The only problem I’ve experienced is the one with windows updates. Security Center tells me automatic updates are turned off. I can’t turn them back on from there. Automatic updates are selected under control panel/system/automatic updates, but are still turned off. The Windows Update site doesn’t work. I can see the main page, but anything I try to do results in an error (The website has encountered a problem and cannot display the page you are trying to view).
Auto updates worked just a few days ago when the last MS security fixes were rolled out. I didn’t experience Security Center warnings before the virus hit. In fact, the Security Center warning was my first indication I had a problem. Second was the XP 2011 Antivirus popup. Third was Avast! blocking a file from accessing the internet (I should probably be very glad it did that). The best hypothesis is that the rogue program blocked access to Windows updates.
I hope you can help. Here’s the report from the OTS fix:
All Processes Killed
[Registry - Safe List]
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Search not found.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6}\ not found.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\{2318C2B1-4965-11D4-9B18-009027A5CD4F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Extensions{E2D4D26B-0180-43a4-B05F-462D6D54C789}\ButtonText deleted successfully.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Extensions{E2D4D26B-0180-43a4-B05F-462D6D54C789}\Default Visible deleted successfully.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Extensions{E2D4D26B-0180-43a4-B05F-462D6D54C789}\HotIcon deleted successfully.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Extensions{E2D4D26B-0180-43a4-B05F-462D6D54C789}\Icon deleted successfully.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Extensions{E2D4D26B-0180-43a4-B05F-462D6D54C789}\MenuText deleted successfully.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Extensions{E2D4D26B-0180-43a4-B05F-462D6D54C789}\Script deleted successfully.
Registry value HKEY_USERS\S-1-5-21-571688815-2063811557-4274646049-1008\Software\Microsoft\Internet Explorer\Extensions{E2D4D26B-0180-43a4-B05F-462D6D54C789}\ToolTip deleted successfully.
[Files/Folders - Created Within 30 Days]
C:\Documents and Settings\HP_Administrator\Desktop\TDSSKiller.exe moved successfully.
[Files/Folders - Modified Within 30 Days]
C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\l1mt4nci68jk2ni176 moved successfully.
C:\Documents and Settings\All Users\Application Data\l1mt4nci68jk2ni176 moved successfully.
[Files - No Company Name]
File C:\Documents and Settings\HP_Administrator\Local Settings\Application Data\l1mt4nci68jk2ni176 not found!
File C:\Documents and Settings\All Users\Application Data\l1mt4nci68jk2ni176 not found!
[Empty Temp Folders]
User: Administrator
->Temp folder emptied: 18090 bytes
->Temporary Internet Files folder emptied: 32768 bytes
User: All Users
User: Default User
->Temp folder emptied: 18090 bytes
->Temporary Internet Files folder emptied: 32768 bytes
->Flash cache emptied: 56502 bytes
User: HP_Administrator
->Temp folder emptied: 84391294 bytes
->Temporary Internet Files folder emptied: 92577905 bytes
->Java cache emptied: 155040 bytes
->FireFox cache emptied: 276557567 bytes
->Flash cache emptied: 59622 bytes
User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 89393 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 19569 bytes
%systemroot%\System32 .tmp files removed: 2577 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 119962 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 18090 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes
RecycleBin emptied: 756503120 bytes
Total Files Cleaned = 1,155.00 mb
[EMPTYFLASH]
User: Administrator
User: All Users
User: Default User
->Flash cache emptied: 0 bytes
User: HP_Administrator
->Flash cache emptied: 0 bytes
User: LocalService
User: NetworkService
Total Flash Files Cleaned = 0.00 mb
Restore point Set: OTS Restore Point (0)
< End of fix log >
OTS by OldTimer - Version 3.1.42.0 fix logfile created on 05192011_135444
Files\Folders moved on Reboot…
C:\Documents and Settings\HP_Administrator\Local Settings\Temp\IadHide5.dll moved successfully.
Registry entries deleted on Reboot…