Jump to content

STILL can't update Malwarebytes (or Microsoft Security Essentials)


Impala

Recommended Posts

Have spent hours on this. Upgraded to Pro. Removed Malwarebytes, redownloaded free version (only one I could find to redownload). Ran Panda's free online scanner. All to no avail.

Here is DDS etc (also attached as Word file):

DDS (Ver_2011-08-26.01) - NTFSx86

Internet Explorer: 8.0.6001.18702

Run by David at 10:54:51 on 2012-02-02

Microsoft Windows XP Home Edition 5.1.2600.3.1252.64.1033.18.2814.1447 [GMT 13:00]

.

AV: Microsoft Security Essentials *Enabled/Updated* {EDB4FA23-53B8-4AFA-8C5D-99752CCA7095}

AV: Microsoft Security Essentials *Disabled/Updated* {BCF43643-A118-4432-AEDE-D861FCBCFCDF}

.

============== Running Processes ===============

.

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\svchost -k DcomLaunch

svchost.exe

c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe

C:\WINDOWS\System32\svchost.exe -k netsvcs

svchost.exe

svchost.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\brsvc01a.exe

C:\WINDOWS\system32\brss01a.exe

C:\WINDOWS\system32\spoolsv.exe

svchost.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

C:\Program Files\Bonjour\mDNSResponder.exe

C:\Program Files\Gigabyte\EasySaver\ESSVR.EXE

C:\Program Files\Java\jre6\bin\jqs.exe

C:\Program Files\CyberLink\Shared files\RichVideo.exe

C:\WINDOWS\system32\svchost.exe -k imgsvc

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE

C:\WINDOWS\system32\SearchIndexer.exe

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe

C:\WINDOWS\system32\RUNDLL32.EXE

C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Microsoft Security Client\msseces.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Gadwin Systems\PrintScreen\PrintScreen.exe

C:\Program Files\Skype\Phone\Skype.exe

C:\Program Files\Nuance\NaturallySpeaking10\Program\natspeak.exe

C:\Program Files\iPod\bin\iPodService.exe

C:\Program Files\iTunes\iTunes.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceHelper.exe

C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe

C:\Program Files\Common Files\Apple\Apple Application Support\distnoted.exe

C:\Program Files\Common Files\Apple\Mobile Device Support\SyncServer.exe

c:\program files\common files\installshield\updateservice\isuspm.exe

C:\Program Files\Common Files\InstallShield\UpdateService\agent.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Mozilla Firefox\plugin-container.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Microsoft Office\Office12\WINWORD.EXE

C:\Program Files\Microsoft\Office Live\OfficeLiveSignIn.exe

C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE

C:\WINDOWS\system32\wiaacmgr.exe

C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe

C:\WINDOWS\system32\SearchProtocolHost.exe

.

============== Pseudo HJT Report ===============

.

uStart Page = hxxp://www.xtra.co.nz/

uInternet Settings,ProxyOverride = *.local;<local>

uInternet Settings,ProxyServer = proxy.chelmer.co.nz:3128

BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll

BHO: MediaBar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\toolbar\imeshdtxmltbpi.dll

BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File

BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll

BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll

BHO: JQSIEStartDetectorImpl Class: {e7e6f031-17ce-4c07-bc86-eabfe594f69c} - c:\program files\java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll

TB: MediaBar: {28387537-e3f9-4ed7-860c-11e69af4a8a0} - c:\progra~1\imesha~1\mediabar\toolbar\imeshdtxmltbpi.dll

uRun: [ctfmon.exe] c:\windows\system32\ctfmon.exe

uRun: [Gadwin PrintScreen] c:\program files\gadwin systems\printscreen\PrintScreen.exe /nosplash

uRun: [skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized

mRun: [nwiz] nwiz.exe /installquiet

mRun: [NvMediaCenter] RUNDLL32.EXE c:\windows\system32\NvMcTray.dll,NvTaskbarInit

mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup

mRun: [sSBkgdUpdate] "c:\program files\common files\scansoft shared\ssbkgdupdate\SSBkgdupdate.exe" -Embedding -boot

mRun: [iSUSPM Startup] c:\progra~1\common~1\instal~1\update~1\ISUSPM.exe -startup

mRun: [DNS7reminder] "c:\program files\nuance\naturallyspeaking10\ereg\ereg.exe" -r "c:\documents and settings\all users\application data\nuance\naturallyspeaking10\Ereg.ini

mRun: [iSUSScheduler] "c:\program files\common files\installshield\updateservice\issch.exe" -start

mRun: [AppleSyncNotifier] c:\program files\common files\apple\mobile device support\AppleSyncNotifier.exe

mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe"

mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey

mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe"

mRun: [APSDaemon] "c:\program files\common files\apple\apple application support\APSDaemon.exe"

mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime

dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE

dRun: [DWQueuedReporting] "c:\progra~1\common~1\micros~1\dw\dwtrig20.exe" -t

StartupFolder: c:\docume~1\david\startm~1\programs\startup\dragon~1.lnk - c:\program files\nuance\naturallyspeaking10\program\natspeak.exe

IE: E&xport to Microsoft Excel - c:\progra~1\mi1933~1\office12\EXCEL.EXE/3000

IE: {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe

IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll

IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\mi1933~1\office12\REFIEBAR.DLL

DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} - hxxp://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1273736035640

DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab

DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab

DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_20-windows-i586.cab

TCP: Interfaces\{65F30851-0CBB-4666-A116-00493489E0FF} : NameServer = 10.66.0.20,10.66.0.21

Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - c:\program files\skype\toolbars\internet explorer\skypeieplugin.dll

AppInit_DLLs:

SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - c:\windows\system32\WPDShServiceObj.dll

SEH: Windows Desktop Search Namespace Manager: {56f9679e-7826-4c84-81f3-532071a8bcc5} - c:\program files\windows desktop search\MSNLNamespaceMgr.dll

.

================= FIREFOX ===================

.

FF - ProfilePath - c:\documents and settings\david\application data\mozilla\firefox\profiles\4ig7p3qh.default\

FF - prefs.js: browser.startup.homepage - hxxp://www.yahoo.co.nz

FF - prefs.js: keyword.URL - hxxp://www.yahoo.co.nz

FF - prefs.js: network.proxy.ftp - proxy.chelmer.co.nz

FF - prefs.js: network.proxy.ftp_port - 3128

FF - prefs.js: network.proxy.http - proxy.chelmer.co.nz

FF - prefs.js: network.proxy.http_port - 3128

FF - prefs.js: network.proxy.socks - proxy.chelmer.co.nz

FF - prefs.js: network.proxy.socks_port - 3128

FF - prefs.js: network.proxy.ssl - proxy.chelmer.co.nz

FF - prefs.js: network.proxy.ssl_port - 3128

FF - prefs.js: network.proxy.type - 1

FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\adobe\reader 9.0\reader\air\nppdf32.dll

FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll

FF - plugin: c:\program files\google\update\1.3.21.79\npGoogleUpdate3.dll

FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll

FF - plugin: c:\program files\microsoft\office live\npOLW.dll

FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll

FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll

.

============= SERVICES / DRIVERS ===============

.

R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2009-12-2 165648]

R1 MpKsl35f75296;MpKsl35f75296;c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ce278de-066a-43b3-b446-db20c6034baf}\MpKsl35f75296.sys [2012-1-31 29904]

R2 ES lite Service;ES lite Service for program management.;c:\program files\gigabyte\easysaver\essvr.exe [2010-5-13 68136]

R3 L1c;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\drivers\l1c51x86.sys [2010-5-13 49664]

R3 NVHDA;Service for NVIDIA High Definition Audio Driver;c:\windows\system32\drivers\nvhda32.sys [2010-5-14 58600]

S2 gupdate1caf52f3c127f96;Google Update Service (gupdate1caf52f3c127f96);c:\program files\google\update\GoogleUpdate.exe [2010-5-17 133104]

S3 Ambfilt;Ambfilt;c:\windows\system32\drivers\Ambfilt.sys [2010-5-13 1684736]

S3 gupdatem;Google Update Service (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-5-17 133104]

S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-8-19 18432]

UnknownUnknown MpKsl27f538d4;MpKsl27f538d4; [x]

UnknownUnknown MpKsl3f5b68b5;MpKsl3f5b68b5; [x]

UnknownUnknown MpKsl57d9d57d;MpKsl57d9d57d; [x]

UnknownUnknown MpKsl5a4fe7fd;MpKsl5a4fe7fd; [x]

UnknownUnknown MpKsl7a393f38;MpKsl7a393f38; [x]

UnknownUnknown MpKsla91fcf5e;MpKsla91fcf5e; [x]

UnknownUnknown MpKslaa72b4f2;MpKslaa72b4f2; [x]

UnknownUnknown MpKsledd5d982;MpKsledd5d982; [x]

.

=============== Created Last 30 ================

.

2012-01-30 23:18:43 56200 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ce278de-066a-43b3-b446-db20c6034baf}\offreg.dll

2012-01-30 23:18:43 29904 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ce278de-066a-43b3-b446-db20c6034baf}\MpKsl35f75296.sys

2012-01-30 00:41:01 6557240 ----a-w- c:\documents and settings\all users\application data\microsoft\microsoft antimalware\definition updates\{5ce278de-066a-43b3-b446-db20c6034baf}\mpengine.dll

2012-01-30 00:24:13 5488 ----a-w- c:\windows\system32\PerfStringBackup.TMP

2012-01-30 00:18:53 -------- d-----w- c:\windows\system32\wbem\repository\FS

2012-01-30 00:18:53 -------- d-----w- c:\windows\system32\wbem\Repository

2012-01-13 00:49:08 626688 ----a-w- c:\program files\mozilla firefox\msvcr80.dll

2012-01-13 00:49:08 548864 ----a-w- c:\program files\mozilla firefox\msvcp80.dll

2012-01-13 00:49:08 479232 ----a-w- c:\program files\mozilla firefox\msvcm80.dll

2012-01-13 00:49:08 43992 ----a-w- c:\program files\mozilla firefox\mozutils.dll

2012-01-09 21:18:17 450352 ----a-w- c:\program files\FixitCenter_Run.exe

2012-01-09 21:14:00 73728 ----a-w- c:\windows\system32\javacpl.cpl

2012-01-09 21:14:00 476904 ----a-w- c:\program files\mozilla firefox\plugins\npdeployJava1.dll

2012-01-03 13:10:44 182672 ----a-w- c:\program files\mozilla firefox\plugins\nppdf32.dll

2012-01-03 13:10:44 182672 ----a-w- c:\program files\internet explorer\plugins\nppdf32.dll

.

==================== Find3M ====================

.

2012-01-30 00:20:02 17488 ----a-w- c:\windows\gdrv.sys

2012-01-09 21:13:21 472808 ----a-w- c:\windows\system32\deployJava1.dll

2011-12-06 21:08:58 236576 ------w- c:\windows\system32\MpSigStub.exe

2011-12-05 00:46:02 273344 ----a-w- c:\windows\system32\nvdrsdb0.bin

2011-12-05 00:46:02 1 ----a-w- c:\windows\system32\nvdrssel.bin

2011-12-05 00:44:54 273344 ----a-w- c:\windows\system32\nvdrsdb1.bin

2011-11-25 21:57:19 293376 ----a-w- c:\windows\system32\winsrv.dll

2011-11-23 13:25:32 1859584 ----a-w- c:\windows\system32\win32k.sys

2011-11-18 12:35:08 60416 ----a-w- c:\windows\system32\packager.exe

2011-11-16 14:21:44 354816 ----a-w- c:\windows\system32\winhttp.dll

2011-11-16 14:21:44 152064 ----a-w- c:\windows\system32\schannel.dll

2011-11-04 19:20:51 916992 ----a-w- c:\windows\system32\wininet.dll

2011-11-04 19:20:51 43520 ----a-w- c:\windows\system32\licmgr10.dll

2011-11-04 19:20:51 1469440 ------w- c:\windows\system32\inetcpl.cpl

2011-11-04 11:23:59 385024 ----a-w- c:\windows\system32\html.iec

2010-05-16 19:30:11 1704744 ----a-w- c:\program files\SkypeSetup.exe

.

============= FINISH: 10:55:08.87 ===============

See also this link: http://www.bleepingc...ml/page__st__30

Recent intensive but ulitmately unsuccessful attempt by an apparent expert to solve the problem.

DDS.doc

Link to post
Share on other sites

Hello Impala,

Kindly provide a current status on the "update issue"; is it still an issue? is it resolved?

eusa_hand.gif and also, are you being currently helped elsewhere? at BC forum? if the latter, it is counter-productive for the commnunity helpers to be helping you at more than one forum !

Link to post
Share on other sites

Due to the lack of feedback this topic is closed to prevent others from posting here. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread.

Other members who need assistance please start your own topic in a new thread. Thanks!

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.