avast cannot update

avast cannot itself. Not sure if its a virus or what. Here is a hijackthis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:39:50 PM, on 6/14/2009
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\System32\hkcmd.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\services.exe
C:\DOCUME~1\Owner\LOCALS~1\Temp\smss.exe
C:\WINDOWS\System32\dwwin.exe
C:\WINDOWS\explorer.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: C:\WINDOWS\System32\gsf83iujid.dll - {b2c7b2a1-00f3-42bd-f434-00aaba2c8952} - C:\WINDOWS\System32\gsf83iujid.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe
O4 - HKLM..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe
O4 - HKLM..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKLM..\Run: [servises] C:\WINDOWS\System32\servises.exe
O4 - HKCU..\Run: [servises] C:\WINDOWS\System32\servises.exe
O4 - HKCU..\Run: [Windows System Recover!] C:\DOCUME~1\Owner\LOCALS~1\Temp\smss.exe
O4 - HKLM..\Policies\Explorer\Run: [servises] C:\WINDOWS\System32\servises.exe
O4 - HKCU..\Policies\Explorer\Run: [servises] C:\WINDOWS\System32\servises.exe
O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra ‘Tools’ menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {A90A5822-F108-45AD-8482-9BC8B12DD539} (Crucial cpcScan) - http://www.crucial.com/controls/cpcScanner.cab
O20 - Winlogon Notify: __c00A8DC6 - C:\WINDOWS\System32__c00A8DC6.dat (file missing)
O22 - SharedTaskScheduler: hs837hiudjgfo9s8gjio4gfd - {B2C7B2A1-00F3-42BD-F434-00AABA2C8952} - C:\WINDOWS\System32\gsf83iujid.dll
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Background Intelligent Transfer Service (BITS) - Unknown owner - C:\WINDOWS
O23 - Service: Dhcp server (DhcpSrv) - Unknown owner - C:\WINDOWS\DLL\RUNDLL32.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS\


End of file - 3469 bytes

roadhawk1,

You already presented a hjt log in SafeMode, this one actually looks considerably worse:

MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
The version (6.00.2800.1106) is out of date. Check Windowsupdate to update the Internet Explorer.

C:\DOCUME~1\Owner\LOCALS~1\Temp\services.exe
This entry is not running from the System32 folder, so it is probably nasty.
Possibly nasty! According to our database this process runs normally in c:\windows\system32!
Check if you know this process and arrange a viruscheck where required.
This process is not running from the System32 folder as it is supposed to be.

C:\DOCUME~1\Owner\LOCALS~1\Temp\smss.exe
This entry is not running from the System32 folder, so it is probably nasty.
Possibly nasty! According to our database this process runs normally in c:\windows\system32!
Check if you know this process and arrange a viruscheck where required.
This process is not running from the System32 folder as it is supposed to be.

O2 - BHO: C:\WINDOWS\System32\gsf83iujid.dll - {b2c7b2a1-00f3-42bd-f434-00aaba2c8952} -
C:\WINDOWS\System32\gsf83iujid.dll Fix

O4 - HKLM..\Run: [servises] C:\WINDOWS\System32\servises.exe Nasty (1.97 / 5.00)

O4 - HKCU..\Run: [servises] C:\WINDOWS\System32\servises.exe Nasty (1.97 / 5.00)
Info re: http://www.threatexpert.com/files/servises.exe.html

O4 - HKCU..\Run: [Windows System Recover!] C:\DOCUME~1\Owner\LOCALS~1\Temp\smss.exe
Must be fixed! Added by the KALEL-E WORM!
Note - this is not the legitimate smss.exe process which should NOT appear in Msconfig/Startup!

O4 - HKLM..\Policies\Explorer\Run: [servises] C:\WINDOWS\System32\servises.exe
Nasty (1.93 / 5.00)

O4 - HKCU..\Policies\Explorer\Run: [servises] C:\WINDOWS\System32\servises.exe
Nasty (1.93 / 5.00)

O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1
Nasty To be fixed immediately! This entry was classified from our visitors as bad.

O22 - SharedTaskScheduler: hs837hiudjgfo9s8gjio4gfd - {B2C7B2A1-00F3-42BD-F434-00AABA2C8952} -
C:\WINDOWS\System32\gsf83iujid.dll Fix

O23 - Service: Dhcp server (DhcpSrv) - Unknown owner - C:\WINDOWS\DLL\RUNDLL32.exe
This entry is not running from the System32 folder, so it is probably nasty. This service (RUNDLL32.exe) seems to be nasty.
This process is not running from the System32 folder as it is supposed to be. check at virustotal.com

O23 - Service: Automatic Updates (wuauserv) - Unknown owner - C:\WINDOWS
Extremely nasty Extremely nasty service. (WINDOWS) if it is trojvbzd.html
upload to virustotal.com else it is a MS updating file for SP2

So not looking good actually, your OS seems outdated, and not upgraded fully or patched.
You have vulnerable third party software running which you can check with Secunia PSI,
download here: http://secunia.com/PSISetup.exe

As I was you I would save my personal data onto peripherals and re-install your PC if cleansing does not help the problems, because you never know to what extent your machine has been compromised by these malware vectors,

polonus

roadhawk, please stick to one topic:
http://forum.avast.com/index.php?topic=46111.0