19-04-2011, 11:26 AM
I am unable to open the Windows Update website - this page can not be displayed - other websites are fine.
Ran MalwareBytes
The computer was infected with:

Could someone look through this HJT log to see if there is anything preventing access to Windows Update site:
Thank you!

Speedy Gonzales
19-04-2011, 11:33 AM
Uninstall Mcafee since NOD32 is installed. You dont need both

Tick these then tick fix checked. Close browsers. Or use ccleaner and delete the startup entries

O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"

O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"

O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [PaperPort PTD] "C:\Program Files\ScanSoft\PaperPort\pptd40nt.exe"

O4 - HKLM\..\Run: [IndexSearch] "C:\Program Files\ScanSoft\PaperPort\IndexSearch.exe"

O4 - HKLM\..\Run: [PPort11reminder] "C:\Program Files\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Documents and Settings\All Users\Application Data\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini"

O4 - Global Startup: McAfee Security Scan Plus.lnk = ?

Get malwarebytes update it then do a full scan

Open the hosts file in notepad./ Go to windows\system32\drivers\etc. See whats in it. May pay to disable system restore as well

19-04-2011, 11:35 AM
Thanks Speedy - do you want a re-scan of HJT?

Speedy Gonzales
19-04-2011, 11:36 AM
We'll see if WU works after you do that first

19-04-2011, 02:41 PM
made the adjustments per above
Malwarebytes removed 1 infection: still unable to view windows updates
downloaded, installed, updated & scanned with Superantispyware: removed 14+ infections: still am unable to view windows update website

Speedy Gonzales
19-04-2011, 02:56 PM
Get teamviewer. Then PM the ID and pw it gives you to me. I'll have a look

19-04-2011, 03:09 PM
Seen this a million times, more than likely the infections have screwed th e update settings -- One thing that usually works unless its really screwed , run Dial a fix (http://download.cnet.com/Dial-a-fix/3000-18512_4-84157.html) - Make sure you select all operations , if you have IE 8 installed, ignore the errors about not compatible, it still works OK.

Also check that the date/time is correct on the PC, if its to far out WU wont work.

OR another option from Microsoft fixit (http://support.microsoft.com/kb/971058) --- OR :p be adventurousness - do it manually, all instruction in that page ;)

19-04-2011, 03:36 PM
will report back

Speedy Gonzales
19-04-2011, 03:42 PM
Its got a rootkit / TDSS.tld4. Rebooting it now. Looks like this can block the windowsupdate site. This is what it is and does (http://www.securelist.com/en/blog/337/TDL4_Starts_Using_0_Day_Vulnerability). So, its part of a botnet? This is what one of the updates from April fixed in x64 systems