This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] I'm Infested, Hijack this Log

7 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Good. That's means Combofix fixed them.


Copy/paste the text in the Codebox below into notepad:

Here's how to do that:
Click Start > Run type Notepad click OK.
This will open an empty notepad file:

Take your mouse, and place your cursor at the beginning of the text in the box below, then click and hold the left mouse button, while pulling your mouse over the text. This should highlight the text. Now release the left mouse button. Now, with the cursor over the highlighted text, right click the mouse for options, and select 'copy'. Now over the empty Notepad box, right click your mouse again, and select 'paste' and you will have copied and pasted the text.

File::
c:\program files\ErrorRepairTool\ErrorRepairTool.exe
c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
c:\program files\Grisoft\AVG Free\bak\avgcc.exe
c:\program files\HP\Digital Imaging\bin\bak\backupnotify.exe
c:\program files\HP\Digital Imaging\bin\BackupNotify.exe
c:\program files\HP\hpcoretech\bak\hpcmpmgr.exe
c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
c:\program files\QuickTime\bak\qttask.exe
c:\program files\Spybot - Search & Destroy\bak\TeaTimer.exe
c:\program files\SymNetDrv\bak\SNDMon.exe
c:\windows\bak\SM1BG.EXE
c:\windows\CREATOR\bak\Remind_XP.exe
c:\windows\SMINST\bak\RECGUARD.EXE
c:\windows\system\bak\hpsysdrv.exe
c:\windows\system32\bak\hphmon05.exe
c:\windows\system32\spool\drivers\w32x86\3\bak\E_S10IC2.EXE

Folder::
c:\program files\ErrorRepairTool
c:\program files\Viewpoint

Save this file to your desktop, Save this as "CFScript"

Here's how to do that:
1.Click File;
2.Click Save As… Change the directory to your desktop;
3.Change the Save as type to "All Files";
4.Type in the file name: CFScript
5.Click Save …


[external image: Posted Image]

Drag CFScript.txt into ComboFix.exe

Then post the results log and a new HijackThis log.


Also please describe how your computer behaves at the moment.
OK hers the Combo Fix with CFScript Log…….

All seems ok, but I still can't get windows or antivirus updates…


ComboFix 08-12-06.01 - Owner 2008-12-06 13:40:27.2 - NTFSx86

Running from: c:\documents and settings\[removed]\My Documents\Dougs Stuff\downloads\ComboFix.exe
Command switches used :: c:\documents and settings\Owner\Desktop\CFScript.txt

FILE ::
c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
c:\program files\ErrorRepairTool\ErrorRepairTool.exe
c:\program files\Grisoft\AVG Free\bak\avgcc.exe
c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
c:\program files\HP\Digital Imaging\bin\BackupNotify.exe
c:\program files\HP\Digital Imaging\bin\bak\backupnotify.exe
c:\program files\HP\hpcoretech\bak\hpcmpmgr.exe
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
c:\program files\QuickTime\bak\qttask.exe
c:\program files\Spybot - Search & Destroy\bak\TeaTimer.exe
c:\program files\SymNetDrv\bak\SNDMon.exe
c:\windows\bak\SM1BG.EXE
c:\windows\CREATOR\bak\Remind_XP.exe
c:\windows\SMINST\bak\RECGUARD.EXE
c:\windows\system\bak\hpsysdrv.exe
c:\windows\system32\bak\hphmon05.exe
c:\windows\system32\spool\drivers\w32x86\3\bak\E_S10IC2.EXE
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

c:\program files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe
c:\program files\Common Files\Real\Update_OB\bak\realsched.exe
c:\program files\Common Files\Sonic\Update Manager\bak\sgtray.exe
c:\program files\Grisoft\AVG Free\bak\avgcc.exe
c:\program files\HP\{45B6180B-DCAB-4093-8EE8-6164457517F0}\bak\hphupd05.exe
c:\program files\HP\Digital Imaging\bin\BackupNotify.exe
c:\program files\HP\Digital Imaging\bin\bak\backupnotify.exe
c:\program files\HP\hpcoretech\bak\hpcmpmgr.exe
c:\program files\iTunes\bak\iTunesHelper.exe
c:\program files\Java\j2re1.4.2_03\bin\bak\jusched.exe
c:\program files\QuickTime\bak\qttask.exe
c:\program files\Spybot - Search & Destroy\bak\TeaTimer.exe
c:\program files\SymNetDrv\bak\SNDMon.exe
c:\program files\Viewpoint
c:\program files\Viewpoint\Viewpoint Media Player\AxMetaStream.dll
c:\program files\Viewpoint\Viewpoint Media Player\ClassIDs.ini
c:\program files\Viewpoint\Viewpoint Media Player\ComponentMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AtmoHWConfig.txt
c:\program files\Viewpoint\Viewpoint Media Player\Components\Atmosphere.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\AvatarsDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\Components\BlueStreak.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\BookmarksDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\Components\DefaultAvatarIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\Components\DefaultWorldIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\Components\ExtremeShot.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\InternetChatHelp.url
c:\program files\Viewpoint\Viewpoint Media Player\Components\JpegReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\LensFlares.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts2Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\Mts3Reader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ObjectMovie.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SceneComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ServiceComponent.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SreeDMMX.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\SWFView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VectorView.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VETsdk.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPSpeech.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\VMPVideo.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\WaveletReader.dll
c:\program files\Viewpoint\Viewpoint Media Player\Components\ZoomView.dll
c:\program files\Viewpoint\Viewpoint Media Player\MetaStreamID.ini
c:\program files\Viewpoint\Viewpoint Media Player\MtsAxInstaller.exe
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AOLUserShell.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AtmoHWConfig.txt
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\AvatarsDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\BookmarksDefault.prf
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\Cursors.dll
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultAvatarIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\DefaultWorldIcon.jpg
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\InternetChatHelp.url
c:\program files\Viewpoint\Viewpoint Media Player\NewComponents\VMgr.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.xpt
c:\windows\bak\SM1BG.EXE
c:\windows\CREATOR\bak\Remind_XP.exe
c:\windows\SMINST\bak\RECGUARD.EXE
c:\windows\system\bak\hpsysdrv.exe
c:\windows\system32\bak\hphmon05.exe
c:\windows\system32\drivers\mrxdavv.sys
c:\windows\system32\kwave.sys
c:\windows\system32\spool\drivers\w32x86\3\bak\E_S10IC2.EXE

.
((((((((((((((((((((((((( Files Created from 2008-11-06 to 2008-12-06 )))))))))))))))))))))))))))))))
.

2008-12-06 10:47 . 2008-12-06 10:47 d——– c:\program files\Trend Micro
2008-12-06 09:22 . 2008-12-06 11:20 d——– c:\program files\Malwarebytes' Anti-Malware
2008-12-06 09:22 . 2008-12-06 09:22 d——– c:\documents and settings\Owner\Application Data\Malwarebytes
2008-12-06 09:22 . 2008-12-06 09:22 d——– c:\documents and settings\All Users\Application Data\Malwarebytes
2008-12-06 09:22 . 2008-12-03 19:52 38,496 –a—— c:\windows\system32\drivers\mbamswissarmy.sys
2008-12-06 09:22 . 2008-12-03 19:52 15,504 –a—— c:\windows\system32\drivers\mbam.sys
2008-12-06 09:06 . 2008-12-06 09:06 d——– c:\program files\ERUNT
2008-12-02 23:40 . 2008-12-02 23:40 d——– c:\documents and settings\Owner\Application Data\F-Secure
2008-12-02 23:05 . 2008-12-02 23:05 d——– c:\documents and settings\All Users\Application Data\f-secure
2008-12-02 23:05 . 2008-04-23 11:12 57,824 –a—— c:\windows\system32\drivers\fsdfw.sys
2008-12-02 23:05 . 2008-04-23 11:12 36,768 –a—— c:\windows\system32\drivers\fsndis5.sys
2008-12-02 23:04 . 2008-12-02 23:07 d——– c:\program files\F-Secure PC Protection Plus
2008-12-02 22:07 . 2008-12-02 22:46 d——– c:\windows\SxsCaPendDel
2008-12-02 21:15 . 2008-12-02 22:54 d——– c:\documents and settings\All Users\Application Data\fssg
2008-12-02 18:55 . 2008-12-02 20:52 d——– c:\documents and settings\All Users\Application Data\SITEguard
2008-12-02 18:54 . 2008-12-02 18:54 d——– c:\program files\Common Files\iS3
2008-12-02 18:54 . 2008-12-02 21:38 d——– c:\documents and settings\All Users\Application Data\STOPzilla!
2008-12-02 08:09 . 2008-12-02 08:09 d–h—– c:\windows\system32\GroupPolicy
2008-12-02 07:46 . 2008-12-02 07:48 d——– c:\documents and settings\Owner\Application Data\ErrorRepairTool

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-03 03:36 ——— d—–w c:\program files\a-squared Free
2008-11-30 19:55 ——— d—–w c:\documents and settings\Owner\Application Data\Lavasoft
2008-11-30 19:54 ——— d—–w c:\program files\SpywareGuard
2008-11-30 19:26 ——— d—–w c:\program files\Google
2008-11-30 19:25 ——— d—–w c:\program files\Spybot - Search & Destroy
2008-11-30 19:25 ——— d—–w c:\documents and settings\All Users\Application Data\Spybot - Search & Destroy
2008-11-30 19:23 ——— d—–w c:\program files\Click'N Design 3D
2008-11-30 17:31 ——— d—–w c:\documents and settings\All Users\Application Data\Apple Computer
2008-11-19 12:50 ——— d—–w c:\program files\Mozilla Thunderbird
2003-08-27 19:19 36,963 —-a-r c:\program files\Common Files\SM1updtr.dll
2007-04-07 11:09 44,624 —-a-w c:\program files\mozilla firefox\plugins\atgpcdec.dll
2007-04-07 11:09 108,184 —-a-w c:\program files\mozilla firefox\plugins\atgpcext.dll
.

((((((((((((((((((((((((((((( snapshot@2008-12-06_12.49.17.98 )))))))))))))))))))))))))))))))))))))))))
.
- 2008-12-06 17:44:19 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
+ 2008-12-06 18:43:31 32,768 —-a-w c:\windows\system32\config\systemprofile\Cookies\index.dat
- 2008-12-06 17:44:19 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
+ 2008-12-06 18:43:31 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\History\History.IE5\index.dat
- 2008-12-06 17:44:19 163,840 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
+ 2008-12-06 18:44:39 32,768 —-a-w c:\windows\system32\config\systemprofile\Local Settings\Temporary Internet Files\Content.IE5\index.dat
- 2008-12-06 17:40:40 262,144 —-a-w c:\windows\system32\config\systemprofile\NTUSER.DAT
+ 2008-12-06 18:40:21 262,144 —-a-w c:\windows\system32\config\systemprofile\NTUSER.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"WD Drive Manager"="c:\program files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe" [2008-02-19 438272]
"F-Secure Manager"="c:\program files\F-Secure PC Protection Plus\Common\FSM32.EXE" [2008-04-23 182936]
"F-Secure TNB"="c:\program files\F-Secure PC Protection Plus\FSGUI\TNBUtil.exe" [2008-04-23 744032]
"VTTimer"="VTTimer.exe" [2004-09-01 c:\windows\system32\VTTimer.exe]
"AGRSMMSG"="AGRSMMSG.exe" [2004-01-16 c:\windows\AGRSMMSG.exe]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"MySpaceIM"="c:\program files\MySpace\IM\MySpaceIM.exe" [2007-01-11 4898816]

c:\documents and settings\Owner\Start Menu\Programs\Startup\
ERUNT AutoBackup.lnk - c:\program files\ERUNT\AUTOBACK.EXE [2005-10-20 38912]

c:\documents and settings\All Users\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2004-07-01 113664]
Adobe Reader Speed Launch.lnk - c:\program files\Adobe\Acrobat 7.0\Reader\reader_sl.exe [2005-09-24 29696]
HotSync Manager.lnk - c:\palm\HOTSYNC.EXE [2004-07-31 282624]
HP Digital Imaging Monitor.lnk - c:\program files\HP\Digital Imaging\bin\hpqtra08.exe [2003-09-16 237568]
Microsoft Office.lnk - c:\program files\Microsoft Office\Office\OSA9.EXE [1999-02-17 65588]
PopSubtract.lnk - c:\program files\InterMute\PopSubtract\PopSub.exe [2004-08-30 233472]
Updates from HP.lnk - c:\program files\Updates from HP\137903\Program\BackWeb-137903.exe [2004-04-01 16384]

.
Contents of the 'Scheduled Tasks' folder

2008-12-02 c:\windows\Tasks\ErrorRepairTool Scheduled Scan.job
- c:\program files\ErrorRepairTool\ErrorRepairTool.exe []

2008-12-02 c:\windows\Tasks\ErrorRepairTool Scheduled Scan.job
- c:\program files\ErrorRepairTool []
.
- - - - ORPHANS REMOVED - - - -

HKCU-Run-AIM - c:\progra~1\AIM\aim.exe
HKCU-Run-BackupNotify - c:\program files\HP\Digital Imaging\bin\backupnotify.exe
HKLM-Run-KBD - c:\hp\KBD\KBD.EXE


.
——- Supplementary Scan ——-
.
uStart Page = hxxp://portal.wowway.com/index.php
uDefault_Search_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=Q304&bd=pavilion&pf=desktop
uInternet Settings,ProxyOverride = localhost
IE: E&xport to Microsoft Excel - c:\progra~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
LSP: c:\program files\F-Secure PC Protection Plus\FSPS\program\FSLSP.DLL
FireFox -: Profile - c:\documents and settings\Owner\Application Data\Mozilla\Firefox\Profiles\7bmrjicx.default\
FireFox -: prefs.js - SEARCH.DEFAULTURL - hxxp://www.google.com/search?lr=&ie=UTF-8&oe=UTF-8&q=
FireFox -: prefs.js - STARTUP.HOMEPAGE - hxxp://portal.wowway.com/index.php
FF -: plugin - c:\program files\Adobe\Acrobat 7.0\Reader\browser\nppdf32.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava11.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava12.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava13.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava14.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJava32.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPJPI142_03.dll
FF -: plugin - c:\program files\Java\j2re1.4.2_03\bin\NPOJI610.dll
FF -: plugin - c:\program files\Mozilla Firefox\plugins\npatgpc.dll
FF -: plugin - c:\program files\Real\RealOne Player\Netscape6\nppl3260.dll
FF -: plugin - c:\program files\Real\RealOne Player\Netscape6\nprjplug.dll
FF -: plugin - c:\program files\Real\RealOne Player\Netscape6\nprpjplug.dll
FF -: plugin - c:\program files\Viewpoint\Viewpoint Media Player\npViewpoint.dll
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-06 13:43:37
Windows 5.1.2600 Service Pack 1 NTFS

scanning hidden processes …

scanning hidden autostart entries …

scanning hidden files …


c:\docume~1\Owner\LOCALS~1\Temp\DIO4.tmp 46713 bytes

scan completed successfully
hidden files: 1

**************************************************************************
.
——————— DLLs Loaded Under Running Processes ———————

- - - - - - - > 'winlogon.exe'(684)
c:\windows\System32\ODBC32.dll

- - - - - - - > 'lsass.exe'(740)
c:\program files\F-Secure PC Protection Plus\FSPS\program\FSLSP.DLL
c:\windows\System32\dssenh.dll
.
———————— Other Running Processes ————————
.
c:\program files\Common Files\EPSON\EBAPI\eEBSvc.exe
c:\program files\a-squared Free\a2service.exe
c:\progra~1\COMMON~1\AOL\ACS\acsd.exe
c:\program files\F-Secure PC Protection Plus\Common\FSMA32.EXE
c:\program files\iPod\bin\iPodService.exe
c:\windows\system32\wdfmgr.exe
c:\program files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
c:\program files\F-Secure PC Protection Plus\Common\FSLAUNCH.EXE
.
**************************************************************************
.
Completion time: 2008-12-06 13:50:42 - machine was rebooted
ComboFix-quarantined-files.txt 2008-12-06 18:50:15
ComboFix2.txt 2008-12-06 17:50:51

Pre-Run: 122,763,218,944 bytes free
Post-Run: 122,736,119,808 bytes free

235
The latest…..

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2:15:14 PM, on 12/6/2008
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\VTTimer.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.EXE
C:\Palm\HOTSYNC.EXE
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\InterMute\PopSubtract\PopSub.exe
C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
C:\Program Files\F-Secure PC Protection Plus\Common\FSMA32.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\F-Secure PC Protection Plus\Common\FSMB32.EXE
C:\WINDOWS\System32\svchost.exe
C:\Program Files\F-Secure PC Protection Plus\Common\FCH32.EXE
C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe
C:\Program Files\F-Secure PC Protection Plus\Common\FAMEH32.EXE
C:\Program Files\F-Secure PC Protection Plus\FSGUI\fsguidll.exe
C:\Program Files\F-Secure PC Protection Plus\FWES\Program\fsdfwd.exe
C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsaua.exe
C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsus.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&a;…&pf=desktop
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://portal.wowway.com/index.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O4 - HKLM\..\Run: [VTTimer] VTTimer.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [WD Drive Manager] C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrUI.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\F-Secure PC Protection Plus\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\F-Secure PC Protection Plus\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User '?')
O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')
O4 - S-1-5-21-2699308062-2599229480-6037751-1003 Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE (User '?')
O4 - S-1-5-21-2699308062-2599229480-6037751-1003 Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe (User '?')
O4 - .DEFAULT User Startup: AutoTBar.exe (User 'Default user')
O4 - Startup: ERUNT AutoBackup.lnk = C:\Program Files\ERUNT\AUTOBACK.EXE
O4 - Startup: IMStart.lnk = C:\Program Files\InterMute\IMStart.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: HotSync Manager.lnk = C:\Palm\HOTSYNC.EXE
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: PopSubtract.lnk = C:\Program Files\InterMute\PopSubtract\PopSub.exe
O4 - Global Startup: Updates from HP.lnk = C:\Program Files\Updates from HP\137903\Program\BackWeb-137903.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O16 - DPF: {0742B9EF-8C83-41CA-BFBA-830A59E23533} (Microsoft Data Collection Control) - https://support.microsoft.com/oas/ActiveX/MSDcode.cab
O16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader1005.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1228341956825
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\PROGRAM FILES\A-SQUARED FREE\a2service.exe
O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\PROGRA~1\COMMON~1\AOL\ACS\acsd.exe
O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe
O23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\FSAUA\program\fsaua.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Program Files\F-Secure PC Protection Plus\Common\FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\System32\HPZipm12.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Unknown owner - C:\WINDOWS\system32\ZoneLabs\vsmon.exe (file missing)
O23 - Service: WD Drive Manager Service (WDBtnMgrSvc.exe) - WDC - C:\Program Files\Western Digital\WD Drive Manager\WDBtnMgrSvc.exe

–
End of file - 6266 bytes
Click Start > Run and Copy/Paste these commands hitting enter after each one:

sc stop a2free Hit enter.

sc delete a2free Hit enter.

Is your Firewall blocking the updates?
ok did the a2 stop and delete Downloads still not working.. I don't know anything about my fire walls windows, antivirus, or router. Don't even know how to look or check which ones are running whats being blocked/allowed etc…
Here's another one

Click Start > Run and Copy/Paste these commands hitting enter after each one:

sc stop vsmon Hit enter.

sc delete vsmon Hit enter.
goto Start>Run> type in Services.msc look for Background Intelligent Transfer Service (bits) start it if tis stopped and then right click it and click Properties>and set its startup type to Automatic restart and now check if any progress
got an error Could not start background intelligent transfer service on local computer error 1083: The executable program that this service is configured to run in does not implement the service
Issues with getting Windows Updates.

This is a free service and toll-free call.

1-866-PCSAFETY
or
[removed]
This phone number is for virus and other security-related support. It is available 24 hours a day for the U.S. and Canada.

For support outside the United States and Canada, please contact your Microsoft Help and Support worldwide. Go to this page and choose your region from the box in the upper right corner: http://support.microsoft.com/?pr=SecurityHome
At least you have a clean PC. Microsoft should be able to help you. If not, post back. Great job :thumbup: You're more then welcome. Glad we were able to help Peace be with you :wavey:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI