From: PA Bear [MS MVP] on
I'll leave you in BroMow's able hands.

Klauwaart wrote:
> "PA Bear [MS MVP]" <PABearMVP(a)gmail.com> wrote in message
> news:#yJTCUu7KHA.3504(a)TK2MSFTNGP05.phx.gbl...
>> Did you upgrade to Win7 or is it a brand-new computer?
> Ran Win 7 from the beginning.
> Not brand new, about 7 months old, but the problem only occurred now
>>
>> Are you running Win7 64-bit?
> 32-bit
>>
>> What anti-virus application or security suite is /installed/ and is your
>> subscription current? What anti-spyware applications (other than
>> Defender)?
> AVG Free, Spybot Search and Destroy, yesterday and to day I also installed
> Lavasoft Ad-Aware and Malwarebytes Anti-Malware.
>> What third-party firewall (if any)?
> None
>>
>> Has a(another) Norton or McAfee application ever been installed on the
>> computer (e.g., a free-trial version that came preinstalled when you
>> bought it)?
> No.
>
> Thank you for your reply.
>
>> --
>> ~Robear Dyer (PA Bear)
>> MS MVP-IE, Mail, Security, Windows Client - since 2002
>>
>>
>> Klauwaart wrote:
>>> Hello,
>>> Since a few days now, it is completely impossible for me to receive
>>> updates
>>> for Windows 7 Ultimate.
>>>
>>> I keep getting an 80072EFE error.
>>> When I try to go to the microsoft update website itself, something seems
>>> to
>>> stop me, saying "The page can not be displayed", and I have had browser
>>> issues for a few days too, ie. when I follow a link I searched on
>>> Google,
>>> I
>>> get sent to advertising websites, and, as mentioned before, something
>>> seems
>>> to block the sites which could help me sort out my problem.
>>>
>>> I have already done Malware checks with Spybot Search and Destroy,
>>> Lavasoft
>>> Ad-Aware and Malwarebytes Anti-Malware, all to no avail at all.
>>> I have also tried the Microsoft FixIt tool, which did not help in the
>>> slightest neither.
>>>
>>> Does anyone recognise my problem?
>>> If anyone can help me sort this out, the advice will be very gratefully
>>> accepted.
>>>
>>> Thank you in advance,
>>> Klauwaart.

From: MowGreen on
Klauwaart wrote:
> 2010-05-08 17:15:48:770 1524 edc Report WER Report sent:
> 7.3.7600.16385 0x80072efe 00000000-0000-0000-0000-000000000000 Scan 101
> Unmanaged 2010-05-08 17:27:25:468 1524 edc Misc WARNING:
> WinHttp: SendRequestUsingProxy failed for
> <http://download.windowsupdate.com/v9/windowsupdate/redir/muv4wuredir.cab>.
> error 0x80072efe
<snip>
> 2010-05-08 17:27:25:468 1524 edc Misc WARNING: WinHttp:
> SendRequestToServerForFileInformation MakeRequest failed. error 0x80072efe
> 2010-05-08 17:27:25:468 1524 edc Misc WARNING: WinHttp:
> SendRequestToServerForFileInformation failed with 0x80072efe
> 2010-05-08 17:27:25:469 1524 edc Misc WARNING: WinHttp:
> ShouldFileBeDownloaded failed with 0x80072efe


The 2 most notable entries indicate that the Windows Update Agent(WUA)
is a Version behind the current one and that a proxy server is
interfering with the communication between the update servers and your
system. I suspect this is related to AVG and/or one of Spybot's protections.

If AVG is set to scan incoming email, then a proxy server has been set
up. You can remove proxy settings but AVG may reset them again unless
you configure it to *not* scan incoming email. There is really no need
to scan incoming email as any reliable AV will detect malicious content
if/when you attempt to view/open it and alert you or, even more likely,
quarantine/delete said malicious content.

One of Spybot's components may be causing an issue with the installation
of the latest Version of the WUA. TeaTimer and SDHelper are 2 of those
components.
The article below shows how to access the options to enable or disable
TeaTimer and SD Helper:

How to enable/disable Spybot Tea timer
http://www.malwarehelp.org/how-to-enabledisable-spybot-teatimer.html
Suggest you configure the system to Clean boot:

How to troubleshoot a problem by performing a clean boot in Windows
Vista or in Windows 7
http://support.microsoft.com/kb/929135

After the Clean boot, download and *save* the latest Version of the WUA:
http://download.windowsupdate.com/windowsupdate/redist/standalone/7.4.7600.226/windowsupdateagent30-x86.exe

You can also obtain it from link on this MS KB:
http://support.microsoft.com/kb/949104

It's under " Windows Vista, Windows Server 2008, Windows XP, Windows
Server 2003, and Windows 2000 Service Pack 4 " but, as you see, Windows
7 is not listed as one of the OS' that it works on:
> For an x86-based computer
>
> Download the windowsupdateagent30-x86.exe package now

Once the download completes, close *any* open programs and browsers.

Click the Start orb > in the 'Search programs and files' field type in
services
Under Programs, *right* click Services and choose 'Run as
administrator'. Agree to the UAC prompt to allow the Services console to
run Elevated.
Scroll down the list of Service and Stop these 2 for now:
Background Intelligent Transfer Service (BITS)
Windows Update
Click on each Service to highlight it and then click the Stop link to
the left.

Run windowsupdateagent30-x86.exe now. If you are prompted to restart the
system, decline to do so. You can close the Services console now as when
the system is restarted, both services should start *unless* their
Startup type has been changed from their Default setting.

Both services should be set to Automatic (Delayed start) but BITS can be
set to Manual if you so desire.

Click the Start orb once more and in the Search field type in
cmd
Under Programs, *right* click cmd.exe and choose 'Run as admin' again;
agree to the UAC prompt.
At the prompt type in the below commands pressing Enter after *each* command

netsh winhttp reset proxy
exit

Restart the system now and, while *still* in the Clean boot state, open
Windows Update in Control Panel and see if the system can search for
updates.
If it can, decline to install the updates and configure the system to
start in normal Windows mode by UNdoing the Clean boot steps.

Once the system is booted to normal Windows mode, see if it can search
for and install updates.

If it can, then you're done.
If it can not, post the last 50 or so lines of the WindowsUpdate.log
into your reply.


MowGreen
================
*-343-* FDNY
Never Forgotten
================

banthecheck.com
"Security updates should *never* have *non-security content* prechecked
From: Klauwaart on
Thanks for that great explanation,
however,
when I go to http://support.microsoft.com/kb/949104 and then click the link
to the Windows Update site, I am greeted with "Internet Explorer cannot
display the webpage", which is what I mentioned in the previous post about
it looks like the websites that can help have been blocked.

By the way, this still happens after the "Clean Boot".

That is why I think the problem of being sent to advertising sites when
clicking on a link in Google search has something to do with it.
I think something is holding my PC hostage and preventing it from going to
Microsoft download sites in the process.

I really don't know where to go from here.
I also completed the steps you mentioned about Spybot and AVG.

So, if you know any further solutions apart from re-formatting the whole
system (which I am very reluctant to do) I would be very grateful for any
further help.

Thank you for all the help you have given so far.


"MowGreen" <mowgreen(a)nowandzen.com> wrote in message
news:OCVuT657KHA.420(a)TK2MSFTNGP02.phx.gbl...
> Klauwaart wrote:
>> 2010-05-08 17:15:48:770 1524 edc Report WER Report sent:
>> 7.3.7600.16385 0x80072efe 00000000-0000-0000-0000-000000000000 Scan 101
>> Unmanaged 2010-05-08 17:27:25:468 1524 edc Misc WARNING:
>> WinHttp: SendRequestUsingProxy failed for
>> <http://download.windowsupdate.com/v9/windowsupdate/redir/muv4wuredir.cab>.
>> error 0x80072efe
> <snip>
>> 2010-05-08 17:27:25:468 1524 edc Misc WARNING: WinHttp:
>> SendRequestToServerForFileInformation MakeRequest failed. error
>> 0x80072efe
>> 2010-05-08 17:27:25:468 1524 edc Misc WARNING: WinHttp:
>> SendRequestToServerForFileInformation failed with 0x80072efe
>> 2010-05-08 17:27:25:469 1524 edc Misc WARNING: WinHttp:
>> ShouldFileBeDownloaded failed with 0x80072efe
>
>
> The 2 most notable entries indicate that the Windows Update Agent(WUA) is
> a Version behind the current one and that a proxy server is interfering
> with the communication between the update servers and your system. I
> suspect this is related to AVG and/or one of Spybot's protections.
>
> If AVG is set to scan incoming email, then a proxy server has been set up.
> You can remove proxy settings but AVG may reset them again unless you
> configure it to *not* scan incoming email. There is really no need to scan
> incoming email as any reliable AV will detect malicious content if/when
> you attempt to view/open it and alert you or, even more likely,
> quarantine/delete said malicious content.
>
> One of Spybot's components may be causing an issue with the installation
> of the latest Version of the WUA. TeaTimer and SDHelper are 2 of those
> components.
> The article below shows how to access the options to enable or disable
> TeaTimer and SD Helper:
>
> How to enable/disable Spybot Tea timer
> http://www.malwarehelp.org/how-to-enabledisable-spybot-teatimer.html
> Suggest you configure the system to Clean boot:
>
> How to troubleshoot a problem by performing a clean boot in Windows Vista
> or in Windows 7
> http://support.microsoft.com/kb/929135
>
> After the Clean boot, download and *save* the latest Version of the WUA:
> http://download.windowsupdate.com/windowsupdate/redist/standalone/7.4.7600.226/windowsupdateagent30-x86.exe
>
> You can also obtain it from link on this MS KB:
> http://support.microsoft.com/kb/949104
>
> It's under " Windows Vista, Windows Server 2008, Windows XP, Windows
> Server 2003, and Windows 2000 Service Pack 4 " but, as you see, Windows 7
> is not listed as one of the OS' that it works on:
>> For an x86-based computer
>>
>> Download the windowsupdateagent30-x86.exe package now
>
> Once the download completes, close *any* open programs and browsers.
>
> Click the Start orb > in the 'Search programs and files' field type in
> services
> Under Programs, *right* click Services and choose 'Run as administrator'.
> Agree to the UAC prompt to allow the Services console to run Elevated.
> Scroll down the list of Service and Stop these 2 for now:
> Background Intelligent Transfer Service (BITS)
> Windows Update
> Click on each Service to highlight it and then click the Stop link to the
> left.
>
> Run windowsupdateagent30-x86.exe now. If you are prompted to restart the
> system, decline to do so. You can close the Services console now as when
> the system is restarted, both services should start *unless* their Startup
> type has been changed from their Default setting.
>
> Both services should be set to Automatic (Delayed start) but BITS can be
> set to Manual if you so desire.
>
> Click the Start orb once more and in the Search field type in
> cmd
> Under Programs, *right* click cmd.exe and choose 'Run as admin' again;
> agree to the UAC prompt.
> At the prompt type in the below commands pressing Enter after *each*
> command
>
> netsh winhttp reset proxy
> exit
>
> Restart the system now and, while *still* in the Clean boot state, open
> Windows Update in Control Panel and see if the system can search for
> updates.
> If it can, decline to install the updates and configure the system to
> start in normal Windows mode by UNdoing the Clean boot steps.
>
> Once the system is booted to normal Windows mode, see if it can search for
> and install updates.
>
> If it can, then you're done.
> If it can not, post the last 50 or so lines of the WindowsUpdate.log into
> your reply.
>
>
> MowGreen
> ================
> *-343-* FDNY
> Never Forgotten
> ================
>
> banthecheck.com
> "Security updates should *never* have *non-security content* prechecked

From: MowGreen on
Klauwaart wrote:
> Thanks for that great explanation,
> however,
> when I go to http://support.microsoft.com/kb/949104 and then click the
> link to the Windows Update site, I am greeted with "Internet Explorer
> cannot display the webpage", which is what I mentioned in the previous
> post about it looks like the websites that can help have been blocked.
>
> By the way, this still happens after the "Clean Boot".
>
> That is why I think the problem of being sent to advertising sites when
> clicking on a link in Google search has something to do with it.
> I think something is holding my PC hostage and preventing it from going
> to Microsoft download sites in the process.
>
> I really don't know where to go from here.
> I also completed the steps you mentioned about Spybot and AVG.
>
> So, if you know any further solutions apart from re-formatting the whole
> system (which I am very reluctant to do) I would be very grateful for
> any further help.
>
> Thank you for all the help you have given so far.

You're mowst welcome ... What happens now when you open Windows Update
in the Control Panel ?

Again, Windows 7 does *NOT* update via Internet Explorer accessing the
Windows Update site and I do not understand why you are clicking links
to WU on the KB article.
In Windows 7, when one clicks a link to the WU site then the Windows
Update Control Panel window is supposed to open. If it's not, then
either the system is being redirected by a DNS exploit or the OS has
been exploited by malware.

1) Did you do the steps to reset the proxy configuration to no proxy
server ?

2)Is the system on a wireless or wired network ?

3)a. Have you checked for the presence of malware while in *Safe Mode*
with MBAM's most *recent* definitions installed ?

b. Where did you download MBAM from and, can you access this page ?
http://www.malwarebytes.org/

4) Open the Windows Update icon in Control Panel.
Click the Check for updates link in the left frame. What happens ?
If the system still can not update, then please post at least the last
50 or so lines of the WindowsUpdate.log into your reply along with the
**above requested information**.


MowGreen
================
*-343-* FDNY
Never Forgotten
================

banthecheck.com
"Security updates should *never* have *non-security content* prechecked
From: dougjosh on
Mow and Klau,

I am having the same issue, same error, same hijacked search engines, with
Winows XP version and IE8. This has to be some sort of bug. I notified
Microsoft, but no answer yet. I even tried to download another browser
(Google Chrome) and it does not allow that either. Windows Onecare and Iobit
ASC can't stop it either. I am using another pc to write this message
because the bug will not allow me to access this forum from the affected
computer.

"MowGreen" wrote:

> Klauwaart wrote:
> > Thanks for that great explanation,
> > however,
> > when I go to http://support.microsoft.com/kb/949104 and then click the
> > link to the Windows Update site, I am greeted with "Internet Explorer
> > cannot display the webpage", which is what I mentioned in the previous
> > post about it looks like the websites that can help have been blocked.
> >
> > By the way, this still happens after the "Clean Boot".
> >
> > That is why I think the problem of being sent to advertising sites when
> > clicking on a link in Google search has something to do with it.
> > I think something is holding my PC hostage and preventing it from going
> > to Microsoft download sites in the process.
> >
> > I really don't know where to go from here.
> > I also completed the steps you mentioned about Spybot and AVG.
> >
> > So, if you know any further solutions apart from re-formatting the whole
> > system (which I am very reluctant to do) I would be very grateful for
> > any further help.
> >
> > Thank you for all the help you have given so far.
>
> You're mowst welcome ... What happens now when you open Windows Update
> in the Control Panel ?
>
> Again, Windows 7 does *NOT* update via Internet Explorer accessing the
> Windows Update site and I do not understand why you are clicking links
> to WU on the KB article.
> In Windows 7, when one clicks a link to the WU site then the Windows
> Update Control Panel window is supposed to open. If it's not, then
> either the system is being redirected by a DNS exploit or the OS has
> been exploited by malware.
>
> 1) Did you do the steps to reset the proxy configuration to no proxy
> server ?
>
> 2)Is the system on a wireless or wired network ?
>
> 3)a. Have you checked for the presence of malware while in *Safe Mode*
> with MBAM's most *recent* definitions installed ?
>
> b. Where did you download MBAM from and, can you access this page ?
> http://www.malwarebytes.org/
>
> 4) Open the Windows Update icon in Control Panel.
> Click the Check for updates link in the left frame. What happens ?
> If the system still can not update, then please post at least the last
> 50 or so lines of the WindowsUpdate.log into your reply along with the
> **above requested information**.
>
>
> MowGreen
> ================
> *-343-* FDNY
> Never Forgotten
> ================
>
> banthecheck.com
> "Security updates should *never* have *non-security content* prechecked
> .
>