This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

windows update issues Code 80072EFE

12 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Here you go: DDS (Ver_10-12-12.02) - NTFSx86 Run by [removed] at 21:15:01.27 on Wed 12/22/2010 Internet Explorer: 8.0.6001.18999 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.2037.817 [GMT -5:00] SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} SP: IObit Security 360 *Enabled/Updated* {FAE2835A-B90A-9E7A-85DA-82DBDA7C1E3A} ============== Running Processes =============== C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\System32\WLTRYSVC.EXE C:\Windows\system32\WLANExt.exe C:\Windows\System32\bcmwltry.exe C:\Program Files\Alwil Software\Avast5\AvastSvc.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\aestsrv.exe C:\Windows\System32\svchost.exe -k Akamai C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Dell Network Assistant\hnm_svc.exe C:\Windows\system32\taskeng.exe C:\Program Files\IObit\IObit Security 360\IS360srv.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe C:\Program Files\Dell Support Center\bin\sprtsvc.exe C:\Windows\system32\STacSV.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Windows\system32\SearchIndexer.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\system32\DRIVERS\xaudio.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\system32\taskeng.exe C:\Program Files\IObit\Game Booster\GameBox.exe C:\Program Files\IObit\Advanced SystemCare 3\AWC.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Dell\MediaDirect\PCMService.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Alwil Software\Avast5\AvastUI.exe C:\Program Files\IObit\IObit Security 360\is360tray.exe C:\Windows\ehome\ehtray.exe C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE C:\Program Files\NBC Direct\DirectPlayerCore.exe C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe C:\Program Files\Dell Network Assistant\ezi_hnm2.exe C:\Program Files\Digital Line Detect\DLG.exe C:\Program Files\Dell\QuickSet\quickset.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\ehome\ehmsas.exe c:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exe C:\Program Files\IObit\IObit Security 360\is360.exe C:\Windows\system32\taskeng.exe C:\Windows\system32\msiexec.exe C:\Windows\system32\vssvc.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\System32\svchost.exe -k swprv C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Internet Explorer\iexplore.exe C:\Program Files\Microsoft\Search Enhancement Pack\SCServer\SCServer.exe C:\Windows\system32\Macromed\Flash\FlashUtil10l_ActiveX.exe C:\Windows\servicing\TrustedInstaller.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Users\Justin\Desktop\Fix file\dds.scr ============== Pseudo HJT Report =============== uStart Page = hxxp://partnerpage.google.com/smallbiz.dell.com/en_us?hl=en&client=dell-usuk&channel=us-smb&ibd=3080426 uURLSearchHooks: H - No File BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - c:\program files\microsoft\search enhancement pack\search helper\SEPsearchhelperie.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Windows Live Messenger Companion Helper: {9fdde16b-836f-4806-ab1f-1455cbeff289} - c:\program files\windows live\companion\companioncore.dll BHO: CBrowserHelperObject Object: {ca6319c0-31b7-401e-a518-a07c3db8f777} - c:\program files\dell\bae\BAE.dll BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe uRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter uRun: [SUPERAntiSpyware] c:\program files\superantispyware\SUPERAntiSpyware.exe uRun: [DirectPlayerCore] "c:\program files\nbc direct\DirectPlayerCore.exe" uRun: [Pando Media Booster] c:\program files\pando networks\media booster\PMB.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [dscactivate] "c:\program files\dell support center\gs_agent\custom\dsca.exe" mRun: [PCMService] "c:\program files\dell\mediadirect\PCMService.exe" mRun: [DellSupportCenter] "c:\program files\dell support center\bin\sprtcmd.exe" /P DellSupportCenter mRun: [IgfxTray] c:\windows\system32\igfxtray.exe mRun: [HotKeysCmds] c:\windows\system32\hkcmd.exe mRun: [Persistence] c:\windows\system32\igfxpers.exe mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mRun: [avast5] "c:\program files\alwil software\avast5\avastUI.exe" /nogui mRun: [IObit Security 360] "c:\program files\iobit\iobit security 360\IS360tray.exe" /autostart StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\blueto~1.lnk - c:\program files\widcomm\bluetooth software\BTTray.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\dellne~1.lnk - c:\windows\installer\{0240bdfb-2995-4a3f-8c96-18d41282b716}\Icon0240BDFB3.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\digita~1.lnk - c:\program files\digital line detect\DLG.exe StartupFolder: c:\progra~2\micros~1\windows\startm~1\programs\startup\quickset.lnk - c:\program files\dell\quickset\quickset.exe mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Send image to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie_ctx.htm IE: Send page to &Bluetooth Device… - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\program files\widcomm\bluetooth software\btsendto_ie.htm IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - c:\program files\windows live\companion\companioncore.dll IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} - hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_23-windows-i586.cab DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll Notify: !SASWinLogon - c:\program files\superantispyware\SASWINLO.DLL Notify: igfxcui - igfxdev.dll SEH: SABShellExecuteHook Class: {5ae067d3-9afb-48e0-853a-ebb7f4a000da} - c:\program files\superantispyware\SASSEH.DLL ============= SERVICES / DRIVERS =============== R1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2009-11-17 165584] R1 mfehidk;McAfee Inc. mfehidk;c:\windows\system32\drivers\mfehidk.sys [2008-5-18 214664] R1 SASDIFSV;SASDIFSV;c:\program files\superantispyware\SASDIFSV.SYS [2009-2-17 12872] R1 SASKUTIL;SASKUTIL;c:\program files\superantispyware\SASKUTIL.SYS [2009-2-17 67656] R2 AESTFilters;Andrea ST Filters Service;c:\windows\system32\AEstSrv.exe [2008-4-26 73728] R2 Akamai;Akamai NetSession Interface;c:\windows\system32\svchost.exe -k Akamai [2008-5-17 21504] R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [2009-11-17 17744] R2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2009-11-17 50768] R2 avast! Antivirus;avast! Antivirus;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-20 40384] R2 IS360service;IS360service;c:\program files\iobit\iobit security 360\is360srv.exe [2010-12-17 312152] R3 avast! Mail Scanner;avast! Mail Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-20 40384] R3 avast! Web Scanner;avast! Web Scanner;c:\program files\alwil software\avast5\AvastSvc.exe [2010-11-20 40384] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2009-12-24 135664] S3 FontCache;Windows Font Cache Service;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-5-17 21504] S3 fssfltr;FssFltr;c:\windows\system32\drivers\fssfltr.sys [2010-10-25 39272] S3 fsssvc;Windows Live Family Safety Service;c:\program files\windows live\family safety\fsssvc.exe [2010-9-22 1493352] S3 mfeavfk;McAfee Inc. mfeavfk;c:\windows\system32\drivers\mfeavfk.sys [2008-5-18 79816] S3 mfebopk;McAfee Inc. mfebopk;c:\windows\system32\drivers\mfebopk.sys [2008-5-18 35272] S3 mferkdk;McAfee Inc. mferkdk;c:\windows\system32\drivers\mferkdk.sys [2008-5-18 34248] S3 mfesmfk;McAfee Inc. mfesmfk;c:\windows\system32\drivers\mfesmfk.sys [2008-5-18 40552] S3 SASENUM;SASENUM;c:\program files\superantispyware\SASENUM.SYS [2009-2-17 12872] S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504] S4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\windows live\mesh\wlcrasvc.exe [2010-9-22 51040] =============== Created Last 30 ================ 2010-12-22 02:00:13 6273872 —-a-w- c:\progra~2\microsoft\windows defender\definition updates\{4c87966a-94d8-46f1-bcc2-635acbae5114}\mpengine.dll 2010-12-22 01:03:16 ——– d—–w- c:\users\justin\appdata\local\temp 2010-12-22 01:02:20 ——– d-sh–w- C:\$RECYCLE.BIN 2010-12-21 04:17:00 2409784 —-a-w- c:\program files\windows mail\OESpamFilter.dat 2010-12-19 22:04:11 98816 —-a-w- c:\windows\sed.exe 2010-12-19 22:04:11 89088 —-a-w- c:\windows\MBR.exe 2010-12-19 22:04:11 256512 —-a-w- c:\windows\PEV.exe 2010-12-19 22:04:11 161792 —-a-w- c:\windows\SWREG.exe 2010-12-18 03:36:45 ——– d—–w- c:\progra~2\IObit 2010-12-18 03:35:19 1841456 —-a-w- c:\users\justin\appdata\roaming\microsoft\windows\templates\DefragSetup.exe 2010-12-18 03:35:16 1887344 —-a-w- c:\users\justin\appdata\roaming\microsoft\windows\templates\PasswordFolderSetup.exe 2010-12-18 03:35:04 6781400 —-a-w- c:\users\justin\appdata\roaming\microsoft\windows\templates\GameBoosterSetup.exe 2010-12-18 03:34:06 ——– d—–w- c:\users\justin\appdata\roaming\IObit 2010-12-18 03:34:05 ——– d—–w- c:\program files\IObit 2010-12-14 03:53:31 ——– d—–w- c:\users\justin\appdata\roaming\Malwarebytes 2010-12-14 03:53:19 38224 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2010-12-14 03:53:19 ——– d—–w- c:\progra~2\Malwarebytes 2010-12-14 03:53:16 20952 —-a-w- c:\windows\system32\drivers\mbam.sys 2010-12-14 03:53:15 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware 2010-12-14 03:19:56 ——– d—–w- c:\program files\CCleaner 2010-12-14 02:57:44 ——– d—–w- c:\progra~2\PC Tools 2010-12-14 02:14:32 ——– d—–w- c:\users\justin\appdata\roaming\ParetoLogic 2010-12-14 02:14:32 ——– d—–w- c:\users\justin\appdata\roaming\DriverCure 2010-12-14 02:14:06 ——– d—–w- c:\progra~2\ParetoLogic 2010-12-14 00:33:26 ——– d—–w- c:\users\justin\appdata\roaming\FixCleaner 2010-12-14 00:33:12 ——– d—–w- c:\program files\FixCleaner 2010-12-13 03:28:39 435736 —-a-w- c:\windows\system32\drivers\iaStor.sys 2010-12-11 02:48:25 45056 —-a-r- c:\users\justin\appdata\roaming\microsoft\installer\{42929f0f-ce14-47af-9fc7-ff297a603021}\NewShortcut1_42929F0FCE1447AF9FC7FF297A603021_1.exe 2010-12-11 02:48:10 ——– d—–w- c:\windows\system32\vmm32 2010-12-11 02:11:05 ——– d—–w- c:\windows\system32\wbem\repository 2010-12-11 02:09:17 ——– d—–w- c:\windows\Registration 2010-11-23 20:49:24 7680 —-a-w- c:\program files\internet explorer\iecompat.dll ==================== Find3M ==================== 2010-11-12 23:53:06 472808 —-a-w- c:\windows\system32\deployJava1.dll 2010-11-04 18:56:07 345600 —-a-w- c:\windows\system32\wmicmiplugin.dll 2010-11-04 18:55:38 352768 —-a-w- c:\windows\system32\taskschd.dll 2010-11-04 18:55:38 270336 —-a-w- c:\windows\system32\taskcomp.dll 2010-11-04 18:55:12 601600 —-a-w- c:\windows\system32\schedsvc.dll 2010-11-04 16:34:06 171520 —-a-w- c:\windows\system32\taskeng.exe 2010-11-02 06:01:54 916480 —-a-w- c:\windows\system32\wininet.dll 2010-11-02 05:57:41 43520 —-a-w- c:\windows\system32\licmgr10.dll 2010-11-02 05:57:27 1469440 —-a-w- c:\windows\system32\inetcpl.cpl 2010-11-02 05:57:11 71680 —-a-w- c:\windows\system32\iesetup.dll 2010-11-02 05:57:11 109056 —-a-w- c:\windows\system32\iesysprep.dll 2010-11-02 05:01:31 385024 —-a-w- c:\windows\system32\html.iec 2010-11-02 04:26:10 133632 —-a-w- c:\windows\system32\ieUnatt.exe 2010-11-02 04:24:44 1638912 —-a-w- c:\windows\system32\mshtml.tlb 2010-10-28 15:44:56 34304 —-a-w- c:\windows\system32\atmlib.dll 2010-10-28 13:27:47 292352 —-a-w- c:\windows\system32\atmfd.dll 2010-10-28 13:20:12 2048 —-a-w- c:\windows\system32\tzres.dll 2010-10-19 15:41:44 222080 ——w- c:\windows\system32\MpSigStub.exe 2010-10-18 13:37:35 81920 —-a-w- c:\windows\system32\consent.exe 2010-10-18 13:31:24 2038272 —-a-w- c:\windows\system32\win32k.sys ============= FINISH: 21:16:40.16 =============== Thanks, Dell-LP

Attachments:

Dell-Laptop,

Log looks good :D


Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Now to remove most of the tools that we have used in fixing your machine:
  • Make sure you have an Internet Connection.
  • Download OTC to your desktop and run it
  • A list of tool components used in the cleanup of malware will be downloaded.
  • If your Firewall or Real Time protection attempts to block OTC to reach the Internet, please allow the application to do so.
  • Click Yes to begin the cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the cleanup process. If you are asked to reboot the machine choose Yes.

Please re-enable any security that was disabled.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI