Search : in
By :

AVG-Windows update failure

Last answer on Nov 28, 2009 5:35:57 am GMT akatextileas, on Dec 9, 2008 2:00:52 pm GMT 
 Report this message to moderators

Hello,
I have got problem with updates ,I think there is new kind of virus type that effecting computor to browse Windows update-antivirus web page update even to open all other antivirus sites at the same time.
it is really a strange type.
I use AVG 8.0 free type addition and surely cannot update+open www.avg.com site to update +to browse any other latest antivirus sites to load latest antivirus editions downloads to solve my problem.
Please help how to solve it.

Configuration: Windows XP
Internet Explorer 7.0

Best answers for « AVG Windows update failure » in :
[Avg free] update failed Show [Avg free] update failed First Solution Second solution When you want to update your antivirus AVG Free, it displays the following message: update failed, the connection with update server has failed First Solution Open AVG...
Windows Update: Prevent a forced reboot ShowWindows Update: Prevent a forced reboot Intro Solution Creating a Shortcut Note that this tip is valid for both Windows XP Home and Professional Intro Normally after finishing installation the latest updates for your computer, a...
No Windows Update with Windows XP SP3 ShowAfter installing Windows XP Service Pack 3, Windows Update won't work. Windows XP Service Pack 3 installs a new version of Windows Update, but it forgets to register it. try the following: Log on as an administrator, and run cmd.exe, and...
Windows Update – Detection Frequency Configuration ShowWindows Update – Detection Frequency Configuration By the registry On the Control Panel Vista XP You can change the Update detection frequency on windows because windows does automatically searches for updates! By the registry Save...
Download AVG ShowDescription: AVG Antivirus Free Edition is a free antivirus. It gives you full protection of your system. It is easy to use, simple clicks needed. The software consumes low resources of the system to operate. It has an Automatic update functionality,...
Download Windows Installer ShowMicrosoft WindowsIinstaller is a service of installation and application configuration, allowing to manage the applications containing the MSI extension MSI. Windows Installer 3.1 is a secondary update of Windows Installer 3.0 published in...
Download Clean the Windows ShowPC became an inevitable environment in daily life for the children of low age. Everything is good to initiate to them in the use of a computer. Clean The Windows is an ideal interactive program for very small, as well as big. Program allows to...
Wuauclt - wuauclt.exe Showwuauclt - wuauclt.exe wuauclt.exe (wuauclt stands for Windows Update client for WindowsME) is a Windows Millenium generic process used for updating Windows Millenium via the Internet. The file that corresponds to this process is normally found in...

1

TheParoxysm, on Dec 9, 2008 5:01:44 pm GMT

There is no such thing as a virus that blocks your ability to browse update sites. Closest thing to it is the virus may disable/uninstall your antivirus, but nothing more. Also if you had a virus 9/10 your antivirus would have found it. You may have a firewall/internet problem, or the software may be corrupted.

You can manually download the latest definitions here.

http://www.softpedia.com/...

Reply to TheParoxysm

2

akatextileas, on Dec 9, 2008 6:05:08 pm GMT
  • +1

Thank you for reply and for your recommended update site for latest
definition for manual loading.
But again I cannot browse your recommended site or anysite who has closest
links to updates of any kind.
The system dont let me to browse all other latest definiton antivirus sites apart from mine only
Avg 8.0 free.
I cannot update even Windows.
But I can browse all other sites so I dont have Internet problem or software problem.
What can be the problem?it is so strange.

Reply to akatextileas

71

verbiouswan, on Jan 17, 2009 1:31:28 pm GMT
  • +4

This is not true. There are plenty of nasty things out there that will render the programs useless. I have a computer that I keep on the net without any protection just to see what kind of problems that it can get.

Right now, AVG will not update, nor will Spybot Search and destroy. Upon reinstall of Spybot S&D, the program will not even run.

You should get your facts to together before you tell people the wron info.

Reply to verbiouswan

74

ancientmath, on Jan 19, 2009 7:09:49 am GMT
  • +4

Unfortunately, very true.

I've got the same situation on a machine i'm troubleshooting. The symptoms discovered so far is that it modifies the network settings so that all antivirus sites and windowsupdate.microsoft.com points to 127.0.0.1 -- naturally, any attempts to browse, even with the all might ff, is for naught...the dns and hosts files are ignored.

I've already been able to use usb flash drives to get the updates, found some; but the symptom still exists. I'll try ripping out the TCP/IP and try to get windows to rebuild it...i'll update the result.

Reply to ancientmath

77

ancientmath, on Jan 19, 2009 7:31:32 am GMT
  • +1

You're a moron.

Reply to ancientmath

84

passer-by, on Jan 20, 2009 6:39:43 pm GMT

You're right but your attitude isn't :)

Reply to passer-by

139

Vgolfmaster, on Feb 9, 2009 4:36:03 am GMT
  • +1

Paroxysm,

As I am sure that you have figured out by now, this is not a single user that you can easily pass off by saying that a virus can not behave in this manner.

I have been working with computers over 15 years, and have been struck with the exact same symptoms. All local A/V programs and Spyware software are denied access to download updates. I can not even get Trend Micro or several other common online virus scans to install the proper instructions to run.

I don't want to be too hard on ya, but it might be best to do a little research before coming back with this type of response. There are a lot of creative people out there directing their energy in some very poor directions, and your response to this could have put someone in a very bad position.

Good luck to you in the future, and please try to be a little more open and informed before giving your 'advice'.

Reply to Vgolfmaster

156

Keifermail, on Feb 14, 2009 4:20:13 am GMT
  • +30

This "malware" not only exists, it's solution was discovered in this very forum. See post 10 Morphine, on Friday January 2, 2009 05:34:38 AM in this forum.


Thank you Morphine!

Reply to Keifermail

170

pukboy8.8, on Feb 19, 2009 2:52:15 am GMT

Thanks for all the help everyone. I am almost done with this week long mess.

It appears trojan remover cleaned it up, now I'm running malewarebytes, yes actually running it, to see if anything has been left behind.

I owe a few of you a kidney.

Reply to pukboy8.8

207

 jm, on Nov 28, 2009 5:35:57 am GMT

Were you born yesterday? viruses, malware, etc. can block you from accessing antivirus websites and updates sites... conficker is one

Reply to jm

3

TheParoxysm, on Dec 9, 2008 6:46:04 pm GMT
  • +2

The chances of this being a virus is low.
The chances of this being non-viral malware is extremely high.



Download and execute HiJack This! (HJT)
http://www.trendsecure.com/portal/en...HJTInstall.exe

Then post the contents of the HJT log here.

Also! this could also be a malware that has edited your host file. Meaning, whenever you look to surf antivirus or antispyware/malware websites, it redirects you to the address of your own internet port! Which is a pain in the butt!

So look at your "host" file, that is,
C:\windows\system32\drivers\etc\hosts. (hosts has no extention; it is just
"hosts".)

(Note, you may need to change windows explorer setting to allow seeing
system and hidden files.)

This file can be used to bypass a DNS server, effectively equating a web
address to a specific place. However, it can also be used to short-circuit
any website, pointing back to the local PC. That is a great way to block
advertsiements, but it could also be used to prevent access to specific
websites, like antivirus.

The minimum contents of a hostfile file is the one line below:

127.0.0.1 localhost

Other lines are optional.

For example, to block a webiste called www.ads.active.com", add a line like:

127.0.0.1 ads.active.com

Placing a "#" in column one of a line makes it a comment.

Reply to TheParoxysm

4

akatextileas, on Dec 10, 2008 8:20:59 am GMT

Thank you once again for your help.
I try all you have written and explained.
But the result is the same.
Shall I download ''hijack this''?
The host file consists of 127.0.0.1 localhost only.
So what shall we do next?
I really appreciate your kind help.

Reply to akatextileas

193

ruben, on Mar 28, 2009 2:51:45 pm GMT
  • +1

Hi,

I have the same problem. My windows defender cannot update, nor can a manual windows update. AVG seems to update, but doesn't detect any errors. I tried to do the TrendMirco HouseCall, but it couldn't work - an error occurred right at the beginning. HijackThis ran normally the first time, then the second time it came up with an error and asked me to run it as administrator. I did this, and it presented the following log. Could someone help me identify the stuff I should remove? Thank you.

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:49:07 PM, on 28/03/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
C:\Windows\System32\igfxtray.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Windows\PLFSetI.exe
C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Launch Manager\LManager.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
C:\Program Files\ScanSoft\OmniPageSE4\OpWareSE4.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Windows\system32\igfxext.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Skype\Phone\Skype.exe
C:\Program Files\Acer\Acer VCM\AcerVCM.exe
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Users\RUBEND~1\AppData\Local\Temp\RtkBtMnt.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Acer\Acer VCM\acp2HID.exe
C:\Program Files\Skype\Plugin Manager\skypePM.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Windows Live\Mail\wlmail.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Common Files\Adobe\Updater6\Adobe_Updater.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://en.us.acer.yahoo.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://en.us.acer.yahoo.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: AVG Security Toolbar - {A057A204-BACC-4D26-9990-79A187E2698E} - C:\PROGRA~1\AVG\AVG8\AVGTOO~1.DLL
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe
O4 - HKLM\..\Run: [eAudio] "C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe"
O4 - HKLM\..\Run: [BkupTray] "C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [Acer Assist Launcher] C:\Program Files\Acer\Acer Assist\launcher.exe
O4 - HKLM\..\Run: [Acer Product Registration] "C:\Program Files\Acer\Acer Registration\ACE1.exe" /startup
O4 - HKLM\..\Run: [PLFSetI] C:\Windows\PLFSetI.exe
O4 - HKLM\..\Run: [ZPdtWzdVitaKey MC3000] "C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe" show
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\LManager.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ArcadeDeluxeAgent] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe"
O4 - HKLM\..\Run: [PlayMovie] "C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [CanonSolutionMenu] C:\Program Files\Canon\SolutionMenu\CNSLMAIN.exe /logon
O4 - HKLM\..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4\OpwareSE4.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [VoipStunt] "C:\Program Files\VoipStunt.com\VoipStunt\VoipStunt.exe" -nosplash -minimized
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: OpenOffice.org 3.0.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Acer VCM.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra 'Tools' menuitem: Quick-Launching Area - {10954C80-4F0F-11d3-B17C-00C0DFE39736} - C:\Program Files\Acer\Acer Bio Protection\PwdBank.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: avgrsstx.dll
O20 - Winlogon Notify: AWinNotifyVitaKey MC3000 - C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: NTI Backup Now 5 Agent Service (BUNAgentSvc) - NewTech Infosystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
O23 - Service: CLHNService - Unknown owner - C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
O23 - Service: eDataSecurity Service - Egis Incorporated - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
O23 - Service: Empowering Technology Service (ETService) - Unknown owner - C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
O23 - Service: getPlus(R) Helper - NOS Microsystems Ltd. - C:\Program Files\NOS\bin\getPlus_HelperSvc.exe
O23 - Service: Google Update Service (gupdate1c98f382744ce9d) (gupdate1c98f382744ce9d) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: iGroupTec Service (IGBASVC) - Unknown owner - C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: MobilityService - Unknown owner - C:\Acer\Mobility Center\MobilityService.exe
O23 - Service: NTI Backup Now 5 Backup Service (NTIBackupSvc) - NewTech InfoSystems, Inc. - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
O23 - Service: NTI Backup Now 5 Scheduler Service (NTISchedulerSvc) - Unknown owner - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\Cyberlink\Shared files\RichVideo.exe
O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe
End of file - 11752 bytes

Reply to ruben

5

TheParoxysm, on Dec 10, 2008 12:47:40 pm GMT
  • +2

I would definitely try to use HiJack this. GoodĀ Luck!
IfĀ myĀ postĀ wasĀ ofĀ help,Ā pleaseĀ giveĀ meĀ aĀ thumbsĀ u­pĀ toĀ theĀ left,Ā andĀ ifĀ thisĀ solvesĀ it,Ā markĀ itĀ asĀ­ resolved!

Reply to TheParoxysm

6

akatextileas, on Dec 11, 2008 6:22:39 pm GMT

Again the browser dont let me to browse your recommended ''http://www.trendsecure.com/portal/en...HJTInstall.exe ''site.
What to do next ?Any suggestion?
How can a Malware think all our best moves to get rid of itself and prepare all them one by one
at advance?
Thank you
Regards

Reply to akatextileas

7

afig13, on Dec 30, 2008 1:46:37 pm GMT

Same thing is happening to me. I upgraded advanced windows care to version 3. scanned only to find a trojan click virus or something. I tried to get HiJack This! (HJT) but when i click on the link i only get an error.

Reply to afig13

8

Morphine, on Dec 31, 2008 9:22:35 pm GMT
  • +1

Argh! I have this same exact thing... on 2 computers that are hard wired to a wireless router.

Blocks ALL update sites; windows, avg, anything. But allows for browsing no problem. The windows updater page redicts to a "page no found", everything else just gives some sort of "failed to connect" message.

I've run every virus and malware software known to man.... nothing fixes it. It has crippled my systems.

Reply to Morphine

26

sheepdog, on Jan 4, 2009 3:58:50 am GMT
  • +1

Morphine - where did you get Trojan Remover? Did you need to DL it on a non-infected PC first? I'm having the same symptoms....Spybot, SUPERAnti-Virus, AVG, et. al. have indicated presence of Virtumonde, smitfraud-c, and win32.sdBot.aad type viruses/malware....smitfraudfix seemed to wipe out Smitfraud-C, yet Virtumonde remains and the win32.sdDobt.aad showed up after smitfraud-c was removed.

Whatever is happening, it seems to block access to ANT site with the words anti-virus, security, removal, etc...as 'thecoat' stated above: "The malware is intercepting windows dns resolutions at the highest levels". Indeed...

Reply to sheepdog

27

Morphine, on Jan 4, 2009 4:13:08 am GMT
  • +3

I got it from here: http://www.google.com/...

Both my PCs were infected, so I loaded it up on both, then just ran it.

Reply to Morphine

96

badman, on Jan 24, 2009 3:15:29 pm GMT

Cheers for the troganremover it sorted my issues out

Reply to badman

204

jj, on Aug 22, 2009 8:25:57 pm BST

Ty all for the help TR did the job

Reply to jj

9

jd, on Jan 1, 2009 10:52:20 pm GMT

My computer has also been blocked for over a week now.

windows update blocked

antivirus update blocked

fix it pages and HIJACK fixes all blocked.

Even SYSTEM RESTORE is blocked!

the HP tools I burned onto a CD that is supposed to boot the computer is also blocked.


this is a MAJOR issue. if you get it, you will understand. I never dreamed that I'd be crippled to this extent.
It seems that the problem gets worse with every attempted fix.

it starts out with a HIJACKED browser ... search results on yahoo or google are redirected to websites that are related to the search, but not what I selected ... basically SPAM

i've tried 5 browsers: Opera Maxtor IE Safari and FIREFOX .... all browsers were the latest edition. ALL browsers are affected.

i tried to back up my data files ... even purchased a new portable hard drive ... but the backup process is interrupted and shuts down every time.
i was able to back up in small sizes by avoiding the spots that cause a hang up ... but this type of backup is not exactly reliable ... 20 backups of bits and pieces.

something is seriously screwy.

if you don't have it, you're darn lucky. this is the first problem that I've been unable to solve in years.

Reply to jd

10

Morphine, on Jan 2, 2009 5:34:38 am GMT
  • +11

I finally was able to cure my PCs from this update blocker virus or whatever it was. It took:

1) SmitFraudFix (normal)
2) SmitFraudFix (safe mode)
2) Spy Subtract
3) SuperAnti Spyware
4) Avira AntiSpywhere
5) Trojan Remover

Doing all this allowed me to update everything, Windows, virus definitions, etc. The Ads are gone.

This was the single most difficult virus I have ever encountered, 4 days of trying to get rid of it. I have no idea how I got it either, but that sucker spread quick!!! I am actually somewhat impressed.

Feel free to shoot me an email if you need any advice.

Additional Keywords: Updater, msn.com, blocked, spyware, ads.

Reply to Morphine

14

joey, on Jan 2, 2009 9:48:17 pm GMT

Ive got it too and this is incredibly annoying. I dont know anything about those fixes you mentioned so could you go into a bit of detail with those? Im sure it would help more than just me...

Reply to joey

15

o, on Jan 2, 2009 10:10:04 pm GMT

Same here!!! It would be great if you could explain the fix more.

Reply to o

23

morphine, on Jan 4, 2009 3:14:47 am GMT

Those are all anti-virus/anti-spyware programs that are FREE. Just search google, and you should be able to download them. These programs should make it past the virus for a download, as they are all relatively unknown. Don't worry about updating the definitions, because you probably won't be able too (virus). Run them all like I listed. It takes a long time too, run/reboot/run/reboot...

Reply to morphine

37

randmac, on Jan 5, 2009 3:19:28 am GMT
  • +8

Yes, thank you! I was able to clean it up with one run of Trojan Remover 6.7.5 available from here:

http://www.simplysup.com/tremover/download.html

It's a free 30 day trial. Worked like a charm!

Thanks again!

Reply to randmac

46

Whitewater1, on Jan 7, 2009 5:13:24 am GMT
  • +2

Thanks for the link, it cleared my CPU and got me going. I was attempting to get rid of window's messenger when this whole thing started. Just wondering if anyone else was doing something similar....

Also, feel free to laugh, but got a web link entitled "Gay Fetish Sex" on my desktop. It wouldn't have been that bad if I was gay, or had my 12 year old son not been watching me try to fight this virus.

Reply to Whitewater1

111

NEED HELP, on Jan 29, 2009 12:09:14 pm GMT

I also have this problem, i'm not computer savy, so i have my pc with best buy to fix the problem. I also remember receiving a web link on my desk top like yours. I just removed it and restored my computer at that time, thinking the problem was fixed. I was told by best buy that i need to restore my computer to the original specification ( like new)and to reinstall all the programs on my pc just like it was out of the box. I gave them all my starting disk that came with my pc. Does anyone know if this will fix the problem for good.

Thanks,
NEED HELP!!!!!

Reply to NEED HELP

59

jabels, on Jan 11, 2009 5:50:59 pm GMT
  • +2

I want to thank "randmac" for the link to Trojan Remover 6.7.5. This saved my butt. It was the only antivirus/antispyware program that I could install.

http://www.simplysup.com/tremover/download.html

All other programs would begin to install and then fail or not even install at all. Everytime I loaded AVG full edition or free edition, it would even strip my license key out in an attempt to keep it from working.

I am a computer technician by day and usually pride myself on spyware removal. But this one was one of the worst I've ever had.

Reply to jabels

146

batesy1027, on Feb 11, 2009 5:57:39 pm GMT

Trojan remover worked for me straight away!! thanx

Reply to batesy1027

69

Halmo, on Jan 15, 2009 9:48:37 pm GMT

PLEASE FORGIVE THE SHOUTING, BUT i AM OVERJOYED. AFTER SCREWING AROUND FOR NEARLY A WEEK WITH TRYING TO SOLVE THE HIJACKED UPDATES PROBLEM, I CAME ACROSS YOUR SOLUTION AND, AS YOU SAID, IT WORKED LIKE A CHARM!

MANNY, MANY THANKS.

Hal

Reply to Halmo

73

tomo, on Jan 18, 2009 10:55:45 pm GMT

Awsome link, thanks heaps, i was totally crippled by this, all the symptoms were identical to the others mentioned, i ran the download (around 7M) , all fixed in under 5mins, top find , cheers, ps select the 30 day free trial and your done,

http://www.simplysup.com/tremover/download.html

Reply to tomo

83

CandyLoo, on Jan 20, 2009 4:16:40 pm GMT

RANDMAC - You are the greatest!!!! Anyone that has not had to deal with this issue - feel blessed and keep the link to the trojan remover saved somewhere just in case. I have been working on my computer non-stop for the past 5 hrs before I found this forum and the link Randmac gave. I have antivirus software that I scan with religiously, but it didn't stop whatever this was from absolutely crippling my computer. My antivirus software was disabled, I was redirected to some lame sites whenever I tried to go to any legitimate antivirus website (Symantec, McAfee, AVG, etc), and even had my computer flat out refuse to load past the point of initial startup. I cannot even begin to convey how frustrated I was. Thankfully, after all the googling I was doing for "virus that blocks antivirus websites", I came across this forum and finally got it fixed. Thanks again Randmac!!!!

Reply to CandyLoo

92

weave, on Jan 23, 2009 5:24:27 pm GMT

Seriously! You saved me. I have worked tirelessly for days to fix this. Kinda makes me feel like riverdancing

Reply to weave

93

Snailyface, on Jan 23, 2009 7:32:19 pm GMT

You're the BEST!!
Spent two days with two computer tech to no event, I should have loged onto this site first.

Reply to Snailyface

98

L1ND0, on Jan 24, 2009 8:55:58 pm GMT

I was having the same problems - unable to go to Windows updates or any of the virus software sites.

I used the trojan remover you suggested and it fixed it first time.

Thanks for your help

Reply to L1ND0

105

geddesclan, on Jan 27, 2009 9:34:29 pm GMT

Thanks Tonnes, this fitted the bill completely. the only thing I could use to actually get updated and remove the trojan.

Good work folks! And thanks again!

Reply to geddesclan

107

cdw92, on Jan 28, 2009 6:36:21 am GMT

Thx my fren ~!!! REALLY SOLVE THIS DAMN PROBLEM ~!! ^^

Reply to cdw92

116

Bart, on Jan 30, 2009 8:24:42 am GMT

Thank you Randmac for the link. Fixed the problem. I also think it's worth the $35 dollars to buy the licence

Reply to Bart

137

Vince, on Feb 7, 2009 6:46:51 am GMT

I think i got the trojan from xvideos, but now thanks to Trojan Remover, my computer is up and healthy again!
Thanks for the link, god knows I needed help with my computer!

Oh yeah, btw this is the first ever review I've ever made for Malware removal software, cause none of them ever worked like this one did!
1 million/ i fking million!

<3

Reply to Vince

143

max, on Feb 10, 2009 12:39:02 am GMT

You're a genius Randmac....
Trojan remover worked perfect.
A word of warning though. If you must repair/replace userinit.exe make sure to extract it from your cd first and have it ready. Otherwise you wont be able to log in! I used 7Zip and just copied it over. Thanks again.

Reply to max

168

ramgv, on Feb 17, 2009 3:14:00 pm GMT

Thanks folks. Trojan Remover helped.

Reply to ramgv

176

denise, on Feb 27, 2009 6:21:01 pm GMT

Thanks so much to you and Morphine. The trojan remover worked for me! I have spent all morning trying to figure out what the heck was wrong with my computer. I couldn't do a system restore, I couldn't run any antivirus from the internet. I couldn't go on IE, my Firefox was not working well. I couldn't even do a disk cleanup! I had let my Trend Micro expire and what was up to date would stall out at 32%. I downloaded a superspyware remover or whatever, I downloaded the malwarebytes but I could not run them!

I don't know a lot about computers but I've always been able to fix the problem by reading stuff on the internet. This problem almost had me ready to haul my tower into Best Buy. I got laid off earlier this month so life's been kind of crappy and to have this trojan too! Geez. BTW it looks like the program found something called trojan.agent or is it agent.trojan. Apparently it disguised itself in my registry.

I just want to thank this message board in general too. I cannot even convey how happy I am!!!!!I have this place bookmarked now, although I hope I don't have to come here again...

Reply to denise

197

praveen, on Apr 23, 2009 6:13:37 pm BST

Thank u Randmac for the link.
It really solved my problem.

Reply to praveen

128

Alec, on Feb 4, 2009 11:03:36 am GMT

Thanks for the info. This has beem my worst infection ever. No idea where it came from and has taken me three days to get rid. Tried everything with no effect then saw your tip about trying Trojan remover,DL, installed and ran. Now I can open and update Spybot and all my virus/malware programs. thsnks again. By the way the first problem found was goapdxserv.sys which I have seen reported on other forums.

Thanks again for your help. I was just on the point of reloading XP !!!

Reply to Alec

22

streinsix, on Jan 4, 2009 3:08:43 am GMT

I'm having all of the problems listed from the above people. Can you provide steps I can follow to correct this problem? I do have a computer that was not affected because it hadn't been turned on in weeks, I've been trying to use that to download programs and then transfer them to the affected computer.
I would really appreciate any advice you can offer!

Reply to streinsix

29

subu, on Jan 4, 2009 8:17:12 am GMT

HI

I am also facing the same problem that you were facing.

I am unable to update my antivirus defination neither i can open any antivirus site.
Can you pls tell me the whole process from the begining, step by step so that i can get rid of this.

I am unable to open any antivirus site and also not able to update anti virus. pls help.

Thanks
Subhasish

Reply to subu

65

shaggy001, on Jan 14, 2009 12:03:33 pm GMT

Hi,
I had the same problem. AVS stopped getting updated, and so the Lavasoft's As-Aware. Both reported, they were unable to connect to update server.
I tried the Morphine's suggestions. They worked! But, unlike many people reporting on this forum, the Trojan Remover did not find anything. And so the rest of the mentioned programs, except for one: SuperAnti Spyware. It found 3 .sys files, removed them, and the ability of getting updates was regained.
Thank you, Morphine, for very good advise!
Btw, there is a sad conclusion: we use so many ways of protecting computers, everybody has a virus scanner, everybody uses anti-spyware programs..., and in case of a need of doing a real job - they all do nothing... :-(

Good luck!

Reply to shaggy001

75

logic_riches, on Jan 19, 2009 7:27:12 am GMT

Morphine, jabels, airy, valevonn, and others,
A heart full of thanks to you guys for solving this problem. In fact I explain how this problem made me crazy.
The malware shuts all updating sites of all reputed antivirus softwares available in the Market.
Shuts down system restore feature
Shuts down IE browser ( I used Firefox to download other antivirus software)
Tried to install Mcafee antivirus program, and the Trojan in the computer not allow to get it installed.
It sets a different id and password to my NETGEAR Ethernet modem and I could not able to boot it. (I never set any user Id for modem but it asks for a password to gain entry. I gave the NETGEAR default password but I could able to log in)
Previously I was using AVG free and the updates been stopped by this malware. Later I installed Norton and again update problems

Guys, just imagine how these problems driven me crazy. After reading this thread I solved this problem by using these steps. Thanks Morphine and other's suggestions.
SmitFraudFix (safe mode). I executed the program and it went fine. During the update it asked me to set the firewall for the program to install the update. I did. Then the program got its updates and finished in a zap.
Trojan Remover. Later I used this program and followed the instructions. It clearly explained the type of Trojans in the system, and I eliminated accordingly with the programs help.
Now the Computer returned to normal state and I could download the updates for my Norton antivirus program. It is working fine.
Thanks to all and wishing you a very Happy New Year

Reply to logic_riches

76

logic_riches, on Jan 19, 2009 7:30:32 am GMT

Thank you guys for posting the links to download the necessary programs. It really helped me a lot.

Reply to logic_riches

80

Jcleric, on Jan 19, 2009 11:53:33 pm GMT

Morphine can you like seriously email me a detailed explanation on how to solve this problem because nothing will update and i've tried everything even my system restore won't restore so if you will please help me out by just walking me through the steps please i would greatly appreciate it. I can't access any update websites and my avg won't update and that is my biggest concern.

Reply to Jcleric

87

islander, on Jan 21, 2009 9:43:47 pm GMT

Hi,

I am encountering the same problem where all AV, Windows Update are blocked. When I downloaded a utility from another computer and copied to the infected one, the system will not even run the program. One thing I also noticed is the startup tab is empty on the MSCONFIG.

Any recommendation on how to proceed in getting rid of this virus/malware.

Thanks

Islander

Reply to islander

102

Muizca, on Jan 26, 2009 8:49:50 pm GMT

I am experiencing the same problem. Can you please advice. I agree with you that this is a serious piece of you know what.

Thanks.

Reply to Muizca

103

Tripwinner, on Jan 27, 2009 2:30:57 pm GMT

Morphine,

You are the bomb! I know several of us have had this issue and with your info we are all fixed!! A million THANK YOU'S!!!!!!!

Reply to Tripwinner

104

Smitty, on Jan 27, 2009 7:41:00 pm GMT

I downloaded smitfraud and trogan downloader... they would no install.. any more suggestions?

Reply to Smitty

114

Ken The Golfer, on Jan 30, 2009 1:19:16 am GMT

I have the same problem. I've ran all the apps you listed, but no ability to update. I've downloaded, AVS, CA, and several other antivirus programs and the end result is no updating and I can't access the www. Removed the programs and can now access the www, but still no updating. After uninstall, I checked and found in the device manager under non plug & play drivers the driver...." AVG Free8 Network Re Director X64". Unstalled it, rebooted and it was still there. Used Avenger to remove it and that worked; however, I still can't update or interface with the servers on sites I contact..."error parsing'" Looked at hosts and under localhost 127.0.0.1 was ::1

I was unable to remove the ::1

Suspect this may be the problem, but I can't remove it.

Have no idea where I got this PIA, but will try almost anything to get rid of it. Any suggestions?

Reply to Ken The Golfer

115

Ken The Golfer, on Jan 30, 2009 2:26:58 am GMT
  • +1

I have the same problem. I've ran all the apps you listed, but no ability to update. I've downloaded, AVS, CA, and several other antivirus programs and the end result is no updating and I can't access the www. Removed the programs and can now access the www, but still no updating. After uninstall, I checked and found in the device manager under non plug & play drivers the driver...." AVG Free8 Network Re Director X64". Unstalled it, rebooted and it was still there. Used Avenger to remove it and that worked; however, I still can't update or interface with the servers on sites I contact..."error parsing'" Looked at hosts and under localhost 127.0.0.1 was ::1

I was unable to remove the ::1

Suspect this may be the problem, but I can't remove it.

Have no idea where I got this PIA, but will try almost anything to get rid of it. Any suggestions?

Reply to Ken The Golfer

189

Ferdinko, on Mar 25, 2009 1:17:07 am GMT

Hi Morphine,

I tried Trojan Remover first as it seemed to work for many people but it did not work for me. It was the SUPERAntiSpyware that did the trick! Thanks a lot! Thanks also go to the guys in SUPERAntiSpyware. You are brilliant!!

My AVG virus database was last updated on March 12, 2009 before I had this nasty thing. Obviously I was unable to update my AVG after March 12. However this bug was first reported several months ago, in as early as Nov 2008. Between then and now I had done many virus definition updates from AVG. That means AVG8, with the Anti-Spyware built-in, was unable to detect this bug which seems to be widespread and has caused huge damages. Microsoft had not done anything about it either. Isn’t it unsettling?

For those who want to download SUPERAntiSpyware you need to go to sites other than SUPERAntiSpyware’s own site as it may be blocked. Following is the link I used. You may not be able to update the definition either. Just use it straight out of the ā€œboxā€ and it worked for me.

http://www.filehippo.com/download_superantispyware/

Once again thanks heaps Morphine and also many others who have provided helpful comments. I am fortunate to have found this website and have the problem solved which had almost crippled my system.

Reply to Ferdinko

201

nick, on May 23, 2009 2:30:34 pm BST

Trojan remover worked for me too! thanks a lot Morphine

Reply to nick

134

keionl.bryant@gmail.com, on Feb 6, 2009 7:30:56 pm GMT
  • +1

I agee. I just came across this situation my self and i just graduated with a degree in computer technology. This the newest, critical computer virus on the internet now. Please email me if u have any ?s about fixing this problem.

keionl.bryant@gmail.com

Reply to keionl.bryant@gmail.com

11

jd, on Jan 2, 2009 6:08:37 am GMT
  • +2

I have this same virus...this is the first site I've found that has an idea of whats going on....

Reply to jd

12

bobby, on Jan 2, 2009 3:47:01 pm GMT

I have it too. Not sure how I got it as we don't visit suspicious sites. Hijacked the browser and then blocks all anti-virus sites. If you get hijacked then disconnect form internet at once.

Reply to bobby

13

Larry, on Jan 2, 2009 4:21:10 pm GMT

I got whatever this thing is after 12/26, since that's my last symantec update. I now have it blocked. Lots of sites reference the hosts file, but that's clearly something different, this is clearly much more difficult.

I ran a few antivirus scans in normal and safe mode, and it cleaned a few files, but the DNS hijack still exists. I'm glad to see other people talking about this, and today!. This is a PIA to get rid of. I'm going to try the list of applications you listed one at a time and see what I can do to eliminate the DNS hijack. The quick test will be to go to the dos prompt (run-->CMD) and try to ping www.symantec.com or whatever, if it pings to 127.0.0.1, the problem is not solved. I'll keep you updated.

Reply to Larry

28

andrew, on Jan 4, 2009 4:57:21 am GMT

This appears to be some kind of Trojan / Rootkit thing. Pretty much out of nowhere, my computer suddenly showed a number of symptons: an Internet Explorer window opened up (by itself: I don't use it) and tried to get me to click on something about spyware removal.

Then Windows Firewall and Windows Update were disabled (Windows Security Centre notified me), and I started getting messages that my computer would shutdown in 60 seconds because of a crash in the Generic Host Process (if this happens to you, click on Start / Run and enter shutdown -a to cancel the shutdown).

I also couldn't access antivirus sites such as trendmicro.com, symantec.com or f-secure.com. These sites did *not* appear in the windows/system32/devices/etc folder as they do with other infections.

I rebooted to safe mode (not necessarily a good idea) and scanned with AVG and spybot. I did a whole lot of manual fooling around before finding this site and following the advice above to use Trojan Remover:

http://www.download.com/...

(thanks!)

You might also try Sophos Anti-Rootkit
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

And you may also want to run:

- AVG Free
http://free.avg.com

- Spybot Search & Destroy
http://www.safernetworking.de

and throw in some other spyware removers if you like.

If you don't have these programs and your browser won't let you access them, try:
- searching on a reputable download site such as tucows.com, download.com or softpedia.com
- accessing through a web proxy of your choice (I used hidemyass.com)
- getting someone else to download them for you...

Good luck

A

Reply to andrew

16

Gevulde Kex, on Jan 3, 2009 12:32:01 pm GMT

Trojan Remover seems to have worked. I tried Morphine's list, some of the sites wouldn't open or the programs wouldn't start just like all the security programs I had already.
Now I can upgrade again. This is TR's log:

***** THE SYSTEM HAS BEEN RESTARTED *****
03/01/2009 14.25.03: Trojan Remover has been restarted
----------
Cleaning up TDSS keys/files:
HKLM\SOFTWARE\TDSS - key (and subkeys) deleted
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata - key (and subkeys) deleted
C:\WINDOWS\system32\TDSSoipa.dll - deleted
C:\WINDOWS\system32\TDSSmupe.dat - deleted
C:\WINDOWS\system32\TDSSirxy.dll - deleted
C:\WINDOWS\system32\TDSSyavu.dll - deleted
C:\WINDOWS\system32\TDSSncur.dll - deleted
C:\WINDOWS\system32\TDSSqxnr.dll - deleted
C:\WINDOWS\system32\TDSSwgod.log - deleted
----------
=======================================================
Removing the following registry keys:
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\TDSSm­hoe.sys - already removed (or did not exist)
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\TDSSm­hoe.sys - already removed (or did not exist)
HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv - already removed (or did not exist)
HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys - removed
HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv) - already removed (or did not exist)
HKLM\SYSTEM\CurrentControlSet\Services\TDSSserv.sys) - already removed (or did not exist)
=======================================================
03/01/2009 14.25.03: Trojan Remover closed
************************************************************­


***** NORMAL SCAN FOR ACTIVE MALWARE *****
Trojan Remover Ver 6.7.5.2559. For information, email support@simplysup1.com
[Unregistered version]
Scan started at: 14.16.05 03 gen 2009
Using Database v7248
Operating System: Windows XP SP3 [Windows XP Professional Service Pack 3 (Build 2600)]
File System: NTFS
Data directory: C:\Documents and Settings\Raf\Application Data\Simply Super Software\Trojan Remover\
Database directory: C:\Program Files\Trojan Remover\
Logfile directory: C:\Documents and Settings\Raf\My Documents\Simply Super Software\Trojan Remover Logfiles\
Program directory: C:\Program Files\Trojan Remover\
Running with Administrator privileges

************************************************************­
The following Anti-Malware program(s) are loaded:
AVG Anti-Virus

************************************************************­

The regfile\shell\open\command Registry Key appears to have been modified.
The current Registry entry is: "regedit.exe" "%1".
This entry calls the following file:
C:\WINDOWS\regedit.exe
Trojan Remover has restored the Registry regfile\shell\open key.
--------------------

************************************************************
14.16.20: Scanning ----------WIN.INI-----------
WIN.INI found in C:\WINDOWS

************************************************************
14.16.20: Scanning --------SYSTEM.INI---------
SYSTEM.INI found in C:\WINDOWS

************************************************************
14.16.20: ----- SCANNING FOR ROOTKIT SERVICES -----
Hidden Service Keyname: TDSSserv.sys
C:\WINDOWS\system32\drivers\TDSSmhoe.sys appears to contain: BACKDOOR.TDSS
C:\WINDOWS\system32\drivers\TDSSmhoe.sys - file backed up to C:\WINDOWS\system32\drivers\TDSSmhoe.sys.vir
C:\WINDOWS\system32\drivers\TDSSmhoe.sys - file has been erased using RAW erasure

************************************************************
14.16.46: Scanning -----WINDOWS REGISTRY-----
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\WinLogon
This key's "Shell" value calls the following program(s):
File: Explorer.exe
C:\WINDOWS\Explorer.exe
1033728 bytes
Created: 16/01/2007
Modified: 14/04/2008
Company: Microsoft Corporation
----------
This key's "Userinit" value calls the following program(s):
File: C:\WINDOWS\system32\userinit.exe
C:\WINDOWS\system32\userinit.exe
26112 bytes
Created: 04/08/2004
Modified: 14/04/2008
Company: Microsoft Corporation
----------
This key's "System" value appears to be blank
----------
This key's "UIHost" value calls the following program:
File: logonui.exe
C:\WINDOWS\system32\logonui.exe
514560 bytes
Created: 04/08/2004
Modified: 14/04/2008
Company: Microsoft Corporation
----------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
--------------------
Checking HKCU\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
Value Name: load
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Value Name: IMJPMIG8.1
Value Data: "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE
208952 bytes
Created: 18/01/2008
Modified: 16/01/2007
Company: Microsoft Corporation
--------------------
Value Name: PHIME2002ASync
Value Data: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
455168 bytes
Created: 18/01/2008
Modified: 03/08/2004
Company: Microsoft Corporation
--------------------
Value Name: PHIME2002A
Value Data: C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE
455168 bytes
Created: 18/01/2008
Modified: 03/08/2004
Company: Microsoft Corporation
--------------------
Value Name: Persistence
Value Data: C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxpers.exe
-R- 135168 bytes
Created: 18/01/2008
Modified: 13/01/2007
Company: Intel Corporation
--------------------
Value Name: NvCplDaemon
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
C:\WINDOWS\system32\NvCpl.dll
13574144 bytes
Created: 05/12/2007
Modified: 07/10/2008
Company: NVIDIA Corporation
--------------------
Value Name: nwiz
Value Data: nwiz.exe /install
C:\WINDOWS\system32\nwiz.exe
1630208 bytes
Created: 05/12/2007
Modified: 07/10/2008
Company: NVIDIA Corporation
--------------------
Value Name: AVG8_TRAY
Value Data: C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
1261336 bytes
Created: 04/07/2008
Modified: 27/11/2008
Company: AVG Technologies CZ, s.r.o.
--------------------
Value Name: NvMediaCenter
Value Data: RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
C:\WINDOWS\system32\NvMcTray.dll
86016 bytes
Created: 05/12/2007
Modified: 07/10/2008
Company: NVIDIA Corporation
--------------------
Value Name: BluetoothAuthenticationAgent
Value Data: rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
C:\WINDOWS\system32\bthprops.cpl
110592 bytes
Created: 04/08/2004
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------
Value Name: TrojanScanner
Value Data: C:\Program Files\Trojan Remover\Trjscan.exe /boot
C:\Program Files\Trojan Remover\Trjscan.exe
1231752 bytes
Created: 03/01/2009
Modified: 01/01/2009
Company: Simply Super Software
--------------------
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty
--------------------
Checking HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Value Name: SpybotSD TeaTimer
Value Data: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe - this entry is globally excluded
--------------------
Value Name: DAEMON Tools Lite
Value Data: "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorun
C:\Program Files\DAEMON Tools Lite\daemon.exe
486856 bytes
Created: 17/01/2008
Modified: 17/01/2008
Company: DT Soft Ltd
--------------------
Value Name: NVIDIA nTune
Value Data: "C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe" clear
C:\Program Files\NVIDIA Corporation\nTune\nTuneCmd.exe
81920 bytes
Created: 04/09/2007
Modified: 04/09/2007
Company: NVIDIA
--------------------
Value Name: CTZDetec.exe
Value Data: C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe
368640 bytes
Created: 22/01/2008
Modified: 24/04/2008
Company: Creative Technology Ltd.
--------------------
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
This Registry Key appears to be empty
--------------------
Checking HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
This Registry Key appears to be empty

************************************************************
14.16.47: Scanning -----SHELLEXECUTEHOOKS-----
ValueName: {AEB6717E-7E19-11d0-97EE-00C04FD91972}
File: shell32.dll - this file is expected and has been left in place
----------

************************************************************
14.16.47: Scanning -----HIDDEN REGISTRY ENTRIES-----
Taskdir check completed
----------
No Hidden File-loading Registry Entries found
----------

************************************************************
14.16.47: Scanning -----ACTIVE SCREENSAVER-----
ScreenSaver: C:\WINDOWS\system32\logon.scr
C:\WINDOWS\system32\logon.scr
220672 bytes
Created: 04/08/2004
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------

************************************************************
14.16.47: Scanning ----- REGISTRY ACTIVE SETUP KEYS -----

************************************************************
14.16.47: Scanning ----- SERVICEDLL REGISTRY KEYS -----
Key: BthServ
Path: %SystemRoot%\System32\bthserv.dll
C:\WINDOWS\System32\bthserv.dll
30208 bytes
Created: 04/08/2004
Modified: 14/04/2008
Company: Microsoft Corporation
--------------------
Key: HidServ
%SystemRoot%\System32\hidserv.dll - file is globally excluded (file cannot be found)
--------------------

************************************************************
14.16.48: Scanning ----- SERVICES REGISTRY KEYS -----
Key: ASPI
ImagePath: \??\C:\WINDOWS\System32\DRIVERS\ASPI32.sys
C:\WINDOWS\System32\DRIVERS\ASPI32.sys
16512 bytes
Created: 07/03/2008
Modified: 17/07/2002
Company: Adaptec
----------
Key: atksgt
ImagePath: system32\DRIVERS\atksgt.sys
C:\WINDOWS\system32\DRIVERS\atksgt.sys
278728 bytes
Created: 22/12/2008
Modified: 22/12/2008
Company: [no info]
----------
Key: avg8emc
ImagePath: C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgemc.exe
875288 bytes
Created: 04/07/2008
Modified: 30/08/2008
Company: AVG Technologies CZ, s.r.o.
----------
Key: avg8wd
ImagePath: C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
231704 bytes
Created: 04/07/2008
Modified: 30/08/2008
Company: AVG Technologies CZ, s.r.o.
----------
Key: AvgLdx86
ImagePath: \SystemRoot\System32\Drivers\avgldx86.sys
C:\WINDOWS\System32\Drivers\avgldx86.sys
97928 bytes
Created: 23/05/2008
Modified: 30/08/2008
Company: AVG Technologies CZ, s.r.o.
----------
Key: AvgMfx86
ImagePath: \SystemRoot\System32\Drivers\avgmfx86.sys
C:\WINDOWS\System32\Drivers\avgmfx86.sys
26824 bytes
Created: 18/01/2008
Modified: 04/07/2008
Company: AVG Technologies CZ, s.r.o.
----------
Key: AvgTdiX
ImagePath: \SystemRoot\System32\Drivers\avgtdix.sys
C:\WINDOWS\System32\Drivers\avgtdix.sys
76040 bytes
Created: 23/05/2008
Modified: 04/07/2008
Company: AVG Technologies CZ, s.r.o.
----------
Key: BlueletAudio
ImagePath: system32\DRIVERS\blueletaudio.sys
C:\WINDOWS\system32\DRIVERS\blueletaudio.sys [file not found to scan]
----------
Key: BlueletSCOAudio
ImagePath: system32\DRIVERS\BlueletSCOAudio.sys
C:\WINDOWS\system32\DRIVERS\BlueletSCOAudio.sys [file not found to scan]
----------
Key: Bonjour Service
ImagePath: "C:\Program Files\Bonjour\mDNSResponder.exe"
C:\Program Files\Bonjour\mDNSResponder.exe
229376 bytes
Created: 28/02/2006
Modified: 28/02/2006
Company: Apple Computer, Inc.
----------
Key: BT
ImagePath: system32\DRIVERS\btnetdrv.sys
C:\WINDOWS\system32\DRIVERS\btnetdrv.sys [file not found to scan]
----------
Key: Btcsrusb
ImagePath: System32\Drivers\btcusb.sys
C:\WINDOWS\System32\Drivers\btcusb.sys [file not found to scan]
----------
Key: BthEnum
ImagePath: system32\DRIVERS\BthEnum.sys
C:\WINDOWS\system32\DRIVERS\BthEnum.sys
17024 bytes
Created: 12/12/2008
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: BTHidEnum
ImagePath: System32\Drivers\vbtenum.sys
C:\WINDOWS\System32\Drivers\vbtenum.sys [file not found to scan]
----------
Key: BTHidMgr
ImagePath: System32\Drivers\BTHidMgr.sys
C:\WINDOWS\System32\Drivers\BTHidMgr.sys [file not found to scan]
----------
Key: BTHMODEM
ImagePath: system32\DRIVERS\bthmodem.sys
C:\WINDOWS\system32\DRIVERS\bthmodem.sys
37888 bytes
Created: 12/12/2008
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: BthPan
ImagePath: system32\DRIVERS\bthpan.sys
C:\WINDOWS\system32\DRIVERS\bthpan.sys
101120 bytes
Created: 12/12/2008
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: BTHPORT
ImagePath: System32\Drivers\BTHport.sys
C:\WINDOWS\System32\Drivers\BTHport.sys
273024 bytes
Created: 12/12/2008
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: BTHUSB
ImagePath: System32\Drivers\BTHUSB.sys
C:\WINDOWS\System32\Drivers\BTHUSB.sys
18944 bytes
Created: 12/12/2008
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: CLEDX
ImagePath: system32\DRIVERS\cledx.sys
C:\WINDOWS\system32\DRIVERS\cledx.sys
33792 bytes
Created: 16/03/2008
Modified: 09/05/2005
Company: Team H2O
----------
Key: CTDevice_Srv
ImagePath: C:\Program Files\Creative\Shared Files\CTDevSrv.exe
C:\Program Files\Creative\Shared Files\CTDevSrv.exe
61440 bytes
Created: 02/04/2007
Modified: 02/04/2007
Company: Creative Technology Ltd
----------
Key: dmxfire
ImagePath: system32\drivers\dmx6fire.sys
C:\WINDOWS\system32\drivers\dmx6fire.sys
148724 bytes
Created: 29/08/2003
Modified: 29/08/2003
Company: Terratec Electronic GmbH
----------
Key: dmxsens
ImagePath: system32\drivers\dmxsens.sys
C:\WINDOWS\system32\drivers\dmxsens.sys
403968 bytes
Created: 22/07/2003
Modified: 22/07/2003
Company: Sensaura Ltd
----------
Key: EagleNT
ImagePath: \??\C:\WINDOWS\system32\drivers\EagleNT.sys
C:\WINDOWS\system32\drivers\EagleNT.sys [file not found to scan]
----------
Key: FLEXnet Licensing Service
ImagePath: "C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe"
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
655624 bytes
Created: 18/01/2008
Modified: 19/11/2008
Company: Acresso Software Inc.
----------
Key: ialm
ImagePath: system32\DRIVERS\igxpmp32.sys
C:\WINDOWS\system32\DRIVERS\igxpmp32.sys
-R- 5672032 bytes
Created: 18/01/2008
Modified: 13/01/2007
Company: Intel Corporation
----------
Key: IDriverT
ImagePath: "C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe"
C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
69632 bytes
Created: 14/11/2005
Modified: 14/11/2005
Company: Macrovision Corporation
----------
Key: irsir
ImagePath: system32\DRIVERS\irsir.sys
C:\WINDOWS\system32\DRIVERS\irsir.sys
18688 bytes
Created: 18/01/2008
Modified: 17/08/2001
Company: Microsoft Corporation
----------
Key: lirsgt
ImagePath: system32\DRIVERS\lirsgt.sys
C:\WINDOWS\system32\DRIVERS\lirsgt.sys
25416 bytes
Created: 22/12/2008
Modified: 22/12/2008
Company: [no info]
----------
Key: mcdbus
ImagePath: system32\DRIVERS\mcdbus.sys
C:\WINDOWS\system32\DRIVERS\mcdbus.sys [file not found to scan]
----------
Key: NMIndexingService
ImagePath: "C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe"
C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe
382248 bytes
Created: 20/09/2007
Modified: 20/09/2007
Company: Nero AG
----------
Key: nocashio
ImagePath: system32\drivers\nocashio.sys
C:\WINDOWS\system32\drivers\nocashio.sys
4096 bytes
Created: 12/05/2008
Modified: 12/05/2008
Company: [no info]
----------
Key: nTuneService
ImagePath: C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe /StartService
C:\Program Files\NVIDIA Corporation\nTune\nTuneService.exe
131072 bytes
Created: 04/09/2007
Modified: 04/09/2007
Company: NVIDIA
----------
Key: NVR0Dev
ImagePath: \??\C:\WINDOWS\nvoclock.sys
C:\WINDOWS\nvoclock.sys
29696 bytes
Created: 04/09/2007
Modified: 04/09/2007
Company: NVidia Corp.
----------
Key: pcouffin
ImagePath: System32\Drivers\pcouffin.sys
C:\WINDOWS\System32\Drivers\pcouffin.sys
47360 bytes
Created: 27/11/2008
Modified: 27/11/2008
Company: VSO Software
----------
Key: PnkBstrA
ImagePath: C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\PnkBstrA.exe
66872 bytes
Created: 20/01/2008
Modified: 21/11/2008
Company: [no info]
----------
Key: RFCOMM
ImagePath: system32\DRIVERS\rfcomm.sys
C:\WINDOWS\system32\DRIVERS\rfcomm.sys
59136 bytes
Created: 12/12/2008
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: RivaTuner32
ImagePath: \??\C:\Program Files\RivaTuner v2.20\RivaTuner32.sys
C:\Program Files\RivaTuner v2.20\RivaTuner32.sys
9088 bytes
Created: 19/11/2008
Modified: 19/11/2008
Company: [no info]
----------
Key: sptd
ImagePath: System32\Drivers\sptd.sys - this file is globally excluded
----------
Key: sr
ImagePath: \SystemRoot\system32\DRIVERS\sr.sys
C:\WINDOWS\system32\DRIVERS\sr.sys
73472 bytes
Created: 18/01/2008
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: SwPrv
ImagePath: C:\WINDOWS\system32\dllhost.exe /Processid:{9C06143E-7556-458C-95F3-F86B10C31391}
C:\WINDOWS\system32\dllhost.exe
5120 bytes
Created: 04/08/2004
Modified: 14/04/2008
Company: Microsoft Corporation
----------
Key: trutil
ImagePath: \??\C:\DOCUME~1\Raf\LOCALS~1\Temp\trutil.sys - this file is a Trojan Remover component
----------
Key: UnlockerDriver5
ImagePath: \??\C:\Program Files\Unlocker\UnlockerDriver5.sys
C:\Program Files\Unlocker\UnlockerDriver5.sys
4096 bytes
Created: 07/09/2006
Modified: 07/09/2006
Company: [no info]
----------
Key: usbsermpt
ImagePath: system32\DRIVERS\usbsermpt.sys
C:\WINDOWS\system32\DRIVERS\usbsermpt.sys
22768 bytes
Created: 21/05/2008
Modified: 21/05/2008
Company: Microsoft Corporation
----------
Key: Useless
ImagePath: \??\C:\Kaizoku_Script\KEngine\Dll\Useless.sys
C:\Kaizoku_Script\KEngine\Dll\Useless.sys [file not found to scan]
----------
Key: usnjsvc
ImagePath: "C:\Program Files\Windows Live\Messenger\usnsvc.exe"
C:\Program Files\Windows Live\Messenger\usnsvc.exe
98840 bytes
Created: 07/11/2007
Modified: 07/11/2007
Company: Microsoft Corporation
----------
Key: VComm
ImagePath: system32\DRIVERS\VComm.sys
C:\WINDOWS\system32\DRIVERS\VComm.sys [file not found to scan]
----------
Key: VcommMgr
ImagePath: System32\Drivers\VcommMgr.sys
C:\WINDOWS\System32\Drivers\VcommMgr.sys [file not found to scan]
----------
Key: VirtualFD
ImagePath: \??\D:\Accumulator\vfd21-080206\vfd.sys
D:\Accumulator\vfd21-080206\vfd.sys [file not found to scan]
----------
Key: WMConnectCDS
ImagePath: C:\Program Files\Windows Media Connect 2\wmccds.exe
C:\Program Files\Windows Media Connect 2\wmccds.exe
855552 bytes
Created: 18/01/2008
Modified: 06/10/2005
Company: Microsoft Corporation
----------
Key: {DEF85C80-216A-43ab-AF70-1665EDBE2780}
ImagePath: \??\C:\WINDOWS\TEMP\60.tmp
C:\WINDOWS\TEMP\60.tmp [file not found to scan]
----------

************************************************************
14.16.53: Scanning -----VXD ENTRIES-----

************************************************************
14.16.53: Scanning ----- WINLOGON\NOTIFY DLLS -----
Key : igfxcui
DLLName: igfxdev.dll
C:\WINDOWS\system32\igfxdev.dll
-R- 204800 bytes
Created: 18/01/2008
Modified: 13/01/2007
Company: Intel Corporation
----------

************************************************************
14.16.53: Scanning ----- CONTEXTMENUHANDLERS -----
Key: Adobe.Acrobat.ContextMenu
CLSID: {D25B2CAB-8A9A-4517-A9B2-CB5F68A5A802}
Path: C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
C:\Program Files\Adobe\Acrobat 8.0\Acrobat Elements\ContextMenu.dll
677504 bytes
Created: 22/10/2006
Modified: 22/10/2006
Company: Adobe Systems Inc.
----------
Key: AVG8 Shell Extension
CLSID: {9F97547E-4609-42C5-AE0C-81C61FFAEBC3}
Path: C:\Program Files\AVG\AVG8\avgse.dll
C:\Program Files\AVG\AVG8\avgse.dll
99608 bytes
Created: 04/07/2008
Modified: 04/07/2008
Company: AVG Technologies CZ, s.r.o.
----------
Key: PowerISO
CLSID: {967B2D40-8B7D-4127-9049-61EA0C2C6DCE}
Path: C:\Program Files\PowerISO\PWRISOSH.DLL
C:\Program Files\PowerISO\PWRISOSH.DLL
208896 bytes
Created: 20/01/2008
Modified: 20/01/2008
Company: PowerISO Computing, Inc.
----------
Key: TagRename_ContextMenu
CLSID: {7C5E74A0-D5E0-11D0-A9BF-E886A83B9BE5}
Path: C:\PROGRA~1\TAGREN~1\TRshell.dll
C:\PROGRA~1\TAGREN~1\TRshell.dll
144640 bytes
Created: 15/02/2008
Modified: 05/12/2007
Company: Softpointer Inc
----------

************************************************************
14.16.53: Scanning ----- FOLDER\COLUMNHANDLERS -----
Key: {7A5117B0-B594-4DA8-829D-D15BF11996F2}
File: C:\Program Files\DAEMON Tools Lite\awxDTools.dll
C:\Program Files\DAEMON Tools Lite\awxDTools.dll
151552 bytes
Created: 18/01/2008
Modified: 27/03/2006
Company: arniWORX
----------
Key: {C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}
File: "C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll"
C:\Program Files\OpenOffice.org 3\Basis\program\shlxthdl\shlxthdl.dll
357888 bytes
Created: 28/08/2008
Modified: 28/08/2008
Company: Sun Microsystems, Inc.
----------

************************************************************
14.16.53: Scanning ----- BROWSER HELPER OBJECTS -----
Key: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
BHO: C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
62080 bytes
Created: 22/10/2006
Modified: 22/10/2006
Company: Adobe Systems Incorporated
----------
Key: {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20}
BHO: C:\Program Files\Winamp Toolbar\winamptb.dll
C:\Program Files\Winamp Toolbar\winamptb.dll
1267040 bytes
Created: 19/03/2008
Modified: 19/03/2008
Company: AOL LLC.
----------
Key: {53707962-6F74-2D53-2644-206D7942484F}
BHO: C:\PROGRA~1\SPYBOT~1\SDHelper.dll
C:\PROGRA~1\SPYBOT~1\SDHelper.dll - file is excluded from scanning [SPYBOT S&D file]
----------
Key: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}
BHO: C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
509328 bytes
Created: 10/11/2008
Modified: 10/06/2008
Company: Sun Microsystems, Inc.
----------
Key: {AE7CD045-E861-484f-8273-0445EE161910}
BHO: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
321120 bytes
Created: 22/10/2006
Modified: 22/10/2006
Company: Adobe Systems Incorporated
----------

************************************************************
14.16.54: Scanning ----- SHELLSERVICEOBJECTS -----

************************************************************
14.16.54: Scanning ----- SHAREDTASKSCHEDULER ENTRIES -----

************************************************************
14.16.54: Scanning ----- IMAGEFILE DEBUGGERS -----
No "Debugger" entries found.

************************************************************
14.16.54: Scanning ----- APPINIT_DLLS -----
The HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows key appears to be locked
AppInitDLLs entry = [avgrsstx.dll]
File: avgrsstx.dll
C:\WINDOWS\system32\avgrsstx.dll
10520 bytes
Created: 23/05/2008
Modified: 04/07/2008
Company: AVG Technologies CZ, s.r.o.
----------

************************************************************
14.16.54: Scanning ----- SECURITY PROVIDER DLLS -----

************************************************************
14.16.54: Scanning ------ COMMON STARTUP GROUP ------
[C:\Documents and Settings\All Users\Start Menu\Programs\Startup]
The Common Startup Group attempts to load the following file(s) at boot time:
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\desktop.ini
-HS- 84 bytes
Created: 18/01/2008
Modified: 18/01/2008
Company: [no info]
--------------------
C:\Program Files\TerraTec\DMX 6fire\DMX6Fire.exe
335872 bytes
Created: 18/01/2008
Modified: 29/08/2003
Company: TerraTec Electronic GmbH
DMX 6fire 2496 ControlPanel.lnk - links to C:\Program Files\TerraTec\DMX 6fire\DMX6Fire.exe
--------------------

************************************************************
14.16.55: Scanning ------ USER STARTUP GROUPS ------
--------------------
Checking Startup Group for: Raf
[C:\Documents and Settings\Raf\START MENU\PROGRAMS\STARTUP]
The Startup Group for Raf attempts to load the following file(s):
C:\Documents and Settings\Raf\START MENU\PROGRAMS\STARTUP\desktop.ini
-HS- 84 bytes
Created: 18/01/2008
Modified: 18/01/2008
Company: [no info]
----------

************************************************************
14.16.55: Scanning ----- SCHEDULED TASKS -----
No Scheduled Tasks found to scan

************************************************************
14.16.55: Scanning ----- SHELLICONOVERLAYIDENTIFIERS -----

************************************************************
14.16.55: ----- ADDITIONAL CHECKS -----
PE386 rootkit checks completed
----------
Winlogon registry rootkit checks completed
----------
1 TDSS rootkit driver(s) heuristically detected
No specific TDSS rootkit drivers could be located - no action taken
-----
Heuristic checks for hidden files/drivers completed
----------
Layered Service Provider entries checks completed
----------
Windows Explorer Policies checks completed
----------
Desktop Wallpaper: C:\Documents and Settings\Raf\Application Data\IrfanView\IrfanView_Wallpaper.bmp
C:\Documents and Settings\Raf\Application Data\IrfanView\IrfanView_Wallpaper.bmp
3888054 bytes
Created: 18/01/2008
Modified: 01/01/2009
Company: [no info]
----------
Web Desktop Wallpaper: %SystemRoot%\web\wallpaper\Bliss.bmp
C:\WINDOWS\web\wallpaper\Bliss.bmp
1440054 bytes
Created: 18/01/2008
Modified: 18/01/2008
Company: [no info]
----------
Checks for rogue DNS NameServers completed
----------
Additional checks completed

************************************************************
14.17.05: Scanning ----- RUNNING PROCESSES -----

C:\WINDOWS\System32\smss.exe
[1 loaded module]
--------------------
C:\WINDOWS\system32\csrss.exe
[15 loaded modules in total]
--------------------
C:\WINDOWS\system32\winlogon.exe
[74 loaded modules in total]
--------------------
C:\WINDOWS\system32\services.exe
[41 loaded modules in total]
--------------------
C:\WINDOWS\system32\lsass.exe
[59 loaded modules in total]
--------------------
C:\WINDOWS\system32\svchost.exe
[68 loaded modules in total]
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
[45 loaded modules in total]
--------------------
C:\WINDOWS\System32\svchost.exe - file already scanned
[140 loaded modules in total]
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
[36 loaded modules in total]
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
[44 loaded modules in total]
--------------------
C:\WINDOWS\Explorer.EXE - file already scanned
[151 loaded modules in total]
--------------------
C:\WINDOWS\system32\spoolsv.exe
[60 loaded modules in total]
--------------------
C:\PROGRA~1\AVG\AVG8\avgtray.exe - file already scanned
[49 loaded modules in total]
--------------------
C:\WINDOWS\system32\RUNDLL32.EXE
[35 loaded modules in total]
--------------------
C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe
[58 loaded modules in total]
--------------------
C:\WINDOWS\system32\rundll32.exe
[38 loaded modules in total]
--------------------
C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
[38 loaded modules in total]
--------------------
C:\Program Files\Creative\Creative Media Lite\CTZDetec.exe - file already scanned
[29 loaded modules in total]
--------------------
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe - file already scanned
[38 loaded modules in total]
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
[35 loaded modules in total]
--------------------
C:\WINDOWS\system32\CTsvcCDA.exe
[22 loaded modules in total]
--------------------
C:\Program Files\Creative\Shared Files\CTDevSrv.exe - file already scanned
[22 loaded modules in total]
--------------------
C:\WINDOWS\system32\nvsvc32.exe
[40 loaded modules in total]
--------------------
C:\WINDOWS\system32\svchost.exe - file already scanned
[44 loaded modules in total]
--------------------
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
[27 loaded modules in total]
--------------------
C:\PROGRA~1\AVG\AVG8\avgemc.exe - file already scanned
[66 loaded modules in total]
--------------------
C:\WINDOWS\System32\alg.exe
[34 loaded modules in total]
--------------------
C:\Program Files\Mozilla Firefox\firefox.exe
[86 loaded modules in total]
--------------------
C:\Documents and Settings\Raf\Application Data\Simply Super Software\Trojan Remover\qri5E.exe
FileSize: 2913144
[This is a Trojan Remover component]
[65 loaded modules in total]
--------------------

************************************************************
14.17.39: Checking AUTOEXEC.BAT file
AUTOEXEC.BAT found in C:\
No malicious entries were found in the AUTOEXEC.BAT file

************************************************************
14.17.39: Checking AUTOEXEC.NT file
AUTOEXEC.NT found in C:\WINDOWS\system32
No malicious entries were found in the AUTOEXEC.NT file

************************************************************
14.17.39: Checking HOSTS file
No malicious entries were found in the HOSTS file

************************************************************
14.17.39: Scanning ------ %TEMP% DIRECTORY ------
C:\DOCUME~1\Raf\LOCALS~1\Temp\etilqs_xCq1O2fXEr6pAmeLBAkT appears to be in-use/locked
************************************************************
14.17.51: Scanning ------ C:\WINDOWS\Temp DIRECTORY ------
************************************************************
14.17.51: Scanning ------ ROOT DIRECTORY ------

************************************************************
14.17.51: ------ Scan for other files to remove ------
No malware-related files found to remove

************************************************************
------ INTERNET EXPLORER HOME/START/SEARCH SETTINGS ------
HKLM\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKLM\Software\Microsoft\Internet Explorer\Main\"Local Page":
%SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Page_URL":
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKLM\Software\Microsoft\Internet Explorer\Main\"Default_Search_URL":
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKLM\Software\Microsoft\Internet Explorer\Search\"CustomizeSearch":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
HKLM\Software\Microsoft\Internet Explorer\Search\"SearchAssistant":
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Start Page":
http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
HKCU\Software\Microsoft\Internet Explorer\Main\"Local Page":
C:\WINDOWS\system32\blank.htm
HKCU\Software\Microsoft\Internet Explorer\Main\"Search Page":
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch

************************************************************
=== CHANGES WERE MADE TO THE WINDOWS REGISTRY ===
=== ONE OR MORE FILES WERE RENAMED OR REMOVED ===
Scan completed at: 14.17.51 03 gen 2009
Total Scan time: 00.01.45
-------------------------------------------------------------------------
One or more files could not be moved or renamed as requested.
They may be in use by Windows, so Trojan Remover needs
to restart the system in order to deal with these files.
03/01/2009 14.17.57: restart commenced
************************************************************

Reply to Gevulde Kex

17

thecoat, on Jan 3, 2009 4:25:29 pm GMT
  • +2

Just some technical info on this issue, working on my girl friends computer atm and she's having this issue. Name resolution is being intercepted in some way. Windows TCP/IP name resolution goes through several steps the first is to check the local systems dns cache. The second is that it checks the hosts file. I added www.agv.com with the correct address in the hosts file. The address still resolved as 127.0.0.1 (localhost). I then did an ipconfig /flushdns which should flush the dns cache on the local machine. This also did not work and www.avg.com still resolved as 127.0.0.1.

ipconfig /displaydns listed only two common correct entries in the dns cache.

This malware is intercepting windows dns resolution at the highest levels. It is not messing with the windows dns cache or the hosts file as is typically the case with hijacks.

This does most likely mean that there is an actively executing program doing the hijack, or a replaced library to which a program is making calls.. most likely the former. I'll post a solution if I find one.

Reply to thecoat

100

alainr345, on Jan 26, 2009 5:12:52 am GMT

Thanks to this forum, I could solve that invasion on my laptop, what I would call the Update Blocker Super Rootkit Virus. Like Dav the culprit for me seems to be:
gaoopdxklowrct.sys" and the Reg key was "HKLM\SYSTEM\CURRENT CONTROL SET\ Services\gaopdxserv.sys" .

Trojan Remover cleared it and I"m crossing my fingers that this Rootkit (named officially TDss.A I think) won"t reappear.

In the meantime, Mr. Coat (or somebody else here), since you seem more technically savvy, could you explain how this can occur: What network layer is compromised when this happens ? What is the mechanism at play and how can we disable it by ourselves (without resorting to Antivirus products)? Thanks, A. R.

Reply to alainr345

187

Ferdinko, on Mar 23, 2009 3:37:10 am GMT

Hi Thecoat,

Do you have any update on this?

I have the exactly same problems recently. My AVG virus database stands as March 14 2009. No updates were successful ever since. Can't do Windows update either.

The scary thing is that I noticed that this malware (or whatever it might be) was first reported around Dec 2008. Between now and then I had performed many virus database updates and I still have it in my computer! I always have my Windows up to date and my Antivirus and Firewall are fully loaded and operational. I don't go to dodgy websites either. How this thing got into my computer was beyond me. From the threads I can tell it affects many security-minded people with good surfing habits too. Isn't it scary?! Microsoft don't seem to do anything about it either.

Your help is much appreciated.

Ferdinko

Reply to Ferdinko

18

airy, on Jan 3, 2009 7:29:14 pm GMT

Trojan Remover did the trick! Been having this issue for about 24 hours now, ran 2 anti-virus and 3 anti-spyware with no luck. Run Trojan Remover!!

THANKS MORPHINE!!!!

Reply to airy

21

doglo, on Jan 3, 2009 11:37:43 pm GMT

It worked for me too!

Reply to doglo

24

morphine, on Jan 4, 2009 3:18:26 am GMT

Glad it helped! If you have any trouble downloading the software, search for mirrors sites... like "Spysubtract mirror" Most have other sites where you can download the EXE, and they are not blocked.

Happy virus-free 2009!

Reply to morphine

31

Rooty Mac, on Jan 4, 2009 5:57:48 pm GMT

Thanks for the info Morphine! I used Trojan Remover first and that did the trick! Happy New Year!

Reply to Rooty Mac

150

sourya_4, on Feb 13, 2009 2:17:44 pm GMT

Hi mate,,,,,i hav d same prob...not abl to open anti-v sites or update avg.....i uninstalled avg n downloaded 'ur' trojandwnldr as proposed. i started d scan when it displayed dat avg is running....proceed with scan? i scanned but my probz still der torturing me. i searched for every single avg file n dltd but still same msg.....pls help me as u did it 4 many


in seach of help

an amateur techfella

Reply to sourya_4

30

Kurosawa, on Jan 4, 2009 8:26:12 am GMT

Trojan Remover worked! I can now access AVG.com, including updates, etc. Thanks a ton.

I also ran AVG (without the update) and Malwarebytes Anti-Malware. They both found lots of stuff, but didn't get rid of the DNS blocks.

Reply to Kurosawa

25

Daver, on Jan 4, 2009 3:30:55 am GMT

WOW! I thought i was the only one with this problem! Thanks for helping morphine that did the trick! I noticed that I could use a proxy to get to AVG to update but it still didn't work but this sure did thanks a bunch!

Reply to Daver

32

valevonn, on Jan 4, 2009 7:25:32 pm GMT

Morphine!!!! THANK YOU SO MUCH. Your link to the trojan removal did the trick. I've been dealing with this for a week and have tried EVERYTHING! Thanks for the tip.

I just used the TR at your first link and everything seems to be running fine. I was able to update my AVG. But I didn't use the other step you mentioned in your later post:
1) SmitFraudFix (normal)
2) SmitFraudFix (safe mode)
2) Spy Subtract
3) SuperAnti Spyware
4) Avira AntiSpywhere
5) Trojan Remover

Do I need to do steps 1-4?

Reply to valevonn

34

tukk, on Jan 4, 2009 8:18:28 pm GMT

Thanks a lot guys!!!! im now updating my avg. Thanks morphine.

Reply to tukk

35

Gallagher, on Jan 4, 2009 9:56:23 pm GMT

Thanks for everything... Thats a nasty infection and one which i never want to see again! Does anyone have any more info on what it is or how it has got on to all these pcs? I for one know i havent been using dodgy sites and still got it??? please let me know if there is any info on what this is as it took me ages to get rid of!

Cheers

Reply to Gallagher

36

YYZ Jim, on Jan 4, 2009 11:45:06 pm GMT

I have (had) it too. Thanks to morphine for the List.
The first thing I noticed when it started to work again was the toolbar accross the top of the google page appeared again !!

Reply to YYZ Jim

38

fatherspeedy, on Jan 5, 2009 12:46:13 pm GMT

Had the same problem after updating on or around xmas... It's all malware dude. I tried all the internet gimmicks - None worked. Solution was simple: Scan your computer with an antivirus which support spyware, spam, rootkit etc.. (i used AVG security Center); then use (Malwarebytes' Anti-Malware) - it found about 30 malware on my machine. Erase malware found... Restart your computer!!! bang bang - my updates worked again... Note: Keep a working antivirus/spyware/spamware software which is updated regularly... WORKS

Reply to fatherspeedy

39

NDGChicago, on Jan 5, 2009 3:12:28 pm GMT

I tried three different anti-virus and two anti-spyware, but none of them could fix it. Trojan Remover did the magic, and it seems to be back to normal. Thanks for all your help, Morphine!

Reply to NDGChicago

40

jmaccjr, on Jan 6, 2009 1:04:56 am GMT

This virus was the worst...I slowed down a fcked up my computer.. Thankfully I was able to surf the web to find valuable information like this to kill it... Good job Fellas

Reply to jmaccjr

41

M AJ mike, on Jan 6, 2009 3:32:32 am GMT

I've been fighting this for 3 weeks. I some how down loaded "ANTI virus 2009" which made things worse. The trojan removial tool did the trick. I also ran Malwarebytes Anti-Malware. I ran them both twice and that cleaned everything up. Thanks for the information!

Reply to M AJ mike

43

DebiDibly, on Jan 6, 2009 2:48:25 pm GMT

I had it too! AVG woudn't update. Every time I started to run scan I'd get an error in the first few seconds but then the scan would continue and not find anything. I tried un-installing and re-installing, figuring maybe a file had gotten corrupted. I tried running windows update and noticed my page kept getting redirected. I was about to buy Trend Micro Pc Cillin because I never had a problem with that program. When I tried to load their site I was also redirected. Seems I was "infected" or "malware-d" without any warning but at least at this point, I knew something was up despite my anti-virus finding nothing.

No idea how I got it. I don't download from people I don't know or visiti strange sites. Wondering what else it was doing in the background. Stealing passwords? Credit cards?

This is the only forum I've been able to find any info on this. So glad I used the Trojan Remover. Found it right away and at the moment - every last thing appears fine. I hope it really is :)

Reply to DebiDibly

45

kalloco, on Jan 6, 2009 10:54:49 pm GMT

That free Kaspersky 30 day trial seems to be going great!

i might even consider purchasing it!

I've run TROJAN REMOVER ... all is clear.

thanks to all on this forum!

Kalloco

Reply to kalloco

51

rainbowrunner, on Jan 9, 2009 5:21:10 am GMT

Thanks guys I hope this works. . . . . . trojan remover

Reply to rainbowrunner

53

zerocool64, on Jan 10, 2009 6:29:14 am GMT

Same problem for me... It will work... Trojan Remover

fixes the update blocks (cannot connect to server) for all antivirus programs, fixes browser redirecting when surfing certain sites, fixes Firefox Homepage "The page - *** - does not exist." and Advertisement pop-up.

Reply to zerocool64

54

zerocool64, on Jan 10, 2009 6:35:34 am GMT

The main problem was the Worm --> msqpdxserv.sys (i don't know where this file exists but Trojan Remover found it). But I do know there is a hidden registry key in HKEY_CLASSES_ROOT>msqpdxvx and could be coupled with several other similarly named hidden keys (like msqpd***) PCTools Spyware Doctor found it before but could not remove it successfully.

Reply to zerocool64

89

Dav, on Jan 22, 2009 2:39:05 am GMT
  • +1

Thanks for the tip and thank the rest of the people on the site. The Trojan Hunter 6.7.5 found in my case was "gaoopdxklowrct.sys" and the Reg key was "HKLM\SYSTEM\CURRENT CONTROL SET\ Services\gaopdxserv.sys" .
It seem to have happen after I loaded a bogus license for Win Media Player which I won't be doing again. But it was on a machine that wouldn't cause any real grief. Thanks again to everybody.

Dav

Reply to Dav

140

Cartoonis, on Feb 9, 2009 7:07:51 am GMT

Cheers guys, I had it hiding in autorun.ini on my external HDD. Trojan remover did the trick.

Reply to Cartoonis

152

mc271283, on Feb 13, 2009 7:25:05 pm GMT

I found that the tools above didn't work. However the Kaspersky solution did.

If you are running Windows XP (And don't have Service Pack 3 installed) then try the Kaspersky tool as mentioned:

http://support.kaspersky.com/faq/?qid=208279973 (Obv you'll have to download this from another machine!).

Follow the instructions there, install the patch (to stop it getting back on), run the tool as suggested, and see if it sorts it after a reboot.

Worked for me, now have 3 other machines to disinfect... :-(

Reply to mc271283

161

ss786, on Feb 14, 2009 6:25:09 pm GMT

Hey mc271283 how to use this administration kit do you have to run kidokiller.exe from local(infected PC) or remote which sql server is recommended. plz... help dude i want sort dis thing. thanks!

Reply to ss786

169

NB who comes out of the dark, on Feb 17, 2009 3:20:32 pm GMT

Thanks a lot

I have the same problem as above
The trojan remover didn't work for me

My notebook got infected with Kido Worm
So your recommendation works very well in this case.

Reply to NB who comes out of the dark

172

LILO, on Feb 22, 2009 1:13:29 pm GMT

I have just fixed this on a customers pc.
Here are the steps I followed.


The symptoms were:

Avg would not update
Could not get into Microsoft update.
PC was extremely slow
PC would not boot into safe mode - got a video display driver load error
Could not get into any recognised antivirus sites.

The fix.

On a clean pc - downloaded the trojan remover from www.simplysup.com/tremover/download.html and saved it to a memeory stick.

On the same clean pc, went and downloaded the latest free AVG and also saved it to the memory stick

On the infected PC, opened Internet explorer and navigated to www.onecare.live.com

Ran the protection scan fron onecare and it worked fine - found 12 Trojans and cleaned them.

Then I ran the trojan remover from simplysup. - it found TDSS files in the drivers directory of windows32- it cleaned them and fixed the registry entries.

Rebooted the PC, and then installed the clean AVG free from the memory stick ( flashdrive)

All worked fine after that - AVG updated, Windows updates downloaded.

Reply to LILO

181

slednecktek, on Mar 9, 2009 3:45:00 am GMT

Issues I had with friends machine….(I know they are cheap bastards, Maybe one day just maybe they will send the folks helpin ā€˜em out some cake, hope diz chiznit don’t effect my networks)!!!

Fresh install XP Home on 8-28-2008 with SP3 and AVG7.5. And it begins, glad they kicked down for some media cuz dis sucka would not boot and the OEM disks did not exist as usual, don’t get me started on the office suite). I love M$FT but the L-users on the other hand…Such are the days of my life. Installed Adobe flash, reader and shockwave (did I forget some of their poo?), Java, QuickTime, Fire Fox, the necessary dung. Also, the lovely QuickBooks poo. Along the way someone installed MBAM ,a program I recommend but also when the problem started according to my buddy (I had no knowledge of this one for real, everyone is searching goog to fix they pcs before calling a tek). Also I-Tunes (with all the ipoo; bonjour, apple updater, ipood service…blah blah), viewpoint manager, seriously not much else, but obviously searched a lot of pron. Really a pretty fckin clean install??? Supposedly the teens are out now and this will not happen again…

6pm Sun 3-8-2009:
Made successful backup of data to DVD. Tried multiple AV and malware programs (uninstall non-updating AVG & MBAM, retry, Avast, Spy-bot S&D, Ad-aware) with latest updates from flash drive, unsuccessful on any kind of update at this point, MBAM will not even run (damn I loved this prog for last 6months, removed lotsa poo for me and saved at least half a dozen comps for friends of mine)

9pm:
after unsuccessful attempts at removing issue tried ā€œTrojan Remover 6.7.6ā€ from ran then reboot. Upon reboot no boot record found, ran recovery console from disk and fixmbr and fixboot. Successful reboot but no view log opens for tr6.76? AVG successfully updates and this is a windows fresh load with XPSP3 and IE7 and almost all updates. This was a gnarly one. No more windows update redirect or anti-virus/malware led searches astray?

10:30pm 3-8-2209:
Thanks for the link and the info. This almost equals my average 5 minute job at work which only takes about 4 hours regularly!!! ( I do take care of COPS on a daily basis, thus the L-users comment cuz they are the most ā€œspecialā€ of all!) Sometimes it is just faster to reload the whole darn winderz………. Be back soon

Reply to slednecktek

194

Spud, on Mar 28, 2009 3:13:15 pm GMT

Hey.
i seem to be having the same sort of problems that have been discribed in this forum. this is the second time that i have had these symtoms before and with the help of this forum managed to get rid of it. but now its back and everything that i have tried previously no longer works.

some the symtoms that are new this second time round.

Itunes will not update or connect to the servers to collect info from CDs in the way that it normaly would if it were connected to the internet.
No program anti virus, malware or any other will update.
Having bought a game throungh miniclip there is no connection to the miniclip serves to register my purchase.

i have tryed all kinds of anti malware most mentioned in this forum but nothing has worked.
SAS found a Trojan but after deleteing it there was no change.

all my internet browsers work with no problems.

Any ideas? im willing to try nything short of reinstallin windows atm.

Reply to Spud

199

khoa, on Apr 28, 2009 10:53:54 pm BST

I have the same prob i try trojan remover but it says com is clean and i can not go to malwarebytes web, cannot update windows xp, cannot update pc tools internet security helllllllllllpppppppppppppppppppp i had this prob for like 4 days and its making me mad!

Reply to khoa

205

JamieTheD, on Nov 6, 2009 10:10:30 pm GMT

Yeah, I'm having these problems too... brand new install, windows XP Home SP... 2, I think... currently got SpyBot S&D, Conficker detector (because I was told that conficker might be the culprit), Trojan Remover trial... tried the MTU fix, the OpenDNS fix, the Trojan Remover fix, and still no micros*** site or antivirus sites (except Spybot and certain links to Trojan Remover)

Really don't know what's up here, but judging by the search I've been doing all day, lots of peeps are having the same problems, worldwide. Might be something new, methinks. Either that, or a global DNS cockup... who knows?

Reply to JamieTheD

206

JamieTheD, on Nov 6, 2009 10:38:30 pm GMT

Interesting... one point of interest is that nearly all owners of nForce Network Controllers seem to solve the problem by rebooting into safe mode, trying to uninstall the controller, then rebooting. It's *currently* working now, although from the reports I've noted, the problem might come back...

...but the *most* interesting thing is that it worked even though I didn't *actually* uninstall the driver! I tried, but it told me I couldn't... wonder if just rebooting in safe mode then rebooting normally might work?

PS - that''s safe mode, no networking, btw.

Reply to JamieTheD