This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Browser Hijacker

36 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

HI again… Just an update again, both the browsers decided to just 'hang' again…for the second time, and the only way to get them to work again is to shutdown and reboot in. Also I went to the windows update page (just to check I'm fully up to date), and that froze as well! .. :pullhair:
Thanks, those were the logs I needed.

It will take me a little while to analyze them. In the meantime. You also have F-Secure installed as well as AVG…does the F-secure program include an antivirus…if it does, then you are getting conflicts between the two AV programs which is causing your system instability…Uninstall one of those programs entirely and see if things improve.

If you see no difference try this:

Start - Run - CMD to open a command prompt.

To Reset WINSOCK entries to installation defaults:(type the following at the command prompt)

netsh winsock reset catalog


To Reset TCP/IP stack to installation defaults. (type the following at the command prompt)

netsh int ip reset reset.log


Reboot the machine.


I'll post back later with further instructions
HI… No F Secure was on the machine, when it was a company one. I uninstalled it over a year ago and put AVG on and there has never been a problem until I 'caught' this infection. In addition to the browsers freezing I also get the dreaded fault box come up sometimes now (the that asks if you want to close the programme or debug the page ..its never done that before either!. The impression I'm getting is that something is controlling the internet access, affecting the browsers stopping antispy and virus software accessing the net. Its also strange that shutting down and starting again makes the browsers work, all be it for a varible amount of time!. For example the last time I simply hit the reply button to you on here ant that locked the browser (just said it was waiting for whatthetech to respond\0, but even refreshing did nothing. In addition when one browser hangs, if you open the other one that is the same …weird stuff!… The machine also seems a lot slower shutting down. I'll pick up your reply tomorrow, hopefully we (well you!!), can resolve this, :smack: One again thanks, you've been so patient and helpful :thumbup: Best Regards, Mick
Sorry ..one more thing if I try: Start - Run - CMD to open a command prompt. The taskbar as the bottom of the screen disappears, then a few seconds of nothing happening, the bar comes back and absolutely nothing happens!… maybe that helps as to what this maybe?… Regards, Mick
Hi,

There was nothing showing in those AVZ logs that would account for the symptoms you are having.

There is a lot of leftover files from f-decure

If you visit their site HERE you can down load a removal tool that should clean up those orphaned files for you.

I'm beginning to think the problems are software conflict related….(did you go through your add/remove programs yet and uninstall anything not needed/required that was work related. If you have any questions about any of the installed programs please ask….)

But we have more tools that will dig a little deeper to root out even the most hidden of malware…so we'll keep looking till we exhaust all the avenues.

Please do the following (don't worry about all these tools we're downloading, we will clean them up at the end)

Download Dr.Web CureIt to the desktop:
  • Doubleclick the drweb-cureit icon to start the program.
  • press start
  • Allow the program to run the initial express scan
  • This will scan the files currently running in memory. If something is found, click the YES button when it asks you if you want to cure it. This is only a short scan.
    Note: A pop up may appear during this phase suggesting you purchase their program - click the X at the top right corner of this pop-up to close it.
  • Once the short scan has finished, check the Complete scan box on the left side, even if nothing was found on the initial scan.
  • Then click the small green arrow button on the right under the Dr.Web Antivirus picture to start the complete scan. (This scan will take several hours)
  • During this complete scan - if Dr.Web finds an infection a window will pop up requesting your attention. Select the Cure button.
    • Note:(If the file cannot be cured, Dr.Web will automatically delete the file)
  • Once the scan is complete, on the menu bar, click file and choose report list.
  • Save the report to your desktop. The report will be called DrWeb.csv
  • Note:this report will need to be renamed to Dr.Web.txt in order to post it on the forum.
  • Close Dr.Web Cureit.
  • Please post the Dr.Web.txt report in your next reply
Thank for this CB, I'll get onto this evening when I get home, so given the time it take the second part of the programme to run it may be tomorrow evening (UK time), before I can post back. Once again thanks for being so patient and 'dogged' with stick with this problem… Best Regards, Mick
Hi CB… Not everything went actually to plan!. The F-Secure removal tool did'nt work (I'll try it again later). The first DrWeb fast scan didn't find anything, but the longer one did..but although it said it saved a fle it didn't, but it did retain an excel file..so I have copied/pasted that below: c.bat;C:\32788R22FWJFW;Probably BATCH.Virus;Incurable.Deleted.; psexec.cfexe;C:\32788R22FWJFW;Program.PsExec.171;Incurable.Deleted.; regLocal.reg;C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Backups;Probably SCRIPT.Virus;Incurable.Deleted.; A0081480.exe\SmitfraudFix\Process.exe;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP343\A0081480.exe;Tool.Prockill;; A0081480.exe\SmitfraudFix\restart.exe;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP343\A0081480.exe;Tool.ShutDown.14;; A0081480.exe;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP343;Archive contains infected objects;Moved.; A0081493.exe;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP343;Tool.Prockill;Incurable.Deleted.; A0081495.exe;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP343;Tool.ShutDown.14;Incurable.Deleted.; A0084086.exe/data002\32788R22FWJFW\c.bat;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP363\A0084086.exe/data002;Probably BATCH.Virus;; A0084086.exe/data002\32788R22FWJFW\psexec.cfexe;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP363\A0084086.exe/data002;Program.PsExec.171;; data002;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP363;Archive contains infected objects;; A0084086.exe;C:\System Volume Information\_restore{3D1D7B25-2548-4BCA-9051-9646019CA7AC}\RP363;Container contains infected objects;Moved.; Process.exe;C:\WINDOWS\system32;Tool.Prockill;Incurable.Deleted.; Seems it found quite a bit!! …would these cause some/all of the issues I have been having?… Regards, Mick
CB - Forgot to mention AVG STILL won't connect to its server!…obviously all the above have either been healed or deleted…so far everything seems back to normal except AVG connection problem. I have now managed to run the F-Secure tool and clean out all the files…but still the AVG connection problem (I've checked the firewall isn't blocking it, and that fine). If the anti-virus was back to normal (please don't let me say this to early!), all seems as it was before … Regards Mick
Hi

Lets do a little clean up first then see where we stand…

Most of those infections were in the old system restore points…so lets cleanthem out…


Click Start > Run > copy and paste the following into the run box:

%SystemRoot%\System32\restore\rstrui.exe


Press OK. Choose Create a Restore Point then click Next.Name it (something you'll remember) and click Create,
when the confirmation screen shows the restore point has been created click Close.

Now remove all previous Restore Points:

Click Start > Run > copy and paste the following into the run box:

cleanmgr


At the top, click on More Options tab. Click the Clean up button in the System Restore box.
Click on the Yes button.
When finished, click on Cancel button to exit.

Now please do the following:

Follow these steps to uninstall Combofix

  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK. Note the space between the ..X and the /U, it needs to be there.

[external image: Posted Image]

Next


Download ToolsCleaner2 to your desktop and run it ( by de A.Rothstein & Dj Quiou )
  • Click the Pt. Restauration button and press OK to the prompts.
  • Click the Corbeille button and press OK to the prompt.
  • Click the Fichiers temp button and press OK to the prompt.
  • Click the Recherche button and let it run ( it may look like it freezes but let it continue )
  • Once it is done click the Suppression button and let it remove anything it finds.
  • Close the program

Next


Now open HJT and run a system scan and save a log file
post the fresh hjt log here
HI …

All done, other then Combo-fix it says it can't find, and the tools cleaner (being in French), I went through each button as you said, but one all done the suppression button remained unlit, so I'm guessing there was nothing to suppress?..

This is the latest HJT log with all the above done…

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:18:25, on 31/03/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18372)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Novell\XTAgent.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
C:\Program Files\Common Files\LightScribe\LSSrvc.exe
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\Program Files\Novell\ZENworks\nalntsrv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Novell\ZENworks\wm.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\wscntfy.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
C:\WINDOWS\system32\iprntctl.exe
C:\WINDOWS\system32\iprntlgn.exe
C:\WINDOWS\system32\dpmw32.exe
C:\WINDOWS\system32\NWTRAY.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\Program Files\AVG\AVG8\avgtray.exe
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE
C:\Program Files\Google\Update\GoogleUpdate.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.virginmedia.com/
O1 - Hosts: ÿþ127.0.0.1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [RestoreIT!] "C:\Program Files\Phoenix Technologies Ltd\RecoverPro_XP\VBPTASK.EXE" VBStart
O4 - HKLM\..\Run: [DisplayManager] C:\Program Files\Samsung\DisplayManager\DisplayManager.exe
O4 - HKLM\..\Run: [RemoteControl] "C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [BatteryManager] C:\Program Files\Samsung\Samsung Battery Manager\BatteryManager.exe
O4 - HKLM\..\Run: [iPrint Tray] C:\WINDOWS\system32\iprntctl.exe TRAY_ICON
O4 - HKLM\..\Run: [iPrint Event Monitor] C:\WINDOWS\system32\iprntlgn.exe
O4 - HKLM\..\Run: [NDPS] C:\WINDOWS\system32\dpmw32.exe
O4 - HKLM\..\Run: [NWTRAY] NWTRAY.EXE
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AdobeUpdateManager.exe" AcPro7_1_0 -reboot 1
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MI69DF~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to &Bluetooth Device… - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dll
O9 - Extra button: (no name) - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra 'Tools' menuitem: Uninstall BitDefender Online Scanner v8 - {85d1f590-48f4-11d9-9669-0800200c9a66} - C:\WINDOWS\bdoscandel.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Novell delivered applications - {C1994287-422F-47aa-8E5E-6323E210A125} - C:\Program Files\Novell\ZENworks\AxNalServer.dll
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {5D86DDB5-BDF9-441B-9E9E-D4730F4EE499} (BDSCANONLINE Control) - http://www.bitdefender.co.uk/scan_uk/scan8/oscan8.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AE66722-3678-49D2-B956-C59100B9D5E3}: Domain = herts.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\..\{4AE66722-3678-49D2-B956-C59100B9D5E3}: NameServer = 147.197.200.2,147.197.200.44
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = herts.ac.uk
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = herts.ac.uk
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: Client Update Service for Novell (cusrvc) - Novell, Inc. - C:\WINDOWS\system32\cusrvc.exe
O23 - Service: Juniper Network Connect Service (dsNcService) - Juniper Networks - C:\Program Files\Juniper Networks\Common Files\dsNcService.exe
O23 - Service: Google Update Service (gupdate1c99396c91d592) (gupdate1c99396c91d592) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Novell Application Launcher (NALNTSERVICE) - Novell, Inc. - C:\Program Files\Novell\ZENworks\nalntsrv.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Novell ZENworks Remote Management Agent (Remote Management Agent) - Novell, Inc. - C:\Program Files\Novell\ZENworks\RemoteManagement\RMAgent\ZenRem32.exe
O23 - Service: Samsung Update Plus - Unknown owner - C:\Program Files\Samsung\Samsung Update Plus\SLUBackgroundService.exe
O23 - Service: SNM WLAN Service - Unknown owner - C:\Program Files\samsung\Samsung Network Manager\SNMWLANService.exe
O23 - Service: SRS PostInstaller Service (SRS_PostInstaller) - SRS Labs, Inc. - C:\Program Files\SRS Labs\WOWXT and TSXT Driver\SRS_PostInstaller.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
O23 - Service: Novell XTier Agent Services (XTAgent) - Novell, Inc. - C:\WINDOWS\System32\Novell\XTAgent.exe
O23 - Service: Workstation Manager (ZFDWM) - Novell, Inc. - C:\Program Files\Novell\ZENworks\wm.exe

–
End of file - 11055 bytes

Regards,

Mick
Sorry CB I keep doing this (adding on after a reply …sorry!), I should of mentioned I totally uninstalled AVG and reinstalled from scratch ..but still no connection to the server to update, this time I kept the firewall switched off just in case, but still no connection. There is a direct link to the avg home page on the page that tells you it can't connect, and when you click on it, it takes to the AVG home page, so the connections are there but something continues to block its update server connection… Regards, Mick
Hi please do this

Run HJT and click on Open the Misc Tools section.
  • Click Open Uninstall Manager…
  • Click Save list… and save it to your Desktop.
  • Copy and paste the file uninstall_list.txt into your reply.


Next completely uninstall AVG again and download ONE of the following…see if the same problem exists with them


· AntiVir


· Avast!

The HJT log looks clean, so we'll have to investigate the AV issue a little further.
Thanks CB… I'll do that tomorrow and get back you. I've had to change to the desktop pc, both the browsers refused to connect to internet again after being ok all evening! I tried to establish a connection manually (via control panel -network connections), and it seemed to think my firewall was blocking connecting via the named ports (sorry I did take what ports they were), only thing is the firewall was switched off!!. Another thing the browser (Firefox), seems to slow right down a while before it fails to connect….not sure if that means anything. It seems that something blocks access to the AVG updater and then finally does the same to the browsers, the only difference is that the browsers work fine again if you shutdown the machine & restart, but the AVG is blocked all the time! I don't think its a software conflict as nothing has changed, other than the 'nasties' you have managed to remove so far…I think (well I hope really!), we are close to sorting it all ..it just seems to be this dropping off or not making of connections issue left. I'll post again one I have followed your instructions tomorrow… Best Regards & again 'Heaps' of thanks… Mick
HI CB… As requested this is the HJT file you requested… 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) 2007 Microsoft Office Suite Service Pack 1 (SP1) Acrobat.com Acrobat.com Adobe Acrobat 7.1.0 Professional Adobe AIR Adobe AIR Adobe Flash Player ActiveX Adobe Reader 9 Advanced SystemCare 3 Atheros WLAN Client AVG 8.5 AVStation Premium 3.75 Birthday Bios CCleaner (remove only) Critical Update for Windows Media Player 11 (KB959772) DisplayManager DivX Web Player EasyBox Google Earth Google Update Helper High Definition Audio Driver Package - KB888111 HijackThis 2.0.2 Hotfix for Microsoft .NET Framework 3.0 (KB932471) Hotfix for Windows Internet Explorer 7 (KB947864) Hotfix for Windows Media Format 11 SDK (KB929399) Hotfix for Windows Media Player 11 (KB939683) Hotfix for Windows XP (KB952287) Install McAfee Intel® PROSet/Wireless Software J2SE Runtime Environment 5.0 Java™ 6 Update 2 Java™ SE Runtime Environment 6 Update 1 Juniper Networks Network Connect 5.4.0 Magic Doctor Magic Keyboard Malwarebytes' Anti-Malware Management Center mDriver Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.1 Hotfix (KB928366) Microsoft .NET Framework 2.0 Service Pack 1 Microsoft .NET Framework 3.0 Service Pack 1 Microsoft Compression Client Pack 1.0 for Windows XP Microsoft Internationalized Domain Names Mitigation APIs Microsoft National Language Support Downlevel APIs Microsoft Office Access MUI (English) 2007 Microsoft Office Access Setup Metadata MUI (English) 2007 Microsoft Office Excel MUI (English) 2007 Microsoft Office InfoPath MUI (English) 2007 Microsoft Office Outlook MUI (English) 2007 Microsoft Office PowerPoint MUI (English) 2007 Microsoft Office Professional Edition 2003 Microsoft Office Professional Plus 2007 Microsoft Office Project Professional 2003 Microsoft Office Proof (English) 2007 Microsoft Office Proof (French) 2007 Microsoft Office Proof (Spanish) 2007 Microsoft Office Proofing (English) 2007 Microsoft Office Publisher MUI (English) 2007 Microsoft Office Shared MUI (English) 2007 Microsoft Office Shared Setup Metadata MUI (English) 2007 Microsoft Office Word MUI (English) 2007 Microsoft User-Mode Driver Framework Feature Pack 1.0 Microsoft Visual C++ 2005 Redistributable Mozilla Firefox (3.0.8) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 Parser and SDK MSXML 6.0 Parser (KB933579) Nero Suite NICI (Shared) U.S./Worldwide (128 bit) (2.7.0-2) NMAS Challenge Response Method NMAS Client Novell iPrint Client v04.20.00 NVIDIA Drivers PowerDVD PowerStarter Recover Pro Samsung Battery Manager Samsung Network Manager 2.0 Samsung Update Plus Security Update for 2007 Microsoft Office System (KB951550) Security Update for 2007 Microsoft Office System (KB951944) Security Update for 2007 Microsoft Office System (KB958439) Security Update for Microsoft Office Excel 2007 (KB958437) Security Update for Microsoft Office PowerPoint 2007 (KB951338) Security Update for Microsoft Office Publisher 2007 (KB950114) Security Update for Microsoft Office system 2007 (KB954326) Security Update for Microsoft Office system 2007 (KB956828) Security Update for Microsoft Office Word 2007 (KB956358) Security Update for Visio 2007 (KB947590) Security Update for Windows Internet Explorer 7 (KB933566) Security Update for Windows Internet Explorer 7 (KB937143) Security Update for Windows Internet Explorer 7 (KB938127) Security Update for Windows Internet Explorer 7 (KB939653) Security Update for Windows Internet Explorer 7 (KB942615) Security Update for Windows Internet Explorer 7 (KB944533) Security Update for Windows Internet Explorer 7 (KB950759) Security Update for Windows Internet Explorer 7 (KB953838) Security Update for Windows Media Player (KB952069) Security Update for Windows Media Player 10 (KB917734) Security Update for Windows Media Player 11 (KB936782) Security Update for Windows Media Player 11 (KB954154) Security Update for Windows XP (KB923789) Security Update for Windows XP (KB938464) Security Update for Windows XP (KB941569) Security Update for Windows XP (KB946648) Security Update for Windows XP (KB950760) Security Update for Windows XP (KB950762) Security Update for Windows XP (KB950974) Security Update for Windows XP (KB951066) Security Update for Windows XP (KB951376) Security Update for Windows XP (KB951376-v2) Security Update for Windows XP (KB951698) Security Update for Windows XP (KB951748) Security Update for Windows XP (KB952954) Security Update for Windows XP (KB953839) Security Update for Windows XP (KB954211) Security Update for Windows XP (KB954459) Security Update for Windows XP (KB954600) Security Update for Windows XP (KB955069) Security Update for Windows XP (KB956391) Security Update for Windows XP (KB956802) Security Update for Windows XP (KB956803) Security Update for Windows XP (KB956841) Security Update for Windows XP (KB957095) Security Update for Windows XP (KB957097) Security Update for Windows XP (KB958644) Security Update for Windows XP (KB958687) Security Update for Windows XP (KB958690) Security Update for Windows XP (KB960225) Security Update for Windows XP (KB960715) SENS LT56ADW Modem Smart Defrag 1.11 SoundMAX Spybot - Search & Destroy Sure Delete 5.1.1 Synaptics Pointing Device Driver Update for Microsoft Office Outlook 2007 (KB952142) Update for Office 2007 (KB946691) Update for Outlook 2007 Junk Email Filter (kb962871) Update for Windows Internet Explorer 8 (KB961813) Update for Windows XP (KB951072-v2) Update for Windows XP (KB951978) Update for Windows XP (KB955839) Update for Windows XP (KB967715) User's Guide VC 9.0 Runtime VC 9.0 Runtime VC80CRTRedist - 8.0.50727.762 VTplus 3.0 (32 Bit Edition) WIDCOMM Bluetooth Software Windows Desktop Search 3.01 Windows Imaging Component Windows Internet Explorer 8 Release Candidate 1 Windows Media Format 11 runtime Windows Media Format 11 runtime Windows Media Player 11 Windows Media Player 11 Windows Presentation Foundation Windows XP Service Pack 3 WOW XT and TSXT Filter Driver X11 VR Showroom ZENworks Desktop Management Agent ZipGenius 6 (6.0.2.1060) ZoneAlarm The browsers are as bad as ever, still hanging, error signs coming up etc!.. I'll go on to use the AVG removal tool, and install one of the AV you have listed…I'll post back once I have done that… Regards, Mick

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI