Nibble Guru - Computing queries demystified Sunday, November 23, 2008
Home
My Account / Register
Login / Logout
Post your Problem!
Search

About Us
Contact Us



List Home > Operating System > Other Problems >   [ Post New Problem ]

Welcome back !
TrackingID : 243
Posted : Saturday, November 22nd, 2003 11:02:30 PM
By : bigjon
Wupdater and PrefetchConfiguration:
When I shut down I get a msg that wupdater is trying to shut down and it won't end task. Also my c drive keeps running when I'm not on the internet and I suspect this might be the cause?? I found the following files: Windows.000\prefetch\updater.exe-ode294.pf and program files\common files\updater\updater
Are these legit fies?
Operating System : MS Windows XP

Related Problems :
Comments :
Re: Wupdater and Prefetch by Anonymous Ghost on November 22nd, 2003 11:29:20 PM
I am having the exact same problem on my laptop. Have you found out what's causing this, and more importantly, how to make it stop?
Wupdater is a VIRUS by bigjon on November 22nd, 2003 11:32:28 PM
You should look at the removal instructions at http://www.safersite.com/PestInfo/e/euniverse.asp
Re: Wupdater and Prefetch by Anonymous Ghost on November 22nd, 2003 11:42:36 PM
Files in the C:\Windows\Prefetch folder are for file optimization in XP. All of them can be deleted periodically and should be.

To shutdown the updater right click on the Taskbar and select Task Manager. On the applications tab select the updater, then End task button.
Re: Wupdater and Prefetch by Anonymous Ghost on November 27th, 2003 01:21:36 PM
I tried to find the prefetch folder and couldn't . How do I find it so I can delete the files periodically? If I run disk cleanup, does that clean out the prefetch folder?
Re: Wupdater and Prefetch by Anonymous Ghost on December 01st, 2003 01:59:01 PM
Have found a program via ms, which detects and removes wupdater from startup menu, www.winpatrol.com you can then delete the .exe of wupdater using find.
Re: Wupdater and Prefetch by Anonymous Ghost on December 03rd, 2003 07:00:02 AM
check this out, i maintain a network of comps at a small business.All of a sudden NONE of them will connect to the internet.After hours of troubleshooting with no good reason for then to not be connecting, I decided to bring a comp from home ( that was connecting just fine) soon as i plug the thing in at work i get this "incredifind" &"wupdater.exe" crap and it will not connect and it is hosed!! WTF is this stuff!!
Re: Wupdater.exe by Anonymous Ghost on December 04th, 2003 06:05:15 AM
The Wupdater file can be removed using a simple trojan scan and destroy tool AKA SPYPOD ect, do a search and download, have not tryed winpatrol yet.
Re: Wupdater and Prefetch by Anonymous Ghost on December 04th, 2003 05:49:49 PM
I have same problem as post on 12/03("incredifind" &"wupdater.exe" crap). I downloaded winpatrol and removed wupdater but I still cannot use IE. My harddrive is still updating also? I can only access the web through WinExplorer. any other ideas?
Re: Wupdater and Prefetch by Anonymous Ghost on December 04th, 2003 07:51:24 PM
Its in startup and you can disable it from running everytime you turn on the computer. Go to start run type msconfig, it will bring up the system configuration utility, click the startup tab in the upper right hand side, uncheck it then click ok it will ask to restart the computer. Do so. When it comes back up it will indicate you have used the system configuration utility. Check dont show this again then ok. Test. eMachine tech.
Re: Wupdater and Prefetch by Anonymous Ghost on December 04th, 2003 08:23:40 PM
QUICK FIX FOR WUPDATER.EXE

If you are having problems with wupdater.exe (some kind of spyware) go to 'Start', then 'Run', then type "msconfig" and click 'OK', select the 'Startup' tab and you will see a list of startup programs. Look for "wupdater.exe" and uncheck it click ok and re-start your computer. This will not remove the program, but it will stop it from starting up.

Vortimaxx
Re: Wupdater and Prefetch by Anonymous Ghost on December 04th, 2003 08:25:52 PM
Looks like the tech that helped me posted just before me. lol

Vortimaxx
Re: Wupdater and Prefetch by Anonymous Ghost on December 04th, 2003 10:12:36 PM
I think I got it!

It looks like wupdater is loaded when Kazaa is installed.

Prove me wrong, let me know if you have the wupdater problem, but havent installed Kazaa.

Vortimaxx
Re: Wupdater and Prefetch by Anonymous Ghost on December 05th, 2003 02:12:00 PM
Oh Great!! I used AD-AWARE6 to remove it and it removed something where I can't get any internet/network connections!! My Linksys card says I'm connected(DSL) but I don't get anything. I tried with dialup and got onto AOL but the browser doesn't work. The problem is on my laptop. My orig post was 12/04 6:49:49
Re: Wupdater and Prefetch by Anonymous Ghost on December 10th, 2003 04:56:51 PM
It looks like when you download the "FREE" Kazaa you get the "Adware" version. So far I have found three sites that work with Kazaa, Prefetch, Perfectnav, and incredifind. If you have problems with your sys. now that you have removed files, try reinstalling Kazaa, and then do a proper un-install. or read my other posts to stop it from starting at boot up.
Hope it helps.

Vortimaxx
Re: Wupdater and Prefetch by Anonymous Ghost on December 15th, 2003 04:29:40 PM
i'm a newbie, got a similar problem. in task manager, an mssys.exe uses all the juice and wma + ie slow right down. someone suggests it's a vius. any idea of how to clean up. deleted from system folder and prefetch folder, still it returns
Re: Wupdater and Prefetch by Anonymous Ghost on December 16th, 2003 01:55:44 PM
This virus is also on my computer. I got it from Kazaa and tried to find: then delete but I still can't browse with Internet Explorer. I'm on cable internet and the server is working correctly and recieving signal from my computer. What can I do to get my internet working without reformating my entire computer??!
Re: Wupdater and Prefetch by Anonymous Ghost on December 16th, 2003 07:45:39 PM
Get "Hijack This" (hijackthis.exe) from http://www.spywareinfo.com/downloads.php?cat=sp#det, run it and post the resulting log and your plight to http://www.computercops.biz Forums in either Security: Virus-Worm Related or Privacy: Spyware-Hijack related. Oh, and spend some time reading the spywareinfo website while you wait for a response (usually pretty quick turnaround)!
Re: Wupdater and Prefetch by Anonymous Ghost on December 17th, 2003 02:05:23 PM
Run the "regedit", go to HKEY_LOCAL_MACHINE then SOFTWARE then MICROSOFT then WINDOWS then CURRENTVERSION then RUN and delete the key named "updater". DONE
Re: Wupdater and Prefetch by Anonymous Ghost on December 18th, 2003 01:40:15 AM
Logfile of HijackThis v1.97.7
Scan saved at 3:48:48 PM, on 12/18/2003
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32Ati2evxx.exe
C:Program FilesMcAfeeMcAfee VirusScanAvsynmgr.exe
C:WINDOWSSystem32driversCDAC11BA.EXE
C:Program FilesCommon FilesMicrosoft SharedVS7Debugmdm.exe
C:Program FilesMcAfeeMcAfee VirusScanVsStat.exe
C:Program FilesMcAfeeMcAfee VirusScanVshwin32.exe
C:Program FilesCommon FilesNetwork AssociatesMcShieldMcshield.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesMcAfeeMcAfee VirusScanalogserv.exe
C:Program FilesMcAfeeMcAfee Shared ComponentsGuardianCMGrdian.exe
C:WINDOWSSystem32P2P NetworkingP2P Networking.exe
C:Program FilesCommon filesupdaterwupdater.exe
C:Program FilesWinamp3winampa.exe
C:Program FilesCommon FilesRealUpdate_OBrealsched.exe
C:WINDOWSSystem32rundll32.exe
C:Program FilesMcAfeeMcAfee VirusScanWebscanx.exe
C:Program FilesMcAfeeMcAfee VirusScanAvconsol.exe
C:Program FilesWinamp3winamp3.exe
D:Program FilesAvant Browseravant.exe
C:Program FilesICQIcq.exe
C:Program FilesInternet ExplorerIEXPLORE.EXE
C:Documents and SettingsAdministratorDesktopHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.hotmail.com/
R3 - URLSearchHook: PerfectNavBHO Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:PROGRA~1PERFEC~1BHOPERFEC~1.DLL
F2 - REG:system.ini: Shell=Explorer.exe
O1 - Hosts: 213.159.117.217 www.0190-dialer.com
O1 - Hosts: 213.159.117.217 www.22469.com
O1 - Hosts: 213.159.117.217 www.3wisp.com
O1 - Hosts: 213.159.117.217 www.adult-cinema.org
O1 - Hosts: 213.159.117.217 www.adultfreehosting.com
O1 - Hosts: 213.159.117.217 www.adulthosting.com
O1 - Hosts: 213.159.117.217 www.adultlinks1.com
O1 - Hosts: 213.159.117.217 www.adultmegamovies.com
O1 - Hosts: 213.159.117.217 www.adultsexmovie.net
O1 - Hosts: 213.159.117.217 www.adultwall.com
O1 - Hosts: 213.159.117.217 www.afro-sex.com
O1 - Hosts: 213.159.117.217 www.agreathost.net
O1 - Hosts: 213.159.117.217 www.alehina.com
O1 - Hosts: 213.159.117.217 www.allnichestgp.com
O1 - Hosts: 213.159.117.217 www.allowednet.com
O1 - Hosts: 213.159.117.217 www.amateurlips.com
O1 - Hosts: 213.159.117.217 www.amateurnudephoto.com
O1 - Hosts: 213.159.117.217 www.amateursgonebad.com
O1 - Hosts: 213.159.117.217 www.ambersamateurhardcore.com
O1 - Hosts: 213.159.117.217 www.anyamateur.com
O1 - Hosts: 213.159.117.217 www.apornhost.com
O1 - Hosts: 213.159.117.217 www.findmodels.com
O1 - Hosts: 213.159.117.217 www.asians*****.com
O1 - Hosts: 213.159.117.217 www.awethumbs.com
O1 - Hosts: 213.159.117.217 www.badassxxx.com
O1 - Hosts: 213.159.117.217 www.badbimbo.com
O1 - Hosts: 213.159.117.217 www.beautifulbondage.com
O1 - Hosts: 213.159.117.217 www.bestpornhost.com
O1 - Hosts: 213.159.117.217 www.biggestdickinporn.net
O1 - Hosts: 213.159.117.217 www1.3wisp.com
O1 - Hosts: 213.159.117.217 www1.kinghost.com
O1 - Hosts: 213.159.117.217 www1.ndhosting.com
O1 - Hosts: 213.159.117.217 www1.sexls.com
O1 - Hosts: 213.159.117.217 www1.smutserver.com
O1 - Hosts: 213.159.117.217 www1.toptgphost.com
O1 - Hosts: 213.159.117.217 www1.xfreehosting.com
O1 - Hosts: 213.159.117.217 www10.kinghost.com
O1 - Hosts: 213.159.117.217 www10.smutserver.com
O1 - Hosts: 213.159.117.217 www11.kinghost.com
O1 - Hosts: 213.159.117.217 www11.smutserver.com
O1 - Hosts: 213.159.117.217 www12.kinghost.com
O1 - Hosts: 213.159.117.217 www12.smutserver.com
O1 - Hosts: 213.159.117.217 www13.smutserver.com
O1 - Hosts: 213.159.117.217 www14.smutserver.com
O1 - Hosts: 213.159.117.217 www15.smutserver.com
O1 - Hosts: 213.159.117.217 www16.smutserver.com
O1 - Hosts: 213.159.117.217 www17.smutserver.com
O1 - Hosts: 213.159.117.217 www18.smutserver.com
O1 - Hosts: 213.159.117.217 www19.smutserver.com
O1 - Hosts: 213.159.117.217 www2.3wisp.com
O1 - Hosts: 213.159.117.217 www2.kinghost.com
O1 - Hosts: 213.159.117.217 www2.ndhosting.com
O1 - Hosts: 213.159.117.217 www2.smutserver.com
O1 - Hosts: 213.159.117.217 www2.toptgphost.com
O1 - Hosts: 213.159.117.217 www2.xfreehosting.com
O1 - Hosts: 213.159.117.217 www2.zpornstars.com
O1 - Hosts: 213.159.117.217 www20.smutserver.com
O1 - Hosts: 213.159.117.217 www21.smutserver.com
O1 - Hosts: 213.159.117.217 www22.smutserver.com
O1 - Hosts: 213.159.117.217 www23.smutserver.com
O1 - Hosts: 213.159.117.217 www24.smutserver.com
O1 - Hosts: 213.159.117.217 www25.smutserver.com
O1 - Hosts: 213.159.117.217 www26.smutserver.com
O1 - Hosts: 213.159.117.217 www27.smutserver.com
O1 - Hosts: 213.159.117.217 www28.smutserver.com
O1 - Hosts: 213.159.117.217 www29.smutserver.com
O1 - Hosts: 213.159.117.217 www3.kinghost.com
O1 - Hosts: 213.159.117.217 www3.ndhosting.com
O1 - Hosts: 213.159.117.217 www3.smutserver.com
O1 - Hosts: 213.159.117.217 www3.xfreehosting.com
O1 - Hosts: 213.159.117.217 www3.zpornstars.com
O1 - Hosts: 213.159.117.217 www30.smutserver.com
O1 - Hosts: 213.159.117.217 www31.smutserver.com
O1 - Hosts: 213.159.117.217 www32.smutserver.com
O1 - Hosts: 213.159.117.217 www4.kinghost.com
O1 - Hosts: 213.159.117.217 www4.smutserver.com
O1 - Hosts: 213.159.117.217 www4.xfreehosting.com
O1 - Hosts: 213.159.117.217 www4.zpornstars.com
O1 - Hosts: 213.159.117.217 www5.kinghost.com
O1 - Hosts: 213.159.117.217 www5.smutserver.com
O1 - Hosts: 213.159.117.217 www6.kinghost.com
O1 - Hosts: 213.159.117.217 www6.smutserver.com
O1 - Hosts: 213.159.117.217 www7.kinghost.com
O1 - Hosts: 213.159.117.217 www7.smutserver.com
O1 - Hosts: 213.159.117.217 www8.kinghost.com
O1 - Hosts: 213.159.117.217 www8.smutserver.com
O1 - Hosts: 213.159.117.217 www9.kinghost.com
O1 - Hosts: 213.159.117.217 www9.smutserver.com
O1 - Hosts: 213.159.117.217 www.bigmovies.com
O1 - Hosts: 213.159.117.217 www.bigpornvideos.com
O1 - Hosts: 213.159.117.217 www.big-xxx-movies.com
O1 - Hosts: 213.159.117.217 www.samplehosting.com
O1 - Hosts: 213.159.117.217 www.blinghosting.com
O1 - Hosts: 213.159.117.217 www.blitz-hosting.com
O1 - Hosts: 213.159.117.217 www.boyanxxx.com
O1 - Hosts: 213.159.117.217 www.bustyx.com
O1 - Hosts: 213.159.117.217 www.cleanadulthost.com
O1 - Hosts: 213.159.117.217 www.cleanpornhost.com
O1 - Hosts: 213.159.117.217 www.cyberxxxhost.com
O1 - Hosts: 213.159.117.217 www.dialcom.com
O1 - Hosts: 213.159.117.217 www.eldererotica.tv
O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:Program FilesDAPDAPBHO.dll
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:Program FilesMyWaySrchAstt1.binMYSRCHAS.DLL (file missing)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C:WINDOWSSystem32BPKwb.dll
O2 - BHO: NavErrRedir Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:PROGRA~1PERFEC~1BHOPERFEC~1.DLL
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:Program FilesDAPDAPIEBar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O4 - HKLM..Run: [IMJPMIG8.1] C:WINDOWSIMEimjp8_1IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM..Run: [PHIME2002ASync] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE /SYNC
O4 - HKLM..Run: [PHIME2002A] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE /IMEName
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 - HKLM..Run: [Alogserv] C:Program FilesMcAfeeMcAfee VirusScanalogserv.exe
O4 - HKLM..Run: [McAfee Guardian] "C:Program FilesMcAfeeMcAfee Shared ComponentsGuardianCMGrdian.exe" /SU
O4 - HKLM..Run: [Mirabilis ICQ] C:PROGRA~1ICQICQNet.exe
O4 - HKLM..Run: [QuickTime Task] "C:Program FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 - HKLM..Run: [updater] C:Program FilesCommon filesupdaterwupdater.exe
O4 - HKLM..Run: [WinampAgent] "C:Program FilesWinamp3\winampa.exe"
O4 - HKLM..Run: [TkBellExe] C:Program FilesCommon FilesRealUpdate_OBrealsched.exe -osboot
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup
O4 - Startup: HotSync Manager.LNK = D:Program FilesPalmHOTSYNC.EXE
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:Program FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:Program FilesMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: &Download with &DAP - C:PROGRA~1DAPdapextie.htm
O8 - Extra context menu item: Download &all with DAP - C:PROGRA~1DAPdapextie2.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: ICQ Pro (HKLM)
O9 - Extra 'Tools' menuitem: ICQ (HKLM)
O9 - Extra button: Run DAP (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {54B52E52-8000-4413-BD67-FC7FE24B59F2} (EARTPatchX Class) - http://www.ea.com/downloads/rtpatch/EARTPX.cab
O16 - DPF: {90C9629E-CD32-11D3-BBFB-00105A1F0D68} (InstallShield International Setup Player) - http://www.installengine.com/engine/isetup.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLMSystemCCSServicesTcpip..{57B50DD3-8787-4DD4-98D3-D3327299CC5E}: NameServer = 202.188.1.5 202.188.0.133


the above is my log from hijackthis.
can anyone help me to remove wupdater.exe & unwanted file?
Re: Wupdater and Prefetch by Anonymous Ghost on December 18th, 2003 08:19:34 PM
In HijackThis, checkmark O4 - HKLM..Run: [updater] C:Program FilesCommon filesupdaterwupdater.exe and click the Fix button. Then reboot and delete the C:Program FilesCommon FilesUpdater folder.

I would also get rid of:
O1 - Hosts: 213.159.117.217 www.0190-dialer.com
O1 - Hosts: 213.159.117.217 www.22469.com
O1 - Hosts: 213.159.117.217 www.3wisp.com
O1 - Hosts: 213.159.117.217 www.adult-cinema.org
O1 - Hosts: 213.159.117.217 www.adultfreehosting.com
O1 - Hosts: 213.159.117.217 www.adulthosting.com
O1 - Hosts: 213.159.117.217 www.adultlinks1.com
O1 - Hosts: 213.159.117.217 www.adultmegamovies.com
O1 - Hosts: 213.159.117.217 www.adultsexmovie.net
O1 - Hosts: 213.159.117.217 www.adultwall.com
O1 - Hosts: 213.159.117.217 www.afro-sex.com
O1 - Hosts: 213.159.117.217 www.agreathost.net
O1 - Hosts: 213.159.117.217 www.alehina.com
O1 - Hosts: 213.159.117.217 www.allnichestgp.com
O1 - Hosts: 213.159.117.217 www.allowednet.com
O1 - Hosts: 213.159.117.217 www.amateurlips.com
O1 - Hosts: 213.159.117.217 www.amateurnudephoto.com
O1 - Hosts: 213.159.117.217 www.amateursgonebad.com
O1 - Hosts: 213.159.117.217 www.ambersamateurhardcore.com
O1 - Hosts: 213.159.117.217 www.anyamateur.com
O1 - Hosts: 213.159.117.217 www.apornhost.com
O1 - Hosts: 213.159.117.217 www.findmodels.com
O1 - Hosts: 213.159.117.217 www.asians*****.com
O1 - Hosts: 213.159.117.217 www.awethumbs.com
O1 - Hosts: 213.159.117.217 www.badassxxx.com
O1 - Hosts: 213.159.117.217 www.badbimbo.com
O1 - Hosts: 213.159.117.217 www.beautifulbondage.com
O1 - Hosts: 213.159.117.217 www.bestpornhost.com
O1 - Hosts: 213.159.117.217 www.biggestdickinporn.net
O1 - Hosts: 213.159.117.217 www1.3wisp.com
O1 - Hosts: 213.159.117.217 www1.kinghost.com
O1 - Hosts: 213.159.117.217 www1.ndhosting.com
O1 - Hosts: 213.159.117.217 www1.sexls.com
O1 - Hosts: 213.159.117.217 www1.smutserver.com
O1 - Hosts: 213.159.117.217 www1.toptgphost.com
O1 - Hosts: 213.159.117.217 www1.xfreehosting.com
O1 - Hosts: 213.159.117.217 www10.kinghost.com
O1 - Hosts: 213.159.117.217 www10.smutserver.com
O1 - Hosts: 213.159.117.217 www11.kinghost.com
O1 - Hosts: 213.159.117.217 www11.smutserver.com
O1 - Hosts: 213.159.117.217 www12.kinghost.com
O1 - Hosts: 213.159.117.217 www12.smutserver.com
O1 - Hosts: 213.159.117.217 www13.smutserver.com
O1 - Hosts: 213.159.117.217 www14.smutserver.com
O1 - Hosts: 213.159.117.217 www15.smutserver.com
O1 - Hosts: 213.159.117.217 www16.smutserver.com
O1 - Hosts: 213.159.117.217 www17.smutserver.com
O1 - Hosts: 213.159.117.217 www18.smutserver.com
O1 - Hosts: 213.159.117.217 www19.smutserver.com
O1 - Hosts: 213.159.117.217 www2.3wisp.com
O1 - Hosts: 213.159.117.217 www2.kinghost.com
O1 - Hosts: 213.159.117.217 www2.ndhosting.com
O1 - Hosts: 213.159.117.217 www2.smutserver.com
O1 - Hosts: 213.159.117.217 www2.toptgphost.com
O1 - Hosts: 213.159.117.217 www2.xfreehosting.com
O1 - Hosts: 213.159.117.217 www2.zpornstars.com
O1 - Hosts: 213.159.117.217 www20.smutserver.com
O1 - Hosts: 213.159.117.217 www21.smutserver.com
O1 - Hosts: 213.159.117.217 www22.smutserver.com
O1 - Hosts: 213.159.117.217 www23.smutserver.com
O1 - Hosts: 213.159.117.217 www24.smutserver.com
O1 - Hosts: 213.159.117.217 www25.smutserver.com
O1 - Hosts: 213.159.117.217 www26.smutserver.com
O1 - Hosts: 213.159.117.217 www27.smutserver.com
O1 - Hosts: 213.159.117.217 www28.smutserver.com
O1 - Hosts: 213.159.117.217 www29.smutserver.com
O1 - Hosts: 213.159.117.217 www3.kinghost.com
O1 - Hosts: 213.159.117.217 www3.ndhosting.com
O1 - Hosts: 213.159.117.217 www3.smutserver.com
O1 - Hosts: 213.159.117.217 www3.xfreehosting.com
O1 - Hosts: 213.159.117.217 www3.zpornstars.com
O1 - Hosts: 213.159.117.217 www30.smutserver.com
O1 - Hosts: 213.159.117.217 www31.smutserver.com
O1 - Hosts: 213.159.117.217 www32.smutserver.com
O1 - Hosts: 213.159.117.217 www4.kinghost.com
O1 - Hosts: 213.159.117.217 www4.smutserver.com
O1 - Hosts: 213.159.117.217 www4.xfreehosting.com
O1 - Hosts: 213.159.117.217 www4.zpornstars.com
O1 - Hosts: 213.159.117.217 www5.kinghost.com
O1 - Hosts: 213.159.117.217 www5.smutserver.com
O1 - Hosts: 213.159.117.217 www6.kinghost.com
O1 - Hosts: 213.159.117.217 www6.smutserver.com
O1 - Hosts: 213.159.117.217 www7.kinghost.com
O1 - Hosts: 213.159.117.217 www7.smutserver.com
O1 - Hosts: 213.159.117.217 www8.kinghost.com
O1 - Hosts: 213.159.117.217 www8.smutserver.com
O1 - Hosts: 213.159.117.217 www9.kinghost.com
O1 - Hosts: 213.159.117.217 www9.smutserver.com
O1 - Hosts: 213.159.117.217 www.bigmovies.com
O1 - Hosts: 213.159.117.217 www.bigpornvideos.com
O1 - Hosts: 213.159.117.217 www.big-xxx-movies.com
O1 - Hosts: 213.159.117.217 www.samplehosting.com
O1 - Hosts: 213.159.117.217 www.blinghosting.com
O1 - Hosts: 213.159.117.217 www.blitz-hosting.com
O1 - Hosts: 213.159.117.217 www.boyanxxx.com
O1 - Hosts: 213.159.117.217 www.bustyx.com
O1 - Hosts: 213.159.117.217 www.cleanadulthost.com
O1 - Hosts: 213.159.117.217 www.cleanpornhost.com
O1 - Hosts: 213.159.117.217 www.cyberxxxhost.com
O1 - Hosts: 213.159.117.217 www.dialcom.com
O1 - Hosts: 213.159.117.217 www.eldererotica.tv

You've got some other stuff there that I'm not sure about:
O2 - BHO: (no name) - {0000CC75-ACF3-4cac-A0A9-DD3868E06852} - C:Program FilesDAPDAPBHO.dll
O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:Program FilesMyWaySrchAstt1.binMYSRCHAS.DLL (file missing)
O2 - BHO: PK IE Plugin - {1E1B2879-88FF-11D3-8D96-D7ACAC95951A} - C:WINDOWSSystem32BPKwb.dll
O2 - BHO: NavErrRedir Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:PROGRA~1PERFEC~1BHOPERFEC~1.DLL
O3 - Toolbar: DAP Bar - {62999427-33FC-4baf-9C9C-BCE6BD127F08} - C:Program FilesDAPDAPIEBar.dll
O4 - HKLM..Run: [IMJPMIG8.1] C:WINDOWSIMEimjp8_1IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM..Run: [PHIME2002ASync] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE /SYNC
O4 - HKLM..Run: [PHIME2002A] C:WINDOWSSystem32IMETINTLGNTTINTSETP.EXE /IMEName
O4 - HKLM..Run: [New.net Startup] rundll32 C:PROGRA~1NEWDOT~1NEWDOT~2.DLL,NewDotNetStartup

Have you run Ad-Aware, Spy Bot, and CWShredder? If not, do so!

If you don't get help here, go to the www.computercops.biz forums...
Re: Wupdater and Prefetch by Anonymous Ghost on December 20th, 2003 10:37:22 PM
i'm haveing a problem with wupdater is it a virus?
Re: Wupdater and Prefetch by Anonymous Ghost on December 20th, 2003 10:57:29 PM
what is wupdater, is it windows update
New log from HJT - Wupdater and Prefetch by elviasan on December 21st, 2003 01:23:27 PM
After reading previous posts about removing wupdater.exe, I have run Lavasoft Ad-ware 6 and scanned my computer with HiJackThis too. Below it's what I found. Please advice on what HiJackThis needs to fix. Thank you.

Logfile of HijackThis v1.97.7
Scan saved at 19:56:15, on 21/12/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSystem32igfxtray.exe
C:WINDOWSSystem32hkcmd.exe
C:Archivos de programaAnalog DevicesSoundMAXPmProxy.exe
C:WINDOWSLTSMMSG.exe
C:WINDOWSSystem320THotkey.exe
C:WINDOWSSystem32TPWRTRAY.EXE
C:WINDOWSSystem32TFNF5.exe
C:Archivos de programaApoint2KApoint.exe
C:Archivos de programaTOSHIBATouchEDTouchED.Exe
C:Archivos de programaAlwil SoftwareAvast4ashDisp.exe
C:ARCHIV~1ALWILS~1Avast4ashmaisv.exe
C:WINDOWSSystem32P2P NetworkingP2P Networking.exe
C:Program FilesAltnetPoints ManagerPoints Manager.exe
C:Archivos de programaWinamp3winampa.exe
C:WINDOWSSystem32ctfmon.exe
C:Archivos de programaApoint2KApntex.exe
C:PROGRA~1AltnetDOWNLO~1asm.exe
C:Archivos de programaAlwil SoftwareAvast4aswUpdSv.exe
C:Archivos de programaAlwil SoftwareAvast4ashserv.exe
C:Archivos de programaAnalog DevicesSoundMAXSMAgent.exe
C:WINDOWSsystem32NOTEPAD.EXE
C:Archivos de programaInternet ExplorerIEXPLORE.EXE
C:Documents and SettingsElvia GonzálezMis documentosinstaladoresarreglar wupdaterhijackthisHijackThis.exe

R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.yahoomail.com/
R0 - HKCUSoftwareMicrosoftInternet ExplorerToolbar,LinksFolderName = Vínculos
R3 - URLSearchHook: PerfectNavBHO Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:ARCHIV~1PERFEC~1BHOPERFEC~1.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:Archivos de programaMyWaymyBar1.binMYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Archivos de programaAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: NavErrRedir Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:ARCHIV~1PERFEC~1BHOPERFEC~1.DLL
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:Archivos de programaMyWaymyBar1.binMYBAR.DLL
O4 - HKLM..Run: [IgfxTray] C:WINDOWSSystem32igfxtray.exe
O4 - HKLM..Run: [HotKeysCmds] C:WINDOWSSystem32hkcmd.exe
O4 - HKLM..Run: [PmProxy] C:Archivos de programaAnalog DevicesSoundMAXPmProxy.exe
O4 - HKLM..Run: [LTSMMSG] LTSMMSG.exe
O4 - HKLM..Run: [00THotkey] C:WINDOWSSystem320THotkey.exe
O4 - HKLM..Run: [000StTHK] 000StTHK.exe
O4 - HKLM..Run: [Tpwrtray] TPWRTRAY.EXE
O4 - HKLM..Run: [TFNF5] TFNF5.exe
O4 - HKLM..Run: [Apoint] C:Archivos de programaApoint2KApoint.exe
O4 - HKLM..Run: [TouchED] C:Archivos de programaTOSHIBATouchEDTouchED.Exe
O4 - HKLM..Run: [avast!] C:Archivos de programaAlwil SoftwareAvast4ashDisp.exe
O4 - HKLM..Run: [ashMaiSv] C:ARCHIV~1ALWILS~1Avast4ashmaisv.exe
O4 - HKLM..Run: [P2P Networking] C:WINDOWSSystem32P2P NetworkingP2P Networking.exe /AUTOSTART
O4 - HKLM..Run: [AltnetPointsManager] C:Program FilesAltnetPoints ManagerPoints Manager.exe -s
O4 - HKLM..Run: [WinampAgent] "C:Archivos de programaWinamp3winampa.exe"
O4 - HKLM..Run: [updater] C:Archivos de programaCommon filesupdaterwupdater.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - Startup: Microsoft Office.lnk = C:Archivos de programaMicrosoft OfficeOfficeOSA9.EXE
O9 - Extra 'Tools' menuitem: Consola de Sun Java (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) -
O16 - DPF: {C3DFA998-A486-11D4-AA25-00C04F72DAEB} (MSN Photo Upload Tool) - http://sc.groups.msn.com/controls/PhotoUC/MsnPUpld.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
O17 - HKLMSystemCCSServicesTcpip..{9A85E7B8-A964-49A4-A923-2378067258BC}: NameServer = 193.144.176.10,130.206.5.234
O17 - HKLMSystemCCSServicesTcpip..{C57CC51B-C522-48B8-B10F-97F69B822C65}: NameServer = 193.144.176.10,130.206.5.234
Re: Wupdater and Prefetch by Anonymous Ghost on December 21st, 2003 10:20:56 PM
I just repaired a system that had this virus. It belonged to a coworker/friend. The system would lockup before hitting the windows logo screen. I did a little history. Seems the system has been shuting down on it's own for a couple months. Then lately it started running slow and finally crashed. They had the w32valla.2048 virus and after I cleared the virus I was getting the "wupdater.exe not responding" error when I shutdown the machine. I deleted the wupdater and prefech files, did the regedit thing, fixboot and fixmbr. Of course not in that order, but the system is not up and running fine. He has also installed Norton now!!!
Re: Wupdater and Prefetch by Anonymous Ghost on December 29th, 2003 01:50:49 PM
Logfile of HijackThis v1.97.7
Scan saved at 19:07:56, on 29/12/2003
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:Program FilesNorton Internet SecurityNISUM.EXE
C:Program FilesNorton Internet SecurityccPxySvc.exe
C:WINDOWSsystem32HPConfig.exe
C:Program FilesHPQNotebook UtilitiesHPWirelessMgr.exe
C:Program FilesNorton AntiVirusnavapsvc.exe
C:WINDOWSwanmpsvc.exe
C:WINDOWSSystem32carpserv.exe
C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
C:Program FilesSynapticsSynTPSynTPLpr.exe
C:Program FilesSynapticsSynTPSynTPEnh.exe
C:Program FilesCommon FilesSymantec SharedccApp.exe
C:Program FilesCommon filesupdaterwupdater.exe
C:windowstempadwarefsg_4104.exe
C:Program FilesMSN MessengerMsnMsgr.Exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesMSNMSNCoreFilesmsn6.exe
C:Documents and SettingsPatrickLocal SettingsTempTemporary Directory 1 for hijackthis[1].zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://go.compaq.com/2Q00CPT/0809/bF8.asp
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.ntl.com/
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumer&ap=b201&c=1c02&lc=0809&ac
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0809&s=search&ap=b204
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0809&s=search&ap=b204
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumer&ap=b201&c=1c02&lc=0809&ac
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0809&s=search&ap=b204
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = wmplayer.exe
R3 - URLSearchHook: PerfectNavBHO Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:PROGRA~1PERFEC~1BHOPERFEC~1.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:Program FilesMyWaymyBar1.binMYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: NavErrRedir Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:PROGRA~1PERFEC~1BHOPERFEC~1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:Program FilesMyWaymyBar1.binMYBAR.DLL
O4 - HKLM..Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM..Run: [CARPService] carpserv.exe
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [PreloadApp] c:hpdriversprintersphotosmarthphprld.exe c:hpdriversprintersphotosmartsetup.exe -d
O4 - HKLM..Run: [srmclean] C:CpqsScomsrmclean.exe
O4 - HKLM..Run: [SynTPLpr] C:Program FilesSynapticsSynTPSynTPLpr.exe
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [Cpqset] C:Program FilesHPQDefault Settingscpqset.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [ccRegVfy] "C:Program FilesCommon FilesSymantec SharedccRegVfy.exe"
O4 - HKLM..Run: [KAZAA] C:Program FilesKazaakazaa.exe /SYSTRAY
O4 - HKLM..Run: [updater] C:Program FilesCommon filesupdaterwupdater.exe
O4 - HKLM..Run: [AltnetPointsManager] c:program filesaltnetpoints managerpoints manager.exe -s
O4 - HKLM..Run: [Trickler] "c:windowstempadwarefsg_4104.exe"
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [DesktopUpdate] rundll32.exe C:WINDOWSSystem32MSA64CHK.dll,DllMostrar Matrix_HTML:DesktopUpdate:t
O4 - HKCU..Run: [ContentDownload] rundll32.exe C:WINDOWSSystem32MSA64CHK.dll,DllMostrar Matrix_HTML:ContentDownload:t
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O9 - Extra button: ContentDownload (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: @C:Program FilesMessengerMsgslang.dll,-61144 (HKLM)
O9 - Extra 'Tools' menuitem: @C:Program FilesMessengerMsgslang.dll,-61144 (HKLM)
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} (Matrix Class) - http://acceso.masminutos.com/aplicacion.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Wupdater R.I.P by Anonymous Ghost on December 29th, 2003 01:51:25 PM
this is a useful url: I hope it helps
http://forums.techguy.org/t186160/sa8130e0d176ca45eb87dabcd9da294b7.html
Re: Wupdater and Prefetch by patrick on December 30th, 2003 04:04:59 AM
my newly scanned hijackthis report. (but im still so lost i can't even remember wot ive done
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C:Program FilesCommon FilesSymantec SharedccEvtMgr.exe
C:Program FilesNorton Internet SecurityNISUM.EXE
C:Program FilesNorton Internet SecurityccPxySvc.exe
C:WINDOWSsystem32HPConfig.exe
C:Program FilesHPQNotebook UtilitiesHPWirelessMgr.exe
C:Program FilesNorton AntiVirusnavapsvc.exe
C:WINDOWSwanmpsvc.exe
C:Program FilesCommon filesupdaterwupdater.exe
C:windowstempadwarefsg_4104.exe
C:Program FilesMSN MessengerMsnMsgr.Exe
C:Program FilesMessengermsmsgs.exe
C:Program FilesMSNMSNCoreFilesmsn6.exe
C:Documents and SettingsPatrickLocal SettingsTemporary Internet FilesContent.IE5D7VBXHGEkazaabegone[1]KazaaBegone.exe
C:Documents and SettingsPatrickLocal SettingsTempTemporary Directory 1 for hijackthis[1].zipHijackThis.exe

R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://go.compaq.com/2Q00CPT/0809/bF8.asp
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.ntl.com/
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumer&ap=b201&c=1c02&lc=0809&ac
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0809&s=search&ap=b204
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0809&s=search&ap=b204
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://desktop.presario.net/scripts/redirectors/presario/deskredir2.dll?s=consumer&ap=b201&c=1c02&lc=0809&ac
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://search.presario.net/scripts/redirectors/presario/srchredir2.dll?c=1c02&lc=0809&s=search&ap=b204
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext = wmplayer.exe
R3 - URLSearchHook: PerfectNavBHO Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:PROGRA~1PERFEC~1BHOPERFEC~1.DLL
O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:Program FilesMyWaymyBar1.binMYBAR.DLL
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:Program FilesAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: NavErrRedir Class - {A045DC85-FC44-45be-8A50-E4F9C62C9A84} - C:PROGRA~1PERFEC~1BHOPERFEC~1.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:Program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:Program FilesNorton AntiVirusNavShExt.dll
O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:Program FilesMyWaymyBar1.binMYBAR.DLL
O4 - HKLM..Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM..Run: [CARPService] carpserv.exe
O4 - HKLM..Run: [ATIPTA] C:Program FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [PreloadApp] c:hpdriversprintersphotosmarthphprld.exe c:hpdriversprintersphotosmartsetup.exe -d
O4 - HKLM..Run: [srmclean] C:CpqsScomsrmclean.exe
O4 - HKLM..Run: [SynTPLpr] C:Program FilesSynapticsSynTPSynTPLpr.exe
O4 - HKLM..Run: [SynTPEnh] C:Program FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [Cpqset] C:Program FilesHPQDefault Settingscpqset.exe
O4 - HKLM..Run: [ccApp] "C:Program FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [ccRegVfy] "C:Program FilesCommon FilesSymantec SharedccRegVfy.exe"
O4 - HKLM..Run: [Trickler] "c:windowstempadwarefsg_4104.exe"
O4 - HKLM..Run: [MSConfig] C:WINDOWSPCHealthHelpCtrBinariesMSConfig.exe /auto
O4 - HKCU..Run: [MsnMsgr] "C:Program FilesMSN MessengerMsnMsgr.Exe" /background
O4 - HKCU..Run: [DesktopUpdate] rundll32.exe C:WINDOWSSystem32MSA64CHK.dll,DllMostrar Matrix_HTML:DesktopUpdate:t
O4 - HKCU..Run: [ContentDownload] rundll32.exe C:WINDOWSSystem32MSA64CHK.dll,DllMostrar Matrix_HTML:ContentDownload:t
O4 - HKCU..Run: [MSMSGS] "C:Program FilesMessengermsmsgs.exe" /background
O9 - Extra button: ContentDownload (HKLM)
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O9 - Extra button: Real.com (HKLM)
O9 - Extra button: @C:Program FilesMessengerMsgslang.dll,-61144 (HKLM)
O9 - Extra 'Tools' menuitem: @C:Program FilesMessengerMsgslang.dll,-61144 (HKLM)
O12 - Plugin for .spop: C:Program FilesInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: {31B7EB4E-8B4B-11D1-A789-00A0CC6651A8} (Cult3D ActiveX Player) - http://www.cult3d.com/download/cult.cab
O16 - DPF: {88C51E90-8E9C-4C96-8A45-574D88B63FAF} (Matrix Class) - http://acceso.masminutos.com/aplicacion.cab
O16 - DPF: {AD7FAFB0-16D6-40C3-AF27-585D6E6453FD} - http://dload.ipbill.com/del/loader.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Re: Wupdater and Prefetch by Anonymous Ghost on December 31st, 2003 05:45:52 PM
i have operating system windows xp and and i keep getting a message that shows up in a box telling me this program in not responding end now or cancel and the program is WUPDATER.EXE what to do? I do not have kazaa but i do have norton antivirus, adware 6.0 and it didn't detection the virus just wandering why.
Re: Wupdater and Prefetch by Anonymous Ghost on January 01st, 2004 10:17:31 AM
c:\temp
Re: Wupdater and Prefetch by Anonymous Ghost on January 06th, 2004 03:44:58 PM
I have same problem. Ad6 and spybot don't help. ANyone has a good solution. Thanks.Is Winupdater.exe a spyware or virus? If I remove it, can the windows be updated?
i cant update automaically xp !!! by serge on January 07th, 2004 06:45:02 AM
Bonjour ŕ tous !!!
Hi all!!!
I have a pb :windows xp doesn t update automatically... i did a scan with Ad aware to expulse spy ware + norton...but i can t update xp manually neither automatically...
i have a file in c/progr/common files/updater is the file updater a valid one? should i erase it ?

please help!!
Re: internet explorer not working?? by Anonymous Ghost on January 08th, 2004 09:03:51 PM
if you cannot get any website with IE check TOOLS - INTERNET OPTION - CONNECTION
Select your connection and press SETTINGS
Check that "use a proxy server for this connection" is not selected. If it is just unclick it.
for me it works... I found out that (I don't know how and why...) the settings for my connection were changed to "use a proxy server for this connection" address 127.0.0.1 port 7212
Re: Wupdater and Prefetch by Anonymous Ghost on January 26th, 2004 01:06:11 AM
Alot of you guy's need to read the previous posts, I already covered allot of info you guy's are looking for.
wupdater is not a virus, it's adware used by Kazaa. I would also NOT recomend you delete ANY files from your computer unless you truely understand what your doing. If you want to still use Kazaa you must have "wupdater" on your computer, you just need to deactivate it on boot. (read my other posts)I had the same problem most of you had, and with a little adjustment solved it.

Vortimaxx
Re: Wupdater and Prefetch by Anonymous Ghost on February 01st, 2004 02:47:09 PM
SO what happens if you have wupdater and DON'T have Kazaa, never have had Kazaa, and don't want Kazaa? Tell me how to fix that?
Re: Wupdater and Prefetch by Anonymous Ghost on February 04th, 2004 10:16:48 PM
What exactly is your problem?

Vortimaxx
Re: Wupdater and Prefetch by Anonymous Ghost on February 05th, 2004 06:53:07 AM
I got the wupdater.exe on my computer telling me it couldn't shut down the computer. Then I deinstalled Kazaa, and the message stopped coming. I did a search for wupdater, and I found it as wupdater.exe-09e1ada.pf in the prefetch folder. I deleted the file, and it's now gone. But the computer is still a bit slow, and it turns shortly black before the log-on screen comes on. What is going on?? I have Norton anti virus, recently updated, and it didn't find anything.
Re: Wupdater and Prefetch by Anonymous Ghost on February 05th, 2004 07:04:23 AM
Not wupdater.exe-09e1ada.pf, but
wupdater.exe-09ce1ada.pf
Re: Wupdater and Prefetch by Anonymous Ghost on February 05th, 2004 12:28:19 PM
It's not a virus, its adware. Kazza uses it and probably manu others. wupdater can be dissabled by selecting "Run" in your start menu and typing "msconfig" a screen will come up and you should select the "startup" tab. You will then see checks beside many programs. You can deselect many of these from starting on boot (you should only need half a dozen or so checked. "msOffice" is one that takes up allot of memery, if you don't use the msoffice toolbar, uncheck it, and of course "wupdater" if it's still there uncheck it.
Hope it helps.

Vortimaxx
Re: Wupdater and Prefetch by scorpio on February 06th, 2004 09:36:36 PM
I got the wupdater.exe on my computer telling me it couldn't shut down the computer. Then I deinstalled Kazaa, and the message stopped coming. I did a search for wupdater, and I found it as wupdater.exe-09e1ada.pf in the prefetch folder. I deleted the file, and it's now gone. But the computer is still a bit slow, and it turns shortly black before the log-on screen comes on. What is going on?? I have Norton anti virus, recently updated, and it didn't find anything.

No need to worry about that screen going black for few seconds. That is a normal thing.

For slow PC thing, just run the tool 'Hijack This' to see if there are any more spywares on your system.
After running 'Hijack This', post the log it gives as a new problem. Someone will definately help you.
Re: Wupdater and Prefetch by Anonymous Ghost on February 08th, 2004 10:03:10 AM
I have wupdater on a machine that does not, never has, and never will have Kazaa on it. Any ideas from whence it cometh?
Re: Wupdater and Prefetch by Anonymous Ghost on February 23rd, 2004 11:50:04 PM
My CPU is a brand new one and I've never installed Kazaa before and yet I still do see the wupdater.exe dialogue box that says it's updating and what not. I run Spybot but I couldn't remove it so I trcked down the folder and deletd almost everything inside. What is left is the .exe program but I couldn't delete that- a message will keep on poping up and said that it can't be deleted either my recycle bin is full or that the program is wire-protected. So hat should I do now?
Re: Wupdater and Prefetch by Anonymous Ghost on March 01st, 2004 11:47:45 AM
OK here is how I got rid of this, Delete the folder updater in Program Files>Common Files>updater. (Make sure wupdater is not running.) then in the local Machine Reg, go to Software>Microsoft>Windows>CurrentVersion>Run and delete its registry key there.
The files in /Prefetch are just .pf used to enhance XP they are created when you or your system run some programs. Also you might want to look for an "updater" installer file.

And rember sex on the internet is like sex in real life... you either pay too much or you get an infection...
Re: Wupdater and Prefetch by Anonymous Ghost on March 15th, 2004 01:19:17 AM
i have problem in wupdater
Re: Wupdater and Prefetch by Anonymous Ghost on March 19th, 2004 11:22:59 AM
I deleted wupdater a couple days ago before reading these posts, and now when I start up my computer a box pops up saying "Wupdater" data1.dat has been removed. How do I get that back, or is it crucial to have that on my computer?
Re: Wupdater and Prefetch by Anonymous Ghost on March 28th, 2004 09:21:33 AM
I installed Aol 9.0 version on my WinMe and every time I try to connected to the internet(clicking the icon for Aol) nothing happens. I then pres ctrl+alt+del and to find that the wupdater is not responding, and I click end task and the connection to Aol works. This also happens while booting the computer. Everytime I desire to connect to the internet or boot my computer,I shouldn't have to go through this. How can this problem be solved.
Re: Wupdater and Prefetch by Anonymous Ghost on May 23rd, 2004 06:15:26 AM
I am running windows 98 and have norton installed. When I go to shutdown the screen freezes and I have to end task everytime we shut down. Also the hard drive sounds like its running programs in the background... can you help?
Re: Wupdater and Prefetch by Anonymous Ghost on May 31st, 2004 07:47:39 AM
Hi,
I thought Wupdater etc was part of Windows. The man was correct. Right click task-bar, open task manager, highlite wupdater click end process, click Yes @ task manager warning. Wupdater is @ C:\Program Files\Common Files\updater. There's also an install for this wupdater. I found mine right on local C:\ updater_112, just delete.
Not a problem here. I haven't checked out "Prefetch" as of yet.
Guess that's it for now. Good Luck!

C73Winklep2@aol.com
Re: Wupdater and Prefetch by Anonymous Ghost on August 11th, 2004 04:35:07 AM
I have a Prefetch folder under Windows (XP) Files appear to be triggered from a service displayed as 'explorer.exe:nokcl' and Resident.exe - not sure where these keep getting generated - tried to delete them but they keep coming back - anyone know how to get rid? Note that Norton AV picks them up by doesn't delete...
Re: Wupdater and Prefetch by Anonymous Ghost on October 25th, 2004 10:00:28 AM
I also have the problem whereby wupdater.exe is not responding. However, i am now not even able to get onto internet explorer any more! when i try clicking on the icon either nothing happens or its says "Ipexplore has generated errors" I have windows 2000 and a broadband wireless connection using an LAN card into my laptop. Any help to get me back onto the internet would be greatly appreciated.cheers
woolfy
Re: Wupdater and Prefetch by Anonymous Ghost on February 06th, 2005 11:42:15 AM
I work forlove

Related Problems :
Post a Note :
UserName (not required in anonymous posts)
Password (not required in anonymous posts)
Post Anonymous (check this only if you wish to post anonymously.)
Subject
Comment (limited HTML allowed)



List Home > Operating System > Other Problems >   [ Post New Problem ]
Copyright © 2001-2008, Nibble Guru