Can't connect to windows update.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by tagged, Dec 13, 2004.

  1. tagged

    tagged Private E-2

    About a month ago I got a bunch of viruses from someone using my computer after work. I've gone through all the steps in the READ ME FIRST BEFORE ASKING FOR SUPPORT tutorial, and seem to have gotten rid of most of the bad stuff. The problems that I'm still having are, 1. I can't get to Windows Update from my Start menu or from clicking on the link on the MSN page. 2. I can't access my e-mail on my company's server.- I can access my personal account off my office computer and I can access either of them off my home computer.
    When I went through the steps, CWS found C:\WINNT\MSCONFIG.exe. Is that a bad thing?
    When I did the Bitdefender scan, it found 6 infected items, but couldn't disinfect them. I scanned the files it found the infections in with Norton, but it didn't find anything.
    I couldn't run a squared without it creating errors and closing.
    I ran HJT and ran my log through the HJT analyzer from the HJT tutorial, and it came up with 28 nasties that I had HJT fix. My last log I ran through there showed no nasties.
    When I restart my computer I get a 'Runtime error 9'. subscript out of range alert, but I closed the box and it finished booting.
    When I try to get into my company e-mail, the page opens and tells me what's in my folders, and then says 'done error on page'. When I check what the error is, it says,' Error on page. Line:72 Char:3 Error: Automation server can't create object. URL: http\\windows update. microsoft.com\.
    When I try to get to Windows update, I get the same error as above.
    When I click on the search button, the side window opens but it's blank.
    I also have an extra volume control icon on my lower right tool bar. When I put my cursor on it, it displays what looks like a URL address.
    My OS is windows 2000.

    Anybody got any ideas?

    Thanks
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I assume your OS is WinXP but you did not say!

    msconfig.exe is not normally in the c:\winnt directory so it probably is malware.

    Make sure you have HJT Version 1.98.2 and follow the guidelines on where to install it and how to post a log as an attachment. This is all covered in the sticky thread NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting

    Now post a HijackThis as a .txt file attachment to your message. All running programs should be closed, including your web browser, e-mail. Close before running Hijack This!

    To repeat: Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file. Place it in its own folder, for example C:\Program Files\HJT
     
  3. tagged

    tagged Private E-2

    Thanks for responding Chasling,
    I had to run back to work to run HJT on the right computer again, that's what took so long. Here it is.
    Hope I attached this right.
    Should I have CWS fix that MS CONFIG thing?
    Hey, I also did write that my OS is windows 2000 on my first message. It was the last line. I thought I was getting fairly longwinded on that thing, you must not have lasted till the end.


    Thanks again for looking!

    Pat
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes have CWShredder fix that (if it can). Then do what I have below. The HJT analyzer missed a lot.

    I noticed you are using both Norton and AVG. You must only use one virus application. Pick one and uninstall the other.

    Do you know what these this DNTUS26.EXE process is? From what I have found it may be part of DameWare Development Remote Command Server. Does this mean anything to you?
    C:\WINNT\SYSTEM32\DNTUS26.EXE
    I'm pretty sure it may be bad but figured I would ask first.

    Make sure you have system restore disabled and viewing of hidden files enabled (per the tutorial).
    Please bring up Task Manager by hitting CTRL-ALT-DEL and click the Processes tab. Look for the below process(es) and if found, End them:
    C:\WINNT\fxsvc.exe
    C:\WINNT\system32\audio.exe
    C:\WINNT\system32\d?dplay.exe

    Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINNT\system32\SearchBar.htm
    O2 - BHO: (no name) - {E4CD8E72-699E-6C4F-E92E-3976166A5793} - C:\WINNT\system32\sgc.dll
    O4 - HKLM\..\Run: [Systemey] systemey.exe
    O4 - HKLM\..\Run: [jpFOqNvY5.exe] C:\documents and settings\ptaggart\local settings\temp\jpFOqNvY5.exe
    O4 - HKLM\..\Run: [8rHG.exe] C:\documents and settings\ptaggart\local settings\temp\8rHG.exe
    O4 - HKLM\..\Run: [b78b327add10] C:\WINNT\system32\catsrvut.exe
    O4 - HKLM\..\RunServices: [Systemey] systemey.exe
    O4 - HKCU\..\Run: [Pjrhei] C:\WINNT\system32\d?dplay.exe

    Boot into safe mode and use Windows Explorer to delete:
    C:\WINNT\system32\SearchBar.htm
    C:\WINNT\system32\sgc.dll
    C:\WINNT\system32\systemey.exe
    C:\documents and settings\ptaggart\local settings\temp\jpFOqNvY5.exe
    C:\documents and settings\ptaggart\local settings\temp\8rHG.exe
    C:\WINNT\system32\catsrvut.exe
    C:\WINNT\fxsvc.exe
    and rename the below audio.exe file to audioexe.bad
    C:\WINNT\system32\audio.exe
    I don't want to delete this file yet. I'm pretty sure it is bad, but I want to be save.
    Now empty your Recycle Bin.

    Now reboot in normal mode and post a new HJT log. And tell us how things are working.
     
    Last edited: Dec 14, 2004
  5. tagged

    tagged Private E-2

    Thanks Chaslang

    OK. I had CWS fix that thing.
    When I tried to unistall AVG I got a message " 16 bit Windows Subsystem C:\Winnt\System 32\AutoEXEC.NT. The system is not suitable for running MS-DOS and Microsoft Windows applications. Choose close to terminate application. I chose close and it quit trying to uninstall. Should I have chosen ignor?

    No, I don't know what DNTUS26.EXE is for. How do I get rid of it?

    I don't think I have system restore on Windows 2000 do I? If I do, I didn't see instructions in the tutorial for disabling it. I checked the show hidden files and it was enabled.

    I brought up task manager. C:\WINNT\fxsvc.exe and C:\WINNT\system32\audio.exe both gave me an access denied message when I tried to end them. C:\WINNT\system32\d?dplay.exe ended ok.

    I ran HJT and fixed the items listed.

    I booted to safe mode. The only thing on the delete list that was found was C:\WINNT\system32\catsrvut.exe and I deleted it.

    I renamed the audio.exe. and emptied the Recycle Bin.

    Rebooted in normal. Ran HJT. Tried to get on Windows update and got the same automation server error I had before. Tried my company e-mail and got an automation server error also, but with different line and character numbers.

    I don't have the extra volume control icon anymore though. That's something!

    I checked for the files on the delete list in normal mode and found C:WINNT\fxsvc.exe. Do you want me to try to do something to it in normal mode?

    Here's my new HJT log. What's next?

    Thanks!
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your right about no System Restore in Win2K. I just cut & pasted a template file I use and forgot to edit that out for your case.

    Hmmm! You are saying that C:\WINNT\fxsvc.exe is still there and you could not delete it or end the process.

    Also please use Win Explorer and see if you actually see: C:\WINNT\MSCONFIG.exe

    Working on your log now.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Questions:

    1) Do you know what this is: c:\winnt\system32\MsOffExport.dll

    2) And this: C:\WINNT\system32\station.exe

    2) what about these?
    O16 - DPF: {2FE68711-8830-417D-95E0-EAB307DB0447} (mpsPwLc7.PMWebSiteLogin) - http://www.tsargent.com/PW/mpsPwLc7.CAB
    O16 - DPF: {A2401FD4-1DD3-47A4-8B9B-B883C6960E6D} (FileMgt.FileMgtCtrl) - http://www.tsargent.com/pmwebsite6/FileMgt.CAB
    O16 - DPF: {DCE60322-DEAB-41F5-BCEA-BF0B9FEE058F} (FileMgt.FileMgtCtrl) - http://www.tsargent.com/pmwebsite6/FileMgt.CAB
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Please download the following tool: Pocket KillBox

    Run Pocket Killbox and choose the Delete on Reboot option. Navigate to C:\WINNT\fxsvc.exe and press the Delete button (red X) and then Yes or OK until your machine reboots.

    After your machine reboots, use Windows Explorer to navigate to c:\winnt and make sure the fxsvc.exe file.

    Let me know if this works.

    Then do the same for C:\WINNT\SYSTEM32\DNTUS26.EXE
     
  9. tagged

    tagged Private E-2

    I checked for C:\WINNT\MSCONFIG.exe and can't find it. CWS must have taken care of it?

    No, I don't know anything about that c:\winnt\system32\MsOffExport.dll.
    No, I don't know anything about C:\WINNT\system32\station.exe

    I'm not sure what those 3 016 deals are, but but they come from my company website, so I was assuming they were ok.

    I'm going to download Pocket Killbox now and go through that stuff.

    I'll be back when I'm done.

    Thanks
     
  10. tagged

    tagged Private E-2

    Pocket Killbox worked on fxsvc.exe. now I'm going to do it to the other one.
     
  11. tagged

    tagged Private E-2

    It looks like it got rid of dntus26.exe also.

    What's next?
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay! I don't like the looks of those other two files but I'm not sure what they are for either so let's be save and instead of deleting them, we will rename them. That way if something does not work correctly afterwards, we can just rename them back.

    But first we could check Properties info on the files too. Right click on them in Win Explorer and select Properties. Then click the Version tab and go thru the Item name info looking for Company and whatever else is given.

    If there is no version tab for either of those files boot into safe mode and use Windows Explorer to rename:

    c:\winnt\system32\MsOffExport.dll to MsOffExportdll.bad
    c:\winnt\system32\station.exe to stationexe.bad

    If there is a version tab for them, give me the info on them first before doing any renaming.

    Let me know if you are able to do that. By the way how is everything working right now.
     
  13. tagged

    tagged Private E-2

    Neither one has version tabs, so I'll go to safe mode and rename them. When I was checking their properties I noticed that both of them have created dates that are after their modified dates. How does that work?

    I just tried to get to Windows update and got the same message as before. I'll let you know if that changes when I get back from safe mode.

    Thanks!
     
  14. tagged

    tagged Private E-2

    I got the names changed in safe mode and the stayed changed in normal.

    Just tried Windows Update again and I get the same page error message.

    What's next?
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  17. tagged

    tagged Private E-2

    Chaslang

    I tried downloading Microsoft Windows Script 5.6 (Windows 2000, XP), but it didn't seem to change anything. I still get the same script error message. I went to http://blogs.msdn.com/jledgard/arch.../23/218994.aspx and read through that. About the only thing I saw that I understood somewhat is that Norton Scriptblocker could be doing it. I opened Norton and looked for the options button he talked about, but it isn't there. Pretty much the rest his page could have been written in Martian and I would have understood it just as well.

    Was there something specific on there that you thought I should do, or what do you suggest?

    Thanks
     
  18. tagged

    tagged Private E-2

    I got to thinking about some of the stuff the Martian guy was saying and remembered that I couldn't uninstall my AVG anti-virus when I tried before. I tried to do it again and got the message, '16 bit Windows Subsystem C:\WINNT\System 32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close" to terminate the application.'

    I checked my files and C:\WINNT\System 32\AUTOEXEC.NT doesn't seem to exist! Why am I getting this message? Should I hit ignore and try to finish the uninstall?

    Any suggestions?

    Thanks again.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  20. Matacumbie

    Matacumbie Rocky Top

    tagged,

    The link below will help you with the 16 bit Windows Subsystem C:\WINNT\System 32\AUTOEXEC.NT. The system file is not suitable for running MS-DOS and Microsoft Windows applications. Choose 'Close" to terminate the application error.

    http://support.microsoft.com/kb/305521

    Good luck.

    Steve
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  22. tagged

    tagged Private E-2

    Yeah, I was going to post back that the link was for XP, then I saw the link for all win systems at the bottom of the page. Now I have to find my 2000 cd. I missplaced it in my stuff somewhere when I moved last spring.

    This might take awhile.

    Thanks guys.
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay let us know when you try that link out.
     
  24. tagged

    tagged Private E-2

    Well, I can't find my installation CD, so the Computer Guy at my home office wants me to send this thing in so he can change the OS over to XP. He's been wanting to do this for a while, but I haven't wanted to sort out everything I want to keep. I guess now I'll have to.

    Thanks alot for all the help, hopefully my problems will go away with my new system.

    If not, I'll be back.
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You still may be able to get away without changing to XP and without the Win2K CD. Just look on your hard disk to see if there is a c:\i386 or c:\winnt\i386 directory. If there is

    expand c:\i386\autoexec.nt_ C:\winnt\system32\autoexec.nt

    or

    expand c:\winnt\i386\autoexec.nt_ C:\winnt\system32\autoexec.nt

    the continue with the directions from step for in the MSKB link.


    If you find the i366 directory but not the autoexec.nt_ , it could already be expanded to autoexec.nt (without the underscore at the end). If this is the case, you can just copy the file directly from i386 to the c:\winnt\system32 folder.
     
  26. tagged

    tagged Private E-2

    Hey good idea!

    I couldn't find it in my i386 files that the search came up with, but I did a c: drive search and it was in a WINNT\repair file. I copied it into system32 and tried to uninstall AVG and it went right to uninstall! No 16 bit message or anything! I didn't unistall yet though. It asked me what I wanted to do with the contents of the virus vault and I'm not sure of the answer. What do I do, delete the files or what?

    On the other hand, should I be getting rid of Norton instead of AVG?

    Oh, by the way putting autoexec back where it was supposed to be didn't change anything as far as being able to get to Windows Update. I still get the same script error as before. Any suggestions?

    Thanks again!
     
  27. Matacumbie

    Matacumbie Rocky Top

    tagged,

    While we are on the subject. Double, triple, fourple check your anti-virus and firewall settings. That might be keeping you from getting to update.

    Any kind of pop-up, spam, blocking settings. There is an option in Norton's, can't remember right now where it is. I will be checking in case you have trouble finding them.

    But check everything.

    Steve
     
  28. Matacumbie

    Matacumbie Rocky Top

    Check for Popup Window Blocking or Ad Blocking.

    Steve
     
  29. tagged

    tagged Private E-2

    Steve

    I can't find where to check the settings for Norton or AVG. Can you point me in the right direction?

    Pat
     
  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes you can remove the virus vault if you decide to uninstall AVG. Personally I would not keep Norton. To much of a resource hog. I would use Avast or AVG. See How to Protect yourself from malware!

    It mentions firewalls too.

    Not sure whats going on with Windows Update.
     
  31. Matacumbie

    Matacumbie Rocky Top

    I am not that familiar with those, been a long time since I had Norton's. I would check under something like Options or Security or Tools or Internet.

    Any function that gives you an option for selecting or not.

    Steve
     
  32. Matacumbie

    Matacumbie Rocky Top

    See if you have a Advanced Options or Web Rules option.

    Steve
     
  33. tagged

    tagged Private E-2

    I'm still fairly lost there Steve. I checked my Internet Options and Security levels are all set at Medium, but that's about all I know.
     
  34. Matacumbie

    Matacumbie Rocky Top

    OK. You are looking in Internet Explorer, that's not where you need to check.

    The settings or options that I am referring to are with your Norton's product, you need to open Norton's anti-virus and check there. You should have a Norton's icon on the bottom right of your computer screen (where the clock is). Left or right-click the icon and it should open to a screen that gives you like a Control Panel where you can adjust certain things.

    Also, which version of Norton's do you have installed?

    Steve
     
  35. tagged

    tagged Private E-2

    I had Norton corporate, but I uninstalled it after reading Chaslang's post on protecting yourself from malware. The funny thing about it was that when I went to uninstall, my computer said it was used infrequently, and that the last time it had been used was like 5-12-02. If that's the case, what was generating the scan results window I've been closing off my screen every morning for the last two years?

    In reading the same post on malware protection I checked out the free firewall downloads. Both say you have to buy them if you're going to use them on a business computer, so if I'm going to buy something, what is the best product?

    Thanks for responding.
     
  36. Matacumbie

    Matacumbie Rocky Top

    Still working on your update problem, check your HOSTS file:

    1. Go to

    C:\WINNT\SYSTEM32\DRIVERS\etc (in Windows 2000)

    2. Use Notepad to view contents of the HOSTS file.

    3. If you see any entries that refer to Microsoft or to Akamai delete them or place a # in the beginning of the line.

    4. Close notepad and save the changes.

    5. On Windows 2000/XP/2003 flush the DNS cache by running the following command from the Command Prompt:

    ipconfig /flushdns

    6. Open Internet Explorer and try the Windows Update site again.

    Also, some of these software programs will add the Akamai URL to the Restricted Sites in Internet Explorer. Make sure you delete any references to Akamai servers:

    1. Open Internet Explorer, on the Tools menu, click Internet Options, and then click the Security tab.

    2. Click Restricted sites, Now click the Sites button.

    3. Remove any URLs that have akamai in the address.

    Steve
     
  37. tagged

    tagged Private E-2

    What's supposed to be in the hosts file? I've got a line that refers to clear-search and some other stuff I don't recognize?
     
  38. Matacumbie

    Matacumbie Rocky Top

    Follow step 3 . Also, if the following entries are listed remove them:

    216.177.73.139 auto.search.msn.com
    216.177.73.139 search.netscape.com
    216.177.73.139 ieautosearch

    (Sometimes the IP address on the left may be slightly different.)

    Steve
     
  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may want to ask in the Software Forum. Many people like Kerio, other like Sygate, but I think that ZoneAlarm may be more popular. Although some people blame ZoneAlarm for problems when using WinXP SP2. I have seen more problems with Norton and WinXP SP2.
     
  40. tagged

    tagged Private E-2

    I don't seem to have any of these or anything that refers to Microsoft or Akamai in my hosts file. I'm sending a copy of my hosts file, but I don't know if anything is bad in it, because I don't know what should be in it.
    What's this look like?

    Thanks
     

    Attached Files:

  41. tagged

    tagged Private E-2

    Oh, by the way, I also downloaded the new v1.99.0 of HJT. Can anyone look at this and tell me if anything on it would keep me from getting on windows update or my company's webmail server?

    Also, is there a new tutorial somewhere that tells what the new stuff in v1.99 does for you? I couldn't find anything in the MG tutorial or on the merijin site.

    Thanks for anything
     

    Attached Files:

  42. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The below quote box is all that really belongs in you hosts file:

     
  43. tagged

    tagged Private E-2

    I deleted everything in my Hosts file that didn't look like the example in Chaslang's post. It didn't change anything on the error messages I get when I try to get to Windows update or to my Webmail folders though.

    Steve, I'm not sure how I get to the Command Prompt to do this step.
    5. On Windows 2000/XP/2003 flush the DNS cache by running the following command from the Command Prompt:

    ipconfig /flushdns

    If that's important, I guess I need some dumbed-down directions on how to do it.

    In my restricted sites list, I didn't find anything that referenced Akamai, and the only site that had MSN in it was MSN-info.net. I didn't know if that was a malware site or not, so I left it there.

    When I put my cursor on Windows Update when I'm on MSN.com, the address bar at the bottom reads,"http://g.msn.com/ovs!s5.31472_315529/46.a3629/5??cm=FromMSFTQL". Does that look like the correct path?
    I can get to the downloads page from the link in the From Msn box on MSN.com, what do you suppose is different about the Updates list?

    Thanks again
     
  44. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Get to the command prompt by click Start, Run, and enter cmd in the box and click OK.
    Then type your ipconfig /flushdns command and hit enter

    Here is the proper address for Windows Update

    As far as I know, MSN-info.net is not related to Microsoft and therefore probably should be restricted.
     
  45. tagged

    tagged Private E-2

    Thanks for the step-by-step Chaslang!

    I got the flush completed. I don't see any difference though. I still get the same 'automation server can't create object' message.

    The funny thing is, the link you sent for Windows Update went right through, no errors, and let me scan for updates, download, everything! Why do you suppose that is?

    One other thing, I was looking through some old notes I took when my problems first started and I found where I wrote down the name or address or something of one of the pop-ups that was on my screen. It was YeAjukZ in brackets. Do you know what that is?

    Thanks again for your time!

    P.S. Do you ever sleep?
     
  46. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Well I would assume you were using the wrong link for Windows Update and now you have the correct one.

    YeAjukZ is a virus/trojan. It was not in your logs from what I remember. Is it there now?

    No I never sleep! ;) You guys keep me too busy for that! :D
     
  47. tagged

    tagged Private E-2

    Before I asked for help, I read through a bunch of threads and tried anything that even resembled my problem. I don't know if one of the scans from the 'Read me first before asking for support" got rid of it, or if I luckily happened to get it when I was in the 'Delete everything I don't recognize' mode. I might have gotten rid of it when I ran my first HJT scan and tried to check the log myself through the sites linked on Merijn. I'm not real sure, because I was just stumbling around blindly, and I'm probably lucky this computer works at all, because my first log I fixed was from a copy of HJT I had put on my desktop, so it didn't give me any backups!

    If the link on my startup menu to Windows Update and the one I get when I click on MSN.com are wrong, how do I change them? Your link worked, but theirs still doesn't?
     
  48. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Don't know! I don't use MSN. Are they editable? Can you right click on them and select properties and change them?
     
  49. tagged

    tagged Private E-2

    I can right click on the icon on the start menu and get to Properties, and it shows the shortcut it's taking "%SystemRoot%\system32\wupgr.exe". When I select 'Find Target' it shows me where it is in C:\Winnt\System32, and shows the file hasn't been modified since 12/7/99. So if that hasn't changed, and it worked before, is there something in the shortcut that has been changed? Do you know what that %SystemRoot% is all about?

    Thanks
     
  50. tagged

    tagged Private E-2

    I just checked on my home computer (which has ME for an OS), and the shortcut is C:\Windows\wupdgr.exe. Do you suppose if I delete the %SystemRoot% and type in C:\Winnt it will do anything? If so I'll try it as soon as I get to work tomorrow.

    Thanks again!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds