windows update redirect to msn,still unable to update windows & antivirus

Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

serf5080

Thread Starter
Joined
Dec 28, 2008
Messages
2
hi, i'm very new in thiz computing stuff. i've tried the steps of other post by mischine regarding using combofix & the system restore stuff, but still in vain. i'm using Fujitsu P1510 tablet pc,freshly re-installed Win XP SP2 & AVG 8.0.previously,i regularly updated to SP3 but due to some reason, i re-installed back and then thiz happens..i didn't get the idea at one part where the system restore was done, . i've done the combofix log but yet the hijackthis.is it necessary to do HJT?i'm really worried whn things not turn out..i also did the secunia scan, it turn out like thiz:

Detection Statistics:
9 Applications Detected in Total
3 Insecure Versions Detected
6 Patched Versions Detected


Running For: 4 Minutes, 53 Seconds


Errors with the scan: 1 Error Detected


Status / Currently Processing:
Detection completed with 1 error

*that error says that unable to find missing updates.


BTW, thz is the combofix log.hope it helps..
--------------------------------------------------------------------
ComboFix 08-12-26.03 - Lil' Baybee 2008-12-29 0:46:46.1 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.502.196 [GMT 8:00]
Running from: c:\documents and settings\Lil' Baybee\Desktop\ComboFix.exe
AV: AVG Anti-Virus Free *On-access scanning disabled* (Outdated)
* Created a new restore point

WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.

C:\Autorun.inf
C:\resycled
c:\resycled\boot.com
D:\Autorun.inf
D:\resycled
d:\resycled\boot.com
F:\Autorun.inf
F:\resycled
f:\resycled\boot.com

.
((((((((((((((((((((((((( Files Created from 2008-11-28 to 2008-12-28 )))))))))))))))))))))))))))))))
.

2008-12-28 23:37 . 2008-12-28 23:37 <DIR> d--hs---- c:\documents and settings\Lil' Baybee\PrivacIE
2008-12-28 23:11 . 2008-12-28 23:11 <DIR> d---s---- c:\documents and settings\Lil' Baybee\UserData
2008-12-28 23:03 . 2008-12-28 23:11 <DIR> d-------- c:\documents and settings\Lil' Baybee\Application Data\AVGTOOLBAR
2008-12-28 22:18 . 2008-12-28 22:18 <DIR> d-------- c:\documents and settings\Lil' Baybee\Application Data\Intel

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-12-28 21:46 --------- d-----w c:\program files\AlpsPoint
2008-12-28 16:19 410,984 ----a-w c:\windows\system32\deploytk.dll
2008-12-28 16:19 --------- d-----w c:\program files\Java
2008-12-28 15:46 --------- d-----w c:\program files\Microsoft Silverlight
2008-12-28 15:36 --------- d-----w c:\documents and settings\All Users\Application Data\avg8
2008-12-28 15:07 --------- d-----w c:\program files\Microsoft ActiveSync
2008-12-28 15:06 --------- d-----w c:\program files\ACW
2008-12-28 15:03 97,928 ----a-w c:\windows\system32\drivers\avgldx86.sys
2008-12-28 15:03 76,040 ----a-w c:\windows\system32\drivers\avgtdix.sys
2008-12-28 15:03 10,520 ----a-w c:\windows\system32\avgrsstx.dll
2008-12-28 15:02 --------- d-----w c:\program files\AVG
2008-12-28 14:21 --------- d-----w c:\program files\AuthenTec
2008-12-28 14:20 --------- d-----w c:\program files\LogOnAssistant
2008-12-28 14:17 17,801 ----a-w c:\windows\system32\drivers\AegisP.sys
2008-12-28 14:17 --------- d-----w c:\documents and settings\All Users\Application Data\Intel
2008-12-28 14:16 --------- d-----w c:\program files\Intel
2008-12-28 14:15 --------- d--h--w c:\program files\InstallShield Installation Information
2008-12-28 14:15 --------- d-----w c:\program files\Softex
2008-12-28 14:15 --------- d-----w c:\program files\Fingerprint Sensor
2008-12-28 14:12 --------- d-----w c:\program files\ltmoh
2008-12-28 14:12 --------- d-----w c:\program files\Fujitsu
2008-12-28 14:11 --------- d-----w c:\program files\Common Files\InstallShield
2008-12-28 14:02 --------- d-----w c:\program files\microsoft frontpage
.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2004-08-04 15360]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ATSwpNav"="c:\program files\Fingerprint Sensor\ATSwpNav -run" [X]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2005-07-27 126976]
"ApMain"="c:\program files\AlpsPoint\ApMain.exe" [2005-06-23 61440]
"IMJPMIG8.1"="c:\windows\IME\imjp8_1\IMJPMIG.EXE" [2004-08-04 208952]
"PHIME2002ASync"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"PHIME2002A"="c:\windows\system32\IME\TINTLGNT\TINTSETP.EXE" [2004-08-04 455168]
"IndicatorUtility"="c:\program files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe" [2005-02-28 81920]
"LtMoh"="c:\program files\ltmoh\Ltmoh.exe" [2004-08-17 184320]
"FjEvents"="c:\program files\Fujitsu\Utils\fjevents.exe" [2005-07-12 20480]
"FjDspMon"="c:\program files\Fujitsu\Utils\FjDspMon.exe" [2005-07-13 20480]
"Fujitsu Menu"="c:\program files\Fujitsu\Utils\FjMnuIco.exe" [2005-07-13 32768]
"Button"="c:\program files\Fujitsu\Utils\fjbtnsrv.exe" [2005-07-12 45056]
"Bright"="c:\program files\Fujitsu\Utils\FjBright.Exe" [2005-07-13 102400]
"OmniPass"="c:\program files\Softex\OmniPass\scureapp.exe" [2005-03-15 1859584]
"IntelZeroConfig"="c:\program files\Intel\Wireless\bin\ZCfgSvc.exe" [2005-05-31 401408]
"IntelWireless"="c:\program files\Intel\Wireless\Bin\ifrmewrk.exe" [2005-06-03 385024]
"AVG8_TRAY"="c:\progra~1\AVG\AVG8\avgtray.exe" [2008-12-28 1261336]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-29 136600]
"SoundMan"="SOUNDMAN.EXE" [2005-07-27 c:\windows\SOUNDMAN.EXE]
"AGRSMMSG"="AGRSMMSG.exe" [2005-05-11 c:\windows\AGRSMMSG.exe]
"FIDMSFLT"="Fidmsflt.exe" [2005-07-27 c:\windows\system32\Fidmsflt.exe]
"FIDMGREP"="FidGrap.exe" [2005-07-27 c:\windows\system32\FidGrap.exe]

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\IntelWireless]
2005-05-31 22:46 110592 c:\program files\Intel\Wireless\Bin\LgNotify.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\OPXPGina]
2005-03-15 18:03 49152 c:\program files\Softex\OmniPass\OPXPGina.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LoaResi]
2005-05-06 11:25 57344 c:\windows\system32\LoaResi.dll

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
"AppInit_DLLs"=avgrsstx.dll

[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgemc.exe"=
"c:\\Program Files\\AVG\\AVG8\\avgupd.exe"=

R1 AvgLdx86;AVG Free AVI Loader Driver x86;c:\windows\system32\Drivers\avgldx86.sys [2008-12-28 97928]
R2 avg8emc;AVG Free8 E-mail Scanner;c:\progra~1\AVG\AVG8\avgemc.exe [2008-12-28 875288]
R2 avg8wd;AVG Free8 WatchDog;c:\progra~1\AVG\AVG8\avgwdsvc.exe [2008-12-28 231704]
R2 AvgTdiX;AVG Free8 Network Redirector;c:\windows\system32\Drivers\avgtdix.sys [2008-12-28 76040]
R3 ApPS2;Alps Pointing-device Driver;c:\windows\system32\DRIVERS\ApPS2.sys [2008-12-29 36428]
R3 FIDMOUS;Fujitsu Touch Panel;c:\windows\system32\DRIVERS\Fidmous.sys [2008-12-29 26792]
R3 Fjbtndrv;Fujitsu Button Driver;c:\windows\system32\DRIVERS\Fjbtndrv.sys [2003-06-20 11392]

*Newly Created Service* - CATCHME
*Newly Created Service* - JAVAQUICKSTARTERSERVICE
*Newly Created Service* - PROCEXP90
.
Contents of the 'Scheduled Tasks' folder

2008-12-28 c:\windows\Tasks\User_Feed_Synchronization-{1D5BC0DC-0694-4FC9-B6CC-919A6A055C0F}.job
- c:\windows\system32\msfeedssync.exe [2008-08-22 03:05]
.
.
------- Supplementary Scan -------
.
uStart Page = hxxp://www.google.com/
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Lil' Baybee\Application Data\Mozilla\Firefox\Profiles\xpd9ya8r.default\
.

**************************************************************************

catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-12-29 00:48:05
Windows 5.1.2600 Service Pack 2 NTFS

scanning hidden processes ...

scanning hidden autostart entries ...

scanning hidden files ...

scan completed successfully
hidden files:

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\msqpdxserv.sys]
"imagepath"="\systemroot\system32\drivers\msqpdxepveawyj.sys"
.
--------------------- DLLs Loaded Under Running Processes ---------------------

- - - - - - - > 'winlogon.exe'(828)
c:\windows\system32\avgrsstx.dll
c:\windows\system32\LoaResi.dll
c:\program files\Softex\OmniPass\opxpgina.dll
c:\program files\Intel\Wireless\Bin\LgNotify.dll

- - - - - - - > 'lsass.exe'(924)
c:\windows\system32\avgrsstx.dll
.
Completion time: 2008-12-29 0:48:41
ComboFix-quarantined-files.txt 2008-12-28 16:48:39

Pre-Run: 26,153,906,176 bytes free
Post-Run: 26,198,544,384 bytes free

144


any urgent help wld be appreciated..thx..

add:HJT log after combofix uninstalled & antivirus etc2 enabled

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 1:35:03 AM, on 12/29/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18241)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Java\jre6\bin\jqs.exe
C:\Program Files\Softex\OmniPass\Omniserv.exe
C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\Program Files\Softex\OmniPass\OPXPApp.exe
C:\Program Files\Intel\Wireless\Bin\ZcfgSvc.exe
C:\PROGRA~1\Intel\Wireless\Bin\1XConfig.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\hkcmd.exe
C:\Program Files\AlpsPoint\ApMain.exe
C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
C:\WINDOWS\system32\igfxext.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\ltmoh\Ltmoh.exe
C:\Program Files\Fujitsu\Utils\fjevents.exe
C:\Program Files\Fujitsu\Utils\FjDspMon.exe
C:\Program Files\Fujitsu\Utils\FjMnuIco.exe
C:\Program Files\Fujitsu\Utils\fjbtnsrv.exe
C:\Program Files\Fujitsu\Utils\FjBright.Exe
C:\Program Files\Fingerprint Sensor\ATSwpNav.exe
C:\Program Files\Softex\OmniPass\scureapp.exe
C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe
C:\WINDOWS\system32\Fidmsflt.exe
C:\WINDOWS\system32\FidGrap.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Java\jre6\bin\java.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program Files\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe
O4 - HKLM\..\Run: [ApMain] C:\Program Files\AlpsPoint\ApMain.exe
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [IndicatorUtility] C:\Program Files\Fujitsu\Fujitsu Hotkey Utility\IndicatorUty.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [LtMoh] C:\Program Files\ltmoh\Ltmoh.exe
O4 - HKLM\..\Run: [FjEvents] C:\Program Files\Fujitsu\Utils\fjevents.exe
O4 - HKLM\..\Run: [FjDspMon] C:\Program Files\Fujitsu\Utils\FjDspMon.exe
O4 - HKLM\..\Run: [Fujitsu Menu] C:\Program Files\Fujitsu\Utils\FjMnuIco.exe
O4 - HKLM\..\Run: [Button] C:\Program Files\Fujitsu\Utils\fjbtnsrv.exe
O4 - HKLM\..\Run: [Bright] C:\Program Files\Fujitsu\Utils\FjBright.Exe
O4 - HKLM\..\Run: [ATSwpNav] "C:\Program Files\Fingerprint Sensor\ATSwpNav" -run
O4 - HKLM\..\Run: [OmniPass] C:\Program Files\Softex\OmniPass\scureapp.exe
O4 - HKLM\..\Run: [IntelZeroConfig] C:\Program Files\Intel\Wireless\bin\ZCfgSvc.exe
O4 - HKLM\..\Run: [IntelWireless] C:\Program Files\Intel\Wireless\Bin\ifrmewrk.exe /tf Intel PROSet/Wireless
O4 - HKLM\..\Run: [FIDMSFLT] Fidmsflt.exe
O4 - HKLM\..\Run: [FIDMGREP] FidGrap.exe
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: LoaResi - C:\WINDOWS\SYSTEM32\LoaResi.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: EvtEng - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program Files\Java\jre6\bin\jqs.exe
O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Program Files\Softex\OmniPass\Omniserv.exe
O23 - Service: RegSrvc - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\S24EvMon.exe

--
End of file - 6169 bytes

p/s:plz tell me what to do..even it requires me to do it all over again...thx..
 

serf5080

Thread Starter
Joined
Dec 28, 2008
Messages
2
add:

i also have problems wit my AVG.it seems that no matter how hard i try to update it,it won't do..is it the same as window update's problem?any help would be appreciated..thx again..
 
Status
This thread has been Locked and is not open to further replies. Please start a New Thread if you're having a similar issue. View our Welcome Guide to learn how to use this site.

Users Who Are Viewing This Thread (Users: 0, Guests: 1)

As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 807,865 other people just like you!

Latest posts

Staff online

Top