) Boot mode: Normal
I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
If you do not reply within 72 hours the thread will be closed, if you need more time let me know. Likewise if I do not respond within 48 hours feel free to PM me.
* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software
HERE
** If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list
HERE
Please proceed as follows :-
Step1
You have Viewpoint installed. Viewpoint developed a behavioral targeting product in 2006. Viewpoint is associated with a program called viewmgr.exe and the ViewPoint Media Player.
Viewpoint is bundled with AOL, AOL Instant Messenger, Adobe Atmosphere, Netscape 7, etc and sometimes not mentioned in the license agreement. Hardware manufacturers pre-install some of these applications.
ViewPoint Toolbar will redirect your search queries and also transmits non personally identifiable information back to their servers. The Viewpoint Toolbar is listed is also classified as a threat in the CounterSpy Threat Library because it hijacks your search queries and also transmits non personally identifiable information back to their servers.
Viewpoint Manager is a media player often bundled with AIM software. Viewpoint Manager is a useless add on.
More info here:
http://ask-leo.com/viewmgrexe.html http://www.kephyr.com/spywarescanner/library/viewpointmediaplayer/index.phtml Because Viewpoint's software will track your web surfing and tailor advertisements based on the web pages you are visiting, I suggest you remove the program.
** Note: Removing Viewpoint Media Player may cause the program that bundled it to not function as intended. For AOL and AIM it is needed to use their 3D icons known as Super Buddies and for customized themes, etc.
If you wish to remove Viewpoint, end process on ViewManager in Task Manager.
Go to Start > Control Panel > Uninstall a Program and remove the following programs if present.
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select "Perform Quick Scan", then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
Please save the log to a location you will remember.
The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Copy and paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Step 3
We need to see some additional information about what is happening in your machine.
Please perform the following scan:
Download DDS by sUBs from one of the following links. Save it to your desktop.
A small box will open, with an explanation about the tool.
When done, DDS will open two (2) logs 1. DDS.txt 2. Attach.txt
Save both reports to your desktop.
The instructions here ask you to attach the Attach.txt.
Instead of attaching, please copy/past both logs into your next reply.
Close the program window, and delete the program from your desktop.
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control
HERE
Step 4
Download Security Check by screen317 from
HERE or
HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Memory Processes Infected: (No malicious items detected)
Memory Modules Infected: (No malicious items detected)
Registry Keys Infected: (No malicious items detected)
Registry Values Infected: (No malicious items detected)
Registry Data Items Infected: (No malicious items detected)
Folders Infected: (No malicious items detected)
Files Infected: (No malicious items detected)
Here is dds.txt
DDS (Ver_09-09-29.01) - NTFSx86 Run by Jamer at 19:56:12.74 on Mon 09/27/2010 Internet Explorer: 8.0.6001.18943 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2036.740 [GMT -4:00]
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-09-29.01)
Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume3 Install Date: 5/6/2008 4:40:29 AM System Uptime: 9/27/2010 7:59:31 AM (13 hours ago)
Motherboard: Dell Inc. | | 0RY007 Processor: Intel(R) Core(TM)2 Duo CPU E4600 @ 2.40GHz | Socket 775 | 2400/200mhz
==== Disk Partitions =========================
C: is FIXED (NTFS) - 456 GiB total, 328.141 GiB free. D: is FIXED (NTFS) - 10 GiB total, 5.857 GiB free. E: is CDROM ()
Ad-Aware Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 8.2.4 Adobe Shockwave Player 11.5 Age of Empires III Age of Empires III - The WarChiefs AIM 7 Apple Application Support Apple Mobile Device Support Apple Software Update AutoUpdate AVG Free 9.0 Bonjour Browser Defender 2.0.6.15 CA Yahoo! Anti-Spy (remove only) Compatibility Pack for the 2007 Office system Dell DataSafe Online Dell Driver Download Manager Dell Getting Started Guide Dell Support Center DivX Codec DivX Converter DivX Version Checker Download Updater (AOL LLC) Google Desktop GoToAssist 8.0.0.514 HiJackThis Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Intel(R) PRO Network Connections 12.1.11.0 iTunes Java(TM) SE Runtime Environment 6 Malwarebytes' Anti-Malware Microsoft .NET Framework 3.5 SP1 Microsoft Age of Empires II Microsoft Age of Empires II: The Conquerors Expansion Microsoft Office PowerPoint Viewer 2007 (English) Microsoft VC9 runtime libraries Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Word 2002 Microsoft Works Microsoft Works 2004 Setup Launcher Microsoft Works Suite Add-in for Microsoft Word MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB941833) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Music, Photos & Videos Launcher Network Play System (Patching) OGA Notifier 2.0.0048.0 Product Documentation Launcher QuickTime RealPlayer Realtek High Definition Audio Driver RealUpgrade 1.0 Return to Castle Wolfenstein - Platinum Edition Roxio Creator Audio Roxio Creator Copy Roxio Creator Data Roxio Creator DE Roxio Creator Tools Roxio Express Labeler 3 Roxio Update Manager SimCity 4 Deluxe Spelling Dictionaries Support For Adobe Reader 8 Star Wars Galactic Battlegrounds Star Wars Galactic Battlegrounds: Clone Campaigns Stronghold The Battle for Middle-earth (tm) Tropico Unity Web Player Update for Microsoft .NET Framework 3.5 SP1 (KB963707) User's Guides VC80CRTRedist - 8.0.50727.4053 Visual C++ 2008 x86 Runtime - (v9.0.30729) Visual C++ 2008 x86 Runtime - v9.0.30729.01 WinZip 14.0 Yahoo! Install Manager Yahoo! Software Update Yahoo! Toolbar
==== Event Viewer Messages From Past Week ========
9/27/2010 8:00:16 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 9/27/2010 6:41:37 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Windows Management Instrumentation service, but this action failed with the following error: An instance of the service is already running. 9/26/2010 9:27:52 PM, Error: Service Control Manager [7023] - The fioo32 service terminated with the following error: The specified module could not be found. 9/26/2010 9:24:28 PM, Error: Service Control Manager [7031] - The Lavasoft Ad-Aware Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 5000 milliseconds: Restart the service. 9/26/2010 9:02:11 PM, Error: Service Control Manager [7001] - The Network List Service service depends on the Network Location Awareness service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 9:02:07 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {9E175B6D-F52A-11D8-B9A5-505054503030} 9/26/2010 9:02:07 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service WSearch with arguments "" in order to run the server: {7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} 9/26/2010 9:01:33 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netprofm with arguments "" in order to run the server: {A47979D2-C419-11D9-A5B4-001185AD2B89} 9/26/2010 9:01:33 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1068" attempting to start the service netman with arguments "" in order to run the server: {BA126AD1-2166-11D1-B1D0-00805FC1270E} 9/26/2010 9:01:31 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service EventSystem with arguments "" in order to run the server: {1BE1F766-5536-11D1-B726-00C04FB926AF} 9/26/2010 9:01:24 PM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service ShellHWDetection with arguments "" in order to run the server: {DD522ACC-F821-461A-A407-50B198B896DC} 9/26/2010 9:00:43 PM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX DfsC NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The Workstation service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The WebDav Client Redirector Driver service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The WebClient service depends on the WebDav Client Redirector Driver service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The TCP/IP NetBIOS Helper service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The SMB MiniRedirector Wrapper and Engine service depends on the Redirected Buffering Sub Sysytem service which failed to start because of the following error: A device attached to the system is not functioning. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The SMB 2.0 MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The SMB 1.x MiniRedirector service depends on the SMB MiniRedirector Wrapper and Engine service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The Network Store Interface Service service depends on the NSI proxy service service which failed to start because of the following error: A device attached to the system is not functioning. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The Network Location Awareness service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The IP Helper service depends on the Network Store Interface Service service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The DNS Client service depends on the NetIO Legacy TDI Support Driver service which failed to start because of the following error: A device attached to the system is not functioning. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The DHCP Client service depends on the Ancilliary Function Driver for Winsock service which failed to start because of the following error: A device attached to the system is not functioning. 9/26/2010 9:00:43 PM, Error: Service Control Manager [7001] - The Computer Browser service depends on the Server service which failed to start because of the following error: The dependency service or group failed to start. 9/26/2010 4:30:12 PM, Error: Service Control Manager [7032] - The Service Control Manager tried to take a corrective action (Restart the service) after the unexpected termination of the Remote Access Connection Manager service, but this action failed with the following error: An instance of the service is already running. 9/26/2010 11:13:17 PM, Error: EventLog [6008] - The previous system shutdown at 11:12:10 PM on 9/26/2010 was unexpected. 9/25/2010 12:16:58 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.2.3 for the Network Card with network address 001D0992D73B has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 9/24/2010 6:28:05 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.2.5 for the Network Card with network address 001D0992D73B has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 9/24/2010 3:40:23 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.101 for the Network Card with network address 001FC65C1006 has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 9/24/2010 3:26:49 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.2.2 for the Network Card with network address 001FC65C1006 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 9/24/2010 3:17:40 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.2.6 for the Network Card with network address 001FC65C1006 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 9/23/2010 8:44:18 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AvgLdx86 mfetdik 9/23/2010 8:44:09 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.1.105 for the Network Card with network address 001FC65C1006 has been denied by the DHCP server 192.168.1.1 (The DHCP Server sent a DHCPNACK message). 9/23/2010 8:44:03 AM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.2.2 for the Network Card with network address 001D0992D73B has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 9/23/2010 8:43:52 AM, Error: EventLog [6008] - The previous system shutdown at 8:42:04 AM on 9/23/2010 was unexpected. 9/23/2010 7:50:10 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/23/2010 7:49:22 AM, Error: Service Control Manager [7031] - The Apple Mobile Device service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/23/2010 12:56:13 AM, Error: Service Control Manager [7022] - The Windows Update service hung on starting. 9/23/2010 12:43:54 AM, Error: EventLog [6008] - The previous system shutdown at 12:42:23 AM on 9/23/2010 was unexpected. 9/23/2010 12:34:33 AM, Error: EventLog [6008] - The previous system shutdown at 12:32:41 AM on 9/23/2010 was unexpected. 9/23/2010 1:46:03 AM, Error: Service Control Manager [7011] - A timeout (30000 milliseconds) was reached while waiting for a transaction response from the Dnscache service. 9/23/2010 1:30:25 AM, Error: Microsoft-Windows-DistributedCOM [10005] - DCOM got error "1084" attempting to start the service wuauserv with arguments "" in order to run the server: {E60687F7-01A1-40AA-86AC-DB1CBF673334} 9/23/2010 1:16:25 AM, Error: Service Control Manager [7026] - The following boot-start or system-start driver(s) failed to load: AFD AvgLdx86 AvgMfx86 AvgTdiX DfsC kl1 KLIF KLIM6 NetBIOS netbt nsiproxy PSched RasAcd rdbss Smb spldr tdx Wanarpv6 ws2ifsl 9/23/2010 1:16:17 AM, Error: EventLog [6008] - The previous system shutdown at 1:14:22 AM on 9/23/2010 was unexpected. 9/23/2010 1:03:05 AM, Error: EventLog [6008] - The previous system shutdown at 1:01:11 AM on 9/23/2010 was unexpected. 9/22/2010 8:54:15 PM, Error: Microsoft-Windows-Dhcp-Client [1002] - The IP address lease 192.168.2.9 for the Network Card with network address 001D0992D73B has been denied by the DHCP server 0.0.0.0 (The DHCP Server sent a DHCPNACK message). 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Windows Management Instrumentation service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The User Profile Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Themes service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Task Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The System Event Notification Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Shell Hardware Detection service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Secondary Logon service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Remote Access Connection Manager service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Multimedia Class Scheduler service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/21/2010 9:00:25 PM, Error: Service Control Manager [7031] - The Application Experience service terminated unexpectedly. It has done this 1 time(s). The following corrective action will be taken in 60000 milliseconds: Restart the service. 9/21/2010 8:53:20 AM, Error: Service Control Manager [7001] - The Remote Access Connection Manager service depends on the Telephony service which failed to start because of the following error: The service has not been started. 9/21/2010 7:38:39 PM, Error: Service Control Manager [7000] - The McAfee Inc. service failed to start due to the following error: The process cannot access the file because it is being used by another process. 9/21/2010 7:37:36 PM, Error: EventLog [6008] - The previous system shutdown at 7:36:35 PM on 9/21/2010 was unexpected. 9/20/2010 9:54:33 AM, Error: Service Control Manager [7031] - The Server service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/20/2010 9:54:33 AM, Error: Service Control Manager [7031] - The IP Helper service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service. 9/20/2010 9:54:33 AM, Error: Service Control Manager [7031] - The IKE and AuthIP IPsec Keying Modules service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 300000 milliseconds: Restart the service. 9/20/2010 9:54:33 AM, Error: Service Control Manager [7031] - The Extensible Authentication Protocol service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service. 9/20/2010 9:54:33 AM, Error: Service Control Manager [7031] - The Background Intelligent Transfer Service service terminated unexpectedly. It has done this 2 time(s). The following corrective action will be taken in 120000 milliseconds: Restart the service.
==== End Of File ===========================
And finally the security screen:
Results of screen317's Security Check version 0.99.5 Windows Vista Service Pack 2 (UAC is disabled!) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! AVG Free 9.0 WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Ad-Aware Malwarebytes' Anti-Malware Java(TM) SE Runtime Environment 6 Adobe Flash Player 10.0.12.36 Adobe Reader 8.2.4 Out of date Adobe Reader installed! ```````````````````````````````` Process Check: objlist.exe by Laurent Ad-Aware AAWService.exe Ad-Aware AAWTray.exe Malwarebytes' Anti-Malware mbam.exe AVG avgwdsvc.exe AVG avgtray.exe AVG avgnsx.exe ```````````````````````````````` DNS Vulnerability Check: Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)
There is still evidence of viewpoint on your system, i`ll remove that later if you want. You have several Antivirus programs on board AVG, Paretologic and Ad-aware (this now has an AV component) If you have more than one AV running with realtime protection they will clash and may even negate function.
Paretologic is not a program i`d personally recommend, it was originally on the Rogue program list as not to be trusted. I also see evidence of tools that are used by Malware removal forum helpers, have you had assistance before?
Personally i`d uninstall Paretologic, regarding Ad-aware, there is a procedure to turn off the AV component as follows if you want to keep the Antispyware engine running after you are clean:
Open Ad-Aware
Click on switch to advanced mode
Click on Settings
Click on the Ad-watch live! tab and under Detection layers ensure Antivirus engine is unchecked
Click OK and close Ad-Aware
Next,
Proceed as follows :-
We will continue with ComboFix.exe. Please visit this webpage for download links, and instructions for running the tool:
Don`t forget
Combofix must be saved to your desktop.
<--Very important
Ensure you have
disabledyour Firewall and all anti virus and anti malware programs so they do not interfere with the running of ComboFix.
<---Very important
Please include the
C:\ComboFix.txt in your next reply for further review.
Examples of how to disable realtime protection available at the following link :-
Note: Do not click combofix's window with your mouse while it's running. That action may cause it to stall.
*EXTRA NOTES*
If Combofix detects any Rootkit/Bootkit activity on your system it will give a warning and prompt for a reboot, you must allow it to do so.
If Combofix reboot's due to a rootkit, the screen may stay black for several minutes on reboot, this is normal
If after running Combofix you receive any type of warning message about registry key's being listed for deletion when trying to open certain items, reboot the system and this will fix the issue (Those items will not be deleted)
When I try to go to add/remove programs Paretologic isn't there...I installed it because someone said it could help I don't know why it isn't there I don't remember unistalling it.
combofix log:
ComboFix 10-09-27.05 - Jamer 09/28/2010 14:29:22.2.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2036.937 [GMT -4:00] Running from: c:\users\Jamer\Desktop\ComboFix.exe SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} .
((((((((((((((((((((((((((((((((((((((( Other Deletions ))))))))))))))))))))))))))))))))))))))))))))))))) . . ---- Previous Run ------- . C:\feed.txt c:\program files\webserver c:\users\Jamer\AppData\Local\Windows Server c:\users\Jamer\AppData\Local\Windows Server\uses32.dat
. ((((((((((((((((((((((((( Files Created from 2010-08-28 to 2010-09-28 ))))))))))))))))))))))))))))))) .
You`ll have to be honest with me, who ran Combofix and OTM , I`ve already asked if you`ve had help previously, you chose not to answer that question. There are too many security programs running. AVG, Spyware Doctor, Ad-aware, Paretologic, Windows defender.
You also have Limewire installed, did you not see the warning in my initial reply about P2P applications and Forum Policy.
Run the following two scans, I need to see if there are any vulnerabilities and look at your security set up:
Doubleclick CKScanner.exe and click Search For Files.
After a very short time, when the cursor hourglass disappears, click Save List To File.
A message box will verify that the file is saved.
Double-click the CKFiles.txt icon on your desktop and copy/paste the contents in your next reply.
Next,
Download Security Check by screen317 from HERE or HERE. Save it to your Desktop. Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked. A Notepad document should open automatically called checkup.txt; please post the contents of that document.
Sorry, I must have missed that question about help. I don't have help. I though I knew enough about computers for what you are tellin me. I unistallled Limewire. When I ran combofix the first time it took me to a login screen for my computer that didn't have my login information. I shut the computer off and I was able to login to my name and I ran combofix again. I forgot to turn off AVG and I have no idea what windows defender is. I have previously before that scan unistalled Paretologic and Spyware Doctor.
Here is the CK Scanner:
CKScanner - Additional Security Risks - These are not necessarily bad c:\program files\firefly studios\stronghold\gm\cracks.gm1 scanner sequence 3.NA.11 ----- EOF -----
Security Check:
Results of screen317's Security Check version 0.99.5 Windows Vista Service Pack 2 (UAC is disabled!) Internet Explorer 8 `````````````````````````````` Antivirus/Firewall Check: Windows Firewall Enabled! AVG Free 9.0 WMI entry may not exist for antivirus; attempting automatic update. ``````````````````````````````` Anti-malware/Other Utilities Check: Ad-Aware Malwarebytes' Anti-Malware Java(TM) SE Runtime Environment 6 Adobe Flash Player 10.0.12.36 Adobe Reader 8.2.4 Out of date Adobe Reader installed! ```````````````````````````````` Process Check: objlist.exe by Laurent Ad-Aware AAWService.exe Ad-Aware AAWTray.exe AVG avgwdsvc.exe AVG avgnsx.exe ```````````````````````````````` DNS Vulnerability Check: Request Timed Out (Wireless Internet connection/Disconnected Internet/Proxy?)
Save this as CFScript.txt, in the same location as ComboFix.exe
Refering to the picture above, drag CFScript into ComboFix.exe
When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.
Step 2
Run an online virus scan with Kaspersky from HERE.Use Internet Explorer to get there. This scan is very thorough and may take several hours to run, please allow it to complete. 1. At the main page. Press on " Accept". After reading the contents. 2. At the next window Select Update. Allow the Database to update. Note: If prompted to run or update your Java, then follow the prompts to do so. Kaspersky requires Java to run. 3. Once the Database has finished, under the Scan icon Select My Computer to start the scan. 4. Select Scan Report. 5. If any threats were found they will appear in the report 6. Select "Save error report as" Then in the file name just type in kaspersky Under "save as type" select text .txt Save it to your Desktop. Copy and post the results of the Kaspersky Online scan. If no threats were found then report that as well.
If you are keeping Ad-aware make sure the AV component is disabled, it will clash with AVG... Also ensure UAC is enabled, not a good idea to keep that switched off..
ComboFix 10-09-28.03 - Jamer 09/29/2010 12:58:16.3.2 - x86 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2036.924 [GMT -4:00] Running from: c:\users\Jamer\Desktop\ComboFix.exe Command switches used :: c:\users\Jamer\Desktop\CFScript.txt SP: Lavasoft Ad-Watch Live! *disabled* (Updated) {67844DAE-4F77-4D69-9457-98E8CFFDAA22} SP: Windows Defender *disabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46} * Created a new restore point
- - End Of File - - ECD7224E378A6C92FA5320FCBCFB9331
Kaspersky:
-------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7.0: scan report Wednesday, September 29, 2010 Operating system: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 2 (build 6002) Kaspersky Online Scanner version: 7.0.26.13 Last database update: Wednesday, September 29, 2010 16:19:42 Records in database: 4257635 --------------------------------------------------------------------------------
Scan settings: scan using the following database: extended Scan archives: yes Scan e-mail databases: yes
File name / Threat / Threats count C:\Users\Jamer\Music\Garth Brooks - Garth Brooks - The dance.mp3 Infected: Trojan-Downloader.WMA.GetCodec.aa 1
Selected area has been scanned.
My computer seems to be running a lot better and faster. My host processes are still stopping but not as much as they used too. I still can't download windows updates.
Please double-click OTM to run it. (Note: If you are running on Vista or Windows 7, right-click on the file and choose Run As Administrator).
Copy all from between the dotted lines below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Return to OTM, right click in the "Paste Instructions for Items to be Moved" window (under the yellow bar) and choose Paste.
Click the red Moveit! button.
Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.
Close OTM and reboot your PC.
Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose
Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter
*.log and press the Enter key, navigate to the
C:\_OTMoveIt\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.
Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.
If an infected file is detected, the default action will be Cure, click on Continue.
If a suspicious file is detected, the default action will be Skip, click on Continue.
It may ask you to reboot the computer to complete the process. Click on Reboot Now.
If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
Post the logs from OTM and TDSSKiller in your reply please.
After I did these steps I was able to update windows finally.
OTM:
All processes killed ========== PROCESSES ========== ========== FILES ========== < ipconfig /flushdns /c > Windows IP Configuration Successfully flushed the DNS Resolver Cache. C:\Users\Jamer\Desktop\cmd.bat deleted successfully. C:\Users\Jamer\Desktop\cmd.txt deleted successfully. C:\Users\Jamer\Music\Garth Brooks - Garth Brooks - The dance.mp3 moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\index folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\wmuf folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\ids\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\ids folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\av\wa\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\av\wa folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\av\kdb\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\av\kdb folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\av\emu\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\av\emu folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\av folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases\apu folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback\bases folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update\rollback folder moved successfully. c:\programdata\PLAV\DatabaseBackup\update folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\index\ForDiff folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\index folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\wmuf folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\ids\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\ids folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\wa\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\wa folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\kdb\i386\ForDiff folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\kdb\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\kdb folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\emu\i386 folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\emu\ForDiff folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av\emu folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\av folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\apu\ForDiff folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases\apu folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder\bases folder moved successfully. c:\programdata\PLAV\DatabaseBackup\temporaryFolder folder moved successfully. c:\programdata\PLAV\DatabaseBackup folder moved successfully. c:\programdata\PLAV\Database\Stat folder moved successfully. c:\programdata\PLAV\Database folder moved successfully. c:\programdata\PLAV folder moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully
OTM by OldTimer - Version 3.1.16.1 log created on 09302010_105714
Files moved on Reboot... File C:\Users\Jamer\AppData\Local\Temp\~DF12B0.tmp not found! File C:\Users\Jamer\AppData\Local\Temp\~DF12CD.tmp not found! File C:\Users\Jamer\AppData\Local\Temp\~DF1324.tmp not found! File C:\Users\Jamer\AppData\Local\Temp\~DF133A.tmp not found! File C:\Users\Jamer\AppData\Local\Temp\~DF1366.tmp not found! File C:\Users\Jamer\AppData\Local\Temp\~DF1372.tmp not found! File C:\Users\Jamer\AppData\Local\Temp\~DFB43A.tmp not found! C:\Users\Jamer\AppData\Local\Temp\~DFD0A8.tmp moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZGPV22BH\01[1].htm moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZGPV22BH\aceUAC[1].htm moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZGPV22BH\B4634285[1].htm moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\WOIOA4Q2\80003_eBay_Q3_2010_Liquid_Default_728x90[1].html moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NTR5P1VI\01[1].htm moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NTR5P1VI\clk[1].htm moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NTR5P1VI\iframe3[1].htm moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\NTR5P1VI\welcome[1].txt moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I3HJAJ2O\DlCkRd[1].aspx moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I3HJAJ2O\RSltPrc[1].aspx moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B1QDIG0Q\DtCol[1].aspx moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PRAD8M1\bkdp[1].aspx moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PRAD8M1\getInPage[1].aspx moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\8PRAD8M1\md[1].php moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\40DJ7RZ2\getInPage[1].aspx moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\40DJ7RZ2\RSltPrc[1].aspx moved successfully. C:\Users\Jamer\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\40DJ7RZ2\st[2] moved successfully.
kevinf80_1d0ac6
2 Intern
•
1131 Posts
1582
0
Posted September 27th, 2010 16:00
I'm kevinf80 and I will be helping with any issues you may have. Please be aware that some of the logs I may ask for can be very complex and can take a long time to decipher. I am a volunteer here with a job and family so I ask that you be patient when waiting for replies.
Please DO NOT run any scans/tools/fixes on your own as this will conflict with the tools we are going to use.
Please Print or Save to Notepad all instructions and please follow them carefully and if there's something you don't understand or that will not work please let me know and we will go through it together.
Malware is often buggy and can be very unstable, with that in mind it is advisable to backup any important data before we begin.
If you do not reply within 72 hours the thread will be closed, if you need more time let me know. Likewise if I do not respond within 48 hours feel free to PM me.
* If you are using any cracked software, please remove it. In addition to being illegal, when you install cracked software, you are running executable files from dubious, unknown sources. You are giving these sources access to information on your hard disk, and potential control over operation of your computer. Definition of cracked software HERE
** If you are using any P2P (file sharing) programs, please remove them before we clean your computer. The nature of such software and the high incidence of malware in files downloaded with them is counter productive to restoring your PC to a healthy state. That includes BitTorrent and similar programs. There is a partial list HERE
Please proceed as follows :-
Step1
You have Viewpoint installed. Viewpoint developed a behavioral targeting product in 2006. Viewpoint is associated with a program called viewmgr.exe and the ViewPoint Media Player.
Viewpoint is bundled with AOL, AOL Instant Messenger, Adobe Atmosphere, Netscape 7, etc and sometimes not mentioned in the license agreement. Hardware manufacturers pre-install some of these applications.
ViewPoint Toolbar will redirect your search queries and also transmits non personally identifiable information back to their servers. The Viewpoint Toolbar is listed is also classified as a threat in the CounterSpy Threat Library because it hijacks your search queries and also transmits non personally identifiable information back to their servers.
Viewpoint Manager is a media player often bundled with AIM software. Viewpoint Manager is a useless add on.
More info here:
http://ask-leo.com/viewmgrexe.html
http://www.kephyr.com/spywarescanner/library/viewpointmediaplayer/index.phtml
Because Viewpoint's software will track your web surfing and tailor advertisements based on the web pages you are visiting, I suggest you remove the program.
** Note: Removing Viewpoint Media Player may cause the program that bundled it to not function as intended. For AOL and AIM it is needed to use their 3D icons known as Super Buddies and for customized themes, etc.
If you wish to remove Viewpoint, end process on ViewManager in Task Manager.
Go to Start > Control Panel > Uninstall a Program and remove the following programs if present.
Step 2
Alernative D/L mirror
Alternative D/L mirror
Double Click mbam-setup.exe to install the application.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
Step 3
We need to see some additional information about what is happening in your machine.
Please perform the following scan:
2. Attach.txt
Please note: You may have to disable any script protection running if the scan fails to run.
After downloading the tool, disconnect from the internet and disable all antivirus protection.
Run the scan, enable your A/V and reconnect to the internet.
Information on A/V control HERE
Step 4
Download Security Check by screen317 from HERE or HERE.
Save it to your Desktop.
Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box. Press any key when asked.
A Notepad document should open automatically called checkup.txt; please post the contents of that document.
What i`d likein your reply :-
Kevin