windows update will not run

windows update will not run

Secure Home | Search | About
 Microsoft Antivirus Discussions    Post an article   get this group's latest topics as an RSS feed add this group's latest topics to your My MSN content add this group's latest topics to your My Yahoo content add this group's latest topics to your Google content
Subject Author Date
windows update will not run Jim Bunton 10-10-2008
Posted by Jim Bunton on October 10, 2008, 2:19 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Windows media centre service pack 3
iexplorer v 7

Windows update will not run
Run services.msc
Check Background Intelligent Transfer Service running - OK
Check Event Log running - ok
Check Automatic Updates NOT running

Automatic Updates is disabled and it's start button is greyed out
Setting the combo to Automatic (or manual) it reverts to disabled

-----------
RECENT EVENTS - seems like some sort of malware
IeExplorer Home page began to default to MyWebHunt
When reset to normal home page on reboot reverted to MyWebHunt
---------------
Googled mywebhunt
--------
found:
http://www.threatexpert.com/report.aspx?uid=dd190d12-5574-4797-8d70-24b662a299ea
The following Registry Value was modified:. [HKEY_CURRENT_USER\Software\
Microsoft\Internet Explorer\Main]. Start Page = "http://www.mywebhunt.com"
...

reports the folowing registry modifications
a.. The following Registry Key was created:
a.. HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
a.. The newly created Registry Values are:
a.. [HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
a.. FR = "1"
b.. BootDays = "23"
b.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
a.. NotifyDownloadComplete = "yes"
c.. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
a.. [filename of the sample #1 without extension] =
"%Windir%\[filename of the sample #1]"

so that [filename of the sample #1] runs every time Windows starts

a.. The following Registry Value was modified:
a.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
a.. Start Page = http://www.mywebhunt.com
---------
I HAVE DELETED
HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
a.. FR = "1"
b.. BootDays = "23"
in the entry
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
a.. [filename of the sample #1 without extension] = "%Windir%\[filename of
the sample #1]"
I found a program named molocha.exe
AND a copy of it
in C:\Windows & Documents and Settings .. . \Temp
CREATED DATE today !!

Deleted the registry entry
"[filename of the sample #1 without extension] =
"%Windir%\[filename of the sample #1]" " for this file

AND, after reboot, renamed the C:\windows instance to Xmolocha.exe
AND deleted it from Documents and Settings\ . . \Temp

----------
This has stopped the hijack of the web browser to MyWebHunt
BUT Internet explorer is occassionally opening new instances with seemingly
random websites.
--- HELP! ---




Posted by Malke on October 10, 2008, 8:11 am
If you were  Registered and logged in, you could reply and use other advanced thread options


Jim Bunton wrote:

> Windows media centre service pack 3
> iexplorer v 7
>
> Windows update will not run
> Run services.msc
> Check Background Intelligent Transfer Service running - OK
> Check Event Log running - ok
> Check Automatic Updates NOT running
>
> Automatic Updates is disabled and it's start button is greyed out
> Setting the combo to Automatic (or manual) it reverts to disabled
> RECENT EVENTS - seems like some sort of malware
> IeExplorer Home page began to default to MyWebHunt
> When reset to normal home page on reboot reverted to MyWebHunt

(snippage)

> I found a program named molocha.exe
> AND a copy of it
> in C:\Windows & Documents and Settings .. . \Temp
> CREATED DATE today !!
>
> Deleted the registry entry
> "[filename of the sample #1 without extension] =
> "%Windir%\[filename of the sample #1]" " for this file
>
> AND, after reboot, renamed the C:\windows instance to Xmolocha.exe
> AND deleted it from Documents and Settings\ . . \Temp
> This has stopped the hijack of the web browser to MyWebHunt
> BUT Internet explorer is occassionally opening new instances with
> seemingly random websites.

Go through these general malware removal steps systematically -
http://www.elephantboycomputers.com/page2.html#Removing_Malware

Include scanning with David Lipman's Multi_AV and follow instructions to do
all scans in Safe Mode. Please see the special Notes regarding using
Multi_AV in Vista.

http://www.elephantboycomputers.com/page2.html#Multi-AV - instructions
http://tinyurl.com/yoeru3 - download link and more instructions

You can also check to see if there are targeted removal steps for your
malware here:
Bleeping Computer removal how-to's -
http://www.bleepingcomputer.com/forums/forum55.html

or here:
Malwarebytes malware removal guides:
http://tinyurl.com/5xrpft

When all else fails, get guided help. Choose one of the specialty forums
listed at the first link. Register and read its posting FAQ. PLEASE DO NOT
POST LOGS IN THE MS NEWSGROUPS.

Malke
--
MS-MVP
Elephant Boy Computers - Don't Panic!
FAQ - http://www.elephantboycomputers.com/#FAQ


Posted by The Real Truth MVP on October 10, 2008, 5:24 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


Use my Remove-it software, it will remove that malware from your system.
Choose yes for all options when prompted. Download it here
http://pcbutts1.com/downloads/tools/tools.htm When done from the same site
download Microsoft's Automatic Update Repair Tool to fix your auto update
issue.


--
Ignore any posts made by the Stalker Leythos, he's still in love with me.
He started stalking me after I spurned his advances towards me.
He said he would stop Stalking me If I stopped mentioning his name.
As you can see that does not work. He is a sick obsessive STALKER.





> Windows media centre service pack 3
> iexplorer v 7
>
> Windows update will not run
> Run services.msc
> Check Background Intelligent Transfer Service running - OK
> Check Event Log running - ok
> Check Automatic Updates NOT running
>
> Automatic Updates is disabled and it's start button is greyed out
> Setting the combo to Automatic (or manual) it reverts to disabled
>
> -----------
> RECENT EVENTS - seems like some sort of malware
> IeExplorer Home page began to default to MyWebHunt
> When reset to normal home page on reboot reverted to MyWebHunt
> ---------------
> Googled mywebhunt
> --------
> found:
>
http://www.threatexpert.com/report.aspx?uid=dd190d12-5574-4797-8d70-24b662a299ea
> The following Registry Value was modified:. [HKEY_CURRENT_USER\Software\
> Microsoft\Internet Explorer\Main]. Start Page = "http://www.mywebhunt.com"
> ...
>
> reports the folowing registry modifications
> a.. The following Registry Key was created:
> a.. HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
> a.. The newly created Registry Values are:
> a.. [HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
> a.. FR = "1"
> b.. BootDays = "23"
> b.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
> a.. NotifyDownloadComplete = "yes"
> c.. [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
> a.. [filename of the sample #1 without extension] =
> "%Windir%\[filename of the sample #1]"
>
> so that [filename of the sample #1] runs every time Windows starts
>
> a.. The following Registry Value was modified:
> a.. [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
> a.. Start Page = http://www.mywebhunt.com
> ---------
> I HAVE DELETED
> HKEY_LOCAL_MACHINE\SOFTWARE\GodLib
> HKEY_LOCAL_MACHINE\SOFTWARE\GodLib]
> a.. FR = "1"
> b.. BootDays = "23"
> in the entry
> [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
> a.. [filename of the sample #1 without extension] = "%Windir%\[filename
> of
> the sample #1]"
> I found a program named molocha.exe
> AND a copy of it
> in C:\Windows & Documents and Settings .. . \Temp
> CREATED DATE today !!
>
> Deleted the registry entry
> "[filename of the sample #1 without extension] =
> "%Windir%\[filename of the sample #1]" " for this file
>
> AND, after reboot, renamed the C:\windows instance to Xmolocha.exe
> AND deleted it from Documents and Settings\ . . \Temp
>
> ----------
> This has stopped the hijack of the web browser to MyWebHunt
> BUT Internet explorer is occassionally opening new instances with
> seemingly
> random websites.
> --- HELP! ---
>
>
>


Posted by Leythos on October 10, 2008, 8:09 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


says...
> Use my Remove-it software
>
Read the truth about PCBUTTS online:

http://tinyurl.com/4rruwd


--
- Igitur qui desiderat pacem, praeparet bellum.
- Calling an illegal alien an "undocumented worker" is like calling a
drug dealer an "unlicensed pharmacist"
spam999free@rrohio.com (remove 999 for proper email address)

Posted by ---Fitz--- on October 10, 2008, 11:57 pm
If you were  Registered and logged in, you could reply and use other advanced thread options


> says...
>> Use my Remove-it software
>>
> Read the truth about PCBUTTS online:
>
> http://tinyurl.com/4rruwd
>
>
> --
> - Igitur qui desiderat pacem, praeparet bellum.
> - Calling an illegal alien an "undocumented worker" is like calling a
> drug dealer an "unlicensed pharmacist"
> spam999free@rrohio.com (remove 999 for proper email address)


Very informative...even through the translation.


Similar ThreadsPosted
windows update blocked... February 4, 2006, 4:01 pm
Windows Update not responding May 1, 2006, 7:56 pm
Windows Defender update... August 22, 2006, 7:06 pm
Re: windows update proublem May 3, 2008, 2:27 am
Windows Sp3 update.. ntoskrnl.exe October 6, 2008, 9:23 pm
Microsoft released update for Windows Defender in Vista April 10, 2007, 2:14 pm
HELP - Security sites and Windows Update blocked - other sites available September 8, 2008, 2:19 pm
JAVA RE update August 10, 2006, 5:38 am
Overdue on a NAV Update November 2, 2006, 11:49 am
Freebie links update July 31, 2007, 9:44 pm

The site map in XML format XML site map

Contact Us | Privacy Policy