Forum Home
Press F1
 
Thread ID: 81437 2007-07-27 22:51:00 Windows downloads will not install tapram (9325) Press F1
Post ID Timestamp Content User
573313 2007-07-27 22:51:00 I can successfully download windows updates but they won't install at the time however most install later as computer closes down. Is there something I can do to overcome this problem. All this on a computer I am setting up for a friend after clearing viruses, trojans and etc. etc. tapram (9325)
573314 2007-07-27 22:54:00 Which update/s? The .Net ones??

Are you sure u removed all viruses / trojans?
Speedy Gonzales (78)
573315 2007-07-27 23:33:00 I refer to the normal weekly windows updates I have tried to do manually.
Have managed to get all downloaded over a period as computer closes off - the security centre icon shows near the close button and delays close down until installed. One or two downloads as for HP Memories Disc Creator as was listed by windows I got direct from H P and installed no problem. Am pretty sure I have got rid of all viruses as all checks with AVG Anti vIrus Adaware and Spyware and etc. all come up clean now.
tapram (9325)
573316 2007-07-27 23:38:00 Well they dont come out weekly they come out monthly.

2nd Tue of each month.

I would post a hjt log here, we'll soon find out if theres anything nasty on it still.

So what are the updates doing after u install then??

Do they bring up any error messages or just do nothing?

You are rebooting after u install them right?
Speedy Gonzales (78)
573317 2007-07-27 23:56:00 Mine can't install one part of Netframework,so the update sits in the right corner till Microsoft come up with a fix,no doubt others have this problem Lawrence (2987)
573318 2007-07-28 00:20:00 Thanks again.
The updates seem to come out rather more regularly. Perhaps as I get older the time passes more quickly.
Log posted below as requested.
When I try to install after download box comes up saying failed to install - there is sometimes an error reference when I check on update history and one I noted was 0x80200010
Yes I do reboot and it is at this stage that sometimes the security centre icon shows and installs are done slowing down th reboot.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:14:04 AM, on 28/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
C:\WINDOWS\system32\HPConfig.exe
C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
C:\Program Files\SiteAdvisor\6066\SAService.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\system32\carpserv.exe
C:\PROGRA~1\Grisoft\AVG7\avgcc.exe
C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = go.microsoft.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = go.microsoft.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = go.microsoft.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Program Files\Canon\Easy-WebPrint\Toolband.dll
O3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLL
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6066\SiteAdv.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [srmclean] C:\Cpqs\Scom\srmclean.exe
O4 - HKLM\..\Run: [QT4HPOT] C:\PROGRA~1\HPQ\ONE-TO~1\OneTouch.EXE
O4 - HKLM\..\Run: [PreloadApp] c:\hp\drivers\printers\photosmart\hphprld.exe c:\hp\drivers\printers\photosmart\setup.exe -d
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [Display Settings] C:\Program Files\HPQ\Notebook Utilities\hptasks.exe /s
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [CARPService] carpserv.exe
O4 - HKLM\..\Run: [BrowserBrand] C:\Program Files\ONLINE~1\XTRA\brand.exe
O4 - HKLM\..\Run: [NI.UERS_0001_N85M0906] "C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\KPABG5QF\ErrorSafeFreeInstall[1].exe" -nag
O4 - HKLM\..\Run: [NI.UERS_0001_N91M2007] "C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\QRYZX7TC\ErrorSafeFreeInstall[1].exe" -nag
O4 - HKLM\..\Run: [NI.UERS_9999_N91S2507] "C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\4PEFG9AF\ErrorSafeNewReleaseInst all[2].exe" -nag
O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [SiteAdvisor] C:\Program Files\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - go.microsoft.com
O16 - DPF: {6B75345B-AA36-438A-BBE6-4078B4C6984D} (HpProductDetection Class) - h20270.www2.hp.com
O16 - DPF: {AB86CE53-AC9F-449F-9399-D8ABCA09EC09} (Get_ActiveX Control) - h17000.www1.hp.com
O23 - Service: AVG Anti-Spyware Guard - GRISOFT s.r.o. - C:\Program Files\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C:\WINDOWS\system32\HPConfig.exe
O23 - Service: HPWirelessMgr - Hewlett-Packard Co. - C:\Program Files\HPQ\Notebook Utilities\HPWirelessMgr.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Program Files\SiteAdvisor\6066\SAService.exe
O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe (file missing)
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 6295 bytes
tapram (9325)
573319 2007-07-28 00:39:00 Hmm a few suss entries in that log.

Run HJT again, tick these entries, then tick fix checked.

Close browser/s.

These entries either belong to rogue software, or trojans.

O4 - HKLM\..\Run: [NI.UERS_0001_N85M0906] "C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\KPABG5QF\ErrorSafeFreeInstall[1].exe" -nag

O4 - HKLM\..\Run: [NI.UERS_0001_N91M2007] "C:\DOCUME~1\Owner\LOCALS~1\Temp\Temporary Internet Files\Content.IE5\QRYZX7TC\ErrorSafeFreeInstall[1].exe" -nag

O4 - HKLM\..\Run: [NI.UERS_9999_N91S2507] "C:\WINDOWS\TEMP\Temporary Internet Files\Content.IE5\4PEFG9AF\ErrorSafeNewReleaseInst all[2].exe" -nag

Get Rogueremover in my sig as well, install it update it, then click on scan.

Get trojan remover in my sig as well. install it update it click on scan.

And select all the options under the utilities menu.

And get ccleaner (http://www.ccleaner.com)

Install this (untick Yahoo toolbar), close browsers. Then click on run cleaner.

To get rid of the temp files etc on your hdd.

Then try those updates again.

0x80200010 looks like it has something to do with a network is disconnected message.

Are you using wireless? How is this computer connected to the internet?
Speedy Gonzales (78)
573320 2007-07-28 04:35:00 Thanks for your continued interest. Did all you suggested very carefully but still have the problem.
The computer owner (a friend) uses dial up but at present I have connected to broadband (ethernet). The computer does have wireless connectivity.
Regards.
tapram (9325)
1