This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Windows update issue

5 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

For some reason the system I am fixing is having issues with installing the Windows xp critical updates. Below is the error I'm getting:

Installation Failure

Error Code: 0x80070005
Try to install the update again, or request help from one of the following resources.

I've attempted the fix suggested by microsoft by granting permissions to all users on my pc and it still is not working. Had Microsoft remotely access my system several times, ran viperescue according to a suggestion by Microsoft which found 2 issues and fixed them. Yet I am still getting the error. I also ran the microsoft fix-it for windows update to no avail. Any help you can give me would be greatly appreciated. DDS and HiJackThis log below:


DDS (Ver_10-10-31.01) - NTFSx86
Run by [removed] at 13:30:52.18 on Sat 02/12/2011
Internet Explorer: 8.0.6001.18702 BrowserJavaVersion: 1.6.0_17
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1345 [GMT -5:00]

AV: AVG Anti-Virus Free Edition 2011 *On-access scanning enabled* (Updated) {17DDD097-36FF-435F-9E1B-52D74245D6BF}

============== Running Processes ===============

C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
C:\WINDOWS\system32\svchost.exe -k WudfServiceGroup
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe -k imgsvc
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Documents and Settings\Paul\My Documents\Downloads\dds.scr

============== Pseudo HJT Report ===============

uStart Page = hxxp://www.yahoo.com/
uSearch Page = hxxp://us.rd.yahoo.com/customize/ie/defaults/sp/msgr9/*http://www.yahoo.com
uWindow Title = Windows Internet Explorer provided by Yahoo!
uSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr9/*http://www.yahoo.com/ext/search/search.html
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
BHO: {02478D38-C3F9-4efb-9B51-7695ECA05670} - No File
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: AVG Safe Search: {3ca2f312-6f6e-4b53-a66e-4e65e497c8c0} - c:\program files\avg\avg10\avgssie.dll
BHO: Spybot-S&D IE Protection: {53707962-6f74-2d53-2644-206d7942484f} - c:\progra~1\spybot~1\SDHelper.dll
BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
TB: {E1BACF55-35E1-4E47-9247-2D48660E5545} - No File
uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe
uPolicies-explorer: ForceClassicControlPanel = 1 (0x1)
uPolicies-system: EnableProfileQuota = 1 (0x1)
IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office11\EXCEL.EXE/3000
IE: {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - c:\program files\aim\aim.exe
IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\program files\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~2\office11\REFIEBAR.DLL
IE: {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - {53707962-6F74-2D53-2644-206D7942484F} - c:\progra~1\spybot~1\SDHelper.dll
Trusted Zone: fanball.com\www
DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} - hxxp://www.creative.com/su/ocx/15026/CTSUEng.cab
DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader5.cab
DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} - hxxp://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
DPF: {17492023-C23A-453E-A040-C7C580BBF700} - hxxp://download.microsoft.com/download/E/5/6/E5611B10-0D6D-4117-8430-A67417AA88CD/LegitCheckControl.cab
DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} - hxxp://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.5.107.cab
DPF: {48DD0448-9209-4F81-9F6D-D83562940134} - hxxp://lads.myspace.com/upload/MySpaceUploader1006.cab
DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} - hxxp://cdn.scan.onecare.live.com/resource/download/scanner/wlscbase6886.cab
DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} - hxxp://upload.facebook.com/controls/FacebookPhotoUploader.cab
DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1297462594453
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/ultrashim.cab
DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} - hxxp://meijer.lifepics.com/net/Uploader/ImageUploader3.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} - hxxp://www.creative.com/su/ocx/15026/CTPID.cab
TCP: {437C9847-8B3A-433A-BB2D-52230D8E6687} = 216.68.4.10,216.68.5.10
TCP: {7ED12615-84F6-4CC6-9A8A-61F6251956C1} = 4.2.2.2,4.2.2.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\logitech\desktop messenger\8876480\program\GAPlugProtocol-8876480.dll
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - c:\program files\avg\avg10\avgpp.dll
SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

================= FIREFOX ===================

FF - ProfilePath - c:\docume~1\paul\applic~1\mozilla\firefox\profiles\ppr7rmp1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
FF - HiddenExtension: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\microsoft.net\framework\v3.5\windows presentation foundation\dotnetassistantextension\
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
FF - HiddenExtension: Java Console: No Registry Reference - c:\program files\mozilla firefox\extensions\{CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}

============= SERVICES / DRIVERS ===============

R0 AVGIDSEH;AVGIDSEH;c:\windows\system32\drivers\AVGIDSEH.sys [2010-9-13 25680]
R0 Avgrkx86;AVG Anti-Rootkit Driver;c:\windows\system32\drivers\avgrkx86.sys [2010-9-7 26064]
R1 Avgldx86;AVG AVI Loader Driver;c:\windows\system32\drivers\avgldx86.sys [2010-12-8 251728]
R1 Avgmfx86;AVG Mini-Filter Resident Anti-Virus Shield;c:\windows\system32\drivers\avgmfx86.sys [2010-9-7 34384]
R1 Avgtdix;AVG TDI Driver;c:\windows\system32\drivers\avgtdix.sys [2010-11-12 299984]
R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2011-2-12 98392]
R3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [2006-3-20 1452032]
S1 mferkdk;VSCore mferkdk;\??\c:\program files\mcafee\virusscan enterprise\mferkdk.sys –> c:\program files\mcafee\virusscan enterprise\mferkdk.sys [?]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S3 AVGIDSDriver;AVGIDSDriver;c:\windows\system32\drivers\AVGIDSDriver.sys [2010-8-3 123472]
S3 AVGIDSFilter;AVGIDSFilter;c:\windows\system32\drivers\AVGIDSFilter.sys [2010-8-3 30288]
S3 AVGIDSShim;AVGIDSShim;c:\windows\system32\drivers\AVGIDSShim.sys [2010-8-3 26192]
S3 USBFVNETR;NETGEAR MA101 USB Adapter;c:\windows\system32\drivers\ma101rnd.sys [2008-9-27 80000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2006-2-28 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\microsoft.net\framework\v4.0.30319\wpf\WPFFontCache_v0400.exe [2010-3-18 753504]
S4 AVGIDSAgent;AVGIDSAgent;c:\program files\avg\avg10\identity protection\agent\bin\AVGIDSAgent.exe [2011-1-6 6128720]
S4 avgwd;AVG WatchDog;c:\program files\avg\avg10\avgwdsvc.exe [2010-10-22 265400]
S4 gupdate1cac49c2c87f8b2;Google Update Service (gupdate1cac49c2c87f8b2);c:\program files\google\update\GoogleUpdate.exe [2010-3-15 133104]
S4 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\microsoft fix it center\Matsvc.exe [2010-11-16 267568]

=============== Created Last 30 ================

2011-02-12 18:08:20 388096 —-a-r- c:\docume~1\paul\applic~1\microsoft\installer\{45a66726-69bc-466b-a7a4-12fcba4883d7}\HiJackThis.exe
2011-02-12 17:59:54 ——– d—–w- c:\program files\Trend Micro
2011-02-12 17:35:34 ——– d—–w- c:\docume~1\paul\locals~1\applic~1\ApplicationHistory
2011-02-12 16:54:44 ——– d—–w- c:\windows\system32\winrm
2011-02-12 16:54:44 ——– d—–w- c:\windows\system32\GroupPolicy
2011-02-12 16:54:27 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-02-12 16:46:05 ——– d—–w- c:\windows\system32\URTTEMP
2011-02-12 16:15:33 ——– d—–w- c:\program files\Windows Resource Kits
2011-02-12 14:48:38 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-02-12 14:48:38 16736 —-a-w- c:\windows\system32\mucltui.dll.mui
2011-02-12 10:10:03 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-02-12 10:10:03 27984 —-a-w- c:\windows\system32\sbbd.exe
2011-02-12 10:09:52 ——– d—–w- C:\VIPRERESCUE
2011-02-12 04:23:28 ——– d—–w- c:\docume~1\paul\applic~1\Malwarebytes
2011-02-12 04:23:26 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-12 04:23:23 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-12 04:23:22 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-12 04:23:22 ——– d—–w- c:\docume~1\alluse~1\applic~1\Malwarebytes
2011-02-12 03:31:25 ——– d—–w- c:\windows\system32\CatRoot2
2011-02-12 02:32:23 ——– d—–w- c:\windows\pss
2011-02-12 02:17:56 ——– d—–w- c:\program files\CCleaner
2011-02-12 00:01:48 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-02-12 00:01:48 ——– d—–w- c:\docume~1\alluse~1\applic~1\Spybot - Search & Destroy
2011-02-11 23:12:33 ——– d—–w- c:\docume~1\paul\locals~1\applic~1\FixItCenter
2011-02-11 23:09:37 ——– d—–w- c:\windows\MATS
2011-02-11 23:09:35 ——– d—–w- c:\program files\Microsoft Fix it Center
2011-02-11 18:29:41 ——– d–h–w- C:\$AVG
2011-02-11 17:29:55 ——– d—–w- c:\docume~1\paul\applic~1\AVG10
2011-02-11 17:28:32 ——– d–h–w- c:\docume~1\alluse~1\applic~1\Common Files
2011-02-11 17:27:15 ——– d—–w- c:\windows\system32\drivers\AVG
2011-02-11 17:27:15 ——– d—–w- c:\docume~1\alluse~1\applic~1\AVG10
2011-02-11 17:26:35 ——– d—–w- c:\program files\AVG
2011-02-11 17:20:49 ——– d—–w- c:\docume~1\alluse~1\applic~1\MFAData

==================== Find3M ====================

2010-11-16 06:10:14 65328 —-a-w- c:\windows\apppatch\matsshim.dll
2009-09-30 06:30:41 16965 —-a-w- c:\program files\common files\neho.com
2009-09-30 06:30:41 11246 —-a-w- c:\program files\common files\lekawavaho.sys
2009-09-29 20:28:39 19086 —-a-w- c:\program files\common files\finuwiqy.sys

============= FINISH: 13:31:52.14 ===============


UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT

DDS (Ver_10-10-31.01)

Microsoft Windows XP Professional
Boot Device: \Device\HarddiskVolume1
Install Date: 10/25/2006 2:05:46 AM
System Uptime: 2/12/2011 12:39:05 PM (1 hours ago)

Motherboard: Intel Corporation | | D875PBZ
Processor: Intel® Pentium® 4 CPU 3.00GHz | J2E1 | 2992/200mhz

==== Disk Partitions =========================

A: is Removable
C: is FIXED (NTFS) - 149 GiB total, 15.643 GiB free.
D: is CDROM ()

==== Disabled Device Manager Items =============

==== System Restore Points ===================

RP910: 2/11/2011 12:11:53 PM - Removed McAfee VirusScan Enterprise
RP911: 2/11/2011 12:26:21 PM - Installed Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
RP912: 2/11/2011 12:26:33 PM - Installed AVG 2011
RP913: 2/11/2011 12:27:01 PM - Installed AVG 2011
RP914: 2/11/2011 3:43:36 PM - Software Distribution Service 3.0
RP915: 2/11/2011 5:15:02 PM - Software Distribution Service 3.0
RP916: 2/11/2011 5:15:42 PM - Software Distribution Service 3.0
RP917: 2/11/2011 5:31:00 PM - Software Distribution Service 3.0
RP918: 2/11/2011 5:54:47 PM - Software Distribution Service 3.0
RP919: 2/11/2011 6:08:57 PM - Installed %1 %2.
RP920: 2/11/2011 6:20:20 PM - Installed Microsoft Fix it 50203
RP921: 2/11/2011 10:42:23 PM - Software Distribution Service 3.0
RP922: 2/11/2011 11:09:31 PM - Installed Microsoft Fix it 50202
RP923: 2/11/2011 11:17:41 PM - Software Distribution Service 3.0
RP924: 2/11/2011 11:58:07 PM - Software Distribution Service 3.0
RP925: 2/12/2011 3:00:20 AM - Software Distribution Service 3.0
RP926: 2/12/2011 9:24:30 AM - Software Distribution Service 3.0
RP927: 2/12/2011 10:14:12 AM - Software Distribution Service 3.0
RP928: 2/12/2011 10:16:37 AM - Software Distribution Service 3.0
RP929: 2/12/2011 10:23:48 AM - Installed Microsoft Fix it 50202
RP930: 2/12/2011 10:36:22 AM - Software Distribution Service 3.0
RP931: 2/12/2011 10:40:16 AM - Software Distribution Service 3.0
RP932: 2/12/2011 10:49:03 AM - Software Distribution Service 3.0
RP933: 2/12/2011 10:52:19 AM - Software Distribution Service 3.0
RP934: 2/12/2011 10:54:29 AM - Software Distribution Service 3.0
RP935: 2/12/2011 11:15:32 AM - Installed Windows Resource Kit Tools - SubInAcl.exe
RP936: 2/12/2011 11:19:53 AM - Software Distribution Service 3.0
RP937: 2/12/2011 11:44:20 AM - Software Distribution Service 3.0
RP938: 2/12/2011 12:34:12 PM - Software Distribution Service 3.0
RP939: 2/12/2011 12:36:51 PM - Software Distribution Service 3.0
RP940: 2/12/2011 1:08:18 PM - Installed HiJackThis

==== Installed Programs ======================

µTorrent
Adobe Flash Player 10 ActiveX
Adobe Flash Player 10 Plugin
Adobe Reader 7.0.8
AOL Instant Messenger
AutoUpdate
AVG 2011
CCleaner
Civilization III Complete Edition
Coupon Printer for Windows
Creative EAX Console
Creative Speaker Settings
Critical Update for Windows Media Player 11 (KB959772)
Device Control
Digimax Master
DivX Codec
DivX Converter
DivX Player
DivX Plus DirectShow Filters
DivX Version Checker
DivX Web Player
GameSpy Arcade
Google Chrome
Google Update Helper
H.264 Decoder
HiJackThis
HijackThis 2.0.2
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595)
Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484)
Hotfix for Windows Internet Explorer 7 (KB947864)
Hotfix for Windows Media Format 11 SDK (KB929399)
Hotfix for Windows Media Player 11 (KB939683)
Hotfix for Windows XP (KB2443685)
Hotfix for Windows XP (KB932716-v2)
Hotfix for Windows XP (KB952287)
Hotfix for Windows XP (KB954550-v5)
Hotfix for Windows XP (KB970653-v3)
Hotfix for Windows XP (KB976098-v2)
Hotfix for Windows XP (KB979306)
Hotfix for Windows XP (KB981793)
IGN Download Manager 2.3.2
Intel® PRO Network Adapters and Drivers
Internet Explorer (Enable DEP)
J2SE Runtime Environment 5.0 Update 10
Java™ 6 Update 17
Java™ 6 Update 7
Lexmark X125
Logitech Desktop Messenger
Logitech Harmony Remote Software 7
MA101 USB Adapter Configuration Utility
Malwarebytes' Anti-Malware
Microsoft .NET Framework 1.1
Microsoft .NET Framework 2.0 Service Pack 2
Microsoft .NET Framework 3.0 Service Pack 2
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 4 Client Profile
Microsoft Application Error Reporting
Microsoft Automated Troubleshooting Services Shim
Microsoft Base Smart Card Cryptographic Service Provider Package
Microsoft Compression Client Pack 1.0 for Windows XP
Microsoft Fix it Center
Microsoft Internationalized Domain Names Mitigation APIs
Microsoft Kernel-Mode Driver Framework Feature Pack 1.5
Microsoft Kernel-Mode Driver Framework Feature Pack 1.7
Microsoft Kernel-Mode Driver Framework Feature Pack 1.9
Microsoft National Language Support Downlevel APIs
Microsoft Office Professional Edition 2003
Microsoft User-Mode Driver Framework Feature Pack 1.9
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
Microsoft Visual C++ 2005 Redistributable
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
Microsoft WinUsb 1.0
MKV Splitter
Mozilla Firefox (2.0)
MSXML 4.0 SP2 (KB927978)
MSXML 4.0 SP2 (KB936181)
MSXML 4.0 SP2 (KB954430)
MSXML 4.0 SP2 (KB973688)
MSXML 6.0 Parser (KB933579)
MSXML4 Parser
NVIDIA Drivers
QuickTime
RealArcade
Remote Control USB Driver
S500/S600 USB Driver
Samsung USB Driver
Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473)
Security Update for Windows Internet Explorer 7 (KB928090)
Security Update for Windows Internet Explorer 7 (KB929969)
Security Update for Windows Internet Explorer 7 (KB931768)
Security Update for Windows Internet Explorer 7 (KB933566)
Security Update for Windows Internet Explorer 7 (KB937143)
Security Update for Windows Internet Explorer 7 (KB938127)
Security Update for Windows Internet Explorer 7 (KB939653)
Security Update for Windows Internet Explorer 7 (KB942615)
Security Update for Windows Internet Explorer 7 (KB944533)
Security Update for Windows Internet Explorer 7 (KB950759)
Security Update for Windows Internet Explorer 7 (KB953838)
Security Update for Windows Internet Explorer 8 (KB969897)
Security Update for Windows Media Player (KB2378111)
Security Update for Windows Media Player (KB911564)
Security Update for Windows Media Player (KB952069)
Security Update for Windows Media Player (KB954155)
Security Update for Windows Media Player (KB968816)
Security Update for Windows Media Player (KB973540)
Security Update for Windows Media Player (KB975558)
Security Update for Windows Media Player (KB978695)
Security Update for Windows Media Player 10 (KB911565)
Security Update for Windows Media Player 11 (KB936782)
Security Update for Windows Media Player 11 (KB954154)
Security Update for Windows Media Player 6.4 (KB925398)
Security Update for Windows Media Player 9 (KB917734)
Security Update for Windows XP (KB923561)
Security Update for Windows XP (KB938464-v2)
Security Update for Windows XP (KB938464)
Security Update for Windows XP (KB941569)
Security Update for Windows XP (KB946648)
Security Update for Windows XP (KB950760)
Security Update for Windows XP (KB950762)
Security Update for Windows XP (KB950974)
Security Update for Windows XP (KB951066)
Security Update for Windows XP (KB951376-v2)
Security Update for Windows XP (KB951376)
Security Update for Windows XP (KB951698)
Security Update for Windows XP (KB951748)
Security Update for Windows XP (KB952004)
Security Update for Windows XP (KB952954)
Security Update for Windows XP (KB953839)
Security Update for Windows XP (KB954211)
Security Update for Windows XP (KB954459)
Security Update for Windows XP (KB954600)
Security Update for Windows XP (KB955069)
Security Update for Windows XP (KB956391)
Security Update for Windows XP (KB956572)
Security Update for Windows XP (KB956802)
Security Update for Windows XP (KB956803)
Security Update for Windows XP (KB956841)
Security Update for Windows XP (KB957095)
Security Update for Windows XP (KB957097)
Security Update for Windows XP (KB958644)
Security Update for Windows XP (KB958687)
Security Update for Windows XP (KB958690)
Security Update for Windows XP (KB959426)
Security Update for Windows XP (KB960225)
Security Update for Windows XP (KB960715)
Security Update for Windows XP (KB960803)
Security Update for Windows XP (KB961373)
Security Update for Windows XP (KB961501)
Security Update for Windows XP (KB968537)
Security Update for Windows XP (KB969898)
Security Update for Windows XP (KB970238)
Sid Meier's Civilization 4
Sid Meier's Civilization 4 - Warlords
Spybot - Search & Destroy
uophx Screen Saver
Update for Microsoft .NET Framework 3.5 SP1 (KB963707)
Update for Microsoft Windows (KB971513)
Update for Windows Internet Explorer 8 (KB971930)
Update for Windows XP (KB951072-v2)
Update for Windows XP (KB951978)
Update for Windows XP (KB955839)
Update for Windows XP (KB967715)
VC80CRTRedist - 8.0.50727.4053
Ventrilo Client
Warcraft III
Warlords III: Darklords Rising
WebFldrs XP
Winamp (remove only)
Windows Genuine Advantage Notifications (KB905474)
Windows Internet Explorer 7
Windows Internet Explorer 8
Windows Management Framework Core
Windows Media Format 11 runtime
Windows Media Player 11
Windows Resource Kit Tools - SubInAcl.exe
Windows XP Service Pack 3
WinRAR archiver
World of Warcraft
Zune
Zune Language Pack (DE)
Zune Language Pack (ES)
Zune Language Pack (FR)
Zune Language Pack (IT)

==== Event Viewer Messages From Past Week ========

2/12/2011 9:24:58 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB2479628).
2/12/2011 9:24:53 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB2483185).
2/12/2011 9:24:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB2478971).
2/12/2011 3:02:35 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB960859).
2/12/2011 3:02:15 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB958869).
2/12/2011 3:02:10 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Cumulative Security Update for ActiveX Killbits for Windows XP (KB980195).
2/12/2011 3:02:06 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB980232).
2/12/2011 3:02:01 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Update for Windows XP (KB955759).
2/12/2011 3:01:56 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB974318).
2/12/2011 3:01:52 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB969059).
2/12/2011 3:01:47 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB2229593).
2/12/2011 3:01:43 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB971657).
2/12/2011 3:01:38 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Update for Windows XP (KB961118).
2/12/2011 3:01:34 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB956744).
2/12/2011 3:01:29 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB974112).
2/12/2011 3:01:25 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB956844).
2/12/2011 3:01:20 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB973869).
2/12/2011 3:01:16 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB974571).
2/12/2011 3:01:11 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB973507).
2/12/2011 3:01:07 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB973904).
2/12/2011 3:01:02 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB974392).
2/12/2011 3:00:57 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB978542).
2/12/2011 3:00:53 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB979482).
2/12/2011 3:00:48 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB973815).
2/12/2011 3:00:44 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB975562).
2/12/2011 3:00:39 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Jscript 5.8 for Windows XP (KB971961).
2/12/2011 3:00:34 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB2478960).
2/12/2011 3:00:29 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Update for Windows XP (KB968389).
2/12/2011 2:11:06 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service MatSvc with arguments "" in order to run the server: {8843B4A2-A3CB-4CB9-9CCE-F443F641009F}
2/12/2011 12:37:34 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Update for Windows XP (KB971029).
2/12/2011 12:37:29 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Update for Internet Explorer 8 Compatibility View List for Windows XP (KB2447568).
2/12/2011 12:01:35 AM, information: Windows File Protection [64021] - The system file c:\windows\system32\inetsloc.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
2/12/2011 12:01:20 AM, information: Windows File Protection [64021] - The system file c:\windows\system32\inetsrv\inetmgr.exe could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
2/12/2011 12:01:13 AM, information: Windows File Protection [64021] - The system file c:\windows\system32\inetsrv\iisui.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
2/12/2011 12:01:04 AM, information: Windows File Protection [64021] - The system file c:\windows\system32\iisrstap.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
2/12/2011 12:00:33 AM, information: Windows File Protection [64021] - The system file c:\windows\system32\iisreset.exe could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
2/12/2011 12:00:08 AM, information: Windows File Protection [64021] - The system file c:\windows\system32\ftpsapi2.dll could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
2/12/2011 11:56:18 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Update for Windows XP (KB971029).
2/12/2011 11:55:52 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Update for Internet Explorer 8 Compatibility View List for Windows XP (KB2447568).
2/12/2011 11:50:07 AM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070643: Windows Search 4.0 for Windows XP (KB940157).
2/12/2011 10:22:50 AM, error: DCOM [10005] - DCOM got error "%1058" attempting to start the service MatSvc with arguments "" in order to run the server: {109DB0ED-7C89-416B-AC66-6D0323941464}
2/12/2011 10:15:34 AM, error: Service Control Manager [7023] - The Office Source Engine service terminated with the following error: The wait operation timed out.
2/11/2011 6:11:59 PM, error: DCOM [10016] - The application-specific permission settings do not grant Local Activation permission for the COM Server application with CLSID {BA126AD1-2166-11D1-B1D0-00805FC1270E} to the user NT AUTHORITY\NETWORK SERVICE SID (S-1-5-20). This security permission can be modified using the Component Services administrative tool.
2/11/2011 5:15:52 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB978601).
2/11/2011 5:15:11 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0x80070005: Security Update for Windows XP (KB979309).
2/11/2011 4:18:23 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2387149).
2/11/2011 4:18:12 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB982214).
2/11/2011 4:18:03 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2478971).
2/11/2011 4:17:55 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2259922).
2/11/2011 4:17:46 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Cumulative Security Update for ActiveX Killbits for Windows XP (KB980195).
2/11/2011 4:17:37 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2296011).
2/11/2011 4:17:28 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2485376).
2/11/2011 4:16:55 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2443105).
2/11/2011 4:16:46 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2229593).
2/11/2011 4:16:38 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2440591).
2/11/2011 4:16:29 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB982132).
2/11/2011 4:16:20 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2479628).
2/11/2011 4:16:11 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2347290).
2/11/2011 4:16:03 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2483185).
2/11/2011 4:15:39 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2079403).
2/11/2011 4:09:35 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB979687).
2/11/2011 4:09:26 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2121546).
2/11/2011 4:00:21 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Cumulative Security Update for Internet Explorer 8 for Windows XP (KB2482017).
2/11/2011 3:55:42 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB980436).
2/11/2011 3:55:35 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB981322).
2/11/2011 3:55:01 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2476687).
2/11/2011 3:54:54 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2419632).
2/11/2011 3:54:44 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB979482).
2/11/2011 3:54:37 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB981997).
2/11/2011 3:54:30 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB975562).
2/11/2011 3:44:58 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB982665).
2/11/2011 3:44:52 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2478960).
2/11/2011 3:44:45 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2393802).
2/11/2011 3:44:34 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2423089).
2/11/2011 3:44:25 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB2360937).
2/11/2011 12:21:56 PM, error: Service Control Manager [7000] - The DgiVecp service failed to start due to the following error: The system cannot find the file specified.
2/11/2011 12:21:55 PM, error: WMPNetworkSvc [14324] - Service 'WMPNetworkSvc' did not start correctly because CoCreateInstance(WindowsMediaPlayer) encountered error '0x80004002'. If possible, reinstall Windows Media Player.
2/11/2011 12:05:31 PM, error: Service Control Manager [7023] - The HIPS Policy Manager service terminated with the following error: Unspecified error
2/11/2011 11:59:34 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB980232).
2/11/2011 11:59:34 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB978542).
2/11/2011 11:59:27 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Update for Windows XP (KB955759).
2/11/2011 11:59:27 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB973904).
2/11/2011 11:59:17 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB974392).
2/11/2011 11:59:17 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB974318).
2/11/2011 11:59:10 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Update for Windows XP (KB968389).
2/11/2011 11:59:10 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB969059).
2/11/2011 11:59:04 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB974112).
2/11/2011 11:59:04 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB958869).
2/11/2011 11:58:59 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB974571).
2/11/2011 11:58:55 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Jscript 5.8 for Windows XP (KB971961).
2/11/2011 11:58:49 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB971657).
2/11/2011 11:58:49 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB956844).
2/11/2011 11:58:42 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB973815).
2/11/2011 11:58:42 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB960859).
2/11/2011 11:58:35 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB973507).
2/11/2011 11:58:35 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB956744).
2/11/2011 11:58:28 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Update for Windows XP (KB961118).
2/11/2011 11:58:28 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB973869).
2/11/2011 11:57:56 PM, information: Windows File Protection [64018] - Windows File Protection file scan was cancelled by user interaction, user name is Paul.
2/11/2011 11:57:48 PM, information: Windows File Protection [64021] - The system file c:\windows\system32\inetsrv\certmap.ocx could not be copied into the DLL cache. The specific error code is 0x000004c7 [The operation was canceled by the user. ]. This file is necessary to maintain system stability.
2/11/2011 11:57:27 PM, information: Windows File Protection [64016] - Windows File Protection file scan was started.
2/11/2011 11:18:02 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB978601).
2/11/2011 11:18:01 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB979309).
2/11/2011 10:43:28 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB981332).
2/11/2011 10:43:28 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB978338).
2/11/2011 10:43:22 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Update for Windows XP (KB976662).
2/11/2011 10:43:22 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB977816).
2/11/2011 10:43:15 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB978706).
2/11/2011 10:43:15 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB977914).
2/11/2011 10:43:10 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB975560).
2/11/2011 10:43:04 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB975713).
2/11/2011 10:42:58 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Update for Windows XP (KB973687).
2/11/2011 10:42:58 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB972270).
2/11/2011 10:42:53 PM, error: Windows Update Agent [20] - Installation Failure: Windows failed to install the following update with error 0xd0000156: Security Update for Windows XP (KB975025).

==== End Of File ===========================




Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 1:09:18 PM, on 2/12/2011
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\svchost.exe
c:\WINDOWS\system32\ZuneBusEnum.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Google\Chrome\Application\chrome.exe
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\Program Files\Internet Explorer\IEXPLORE.EXE
C:\WINDOWS\system32\msiexec.exe
C:\Program Files\Trend Micro\HijackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaul…//www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Windows Internet Explorer provided by Yahoo!
O1 - Hosts: ::1 localhost
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG10\avgssie.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/su/ocx/15026/CTSUEng.cab
O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5) - http://upload.facebook.com/controls/Facebo…toUploader5.cab
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} (PCPitstop Utility) - http://www.pcpitstop.com/pcpitstop/PCPitStop.CAB
O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.5.107.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1006.cab
O16 - DPF: {5ED80217-570B-4DA9-BF44-BE107C0EC166} (Windows Live Safety Center Base Module) - http://cdn.scan.onecare.live.com/resource/…lscbase6886.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/Facebo…otoUploader.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1297462594453
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {A18962F6-E6ED-40B1-97C9-1FB36F38BFA8} (Aurigma Image Uploader 3.5 Control) - http://meijer.lifepics.com/net/Uploader/ImageUploader3.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/su/ocx/15026/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{437C9847-8B3A-433A-BB2D-52230D8E6687}: NameServer = 216.68.4.10,216.68.5.10
O17 - HKLM\System\CCS\Services\Tcpip\..\{7ED12615-84F6-4CC6-9A8A-61F6251956C1}: NameServer = 4.2.2.2,4.2.2.1
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Program Files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG10\avgpp.dll
O18 - Filter hijack: text/html - {9c4a0df6-c730-4128-bfe9-bb07e8f1102a} - (no file)
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

–
End of file - 6424 bytes
Hello SNiemoelle and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem. Please read the following guidelines which will help to make cleaning your machine easier:
• Please do not install/uninstall any programs unless asked to.
• Please do not run any scans other than those requested
• Please follow all instructions in the order posted
• Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
• If you don't understand something, please don't hesitate to ask for clarification before proceeding
• The fixes are specific to your problem and should only be used for this issue on this machine.
• Please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!
Please note that I am still in training and my replies need to be checked by an expert in order for you to receive the best possible advice. This may result in a small delay between my posts but I shall try to keep this to a minimum.

I am looking through your logs now and will reply as soon as possible.

Satchfan
Hello again SNiemoelle

Run HijackThis

Open HijackThis and click Do a system scan only.

Place a check mark next to:

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O18 - Filter hijack: text/html - {9c4a0df6-c730-4128-bfe9-bb07e8f1102a} - (no file)


Close all windows except for HijackThis and click Fix checked.


Download and run ComboFix

Download ComboFix from the following location:

Link

* IMPORTANT !!! Save ComboFix.exe to your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools
  • See this Link for programs that need to be disabled and instruction on how to disable them.
  • Remember to re-enable them when we're done.
  • Double click on ComboFix.exe & follow the prompts.
  • As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
  • Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.

    **Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue its malware removal procedures.

    [external image: Posted Image]


    Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:

    [external image: Posted Image]


    Click on Yes, to continue scanning for malware.
Note: Do not mouse-click combofix's window while it is running. That may cause it to stall.

When finished, it will produce a log. Please include the ComboFix.txt in your next reply. It can be found at C:\ComboFix.txt

Satchfan
Windows is still not updating. Below is the combofix log:


ComboFix 11-02-13.03 - Paul 02/14/2011 9:26.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1748 [GMT -5:00]
Running from: c:\documents and settings\[removed]\My Documents\Downloads\ComboFix.exe
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}
AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\documents and settings\Paul\Application Data\iniasd.txt
c:\documents and settings\Paul\Cookies\ezanepig.db
c:\documents and settings\Paul\Cookies\mecubu.dl
c:\documents and settings\Paul\Cookies\riquwaw.com
c:\windows\bf23567.dat
c:\windows\jmmark2.dat
c:\windows\mocu.dll
c:\windows\search_res.txt
c:\windows\settings.reg
c:\windows\system32\Data
c:\windows\ufufyjy.scr

c:\windows\system32\proquota.exe was missing
Restored copy from - c:\windows\ServicePackFiles\i386\proquota.exe

.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.

——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
——-\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}


((((((((((((((((((((((((( Files Created from 2011-01-14 to 2011-02-14 )))))))))))))))))))))))))))))))
.

2011-02-14 14:31 . 2008-04-14 00:12 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2011-02-13 18:35 . 2011-01-13 06:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2011-02-13 18:35 . 2011-01-13 06:41 5890896 —-a-w- c:\documents and settings\All Users\Application Data\Microsoft\Microsoft Antimalware\Definition Updates\{B34F15AE-7A05-4340-A292-ED256C383225}\mpengine.dll
2011-02-13 18:32 . 2011-02-13 18:32 ——– d—–w- c:\program files\Microsoft Security Client
2011-02-13 17:57 . 2011-02-13 17:57 ——– d—–w- c:\documents and settings\Steve
2011-02-13 16:52 . 2011-02-13 16:52 ——– d—–w- c:\program files\ESET
2011-02-13 05:01 . 2010-10-19 20:51 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-02-12 18:08 . 2011-02-12 18:08 388096 —-a-r- c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-12 17:59 . 2011-02-12 17:59 ——– d—–w- c:\program files\Trend Micro
2011-02-12 17:35 . 2011-02-13 04:34 ——– d—–w- c:\documents and settings\Paul\Local Settings\Application Data\ApplicationHistory
2011-02-12 16:54 . 2011-02-12 16:54 ——– d—–w- c:\windows\system32\winrm
2011-02-12 16:54 . 2011-02-12 16:54 ——– d—–w- c:\windows\system32\GroupPolicy
2011-02-12 16:54 . 2011-02-12 16:55 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-02-12 16:46 . 2011-02-12 16:46 ——– d—–w- c:\windows\system32\URTTEMP
2011-02-12 16:15 . 2011-02-12 16:15 ——– d—–w- c:\program files\Windows Resource Kits
2011-02-12 14:48 . 2009-08-07 00:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-02-12 10:10 . 2010-11-09 18:56 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-02-12 10:10 . 2010-11-09 18:56 27984 —-a-w- c:\windows\system32\sbbd.exe
2011-02-12 10:09 . 2011-02-12 13:30 ——– d—–w- C:\VIPRERESCUE
2011-02-12 04:23 . 2011-02-12 04:23 ——– d—–w- c:\documents and settings\Paul\Application Data\Malwarebytes
2011-02-12 04:23 . 2009-01-04 23:38 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-12 04:23 . 2009-01-04 23:39 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-12 04:23 . 2011-02-12 04:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-12 04:23 . 2011-02-12 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-12 03:31 . 2011-02-14 14:11 ——– d—–w- c:\windows\system32\CatRoot2
2011-02-12 03:00 . 2011-02-13 14:40 ——– d—–w- c:\program files\Windows Live Safety Center
2011-02-12 02:17 . 2011-02-12 02:17 ——– d—–w- c:\program files\CCleaner
2011-02-12 00:01 . 2011-02-12 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-02-12 00:01 . 2011-02-12 00:03 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-02-11 23:12 . 2011-02-11 23:12 ——– d—–w- c:\documents and settings\Paul\Local Settings\Application Data\FixItCenter
2011-02-11 23:09 . 2011-02-11 23:09 ——– d—–w- c:\windows\MATS
2011-02-11 23:09 . 2011-02-11 23:09 ——– d—–w- c:\program files\Microsoft Fix it Center
2011-02-11 18:29 . 2011-02-11 18:29 ——– d—–w- C:\$AVG
2011-02-11 17:29 . 2011-02-11 17:29 ——– d—–w- c:\documents and settings\Paul\Application Data\AVG10
2011-02-11 17:28 . 2011-02-11 17:28 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-02-11 17:27 . 2011-02-14 14:00 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG10
2011-02-11 17:20 . 2011-02-11 17:26 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-09-30 06:30 . 2009-09-30 06:30 16965 —-a-w- c:\program files\Common Files\neho.com
2009-09-30 06:30 . 2009-09-30 06:30 11246 —-a-w- c:\program files\Common Files\lekawavaho.sys
2009-09-29 20:28 . 2009-09-29 20:28 19086 —-a-w- c:\program files\Common Files\finuwiqy.sys
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

——- Sigcheck ——-

[7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
[7] 2008-10-15 . 9D3DB9ADFABD2F0BC778EC03250A3ABB . 633632 . . [7.00.6000.16762] . . c:\windows\SoftwareDistribution.old\Download\1aada90d3aca2362b0231ac90aa9a9fd\SP2GDR\iexplore.exe
[7] 2008-10-15 . 056C927CF7207857E8B34F7A8FFD9B9E . 633632 . . [7.00.6000.20935] . . c:\windows\SoftwareDistribution.old\Download\1aada90d3aca2362b0231ac90aa9a9fd\SP2QFE\iexplore.exe
[7] 2008-06-23 . C52A9EF571E91535EB78DB4B8B95EA07 . 625664 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[7] 2008-04-22 . 197B7E4030CFBD8D2979D375E1787AA2 . 625664 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[7] 2008-04-22 . 232B22817B90AE0AFF2D189E3E3735AC . 625664 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\iexplore.exe
[7] 2008-04-14 . 55794B97A7FAABD2910873C85274F409 . 93184 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\iexplore.exe
[7] 2008-02-29 . 2D0E5592AB5A46C27DAF7CCAFF4F5B59 . 625664 . . [7.00.6000.16640] . . c:\windows\ie7updates\KB950759-IE7\iexplore.exe
[7] 2008-02-22 . 6E0888626E0CAC79F57149814E22DB4D . 625664 . . [7.00.6000.20772] . . c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[7] 2007-12-06 . 2703D940A62B731AA220529DD7331A78 . 625664 . . [7.00.6000.16608] . . c:\windows\ie7updates\KB947864-IE7\iexplore.exe
[7] 2007-12-06 . 809D17D8FA0FDAEE07778CD821CAFFDE . 625664 . . [7.00.6000.20733] . . c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[7] 2007-10-10 . E854D02E4231F704D9BE782A424E6D8B . 625152 . . [7.00.6000.16574] . . c:\windows\ie7updates\KB944533-IE7\iexplore.exe
[7] 2007-10-10 . 632BDE0179847234433CA50945442ACB . 625664 . . [7.00.6000.20696] . . c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[7] 2007-08-17 . 3AC2BC667DA0AF2C968E96E1630F5AB5 . 625152 . . [7.00.6000.16544] . . c:\windows\ie7updates\KB942615-IE7\iexplore.exe
[7] 2007-08-17 . 5577D0E3AC2F9F035ACD81B44AF5F511 . 625152 . . [7.00.6000.20661] . . c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[7] 2007-06-27 . BD8502DFD53FC24FB8D6929DC46B8C2C . 625152 . . [7.00.6000.20627] . . c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[7] 2007-06-27 . 275CEE268B9E5D82474C43D5D249D111 . 625152 . . [7.00.6000.16512] . . c:\windows\ie7updates\KB939653-IE7\iexplore.exe
[7] 2007-04-24 . 10BDB55982586A432A3951EB19A26009 . 625152 . . [7.00.6000.16473] . . c:\windows\ie7updates\KB937143-IE7\iexplore.exe
[7] 2007-04-24 . 9B3516C1F30DA17ADD3818573047D63C . 625152 . . [7.00.6000.20583] . . c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[7] 2007-02-28 . D321092F8529CDAE843D6E24E3CAC6CB . 625152 . . [7.00.6000.20544] . . c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[7] 2007-02-21 . 683DDE71BCF03B501B912D20CB93B549 . 623616 . . [7.00.6000.16441] . . c:\windows\ie7updates\KB933566-IE7\iexplore.exe
[7] 2007-01-08 . 93A6A4F5293AE19E3B37021AABCF0902 . 623616 . . [7.00.6000.16414] . . c:\windows\ie7updates\KB931768-IE7\iexplore.exe
[7] 2006-10-17 . 5334D4461AA92A7B008755FE6D13C5F2 . 622080 . . [7.00.5730.11] . . c:\windows\ie7updates\KB928090-IE7\iexplore.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2010-11-30 997408]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lexmark X125 Settings Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lexmark X125 Settings Utility.lnk
backup=c:\windows\pss\Lexmark X125 Settings Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
2006-11-07 22:22 972432 —-a-w- c:\program files\IGN\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMPDPSRV]
2002-09-05 14:05 45056 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\LMpdpsrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-03-18 22:50 4363504 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 17:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 17:22 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 17:22 1622016 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-05-27 14:50 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
2006-03-30 20:45 313472 —-a-r- c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-01-07 18:38 158448 —-a-w- c:\program files\Zune\ZuneLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneNetworkSvc"=2 (0x2)
"WMPNetworkSvc"=2 (0x2)
"ose"=2 (0x2)
"NVSvc"=2 (0x2)
"MatSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"gupdate1cac49c2c87f8b2"=2 (0x2)
"avgwd"=2 (0x2)
"AVGIDSAgent"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\LMpdpsrv.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2/12/2011 5:10 AM 98392]
R3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [3/20/2006 5:34 PM 1452032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 USBFVNETR;NETGEAR MA101 USB Adapter;c:\windows\system32\drivers\ma101rnd.sys [9/27/2008 1:02 PM 80000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2/28/2006 7:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 gupdate1cac49c2c87f8b2;Google Update Service (gupdate1cac49c2c87f8b2);c:\program files\Google\Update\GoogleUpdate.exe [3/15/2010 7:03 PM 133104]
S4 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [11/16/2010 1:10 AM 267568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder

2011-02-14 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 00:03]

2011-02-13 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 00:03]

2011-02-13 c:\windows\Tasks\MP Scheduled Scan.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 17:26]

2011-02-14 c:\windows\Tasks\MpIdleTask.job
- c:\program files\Microsoft Security Client\Antimalware\MpCmdRun.exe [2010-11-11 17:26]

2011-02-14 c:\windows\Tasks\User_Feed_Synchronization-{DC333751-AC4B-41F6-9B39-8B9D4F00AF85}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: fanball.com\www
TCP: {437C9847-8B3A-433A-BB2D-52230D8E6687} = 216.68.4.10,216.68.5.10
TCP: {7ED12615-84F6-4CC6-9A8A-61F6251956C1} = 4.2.2.2,4.2.2.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\ppr7rmp1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
.
- - - - ORPHANS REMOVED - - - -

Notify-AtiExtEvent - (no file)
SafeBoot-WudfPf
SafeBoot-WudfRd
MSConfigStartUp-AVG_TRAY - c:\program files\AVG\AVG10\avgtray.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-14 10:21
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-861567501-839522115-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:16,9c,44,0c,6a,c0,5f,7a,97,03,ad,c1,c1,ca,df,4b,e2,1b,25,db,5f,5c,cc,
ad,5c,51,01,3a,67,97,da,c5,cd,94,ac,05,13,29,a7,3a,88,61,da,78,73,2f,92,33,\
"??"=hex:85,c2,38,54,52,62,f7,21,b7,91,9d,42,a7,94,e8,6a
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(540)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\ZuneBusEnum.exe
.
**************************************************************************
.
Completion time: 2011-02-14 10:30:11 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-14 15:30

Pre-Run: 14,858,133,504 bytes free
Post-Run: 17,329,123,328 bytes free

WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
[spybotsd]
timeout.old=30

- - End Of File - - 03186A331CFC9A99BA83D3149F55B655
Hi SNiemoelle

Submit files to VirusTotal

There are files on your computer that need to be checked further.

Go to VirusTotal and submit these files for analysis:

c:\program files\common files\lekawavaho.sys
c:\program files\common files\finuwiqy.sys

1. Click on Browse
2. Click on the arrow and choose Local Disc (C:)
🖼Click to load external image (Posted Image)
3. Below, double-click on Program Files
4. Double-click on the Common Filesfolder
5. Locate the file lekawavaho.sys, click on it and then on Open
6. Click on Send File.
You will get a report back, post the report into this thread for me to see.

Repeat the steps above and this time at step 5, choose finuwiqy.sys

Satchfan
0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: lekawavaho.sys Submission date: 2011-02-16 14:14:23 (UTC) Current status: finished Result: 0/ 43 (0.0%) 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is goodware. 0 VT Community user(s) with a total of 0 reputation credit(s) say(s) this sample is malware. File name: finuwiqy.sys Submission date: 2011-02-16 14:18:28 (UTC) Current status: finished Result: 0/ 43 (0.0%)
Hi SNiemoelle

P2P - I see you have P2P software, (uTorrent, ), installed on your machine. We are not here to pass judgment on file-sharing as a concept. However, we will warn you that engaging in this activity and having this kind of software installed on your machine will always make you more susceptible to re-infection. If your computer is infected, it almost certainly contributed to your current situation.

Please note: Even if you are using a "safe" P2P program, it is only the program that is safe. You will be sharing files from uncertified sources, and these are more often than not, infected. The bad guys use P2P file-sharing as a major conduit to spread their wares.

Please see this topic for more information:

Perils of P2P File Sharing.

I would strongly recommend that you uninstall it now. You can do so via Control Panel, Add/Remove programs.

Should you decide to keep it, please don’t use it until we have finished up here.

===================================================

There are some signs of infection on your computer but we’ll need to do some more scans to see if there are more.


Open ComboFix

Please do the following:• Close any open browsers.
• Close/disable all anti virus and anti malware programs so that they do not interfere with the running of ComboFix.
• Open notepad and copy/paste the text in the codebox below into it:
File::
c:\program files\common files\neho.com
c:\program files\common files\lekawavaho.sys
c:\program files\common files\finuwiqy.sys
c:\Windows\System32\CatRoot2\edb.log

DirLook::
C:\Window\System32\Wbem

DDS::
TB: {E1BACF55-35E1-4E47-9247-2D48660E5545}
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_07-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_17-windows-i586.cab

Save this as "CFScript.txt", and as Type: All Files (*.*) in the same location as ComboFix.exe

[external image: Posted Image]

Referring to the picture above, drag CFScript into ComboFix.exe

When finished, it produces a log at C:\ComboFix.txt. Post the contents of Combofix.txt in your next reply.


Run TDSSKiller

Please read carefully and follow these steps.
  • download TDSSKiller and save it to your Desktop
  • extract its contents to your desktop
  • once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan

    if an infected file is detected, ensure Cure is selected,then click on Continue
    if a suspicious file is detected, the default action will be Skip, click on Continue

  • it may ask you to reboot the computer to complete the process. Click on Reboot Now
  • if no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here
  • if a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.
When you've done this, try updating Windows again and post back with the ComboFix and TDSSKiller logs. Also let me know if there are any other issues.

Thanks

Satchfan
Still unable to update. Removed utorrent. Please find the logs below:


ComboFix 11-02-15.04 - Paul 02/16/2011 10:53:20.2.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.2047.1592 [GMT -5:00]
Running from: c:\documents and settings\[removed]\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Paul\Desktop\CFScript.txt
AV: AVG Anti-Virus Free Edition 2011 *Enabled/Updated* {17DDD097-36FF-435F-9E1B-52D74245D6BF}

FILE ::
"c:\program files\common files\finuwiqy.sys"
"c:\program files\common files\lekawavaho.sys"
"c:\program files\common files\neho.com"
"c:\windows\System32\CatRoot2\edb.log"
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\common files\finuwiqy.sys
c:\program files\common files\lekawavaho.sys
c:\program files\common files\neho.com
c:\windows\System32\CatRoot2\edb.log

.
((((((((((((((((((((((((( Files Created from 2011-01-16 to 2011-02-16 )))))))))))))))))))))))))))))))
.

2011-02-14 14:31 . 2008-04-14 00:12 50176 -c–a-w- c:\windows\system32\dllcache\proquota.exe
2011-02-14 14:31 . 2008-04-14 00:12 50176 —-a-w- c:\windows\system32\proquota.exe
2011-02-13 17:57 . 2011-02-13 17:57 ——– d—–w- c:\documents and settings\Steve
2011-02-13 16:52 . 2011-02-13 16:52 ——– d—–w- c:\program files\ESET
2011-02-13 05:01 . 2010-10-19 20:51 222080 ——w- c:\windows\system32\MpSigStub.exe
2011-02-12 18:08 . 2011-02-12 18:08 388096 —-a-r- c:\documents and settings\Paul\Application Data\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2011-02-12 17:59 . 2011-02-12 17:59 ——– d—–w- c:\program files\Trend Micro
2011-02-12 17:35 . 2011-02-13 04:34 ——– d—–w- c:\documents and settings\Paul\Local Settings\Application Data\ApplicationHistory
2011-02-12 16:54 . 2011-02-16 15:45 ——– d–h–w- c:\windows\system32\GroupPolicy
2011-02-12 16:54 . 2011-02-12 16:54 ——– d—–w- c:\windows\system32\winrm
2011-02-12 16:54 . 2011-02-12 16:55 ——– dc-h–w- c:\windows\$968930Uinstall_KB968930$
2011-02-12 16:46 . 2011-02-12 16:46 ——– d—–w- c:\windows\system32\URTTEMP
2011-02-12 16:15 . 2011-02-12 16:15 ——– d—–w- c:\program files\Windows Resource Kits
2011-02-12 14:48 . 2009-08-07 00:23 274288 —-a-w- c:\windows\system32\mucltui.dll
2011-02-12 10:10 . 2010-11-09 18:56 98392 —-a-w- c:\windows\system32\drivers\SBREDrv.sys
2011-02-12 10:10 . 2010-11-09 18:56 27984 —-a-w- c:\windows\system32\sbbd.exe
2011-02-12 10:09 . 2011-02-12 13:30 ——– d—–w- C:\VIPRERESCUE
2011-02-12 04:23 . 2011-02-12 04:23 ——– d—–w- c:\documents and settings\Paul\Application Data\Malwarebytes
2011-02-12 04:23 . 2009-01-04 23:38 15504 —-a-w- c:\windows\system32\drivers\mbam.sys
2011-02-12 04:23 . 2009-01-04 23:39 38496 —-a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2011-02-12 04:23 . 2011-02-12 04:23 ——– d—–w- c:\program files\Malwarebytes' Anti-Malware
2011-02-12 04:23 . 2011-02-12 04:23 ——– d—–w- c:\documents and settings\All Users\Application Data\Malwarebytes
2011-02-12 03:31 . 2011-02-16 16:07 ——– d—–w- c:\windows\system32\CatRoot2
2011-02-12 03:00 . 2011-02-13 14:40 ——– d—–w- c:\program files\Windows Live Safety Center
2011-02-12 02:17 . 2011-02-12 02:17 ——– d—–w- c:\program files\CCleaner
2011-02-12 00:01 . 2011-02-12 02:22 ——– d—–w- c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2011-02-12 00:01 . 2011-02-12 00:03 ——– d—–w- c:\program files\Spybot - Search & Destroy
2011-02-11 23:12 . 2011-02-11 23:12 ——– d—–w- c:\documents and settings\Paul\Local Settings\Application Data\FixItCenter
2011-02-11 23:09 . 2011-02-11 23:09 ——– d—–w- c:\windows\MATS
2011-02-11 23:09 . 2011-02-11 23:09 ——– d—–w- c:\program files\Microsoft Fix it Center
2011-02-11 18:29 . 2011-02-11 18:29 ——– d—–w- C:\$AVG
2011-02-11 17:29 . 2011-02-11 17:29 ——– d—–w- c:\documents and settings\Paul\Application Data\AVG10
2011-02-11 17:28 . 2011-02-11 17:28 ——– d–h–w- c:\documents and settings\All Users\Application Data\Common Files
2011-02-11 17:27 . 2011-02-14 14:00 ——– d—–w- c:\documents and settings\All Users\Application Data\AVG10
2011-02-11 17:20 . 2011-02-11 17:26 ——– d—–w- c:\documents and settings\All Users\Application Data\MFAData

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-01 21:02 . 2009-05-01 21:02 1044480 —-a-w- c:\program files\mozilla firefox\plugins\libdivx.dll
2009-05-01 21:02 . 2009-05-01 21:02 200704 —-a-w- c:\program files\mozilla firefox\plugins\ssldivx.dll
.

(((((((((((((((((((((((((((((((((((((((((((( Look )))))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
—- Directory of c:\window\System32\Wbem —-



——- Sigcheck ——-

[7] 2009-03-08 . B60DDDD2D63CE41CB8C487FCFBB6419E . 638816 . . [8.00.6001.18702] . . c:\windows\system32\dllcache\iexplore.exe
[7] 2008-10-15 . 9D3DB9ADFABD2F0BC778EC03250A3ABB . 633632 . . [7.00.6000.16762] . . c:\windows\SoftwareDistribution.old\Download\1aada90d3aca2362b0231ac90aa9a9fd\SP2GDR\iexplore.exe
[7] 2008-10-15 . 056C927CF7207857E8B34F7A8FFD9B9E . 633632 . . [7.00.6000.20935] . . c:\windows\SoftwareDistribution.old\Download\1aada90d3aca2362b0231ac90aa9a9fd\SP2QFE\iexplore.exe
[7] 2008-06-23 . C52A9EF571E91535EB78DB4B8B95EA07 . 625664 . . [7.00.6000.20861] . . c:\windows\$hf_mig$\KB953838-IE7\SP2QFE\iexplore.exe
[7] 2008-04-22 . 197B7E4030CFBD8D2979D375E1787AA2 . 625664 . . [7.00.6000.20815] . . c:\windows\$hf_mig$\KB950759-IE7\SP2QFE\iexplore.exe
[7] 2008-04-22 . 232B22817B90AE0AFF2D189E3E3735AC . 625664 . . [7.00.6000.16674] . . c:\windows\ie7updates\KB953838-IE7\iexplore.exe
[7] 2008-04-14 . 55794B97A7FAABD2910873C85274F409 . 93184 . . [6.00.2900.5512] . . c:\windows\ServicePackFiles\i386\iexplore.exe
[7] 2008-02-29 . 2D0E5592AB5A46C27DAF7CCAFF4F5B59 . 625664 . . [7.00.6000.16640] . . c:\windows\ie7updates\KB950759-IE7\iexplore.exe
[7] 2008-02-22 . 6E0888626E0CAC79F57149814E22DB4D . 625664 . . [7.00.6000.20772] . . c:\windows\$hf_mig$\KB947864-IE7\SP2QFE\iexplore.exe
[7] 2007-12-06 . 2703D940A62B731AA220529DD7331A78 . 625664 . . [7.00.6000.16608] . . c:\windows\ie7updates\KB947864-IE7\iexplore.exe
[7] 2007-12-06 . 809D17D8FA0FDAEE07778CD821CAFFDE . 625664 . . [7.00.6000.20733] . . c:\windows\$hf_mig$\KB944533-IE7\SP2QFE\iexplore.exe
[7] 2007-10-10 . E854D02E4231F704D9BE782A424E6D8B . 625152 . . [7.00.6000.16574] . . c:\windows\ie7updates\KB944533-IE7\iexplore.exe
[7] 2007-10-10 . 632BDE0179847234433CA50945442ACB . 625664 . . [7.00.6000.20696] . . c:\windows\$hf_mig$\KB942615-IE7\SP2QFE\iexplore.exe
[7] 2007-08-17 . 3AC2BC667DA0AF2C968E96E1630F5AB5 . 625152 . . [7.00.6000.16544] . . c:\windows\ie7updates\KB942615-IE7\iexplore.exe
[7] 2007-08-17 . 5577D0E3AC2F9F035ACD81B44AF5F511 . 625152 . . [7.00.6000.20661] . . c:\windows\$hf_mig$\KB939653-IE7\SP2QFE\iexplore.exe
[7] 2007-06-27 . BD8502DFD53FC24FB8D6929DC46B8C2C . 625152 . . [7.00.6000.20627] . . c:\windows\$hf_mig$\KB937143-IE7\SP2QFE\iexplore.exe
[7] 2007-06-27 . 275CEE268B9E5D82474C43D5D249D111 . 625152 . . [7.00.6000.16512] . . c:\windows\ie7updates\KB939653-IE7\iexplore.exe
[7] 2007-04-24 . 10BDB55982586A432A3951EB19A26009 . 625152 . . [7.00.6000.16473] . . c:\windows\ie7updates\KB937143-IE7\iexplore.exe
[7] 2007-04-24 . 9B3516C1F30DA17ADD3818573047D63C . 625152 . . [7.00.6000.20583] . . c:\windows\$hf_mig$\KB933566-IE7\SP2QFE\iexplore.exe
[7] 2007-02-28 . D321092F8529CDAE843D6E24E3CAC6CB . 625152 . . [7.00.6000.20544] . . c:\windows\$hf_mig$\KB931768-IE7\SP2QFE\iexplore.exe
[7] 2007-02-21 . 683DDE71BCF03B501B912D20CB93B549 . 623616 . . [7.00.6000.16441] . . c:\windows\ie7updates\KB933566-IE7\iexplore.exe
[7] 2007-01-08 . 93A6A4F5293AE19E3B37021AABCF0902 . 623616 . . [7.00.6000.16414] . . c:\windows\ie7updates\KB931768-IE7\iexplore.exe
[7] 2006-10-17 . 5334D4461AA92A7B008755FE6D13C5F2 . 622080 . . [7.00.5730.11] . . c:\windows\ie7updates\KB928090-IE7\iexplore.exe

.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WudfSvc]
@="Service"

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Lexmark X125 Settings Utility.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Lexmark X125 Settings Utility.lnk
backup=c:\windows\pss\Lexmark X125 Settings Utility.lnkCommon Startup

[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Logitech Desktop Messenger.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Logitech Desktop Messenger.lnk
backup=c:\windows\pss\Logitech Desktop Messenger.lnkCommon Startup

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ctfmon.exe]
2008-04-14 00:12 15360 —-a-w- c:\windows\system32\ctfmon.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\igndlm.exe]
2006-11-07 22:22 972432 —-a-w- c:\program files\IGN\Download Manager\DLM.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LMPDPSRV]
2002-09-05 14:05 45056 —-a-w- c:\windows\system32\spool\drivers\w32x86\3\LMpdpsrv.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Messenger (Yahoo!)]
2009-03-18 22:50 4363504 —-a-w- c:\program files\Yahoo!\Messenger\YahooMessenger.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon]
2006-10-22 17:22 7700480 —-a-w- c:\windows\system32\nvcpl.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter]
2006-10-22 17:22 86016 —-a-w- c:\windows\system32\nvmctray.dll

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz]
2006-10-22 17:22 1622016 —-a-w- c:\windows\system32\nwiz.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task]
2008-05-27 14:50 413696 —-a-w- c:\program files\QuickTime\QTTask.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer]
2009-03-05 21:07 2260480 –sha-r- c:\program files\Spybot - Search & Destroy\TeaTimer.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr]
2006-03-30 20:45 313472 —-a-r- c:\program files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Zune Launcher]
2010-01-07 18:38 158448 —-a-w- c:\program files\Zune\ZuneLauncher.exe

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"ZuneNetworkSvc"=2 (0x2)
"WMPNetworkSvc"=2 (0x2)
"ose"=2 (0x2)
"NVSvc"=2 (0x2)
"MatSvc"=3 (0x3)
"JavaQuickStarterService"=2 (0x2)
"idsvc"=3 (0x3)
"IDriverT"=3 (0x3)
"gupdate1cac49c2c87f8b2"=2 (0x2)
"avgwd"=2 (0x2)
"AVGIDSAgent"=2 (0x2)

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\WINDOWS\\system32\\spool\\drivers\\w32x86\\3\\LMpdpsrv.exe"=
"c:\\Program Files\\AIM\\aim.exe"=
"c:\\Program Files\\Warcraft III\\Warcraft III.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YahooMessenger.exe"=
"c:\\Program Files\\Logitech\\Desktop Messenger\\8876480\\Program\\LogitechDesktopMessenger.exe"=
"c:\\Program Files\\Logitech\\Logitech Harmony Remote Software 7\\HarmonyRemote.exe"=
"c:\\Program Files\\Ventrilo\\Ventrilo.exe"=
"c:\\Program Files\\World of Warcraft\\WoW-3.2.0-enUS-downloader.exe"=
"c:\\Program Files\\World of Warcraft\\Launcher.exe"=
"c:\\Program Files\\World of Warcraft\\BackgroundDownloader.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"3724:TCP"= 3724:TCP:Blizzard Downloader: 3724
"5985:TCP"= 5985:TCP:*:Disabled:Windows Remote Management

R1 SBRE;SBRE;c:\windows\system32\drivers\SBREDrv.sys [2/12/2011 5:10 AM 98392]
R3 p17filt;p17filt;c:\windows\system32\drivers\p17filt.sys [3/20/2006 5:34 PM 1452032]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3/18/2010 1:16 PM 130384]
S3 USBFVNETR;NETGEAR MA101 USB Adapter;c:\windows\system32\drivers\ma101rnd.sys [9/27/2008 1:02 PM 80000]
S3 WinRM;Windows Remote Management (WS-Management);c:\windows\system32\svchost.exe -k WINRM [2/28/2006 7:00 AM 14336]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;c:\windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe [3/18/2010 1:16 PM 753504]
S4 gupdate1cac49c2c87f8b2;Google Update Service (gupdate1cac49c2c87f8b2);c:\program files\Google\Update\GoogleUpdate.exe [3/15/2010 7:03 PM 133104]
S4 MatSvc;Microsoft Automated Troubleshooting Service;c:\program files\Microsoft Fix it Center\Matsvc.exe [11/16/2010 1:10 AM 267568]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
WINRM REG_MULTI_SZ WINRM
.
Contents of the 'Scheduled Tasks' folder

2011-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 00:03]

2011-02-16 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-03-16 00:03]

2011-02-16 c:\windows\Tasks\User_Feed_Synchronization-{DC333751-AC4B-41F6-9B39-8B9D4F00AF85}.job
- c:\windows\system32\msfeedssync.exe [2006-10-17 08:31]
.
.
——- Supplementary Scan ——-
.
uSearchURL,(Default) = hxxp://us.rd.yahoo.com/customize/ie/defaults/su/msgr9/*http://www.yahoo.com
IE: E&xport; to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
Trusted Zone: fanball.com\www
TCP: {437C9847-8B3A-433A-BB2D-52230D8E6687} = 216.68.4.10,216.68.5.10
TCP: {7ED12615-84F6-4CC6-9A8A-61F6251956C1} = 4.2.2.2,4.2.2.1
Handler: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - c:\program files\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
FF - ProfilePath - c:\documents and settings\Paul\Application Data\Mozilla\Firefox\Profiles\ppr7rmp1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.com/
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2011-02-16 11:09
Windows 5.1.2600 Service Pack 3 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …

scan completed successfully
hidden files: 0

**************************************************************************
.
——————— LOCKED REGISTRY KEYS ———————

[HKEY_USERS\S-1-5-21-861567501-839522115-725345543-1003\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
@Allowed: (Read) (RestrictedCode)
@Allowed: (Read) (RestrictedCode)
"??"=hex:16,9c,44,0c,6a,c0,5f,7a,97,03,ad,c1,c1,ca,df,4b,e2,1b,25,db,5f,5c,cc,
ad,5c,51,01,3a,67,97,da,c5,cd,94,ac,05,13,29,a7,3a,88,61,da,78,73,2f,92,33,\
"??"=hex:85,c2,38,54,52,62,f7,21,b7,91,9d,42,a7,94,e8,6a
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'explorer.exe'(2992)
c:\windows\system32\WININET.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
.
———————— Other Running Processes ————————
.
c:\windows\system32\msiexec.exe
c:\windows\system32\ZuneBusEnum.exe
.
**************************************************************************
.
Completion time: 2011-02-16 11:15:45 - machine was rebooted
ComboFix-quarantined-files.txt 2011-02-16 16:15
ComboFix2.txt 2011-02-14 15:30

Pre-Run: 17,345,404,928 bytes free
Post-Run: 17,325,645,824 bytes free

- - End Of File - - 214243F1DAEC28919193C1E8EADD830D


2011/02/16 11:26:20.0718 2728 TDSS rootkit removing tool 2.4.17.0 Feb 10 2011 11:07:20
2011/02/16 11:26:20.0828 2728 ================================================================================
2011/02/16 11:26:20.0828 2728 SystemInfo:
2011/02/16 11:26:20.0828 2728
2011/02/16 11:26:20.0828 2728 OS Version: 5.1.2600 ServicePack: 3.0
2011/02/16 11:26:20.0828 2728 Product type: Workstation
2011/02/16 11:26:20.0828 2728 ComputerName: P
2011/02/16 11:26:20.0828 2728 UserName: Paul
2011/02/16 11:26:20.0828 2728 Windows directory: C:\WINDOWS
2011/02/16 11:26:20.0828 2728 System windows directory: C:\WINDOWS
2011/02/16 11:26:20.0828 2728 Processor architecture: Intel x86
2011/02/16 11:26:20.0828 2728 Number of processors: 2
2011/02/16 11:26:20.0828 2728 Page size: 0x1000
2011/02/16 11:26:20.0828 2728 Boot type: Normal boot
2011/02/16 11:26:20.0828 2728 ================================================================================
2011/02/16 11:26:20.0968 2728 Initialize success
2011/02/16 11:26:23.0562 2812 ================================================================================
2011/02/16 11:26:23.0562 2812 Scan started
2011/02/16 11:26:23.0562 2812 Mode: Manual;
2011/02/16 11:26:23.0562 2812 ================================================================================
2011/02/16 11:26:24.0515 2812 ACPI (8fd99680a539792a30e97944fdaecf17) C:\WINDOWS\system32\DRIVERS\ACPI.sys
2011/02/16 11:26:24.0578 2812 ACPIEC (9859c0f6936e723e4892d7141b1327d5) C:\WINDOWS\system32\drivers\ACPIEC.sys
2011/02/16 11:26:24.0640 2812 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys
2011/02/16 11:26:24.0687 2812 AFD (7e775010ef291da96ad17ca4b17137d7) C:\WINDOWS\System32\drivers\afd.sys
2011/02/16 11:26:24.0750 2812 agp440 (08fd04aa961bdc77fb983f328334e3d7) C:\WINDOWS\system32\DRIVERS\agp440.sys
2011/02/16 11:26:25.0046 2812 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys
2011/02/16 11:26:25.0078 2812 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys
2011/02/16 11:26:25.0125 2812 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys
2011/02/16 11:26:25.0171 2812 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys
2011/02/16 11:26:25.0218 2812 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys
2011/02/16 11:26:25.0281 2812 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys
2011/02/16 11:26:25.0343 2812 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys
2011/02/16 11:26:25.0406 2812 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys
2011/02/16 11:26:25.0453 2812 Cdrom (4b0a100eaf5c49ef3cca8c641431eacc) C:\WINDOWS\system32\DRIVERS\cdrom.sys
2011/02/16 11:26:25.0625 2812 ctsfm2k (fcbb8ea6fe935d2c531d3a4dee9f985b) C:\WINDOWS\system32\DRIVERS\ctsfm2k.sys
2011/02/16 11:26:25.0750 2812 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys
2011/02/16 11:26:25.0796 2812 dmboot (d992fe1274bde0f84ad826acae022a41) C:\WINDOWS\system32\drivers\dmboot.sys
2011/02/16 11:26:25.0843 2812 dmio (7c824cf7bbde77d95c08005717a95f6f) C:\WINDOWS\system32\drivers\dmio.sys
2011/02/16 11:26:25.0859 2812 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys
2011/02/16 11:26:25.0890 2812 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys
2011/02/16 11:26:25.0984 2812 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys
2011/02/16 11:26:26.0031 2812 E1000 (2476936f4994e9084ccfe75ed4f6226a) C:\WINDOWS\system32\DRIVERS\e1000325.sys
2011/02/16 11:26:26.0078 2812 ENTECH (fd9fc82f134b1c91004ffc76a5ae494b) C:\WINDOWS\system32\DRIVERS\ENTECH.sys
2011/02/16 11:26:26.0140 2812 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys
2011/02/16 11:26:26.0171 2812 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\DRIVERS\fdc.sys
2011/02/16 11:26:26.0218 2812 Fips (d45926117eb9fa946a6af572fbe1caa3) C:\WINDOWS\system32\drivers\Fips.sys
2011/02/16 11:26:26.0234 2812 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\DRIVERS\flpydisk.sys
2011/02/16 11:26:26.0296 2812 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\drivers\fltmgr.sys
2011/02/16 11:26:26.0328 2812 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys
2011/02/16 11:26:26.0343 2812 Ftdisk (6ac26732762483366c3969c9e4d2259d) C:\WINDOWS\system32\DRIVERS\ftdisk.sys
2011/02/16 11:26:26.0375 2812 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys
2011/02/16 11:26:26.0421 2812 HidUsb (ccf82c5ec8a7326c3066de870c06daf1) C:\WINDOWS\system32\DRIVERS\hidusb.sys
2011/02/16 11:26:26.0484 2812 HTTP (f6aacf5bce2893e0c1754afeb672e5c9) C:\WINDOWS\system32\Drivers\HTTP.sys
2011/02/16 11:26:26.0562 2812 i8042prt (4a0b06aa8943c1e332520f7440c0aa30) C:\WINDOWS\system32\DRIVERS\i8042prt.sys
2011/02/16 11:26:26.0578 2812 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys
2011/02/16 11:26:26.0640 2812 IntelIde (b5466a9250342a7aa0cd1fba13420678) C:\WINDOWS\system32\DRIVERS\intelide.sys
2011/02/16 11:26:26.0703 2812 intelppm (8c953733d8f36eb2133f5bb58808b66b) C:\WINDOWS\system32\DRIVERS\intelppm.sys
2011/02/16 11:26:26.0734 2812 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\drivers\ip6fw.sys
2011/02/16 11:26:26.0781 2812 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys
2011/02/16 11:26:26.0796 2812 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys
2011/02/16 11:26:26.0828 2812 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys
2011/02/16 11:26:26.0859 2812 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys
2011/02/16 11:26:26.0890 2812 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys
2011/02/16 11:26:26.0921 2812 isapnp (05a299ec56e52649b1cf2fc52d20f2d7) C:\WINDOWS\system32\DRIVERS\isapnp.sys
2011/02/16 11:26:26.0937 2812 Kbdclass (463c1ec80cd17420a542b7f36a36f128) C:\WINDOWS\system32\DRIVERS\kbdclass.sys
2011/02/16 11:26:26.0984 2812 kbdhid (9ef487a186dea361aa06913a75b3fa99) C:\WINDOWS\system32\DRIVERS\kbdhid.sys
2011/02/16 11:26:27.0031 2812 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys
2011/02/16 11:26:27.0046 2812 KSecDD (1705745d900dabf2d89f90ebaddc7517) C:\WINDOWS\system32\drivers\KSecDD.sys
2011/02/16 11:26:27.0187 2812 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys
2011/02/16 11:26:27.0234 2812 Modem (dfcbad3cec1c5f964962ae10e0bcc8e1) C:\WINDOWS\system32\drivers\Modem.sys
2011/02/16 11:26:27.0281 2812 Mouclass (35c9e97194c8cfb8430125f8dbc34d04) C:\WINDOWS\system32\DRIVERS\mouclass.sys
2011/02/16 11:26:27.0312 2812 mouhid (b1c303e17fb9d46e87a98e4ba6769685) C:\WINDOWS\system32\DRIVERS\mouhid.sys
2011/02/16 11:26:27.0375 2812 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys
2011/02/16 11:26:27.0421 2812 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys
2011/02/16 11:26:27.0468 2812 MRxSmb (60ae98742484e7ab80c3c1450e708148) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys
2011/02/16 11:26:27.0500 2812 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys
2011/02/16 11:26:27.0546 2812 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys
2011/02/16 11:26:27.0578 2812 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys
2011/02/16 11:26:27.0609 2812 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys
2011/02/16 11:26:27.0656 2812 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys
2011/02/16 11:26:27.0687 2812 Mup (2f625d11385b1a94360bfc70aaefdee1) C:\WINDOWS\system32\drivers\Mup.sys
2011/02/16 11:26:27.0781 2812 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys
2011/02/16 11:26:27.0796 2812 NdisTapi (1ab3d00c991ab086e69db84b6c0ed78f) C:\WINDOWS\system32\DRIVERS\ndistapi.sys
2011/02/16 11:26:27.0828 2812 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys
2011/02/16 11:26:27.0843 2812 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys
2011/02/16 11:26:27.0875 2812 NDProxy (6215023940cfd3702b46abc304e1d45a) C:\WINDOWS\system32\drivers\NDProxy.sys
2011/02/16 11:26:27.0906 2812 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys
2011/02/16 11:26:27.0937 2812 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys
2011/02/16 11:26:27.0984 2812 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys
2011/02/16 11:26:28.0000 2812 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys
2011/02/16 11:26:28.0062 2812 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys
2011/02/16 11:26:28.0218 2812 nv (ba1b732c1a70cfea0c1b64f2850bf44f) C:\WINDOWS\system32\DRIVERS\nv4_mini.sys
2011/02/16 11:26:28.0343 2812 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys
2011/02/16 11:26:28.0359 2812 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys
2011/02/16 11:26:28.0406 2812 ossrv (3649eefa90990249267dd6c7808cbc86) C:\WINDOWS\system32\DRIVERS\ctoss2k.sys
2011/02/16 11:26:28.0468 2812 P17 (9a1c06e3888891757913ef08cb9f8a81) C:\WINDOWS\system32\drivers\P17.sys
2011/02/16 11:26:28.0531 2812 p17filt (71ddb3a663ddce1651cfe35993fb1c31) C:\WINDOWS\system32\drivers\p17filt.sys
2011/02/16 11:26:28.0625 2812 Parport (5575faf8f97ce5e713d108c2a58d7c7c) C:\WINDOWS\system32\DRIVERS\parport.sys
2011/02/16 11:26:28.0656 2812 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys
2011/02/16 11:26:28.0687 2812 ParVdm (70e98b3fd8e963a6a46a2e6247e0bea1) C:\WINDOWS\system32\drivers\ParVdm.sys
2011/02/16 11:26:28.0703 2812 PCI (a219903ccf74233761d92bef471a07b1) C:\WINDOWS\system32\DRIVERS\pci.sys
2011/02/16 11:26:28.0781 2812 PCIIde (ccf5f451bb1a5a2a522a76e670000ff0) C:\WINDOWS\system32\DRIVERS\pciide.sys
2011/02/16 11:26:28.0828 2812 Pcmcia (9e89ef60e9ee05e3f2eef2da7397f1c1) C:\WINDOWS\system32\drivers\Pcmcia.sys
2011/02/16 11:26:29.0046 2812 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys
2011/02/16 11:26:29.0062 2812 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys
2011/02/16 11:26:29.0109 2812 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys
2011/02/16 11:26:29.0156 2812 PxHelp20 (d86b4a68565e444d76457f14172c875a) C:\WINDOWS\system32\Drivers\PxHelp20.sys
2011/02/16 11:26:29.0281 2812 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys
2011/02/16 11:26:29.0328 2812 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys
2011/02/16 11:26:29.0421 2812 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys
2011/02/16 11:26:29.0500 2812 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys
2011/02/16 11:26:29.0578 2812 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys
2011/02/16 11:26:29.0593 2812 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys
2011/02/16 11:26:29.0640 2812 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys
2011/02/16 11:26:29.0703 2812 RDPWD (6728e45b66f93c08f11de2e316fc70dd) C:\WINDOWS\system32\drivers\RDPWD.sys
2011/02/16 11:26:29.0718 2812 redbook (f828dd7e1419b6653894a8f97a0094c5) C:\WINDOWS\system32\DRIVERS\redbook.sys
2011/02/16 11:26:29.0796 2812 SBRE (c1ae5d1f53285d79a0b73a62af20734f) C:\WINDOWS\system32\drivers\SBREdrv.sys
2011/02/16 11:26:29.0859 2812 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys
2011/02/16 11:26:29.0921 2812 serenum (0f29512ccd6bead730039fb4bd2c85ce) C:\WINDOWS\system32\DRIVERS\serenum.sys
2011/02/16 11:26:29.0953 2812 Serial (cca207a8896d4c6a0c9ce29a4ae411a7) C:\WINDOWS\system32\DRIVERS\serial.sys
2011/02/16 11:26:30.0015 2812 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys
2011/02/16 11:26:30.0125 2812 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys
2011/02/16 11:26:30.0234 2812 sr (76bb022c2fb6902fd5bdd4f78fc13a5d) C:\WINDOWS\system32\DRIVERS\sr.sys
2011/02/16 11:26:30.0281 2812 Srv (3bb03f2ba89d2be417206c373d2af17c) C:\WINDOWS\system32\DRIVERS\srv.sys
2011/02/16 11:26:30.0343 2812 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys
2011/02/16 11:26:30.0375 2812 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys
2011/02/16 11:26:30.0500 2812 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys
2011/02/16 11:26:30.0546 2812 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys
2011/02/16 11:26:30.0578 2812 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys
2011/02/16 11:26:30.0609 2812 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys
2011/02/16 11:26:30.0640 2812 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys
2011/02/16 11:26:30.0734 2812 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys
2011/02/16 11:26:30.0828 2812 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys
2011/02/16 11:26:30.0906 2812 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys
2011/02/16 11:26:30.0937 2812 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys
2011/02/16 11:26:30.0984 2812 USBFVNETR (33723ec6f7aede7b40deba4aea2f5c05) C:\WINDOWS\system32\DRIVERS\ma101rnd.sys
2011/02/16 11:26:31.0046 2812 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys
2011/02/16 11:26:31.0093 2812 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys
2011/02/16 11:26:31.0140 2812 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys
2011/02/16 11:26:31.0218 2812 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS
2011/02/16 11:26:31.0234 2812 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys
2011/02/16 11:26:31.0296 2812 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys
2011/02/16 11:26:31.0375 2812 VolSnap (4c8fcb5cc53aab716d810740fe59d025) C:\WINDOWS\system32\drivers\VolSnap.sys
2011/02/16 11:26:31.0421 2812 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys
2011/02/16 11:26:31.0484 2812 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\DRIVERS\Wdf01000.sys
2011/02/16 11:26:31.0531 2812 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys
2011/02/16 11:26:31.0625 2812 WinUSB (fd600b032e741eb6aab509fc630f7c42) C:\WINDOWS\system32\DRIVERS\WinUSB.sys
2011/02/16 11:26:31.0718 2812 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys
2011/02/16 11:26:31.0796 2812 WudfPf (eaa6324f51214d2f6718977ec9ce0def) C:\WINDOWS\system32\DRIVERS\WudfPf.sys
2011/02/16 11:26:31.0828 2812 WudfRd (f91ff1e51fca30b3c3981db7d5924252) C:\WINDOWS\system32\DRIVERS\wudfrd.sys
2011/02/16 11:26:31.0890 2812 zumbus (6bfb54f73aae470e9299e66cbc7bb632) C:\WINDOWS\system32\DRIVERS\zumbus.sys
2011/02/16 11:26:32.0031 2812 ================================================================================
2011/02/16 11:26:32.0031 2812 Scan finished
2011/02/16 11:26:32.0031 2812 ================================================================================
Hi SNiemoelle

There is nothing “bad” remaining in your log but the update issue is a bit worrying. Before I can decide on the best course of action to resolve this issue, can you answer a few questions:

1. The SoftwareDistribution folder has been renamed – can you explain when and how?

2. The file proquota.exe seems to have also been altered/replaced – is this something that was done by the MS Help Centre?

3. When did the problem first start?.

4. How are you trying to update Windows?

Have you tried disabling Windows firewall and then trying to access MS updates?

Disable Windows firewall:• Click on Start, Settings and then Control Panel
• Click on the Security Center icon.
• Click on the Windows Firewall icon
• Click Off (not recommended) and then click OK.
When you have done that go here to try and get updates.

===================================================

Another look using a different program might also shed some more light:

Download and run OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    drivers32
    %SYSTEMDRIVE%\*.*
    /md5start
    wuapi.dll
    wuaueng.dll
    wuaueng1.dll
    wuauserv.dll
    wucltui.dll
    wups.dll
    wups2.dll
    wuweb.dll
    MSXML3.dll
    qmgr.dll
    qmgrprxy.dll
    jscript.dll
    mucltui.dll
    atl.dll
    /md5stop
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\OLE
    HKEY_LOCAL_MACHINE\SOFTWARE\Classes
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan won’t take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Thanks

Satchfan
Hello SNiemoelle It has been several days since I sent my last post with instructions to help with your computer problem.. Please let me know if you are having problems and still require help. Thanks Satchfan

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI