Hijack.WindowsUpdate

Order SP2 CD:
https://om2.one.microsoft.com/opa/CASearch.aspx?StoreID=d7a098f4-4034-4ccb-a785-9e890e6b4f5b&LocaleCode=en-us&JavaScriptOn=yes

Order the Windows XP SP3 CD then scroll down to select language:
http://www.microsoft.com/windows/products/windowsxp/sp3/default.mspx

I believe each cost about $10.00 shipping and arrived within a week but I keep them handy for whenever I build a system to install before putting the system on the Internet to have a base level of security.

I would never put an XP system without at least SP1 on the Internet as it will become infected within a few minutes.

Hey all,

I too recently had this problem and have now found a fix. This worked for me perfectly but don’t know if it will work for everyone else. so the problem is that the virus that I had had edited the registry which was stopping the automatic update services from running.

to fix go in to regedit either do a search for fystemroot or go down to the path:HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath. Where it says (%fystemRoot%\system32\svchost.exe -k netsvcs) it needs to read %systemRoot%\system32\svchost.exe -k netsvcs
If you can’t edit it go into edit in your toolbar and change your permissions to allow full access. to edit you only need to double click on the file that says imagepath. Once changed go into start bar and run services.msc. Go down to automatic update and restart the service. I manually went in and updated windows after this. My next Malwarebytes scan was free of this stupidly painful infection. Hopefully this will work for everyone else too.

cheers

Thanks, drfire for posting a solution to this perplexing problem. It will certainly bring some long-due cheer to others similarly affected.

As for me, like stated earlier in this thread… consider myself lucky, having rid myself of this scourge in a state of blissful unawareness.

Truth be told… till your post arrived, had not even noticed the funny spelling in the file path:

%fystemRoot%\system32\svchost.exe -k netsvcs

Am grappling now with another mysterious alien that has nixed my administrator account, depriving me of the privileges/permissions granted while being part of the Administrator Operators Group… never a dull day here :wink: … but that’s for another topic.

thanks again for sharing.

~cheers!