Malware bytes runs nd then shows two registry enteries were found to be contaminated.
It removes the infection. If I waid 2 min, the infection will be back.
MB recognizes it as hijack.hijack.windows.hijack. I have run avast (regular scan), Norton online scans.
I cannot run windows updates and my pc will not load service pack 3.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\BITS\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemRoot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Not selected for removal.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\wuauserv\ImagePath (Hijack.WindowsUpdates) -> Bad: (%fystemroot%\system32\svchost.exe -k netsvcs) Good: (%SystemRoot%\System32\svchost.exe -k netsvcs) -> Quarantined and deleted successfully.
I would like to know how to remove this threat.