Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Update > Problem Installing BITS

Reply
Thread Tools Display Modes

Problem Installing BITS

 
 
William_Holt
Guest
Posts: n/a

 
      08-26-2009
MowGreenMVP
0Sign In to VoteI just started using my old Windows XP computer and I need
to install some updates, but everytime I try to do that it says I need to
install BITS. When I tried to install it TWICE it did not work either times.
First time I tried to install it from this website and the second time I
manually downloaded it from this site and tried to install, but nothing. When
I tried to install it from this site nothing happened, it did not tell me why
the "instillation failed" and when I tried to install it manually it wold
start to extract the files and then say "File is corrupt". What is going on?

By the way, I have so SP installed because I cant get the BITS to install. I
have no type of Virus Protection.
 
Reply With Quote
 
 
 
 
MowGreen
Guest
Posts: n/a

 
      08-26-2009
William_Holt wrote:

> MowGreenMVP
> 0Sign In to VoteI just started using my old Windows XP computer and I need
> to install some updates, but everytime I try to do that it says I need to
> install BITS. When I tried to install it TWICE it did not work either times.
> First time I tried to install it from this website and the second time I
> manually downloaded it from this site and tried to install, but nothing. When
> I tried to install it from this site nothing happened, it did not tell me why
> the "instillation failed" and when I tried to install it manually it wold
> start to extract the files and then say "File is corrupt". What is going on?
>
> By the way, I have so SP installed because I cant get the BITS to install. I
> have no type of Virus Protection.


Which BITS package are you trying to install ? There are different
packages available. In release order:

http://support.microsoft.com/kb/842773
http://support.microsoft.com/kb/923845

Since there's no AV installed there may be 'unwanted visitors' resident
that is corrupting the BITS *download* so that SPs and Security updates
can not be applied.
See if you can download, install, update, and then scan the system with:

Malware Bytes Anti-malware
http://www.malwarebytes.org/

Click the Download free version button.
*Save* the file. When the download completes install and allow MBAM to
update it's defintions. When it's done, do a Quick scan.

Please post back to *this thread* with what MBAM detected, if anything.

BTW, you can download the full SP packages from the MS download center
thereby bypassing the need to reinstall BITS as the updated BITS
components are included in SPs.
* That still is dependent upon the system being free of malware *


MowGreen
===============
*-343-* FDNY
Never Forgotten
===============
 
Reply With Quote
 
William_Holt
Guest
Posts: n/a

 
      08-27-2009
Thanks for the quick reply. Fisrt off I am trying to Install the latest
version of BITS AlsocI have tried to manually download the files, but when I
am installing it, I get a message saying "The file
c:\windows\system32\drivers\ndis.sys is open or in use by another
application" Close all other applications and then click Retry". I have all
other things close, but it still says that. As for the scan it found 63
infected objects. Here is what it siad:

Malwarebytes' Anti-Malware 1.40
Database version: 2702
Windows 5.1.2600 Service Pack 1

8/26/2009 11:58:00 PM
mbam-log-2009-08-26 (23-57-20).txt

Scan type: Quick Scan
Objects scanned: 100592
Time elapsed: 35 minute(s), 21 second(s)

Memory Processes Infected: 4
Memory Modules Infected: 3
Registry Keys Infected: 12
Registry Values Infected: 9
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 33

Memory Processes Infected:
C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
taken.
C:\WINDOWS\services.exe (Trojan.Agent) -> No action taken.

Memory Modules Infected:
C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
c:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\n etlogin (Trojan.Dropper)
-> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\n etlogin (Trojan.Dropper)
-> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\netlogin
(Trojan.Dropper) -> No action taken.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\netskt (Rootkit.Agent)
-> No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6 to4 (Trojan.Agent) -> No
action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\6 to4 (Trojan.Agent) -> No
action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\6to4 (Trojan.Agent) ->
No action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i as (Backdoor.Bot) -> No
action taken.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\i as (Backdoor.Bot) -> No
action taken.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\ias (Backdoor.Bot) ->
No action taken.
HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> No
action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\services
(Trojan.FakeAlert.H) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\reader_s
(Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\reader_s
(Trojan.Agent) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host
(Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id
(Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> No action
taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateN ew (Malware.Trace) -> No
action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Services\del
(Malware.Trace) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\Regedit32
(Trojan.Agent) -> No action taken.

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify
(Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
C:\Program Files\Protection System (Rogue.ProtectionSystem) -> No action
taken.

Files Infected:
C:\WINDOWS\services.exe (Trojan.FakeAlert.H) -> No action taken.
C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\netskt.sys (Rootkit.Agent) -> No action taken.
C:\WINDOWS\system32\22.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\25.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\28.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\system32\2A.tmp (Trojan.Downloader) -> No action taken.
C:\WINDOWS\Temp\VRT1.tmp (Trojan.Agent) -> No action taken.
C:\Documents and Settings\Owner\Local Settings\Temporary Internet
Files\Content.IE5\CXQ709UV\svc[1].php (Backdoor.Bot) -> No action taken.
C:\WINDOWS\sv3.exe (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\A.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\B.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\C.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\D.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\E.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\F.tmp (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> No action taken.
C:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
C:\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashd iuasdhasd
(Trace.Pandex) -> No action taken.
C:\Documents and Settings\Owner\oashdihasidhasuidhiasdhiashdiuasdha sd
(Trace.Pandex) -> No action taken.
C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
taken.
C:\WINDOWS\sc.exe (Trojan.FakeAlert) -> No action taken.

Hope that helps a little.

"MowGreen" wrote:

> William_Holt wrote:
>
> > MowGreenMVP
> > 0Sign In to VoteI just started using my old Windows XP computer and I need
> > to install some updates, but everytime I try to do that it says I need to
> > install BITS. When I tried to install it TWICE it did not work either times.
> > First time I tried to install it from this website and the second time I
> > manually downloaded it from this site and tried to install, but nothing. When
> > I tried to install it from this site nothing happened, it did not tell me why
> > the "instillation failed" and when I tried to install it manually it wold
> > start to extract the files and then say "File is corrupt". What is going on?
> >
> > By the way, I have so SP installed because I cant get the BITS to install. I
> > have no type of Virus Protection.

>
> Which BITS package are you trying to install ? There are different
> packages available. In release order:
>
> http://support.microsoft.com/kb/842773
> http://support.microsoft.com/kb/923845
>
> Since there's no AV installed there may be 'unwanted visitors' resident
> that is corrupting the BITS *download* so that SPs and Security updates
> can not be applied.
> See if you can download, install, update, and then scan the system with:
>
> Malware Bytes Anti-malware
> http://www.malwarebytes.org/
>
> Click the Download free version button.
> *Save* the file. When the download completes install and allow MBAM to
> update it's defintions. When it's done, do a Quick scan.
>
> Please post back to *this thread* with what MBAM detected, if anything.
>
> BTW, you can download the full SP packages from the MS download center
> thereby bypassing the need to reinstall BITS as the updated BITS
> components are included in SPs.
> * That still is dependent upon the system being free of malware *
>
>
> MowGreen
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>

 
Reply With Quote
 
MowGreen
Guest
Posts: n/a

 
      08-27-2009
You need to have MBAM delete/quarantine the objects it detected,
William. You did download the *free* version, correct ?
When the scan completed all detected objects should have been checked
already.

*** First, do a check for updates from within MBAM. Then boot to
Safe Mode, do a Full Scan, and have it 'Remove Selected. ***

A description of the Safe Mode options in Windows XP
http://support.microsoft.com/kb/315222

Do *NOT* boot to Safe Mode w/networking, boot to *Safe Mode*.

That will get rid of most of the malware and, I suspect, MBAM will ask
to reboot the system in order to remove the remaining detected objects.

Boot back to normal Windows mode and do a Quick scan to see if anything
remains.

Until the malware is removed from the system then the BITS download will
become corrupted each time you download it.


MowGreen
===============
*-343-* FDNY
Never Forgotten
===============




William_Holt wrote:

> Thanks for the quick reply. Fisrt off I am trying to Install the latest
> version of BITS AlsocI have tried to manually download the files, but when I
> am installing it, I get a message saying "The file
> c:\windows\system32\drivers\ndis.sys is open or in use by another
> application" Close all other applications and then click Retry". I have all
> other things close, but it still says that. As for the scan it found 63
> infected objects. Here is what it siad:
>
> Malwarebytes' Anti-Malware 1.40
> Database version: 2702
> Windows 5.1.2600 Service Pack 1
>
> 8/26/2009 11:58:00 PM
> mbam-log-2009-08-26 (23-57-20).txt
>
> Scan type: Quick Scan
> Objects scanned: 100592
> Time elapsed: 35 minute(s), 21 second(s)
>
> Memory Processes Infected: 4
> Memory Modules Infected: 3
> Registry Keys Infected: 12
> Registry Values Infected: 9
> Registry Data Items Infected: 1
> Folders Infected: 1
> Files Infected: 33
>
> Memory Processes Infected:
> C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
> C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
> C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
> taken.
> C:\WINDOWS\services.exe (Trojan.Agent) -> No action taken.
>
> Memory Modules Infected:
> C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
> c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
> c:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
>
> Registry Keys Infected:
> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\n etlogin (Trojan.Dropper)
> -> No action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\n etlogin (Trojan.Dropper)
> -> No action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\netlogin
> (Trojan.Dropper) -> No action taken.
> HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\netskt (Rootkit.Agent)
> -> No action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6 to4 (Trojan.Agent) -> No
> action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\6 to4 (Trojan.Agent) -> No
> action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\6to4 (Trojan.Agent) ->
> No action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i as (Backdoor.Bot) -> No
> action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\i as (Backdoor.Bot) -> No
> action taken.
> HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\ias (Backdoor.Bot) ->
> No action taken.
> HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> No
> action taken.
> HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> No action taken.
>
> Registry Values Infected:
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\services
> (Trojan.FakeAlert.H) -> No action taken.
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\reader_s
> (Trojan.Agent) -> No action taken.
> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\reader_s
> (Trojan.Agent) -> No action taken.
> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host
> (Malware.Trace) -> No action taken.
> HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id
> (Malware.Trace) -> No action taken.
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> No action
> taken.
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateN ew (Malware.Trace) -> No
> action taken.
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Services\del
> (Malware.Trace) -> No action taken.
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\Regedit32
> (Trojan.Agent) -> No action taken.
>
> Registry Data Items Infected:
> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify
> (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
>
> Folders Infected:
> C:\Program Files\Protection System (Rogue.ProtectionSystem) -> No action
> taken.
>
> Files Infected:
> C:\WINDOWS\services.exe (Trojan.FakeAlert.H) -> No action taken.
> C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
> C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\netskt.sys (Rootkit.Agent) -> No action taken.
> C:\WINDOWS\system32\22.tmp (Trojan.Downloader) -> No action taken.
> C:\WINDOWS\system32\25.tmp (Trojan.Downloader) -> No action taken.
> C:\WINDOWS\system32\28.tmp (Trojan.Downloader) -> No action taken.
> C:\WINDOWS\system32\2A.tmp (Trojan.Downloader) -> No action taken.
> C:\WINDOWS\Temp\VRT1.tmp (Trojan.Agent) -> No action taken.
> C:\Documents and Settings\Owner\Local Settings\Temporary Internet
> Files\Content.IE5\CXQ709UV\svc[1].php (Backdoor.Bot) -> No action taken.
> C:\WINDOWS\sv3.exe (Backdoor.Bot) -> No action taken.
> C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\A.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\B.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\C.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\D.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\E.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\F.tmp (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> No action taken.
> C:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
> C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
> C:\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashd iuasdhasd
> (Trace.Pandex) -> No action taken.
> C:\Documents and Settings\Owner\oashdihasidhasuidhiasdhiashdiuasdha sd
> (Trace.Pandex) -> No action taken.
> C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
> taken.
> C:\WINDOWS\sc.exe (Trojan.FakeAlert) -> No action taken.
>
> Hope that helps a little.
>
> "MowGreen" wrote:
>
>
>>William_Holt wrote:
>>
>>
>>>MowGreenMVP
>>>0Sign In to VoteI just started using my old Windows XP computer and I need
>>>to install some updates, but everytime I try to do that it says I need to
>>>install BITS. When I tried to install it TWICE it did not work either times.
>>>First time I tried to install it from this website and the second time I
>>>manually downloaded it from this site and tried to install, but nothing. When
>>>I tried to install it from this site nothing happened, it did not tell me why
>>>the "instillation failed" and when I tried to install it manually it wold
>>>start to extract the files and then say "File is corrupt". What is going on?
>>>
>>>By the way, I have so SP installed because I cant get the BITS to install. I
>>>have no type of Virus Protection.

>>
>>Which BITS package are you trying to install ? There are different
>>packages available. In release order:
>>
>>http://support.microsoft.com/kb/842773
>>http://support.microsoft.com/kb/923845
>>
>>Since there's no AV installed there may be 'unwanted visitors' resident
>>that is corrupting the BITS *download* so that SPs and Security updates
>>can not be applied.
>>See if you can download, install, update, and then scan the system with:
>>
>>Malware Bytes Anti-malware
>>http://www.malwarebytes.org/
>>
>>Click the Download free version button.
>>*Save* the file. When the download completes install and allow MBAM to
>>update it's defintions. When it's done, do a Quick scan.
>>
>>Please post back to *this thread* with what MBAM detected, if anything.
>>
>>BTW, you can download the full SP packages from the MS download center
>>thereby bypassing the need to reinstall BITS as the updated BITS
>>components are included in SPs.
>>* That still is dependent upon the system being free of malware *
>>
>>
>>MowGreen
>>===============
>> *-343-* FDNY
>>Never Forgotten
>>===============
>>

 
Reply With Quote
 
William_Holt
Guest
Posts: n/a

 
      08-27-2009
So I have removed all the maleware and stuff, but when I went back to the
Windows Update page to install it again it failed and gave me Error Code:
0xD00E4104. What does that mean?

"MowGreen" wrote:

> You need to have MBAM delete/quarantine the objects it detected,
> William. You did download the *free* version, correct ?
> When the scan completed all detected objects should have been checked
> already.
>
> *** First, do a check for updates from within MBAM. Then boot to
> Safe Mode, do a Full Scan, and have it 'Remove Selected. ***
>
> A description of the Safe Mode options in Windows XP
> http://support.microsoft.com/kb/315222
>
> Do *NOT* boot to Safe Mode w/networking, boot to *Safe Mode*.
>
> That will get rid of most of the malware and, I suspect, MBAM will ask
> to reboot the system in order to remove the remaining detected objects.
>
> Boot back to normal Windows mode and do a Quick scan to see if anything
> remains.
>
> Until the malware is removed from the system then the BITS download will
> become corrupted each time you download it.
>
>
> MowGreen
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
>
>
>
> William_Holt wrote:
>
> > Thanks for the quick reply. Fisrt off I am trying to Install the latest
> > version of BITS AlsocI have tried to manually download the files, but when I
> > am installing it, I get a message saying "The file
> > c:\windows\system32\drivers\ndis.sys is open or in use by another
> > application" Close all other applications and then click Retry". I have all
> > other things close, but it still says that. As for the scan it found 63
> > infected objects. Here is what it siad:
> >
> > Malwarebytes' Anti-Malware 1.40
> > Database version: 2702
> > Windows 5.1.2600 Service Pack 1
> >
> > 8/26/2009 11:58:00 PM
> > mbam-log-2009-08-26 (23-57-20).txt
> >
> > Scan type: Quick Scan
> > Objects scanned: 100592
> > Time elapsed: 35 minute(s), 21 second(s)
> >
> > Memory Processes Infected: 4
> > Memory Modules Infected: 3
> > Registry Keys Infected: 12
> > Registry Values Infected: 9
> > Registry Data Items Infected: 1
> > Folders Infected: 1
> > Files Infected: 33
> >
> > Memory Processes Infected:
> > C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
> > C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
> > C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
> > taken.
> > C:\WINDOWS\services.exe (Trojan.Agent) -> No action taken.
> >
> > Memory Modules Infected:
> > C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
> > c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
> > c:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
> >
> > Registry Keys Infected:
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\n etlogin (Trojan.Dropper)
> > -> No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\n etlogin (Trojan.Dropper)
> > -> No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\netlogin
> > (Trojan.Dropper) -> No action taken.
> > HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\netskt (Rootkit.Agent)
> > -> No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6 to4 (Trojan.Agent) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\6 to4 (Trojan.Agent) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\6to4 (Trojan.Agent) ->
> > No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i as (Backdoor.Bot) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\i as (Backdoor.Bot) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\ias (Backdoor.Bot) ->
> > No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> No action taken.
> >
> > Registry Values Infected:
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\services
> > (Trojan.FakeAlert.H) -> No action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\reader_s
> > (Trojan.Agent) -> No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\reader_s
> > (Trojan.Agent) -> No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host
> > (Malware.Trace) -> No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id
> > (Malware.Trace) -> No action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> No action
> > taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateN ew (Malware.Trace) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Services\del
> > (Malware.Trace) -> No action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\Regedit32
> > (Trojan.Agent) -> No action taken.
> >
> > Registry Data Items Infected:
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify
> > (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
> >
> > Folders Infected:
> > C:\Program Files\Protection System (Rogue.ProtectionSystem) -> No action
> > taken.
> >
> > Files Infected:
> > C:\WINDOWS\services.exe (Trojan.FakeAlert.H) -> No action taken.
> > C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
> > C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\netskt.sys (Rootkit.Agent) -> No action taken.
> > C:\WINDOWS\system32\22.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\system32\25.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\system32\28.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\system32\2A.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\Temp\VRT1.tmp (Trojan.Agent) -> No action taken.
> > C:\Documents and Settings\Owner\Local Settings\Temporary Internet
> > Files\Content.IE5\CXQ709UV\svc[1].php (Backdoor.Bot) -> No action taken.
> > C:\WINDOWS\sv3.exe (Backdoor.Bot) -> No action taken.
> > C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\A.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\B.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\C.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\D.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\E.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\F.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
> > C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
> > C:\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashd iuasdhasd
> > (Trace.Pandex) -> No action taken.
> > C:\Documents and Settings\Owner\oashdihasidhasuidhiasdhiashdiuasdha sd
> > (Trace.Pandex) -> No action taken.
> > C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
> > taken.
> > C:\WINDOWS\sc.exe (Trojan.FakeAlert) -> No action taken.
> >
> > Hope that helps a little.
> >
> > "MowGreen" wrote:
> >
> >
> >>William_Holt wrote:
> >>
> >>
> >>>MowGreenMVP
> >>>0Sign In to VoteI just started using my old Windows XP computer and I need
> >>>to install some updates, but everytime I try to do that it says I need to
> >>>install BITS. When I tried to install it TWICE it did not work either times.
> >>>First time I tried to install it from this website and the second time I
> >>>manually downloaded it from this site and tried to install, but nothing. When
> >>>I tried to install it from this site nothing happened, it did not tell me why
> >>>the "instillation failed" and when I tried to install it manually it wold
> >>>start to extract the files and then say "File is corrupt". What is going on?
> >>>
> >>>By the way, I have so SP installed because I cant get the BITS to install. I
> >>>have no type of Virus Protection.
> >>
> >>Which BITS package are you trying to install ? There are different
> >>packages available. In release order:
> >>
> >>http://support.microsoft.com/kb/842773
> >>http://support.microsoft.com/kb/923845
> >>
> >>Since there's no AV installed there may be 'unwanted visitors' resident
> >>that is corrupting the BITS *download* so that SPs and Security updates
> >>can not be applied.
> >>See if you can download, install, update, and then scan the system with:
> >>
> >>Malware Bytes Anti-malware
> >>http://www.malwarebytes.org/
> >>
> >>Click the Download free version button.
> >>*Save* the file. When the download completes install and allow MBAM to
> >>update it's defintions. When it's done, do a Quick scan.
> >>
> >>Please post back to *this thread* with what MBAM detected, if anything.
> >>
> >>BTW, you can download the full SP packages from the MS download center
> >>thereby bypassing the need to reinstall BITS as the updated BITS
> >>components are included in SPs.
> >>* That still is dependent upon the system being free of malware *
> >>
> >>
> >>MowGreen
> >>===============
> >> *-343-* FDNY
> >>Never Forgotten
> >>===============
> >>

>

 
Reply With Quote
 
William_Holt
Guest
Posts: n/a

 
      08-27-2009
I tried again and all I got was Error Code: 0xD00E4104

"MowGreen" wrote:

> You need to have MBAM delete/quarantine the objects it detected,
> William. You did download the *free* version, correct ?
> When the scan completed all detected objects should have been checked
> already.
>
> *** First, do a check for updates from within MBAM. Then boot to
> Safe Mode, do a Full Scan, and have it 'Remove Selected. ***
>
> A description of the Safe Mode options in Windows XP
> http://support.microsoft.com/kb/315222
>
> Do *NOT* boot to Safe Mode w/networking, boot to *Safe Mode*.
>
> That will get rid of most of the malware and, I suspect, MBAM will ask
> to reboot the system in order to remove the remaining detected objects.
>
> Boot back to normal Windows mode and do a Quick scan to see if anything
> remains.
>
> Until the malware is removed from the system then the BITS download will
> become corrupted each time you download it.
>
>
> MowGreen
> ===============
> *-343-* FDNY
> Never Forgotten
> ===============
>
>
>
>
> William_Holt wrote:
>
> > Thanks for the quick reply. Fisrt off I am trying to Install the latest
> > version of BITS AlsocI have tried to manually download the files, but when I
> > am installing it, I get a message saying "The file
> > c:\windows\system32\drivers\ndis.sys is open or in use by another
> > application" Close all other applications and then click Retry". I have all
> > other things close, but it still says that. As for the scan it found 63
> > infected objects. Here is what it siad:
> >
> > Malwarebytes' Anti-Malware 1.40
> > Database version: 2702
> > Windows 5.1.2600 Service Pack 1
> >
> > 8/26/2009 11:58:00 PM
> > mbam-log-2009-08-26 (23-57-20).txt
> >
> > Scan type: Quick Scan
> > Objects scanned: 100592
> > Time elapsed: 35 minute(s), 21 second(s)
> >
> > Memory Processes Infected: 4
> > Memory Modules Infected: 3
> > Registry Keys Infected: 12
> > Registry Values Infected: 9
> > Registry Data Items Infected: 1
> > Folders Infected: 1
> > Files Infected: 33
> >
> > Memory Processes Infected:
> > C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
> > C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
> > C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
> > taken.
> > C:\WINDOWS\services.exe (Trojan.Agent) -> No action taken.
> >
> > Memory Modules Infected:
> > C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
> > c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
> > c:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
> >
> > Registry Keys Infected:
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\n etlogin (Trojan.Dropper)
> > -> No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\n etlogin (Trojan.Dropper)
> > -> No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\netlogin
> > (Trojan.Dropper) -> No action taken.
> > HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\netskt (Rootkit.Agent)
> > -> No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\6 to4 (Trojan.Agent) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\6 to4 (Trojan.Agent) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\6to4 (Trojan.Agent) ->
> > No action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\i as (Backdoor.Bot) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\i as (Backdoor.Bot) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\ias (Backdoor.Bot) ->
> > No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> No action taken.
> >
> > Registry Values Infected:
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\services
> > (Trojan.FakeAlert.H) -> No action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\reader_s
> > (Trojan.Agent) -> No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\reader_s
> > (Trojan.Agent) -> No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host
> > (Malware.Trace) -> No action taken.
> > HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id
> > (Malware.Trace) -> No action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\uid (Malware.Trace) -> No action
> > taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\UpdateN ew (Malware.Trace) -> No
> > action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Services\del
> > (Malware.Trace) -> No action taken.
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\Regedit32
> > (Trojan.Agent) -> No action taken.
> >
> > Registry Data Items Infected:
> > HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify
> > (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
> >
> > Folders Infected:
> > C:\Program Files\Protection System (Rogue.ProtectionSystem) -> No action
> > taken.
> >
> > Files Infected:
> > C:\WINDOWS\services.exe (Trojan.FakeAlert.H) -> No action taken.
> > C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
> > C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\netskt.sys (Rootkit.Agent) -> No action taken.
> > C:\WINDOWS\system32\22.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\system32\25.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\system32\28.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\system32\2A.tmp (Trojan.Downloader) -> No action taken.
> > C:\WINDOWS\Temp\VRT1.tmp (Trojan.Agent) -> No action taken.
> > C:\Documents and Settings\Owner\Local Settings\Temporary Internet
> > Files\Content.IE5\CXQ709UV\svc[1].php (Backdoor.Bot) -> No action taken.
> > C:\WINDOWS\sv3.exe (Backdoor.Bot) -> No action taken.
> > C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\A.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\B.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\C.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\D.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\E.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\F.tmp (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> No action taken.
> > C:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
> > C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
> > C:\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashd iuasdhasd
> > (Trace.Pandex) -> No action taken.
> > C:\Documents and Settings\Owner\oashdihasidhasuidhiasdhiashdiuasdha sd
> > (Trace.Pandex) -> No action taken.
> > C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
> > taken.
> > C:\WINDOWS\sc.exe (Trojan.FakeAlert) -> No action taken.
> >
> > Hope that helps a little.
> >
> > "MowGreen" wrote:
> >
> >
> >>William_Holt wrote:
> >>
> >>
> >>>MowGreenMVP
> >>>0Sign In to VoteI just started using my old Windows XP computer and I need
> >>>to install some updates, but everytime I try to do that it says I need to
> >>>install BITS. When I tried to install it TWICE it did not work either times.
> >>>First time I tried to install it from this website and the second time I
> >>>manually downloaded it from this site and tried to install, but nothing. When
> >>>I tried to install it from this site nothing happened, it did not tell me why
> >>>the "instillation failed" and when I tried to install it manually it wold
> >>>start to extract the files and then say "File is corrupt". What is going on?
> >>>
> >>>By the way, I have so SP installed because I cant get the BITS to install. I
> >>>have no type of Virus Protection.
> >>
> >>Which BITS package are you trying to install ? There are different
> >>packages available. In release order:
> >>
> >>http://support.microsoft.com/kb/842773
> >>http://support.microsoft.com/kb/923845
> >>
> >>Since there's no AV installed there may be 'unwanted visitors' resident
> >>that is corrupting the BITS *download* so that SPs and Security updates
> >>can not be applied.
> >>See if you can download, install, update, and then scan the system with:
> >>
> >>Malware Bytes Anti-malware
> >>http://www.malwarebytes.org/
> >>
> >>Click the Download free version button.
> >>*Save* the file. When the download completes install and allow MBAM to
> >>update it's defintions. When it's done, do a Quick scan.
> >>
> >>Please post back to *this thread* with what MBAM detected, if anything.
> >>
> >>BTW, you can download the full SP packages from the MS download center
> >>thereby bypassing the need to reinstall BITS as the updated BITS
> >>components are included in SPs.
> >>* That still is dependent upon the system being free of malware *
> >>
> >>
> >>MowGreen
> >>===============
> >> *-343-* FDNY
> >>Never Forgotten
> >>===============
> >>

>

 
Reply With Quote
 
MowGreen
Guest
Posts: n/a

 
      08-27-2009
Are your referring to another attempt to install BITS again from the
Windows Update site ?
*STRONGLY* suggest that you download and install the free version of
Avast antivirus first:
http://www.avast.com/eng/download-avast-home.html

Register it so that they send you a serial number which is good for 14
months: http://www.avast.com/eng/home-registration.php

Install Avast and it should update atuomatically.
It will do a system scan after the installation completes and you
restart the system. Choose to restart when the prompt comes up.

After it's finished scanning *Right* click the Avast icon in the
Notification area and choose 'About avast !'
Click the 'License key' button and enter the serial number they sent to
you. (Their email will arrive very quickly and should be where you had
it sent to by now)

The system should be relatively clean at this point in time.

*IF not, then please post back with anything that Avast detected.*

If it is, then suggest you go here using Internet Explorer:
http://support.microsoft.com/kb/971058

This Fixit will reset the Windows Update components. Suggest you
download and *save* WindowsFixit50202.msi when you click the Fixit
button, do NOT run it with IE open.
Once the download completes run the Fixit and use the *Aggressive option*
This requires that the system be connected to the internet when it's
being run. Once it's finished, restart the system.

Now see if it can access Windows Update.


MowGreen
===============
*-343-* FDNY
Never Forgotten
===============

banthecheck.com
"Security updates should *not* have *non-security content* prechecked"



William_Holt wrote:

> So I have removed all the maleware and stuff, but when I went back to the
> Windows Update page to install it again it failed and gave me Error Code:
> 0xD00E4104. What does that mean?
>
> "MowGreen" wrote:
>
>
>>You need to have MBAM delete/quarantine the objects it detected,
>>William. You did download the *free* version, correct ?
>>When the scan completed all detected objects should have been checked
>>already.
>>
>>*** First, do a check for updates from within MBAM. Then boot to
>>Safe Mode, do a Full Scan, and have it 'Remove Selected. ***
>>
>>A description of the Safe Mode options in Windows XP
>>http://support.microsoft.com/kb/315222
>>
>>Do *NOT* boot to Safe Mode w/networking, boot to *Safe Mode*.
>>
>>That will get rid of most of the malware and, I suspect, MBAM will ask
>>to reboot the system in order to remove the remaining detected objects.
>>
>>Boot back to normal Windows mode and do a Quick scan to see if anything
>>remains.
>>
>>Until the malware is removed from the system then the BITS download will
>>become corrupted each time you download it.
>>
>>
>>MowGreen
>>===============
>> *-343-* FDNY
>>Never Forgotten
>>===============
>>
>>
>>
>>
>>William_Holt wrote:
>>
>>
>>>Thanks for the quick reply. Fisrt off I am trying to Install the latest
>>>version of BITS AlsocI have tried to manually download the files, but when I
>>>am installing it, I get a message saying "The file
>>>c:\windows\system32\drivers\ndis.sys is open or in use by another
>>>application" Close all other applications and then click Retry". I have all
>>>other things close, but it still says that. As for the scan it found 63
>>>infected objects. Here is what it siad:
>>>
>>>Malwarebytes' Anti-Malware 1.40
>>>Database version: 2702
>>>Windows 5.1.2600 Service Pack 1
>>>
>>>8/26/2009 11:58:00 PM
>>>mbam-log-2009-08-26 (23-57-20).txt
>>>
>>>Scan type: Quick Scan
>>>Objects scanned: 100592
>>>Time elapsed: 35 minute(s), 21 second(s)
>>>
>>>Memory Processes Infected: 4
>>>Memory Modules Infected: 3
>>>Registry Keys Infected: 12
>>>Registry Values Infected: 9
>>>Registry Data Items Infected: 1
>>>Folders Infected: 1
>>>Files Infected: 33
>>>
>>>Memory Processes Infected:
>>>C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
>>>C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
>>>C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
>>>taken.
>>>C:\WINDOWS\services.exe (Trojan.Agent) -> No action taken.
>>>
>>>Memory Modules Infected:
>>>C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
>>>c:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
>>>c:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
>>>
>>>Registry Keys Infected:
>>>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Service s\netlogin (Trojan.Dropper)
>>>-> No action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Service s\netlogin (Trojan.Dropper)
>>>-> No action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Ser vices\netlogin
>>>(Trojan.Dropper) -> No action taken.
>>>HKEY_LOCAL_MACHINE\System\CurrentControlSet\Ser vices\netskt (Rootkit.Agent)
>>>-> No action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Service s\6to4 (Trojan.Agent) -> No
>>>action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Service s\6to4 (Trojan.Agent) -> No
>>>action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Ser vices\6to4 (Trojan.Agent) ->
>>>No action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Service s\ias (Backdoor.Bot) -> No
>>>action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Service s\ias (Backdoor.Bot) -> No
>>>action taken.
>>>HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Ser vices\ias (Backdoor.Bot) ->
>>>No action taken.
>>>HKEY_CURRENT_USER\SOFTWARE\Protection System (Rogue.ProtectionSystem) -> No
>>>action taken.
>>>HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> No action taken.
>>>
>>>Registry Values Infected:
>>>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C urrentVersion\Run\services
>>>(Trojan.FakeAlert.H) -> No action taken.
>>>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C urrentVersion\Run\reader_s
>>>(Trojan.Agent) -> No action taken.
>>>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Cu rrentVersion\Run\reader_s
>>>(Trojan.Agent) -> No action taken.
>>>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\host
>>>(Malware.Trace) -> No action taken.
>>>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Desktop\id
>>>(Malware.Trace) -> No action taken.
>>>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\ui d (Malware.Trace) -> No action
>>>taken.
>>>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WBEM\Upda teNew (Malware.Trace) -> No
>>>action taken.
>>>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C urrentVersion\Services\del
>>>(Malware.Trace) -> No action taken.
>>>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\C urrentVersion\Run\Regedit32
>>>(Trojan.Agent) -> No action taken.
>>>
>>>Registry Data Items Infected:
>>>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Securit y Center\FirewallDisableNotify
>>>(Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken.
>>>
>>>Folders Infected:
>>>C:\Program Files\Protection System (Rogue.ProtectionSystem) -> No action
>>>taken.
>>>
>>>Files Infected:
>>>C:\WINDOWS\services.exe (Trojan.FakeAlert.H) -> No action taken.
>>>C:\WINDOWS\svchost.exe (Trojan.Dropper) -> No action taken.
>>>C:\WINDOWS\Temp\35.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\netskt.sys (Rootkit.Agent) -> No action taken.
>>>C:\WINDOWS\system32\22.tmp (Trojan.Downloader) -> No action taken.
>>>C:\WINDOWS\system32\25.tmp (Trojan.Downloader) -> No action taken.
>>>C:\WINDOWS\system32\28.tmp (Trojan.Downloader) -> No action taken.
>>>C:\WINDOWS\system32\2A.tmp (Trojan.Downloader) -> No action taken.
>>>C:\WINDOWS\Temp\VRT1.tmp (Trojan.Agent) -> No action taken.
>>>C:\Documents and Settings\Owner\Local Settings\Temporary Internet
>>>Files\Content.IE5\CXQ709UV\svc[1].php (Backdoor.Bot) -> No action taken.
>>>C:\WINDOWS\sv3.exe (Backdoor.Bot) -> No action taken.
>>>C:\WINDOWS\system32\2.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\3.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\4.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\5.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\6.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\7.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\8.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\9.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\A.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\B.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\C.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\D.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\E.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\F.tmp (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\6to4v32.dll (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\certstore.dat (Trojan.Agent) -> No action taken.
>>>C:\WINDOWS\system32\Iasex.dll (Backdoor.Bot) -> No action taken.
>>>C:\WINDOWS\system32\reader_s.exe (Trojan.Agent) -> No action taken.
>>>C:\Documents and Settings\LocalService\oashdihasidhasuidhiasdhiashd iuasdhasd
>>>(Trace.Pandex) -> No action taken.
>>>C:\Documents and Settings\Owner\oashdihasidhasuidhiasdhiashdiuasdha sd
>>>(Trace.Pandex) -> No action taken.
>>>C:\Documents and Settings\Owner\reader_s.exe (Trojan.Agent) -> No action
>>>taken.
>>>C:\WINDOWS\sc.exe (Trojan.FakeAlert) -> No action taken.
>>>
>>>Hope that helps a little.
>>>
>>>"MowGreen" wrote:
>>>
>>>
>>>
>>>>William_Holt wrote:
>>>>
>>>>
>>>>
>>>>>MowGreenMVP
>>>>>0Sign In to VoteI just started using my old Windows XP computer and I need
>>>>>to install some updates, but everytime I try to do that it says I need to
>>>>>install BITS. When I tried to install it TWICE it did not work either times.
>>>>>First time I tried to install it from this website and the second time I
>>>>>manually downloaded it from this site and tried to install, but nothing. When
>>>>>I tried to install it from this site nothing happened, it did not tell me why
>>>>>the "instillation failed" and when I tried to install it manually it wold
>>>>>start to extract the files and then say "File is corrupt". What is going on?
>>>>>
>>>>>By the way, I have so SP installed because I cant get the BITS to install. I
>>>>>have no type of Virus Protection.
>>>>
>>>>Which BITS package are you trying to install ? There are different
>>>>packages available. In release order:
>>>>
>>>>http://support.microsoft.com/kb/842773
>>>>http://support.microsoft.com/kb/923845
>>>>
>>>>Since there's no AV installed there may be 'unwanted visitors' resident
>>>>that is corrupting the BITS *download* so that SPs and Security updates
>>>>can not be applied.
>>>>See if you can download, install, update, and then scan the system with:
>>>>
>>>>Malware Bytes Anti-malware
>>>>http://www.malwarebytes.org/
>>>>
>>>>Click the Download free version button.
>>>>*Save* the file. When the download completes install and allow MBAM to
>>>>update it's defintions. When it's done, do a Quick scan.
>>>>
>>>>Please post back to *this thread* with what MBAM detected, if anything.
>>>>
>>>>BTW, you can download the full SP packages from the MS download center
>>>>thereby bypassing the need to reinstall BITS as the updated BITS
>>>>components are included in SPs.
>>>>* That still is dependent upon the system being free of malware *
>>>>
>>>>
>>>>MowGreen
>>>>===============
>>>> *-343-* FDNY
>>>>Never Forgotten
>>>>===============
>>>>

>>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Re: Recent MS update causes IIS to serve simple web page VERY SLOW (20 seconds) PA Bear [MS MVP] Windows Server 1 04-20-2009 06:07 AM
Troubleshooting: Event ID:40961 Chris Windows Server 11 12-04-2008 12:27 PM
Installing windows 2003 64 bits standard server without R2 SinghRoc Windows 64 Bit 6 10-09-2007 01:03 AM
Problem after installing x64 in dual boot config with 32-bit windo samthecrazyman Windows 64 Bit 7 05-18-2006 11:56 PM
trouble installing windows xp 64 bits Orlando Windows 64 Bit 4 10-12-2005 12:02 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59