emsbronco
Member
- Reaction score
- 12
- Location
- Wayland, NY
I have a windows XP system on the bench that is driving me nuts. Well, it's the 2nd crazy system of the day and the customer is driving me nuts callign every 2 hours for an update.
It originally came in with a description of nothing is updating and its running really slow. I got rid of the 2 expired AVs, ComboFix deleted some FunWebProducts, nothing else, HitManPro came back clean, SuperAntiSpyware showed only cookies. The system originally had SP2 and IE7, Updated to SP3 and IE8 without issue. Doing google and yahoo searches show no redirects.
Windows Update is failing and redirecting to a MS KB item that states I need to upgrade to SP3. Well, the computer is already on SP3. I re-registered the Windows Updates and BITS components. TDSSKiller shows clean. Installed Microsoft Security Essentials - clean. Ran SFC, which replaced a few files, then reapplied SP3. No change.
I checked the WU logs and found that WU is trying to conenct to a proxy server starting with 168.x.x.x. So, I verified that IE has no proxy server set, Reset IE, Reset Winsock, reset the Windows Firewall, reset TCP/IP. checked Proxycfg, it showed no proxy set, but I ran Proxycfg -d anyway to reset defaults. I verified that there are no policies set on the system. I also recreated the MBR, just in case it is a new rootkit. I got everything else working except Windows Updates. And, the logs are still showing that it is trying to connect to a proxy server.
So, is there anywhere else that Windows Update may be getting this proxy setting? Or does anybody have any other ideas on how to fix this?
It originally came in with a description of nothing is updating and its running really slow. I got rid of the 2 expired AVs, ComboFix deleted some FunWebProducts, nothing else, HitManPro came back clean, SuperAntiSpyware showed only cookies. The system originally had SP2 and IE7, Updated to SP3 and IE8 without issue. Doing google and yahoo searches show no redirects.
Windows Update is failing and redirecting to a MS KB item that states I need to upgrade to SP3. Well, the computer is already on SP3. I re-registered the Windows Updates and BITS components. TDSSKiller shows clean. Installed Microsoft Security Essentials - clean. Ran SFC, which replaced a few files, then reapplied SP3. No change.
I checked the WU logs and found that WU is trying to conenct to a proxy server starting with 168.x.x.x. So, I verified that IE has no proxy server set, Reset IE, Reset Winsock, reset the Windows Firewall, reset TCP/IP. checked Proxycfg, it showed no proxy set, but I ran Proxycfg -d anyway to reset defaults. I verified that there are no policies set on the system. I also recreated the MBR, just in case it is a new rootkit. I got everything else working except Windows Updates. And, the logs are still showing that it is trying to connect to a proxy server.
So, is there anywhere else that Windows Update may be getting this proxy setting? Or does anybody have any other ideas on how to fix this?