As the title says, I can't access any anti-virus website, or Microsoft update, as well as getting random popups. I suspected the Conficker worm, so have ran two different removal tools (one from Symantic, one from Grisoft), as well as Microsoft's Malicious Software Removal tool, with no results reported and no change. The affected computer had Norton installed, which reported nothing. I removed Norton and installed AVG 8.5 (free version). It reported 37 problems found and repaired, but the problem still persists. I'll include a log of what it reported below. Tried to install Malwarebyte's Antimalware, and it won't even install; I double-click it, and nothing ever happens. This computer is a friend's, so I unfortunately have no idea where he may have been with it or what he may have been doing with it.
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:00:52 AM, on 8/9/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wltrysvc.exe
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\AVG\AVG8\avgemc.exe
C:\PROGRA~1\AVG\AVG8\avgrsx.exe
C:\PROGRA~1\AVG\AVG8\avgnsx.exe
C:\Program Files\AVG\AVG8\avgcsrvx.exe
C:\PROGRA~1\AVG\AVG8\avgtray.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\Stephen\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cub91.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dell4me.com/mywaybiz
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13149&gct=&gc=1&q=
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dell4me.com/mywaybiz
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = http://toolbar.ask.com/toolbarv/askRedirect?o=13149&gct=&gc=1&q=
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://toolbar.ask.com/toolbarv/askRedirect?o=13149&gct=&gc=1&q=%s
R3 - URLSearchHook: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
R3 - URLSearchHook: (no name) - *{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
R3 - URLSearchHook: (no name) - *{C94E154B-1459-4A47-966B-4B843BEFC7DB} - (no file)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: AVG Security Toolbar BHO - {A3BC75A2-1F87-4686-AA43-5347D756017C} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - C:\Program Files\AVG\AVG8\Toolbar\IEToolbar.dll
O4 - HKLM\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\RunOnce: [NSSInstallation] C:\WINDOWS\system32\Adobe\Shockwave 11\nssstub.exe /RunOnce
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\FlashUtil9f.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\j2re1.4.2_03\bin\npjpi142_03.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - C:\WINDOWS\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe (file missing)
O23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\wltrysvc.exe
--
End of file - 4487 bytes
AVG log (infections):
"C:\WINDOWS\explorer.exe (1612)";"Trojan horse Generic12.CASA";"Reboot is required to finish the action"
"C:\WINDOWS\instsp2.exe";"Trojan horse Downloader.Generic8.ABWY";"Moved to Virus Vault"
"C:\WINDOWS\system32\cviilz.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\deyagehu.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\dmgivq.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\fulefoze.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\guyohimu.dll";"Trojan horse Generic13.AMVO";"Moved to Virus Vault"
"C:\WINDOWS\system32\huyowoza.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\huyowoza.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\jorukiyi.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\nezogeju.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"c:\windows\system32\refobaju.dll";"Trojan horse Generic13.ARFX";"Moved to Virus Vault"
"c:\windows\system32\refobaju.dll";"Trojan horse Generic13.ARFX";"Moved to Virus Vault"
"C:\WINDOWS\system32\ketedoti.dll";"Trojan horse Downloader.Generic8.ABWN";"Moved to Virus Vault"
"C:\WINDOWS\system32\neletato.dll";"Trojan horse PSW.Agent.ZDA";"Moved to Virus Vault"
"C:\WINDOWS\system32\nezogeju.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\suwumuwo.dll";"Trojan horse Generic13.UWD";"Moved to Virus Vault"
"C:\WINDOWS\system32\winlogon.exe (776)";"Trojan horse Generic12.CASA";"Reboot is required to finish the action"
"C:\WINDOWS\system32\wqnggx.dll";"Trojan horse Generic13.AMVO";"Moved to Virus Vault"
"C:\WINDOWS\system32\zavidegu.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\nudeleze.dll";"Trojan horse Generic13.SKB";"Moved to Virus Vault"
"C:\WINDOWS\system32\pubulasi.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\refobaju.dll";"Trojan horse Generic13.ARFX";"Moved to Virus Vault"
"C:\WINDOWS\system32\sesidasu.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\suwumuwo.dll";"Trojan horse Generic13.UWD";"Moved to Virus Vault"
"C:\WINDOWS\system32\toturobe.dll";"Virus found Win32/Heur";"Moved to Virus Vault"
"C:\WINDOWS\system32\zavidegu.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\velivomo.dll";"Trojan horse Generic13.IPJ";"Moved to Virus Vault"
"C:\WINDOWS\system32\zavidegu.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\wolsmv.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\zavidegu.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\wqnggx.dll";"Trojan horse Generic13.AMVO";"Moved to Virus Vault"
"C:\WINDOWS\system32\xqrzbs.dll";"Trojan horse Generic13.SKB";"Moved to Virus Vault"
"C:\WINDOWS\system32\yekanezu.dll";"Trojan horse Vundo.FR";"Moved to Virus Vault"
"C:\WINDOWS\system32\zavidegu.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\zavidegu.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
"C:\WINDOWS\system32\zavidegu.dll";"Trojan horse Generic12.CASA";"Moved to Virus Vault"
AVG log (warnings):
"HKU\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Run\\tirodehete";"Found registry key with reference to infected file C:\WINDOWS\system32\zavidegu.dll";"Moved to Virus Vault"
"HKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Run\\tirodehete";"Found registry key with reference to infected file C:\WINDOWS\system32\zavidegu.dll";"Moved to Virus Vault"
"HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\tirodehete";"Found registry key with reference to infected file C:\WINDOWS\system32\zavidegu.dll";"Deleted"
"C:\Documents and Settings\Stephen\Local Settings\Temp\Cookies\stephen@doubleclick[1].txt:\doubleclick.net.1d39bd48";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
"HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\tirodehete";"Found registry key with reference to infected file C:\WINDOWS\system32\zavidegu.dll";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Local Settings\Temp\Cookies\stephen@doubleclick[1].txt";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@serving-sys[2].txt:\serving-sys.com.c9034af6";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@serving-sys[2].txt:\serving-sys.com.6a1cf9e8";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\tirodehete";"Found registry key with reference to infected file C:\WINDOWS\system32\zavidegu.dll";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@serving-sys[2].txt:\serving-sys.com.606c3d3b";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@serving-sys[2].txt:\serving-sys.com.4b416ef8";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@serving-sys[2].txt:\serving-sys.com.400f83f";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@serving-sys[2].txt:\serving-sys.com.255d6f2f";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\CPM33fcfd75";"Found registry key with reference to infected file c:\windows\system32\refobaju.dll";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@serving-sys[2].txt";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@revsci[2].txt:\revsci.net.e9dbeb91";"Found Tracking cookie.Revsci";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@revsci[2].txt:\revsci.net.55564293";"Found Tracking cookie.Revsci";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@revsci[2].txt:\revsci.net.44927ec";"Found Tracking cookie.Revsci";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@revsci[2].txt:\revsci.net.2df99d79";"Found Tracking cookie.Revsci";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@revsci[2].txt";"Found Tracking cookie.Revsci";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@pro-market[2].txt:\pro-market.net.bbf67f2d";"Found Tracking cookie.Pro-market";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@pro-market[2].txt:\pro-market.net.266912e2";"Found Tracking cookie.Pro-market";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@pro-market[2].txt";"Found Tracking cookie.Pro-market";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@media.adrevolver[1].txt:\media.adrevolver.com.5fed601d";"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@media.adrevolver[1].txt";"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@doubleclick[1].txt:\doubleclick.net.bf396750";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@doubleclick[1].txt";"Found Tracking cookie.Doubleclick";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@clickbank[1].txt:\clickbank.net.82079eb1";"Found Tracking cookie.Clickbank";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@clickbank[1].txt";"Found Tracking cookie.Clickbank";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@bs.serving-sys[1].txt:\bs.serving-sys.com.5bf1f00f";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@bs.serving-sys[1].txt";"Found Tracking cookie.Serving-sys";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@atdmt[2].txt:\atdmt.com.b3e33b5f";"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@atdmt[2].txt";"Found Tracking cookie.Atdmt";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@adrevolver[2].txt:\adrevolver.com.f6cfcad4";"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@adrevolver[2].txt:\adrevolver.com.9b9d670a";"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@adrevolver[2].txt";"Found Tracking cookie.Adrevolver";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@ad.yieldmanager[2].txt:\ad.yieldmanager.com.ff92306";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@ad.yieldmanager[2].txt:\ad.yieldmanager.com.b68f2b7b";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@ad.yieldmanager[2].txt:\ad.yieldmanager.com.8a47878";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@ad.yieldmanager[2].txt:\ad.yieldmanager.com.830b6f08";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@ad.yieldmanager[2].txt:\ad.yieldmanager.com.557bf2b0";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@ad.yieldmanager[2].txt:\ad.yieldmanager.com.539b0606";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"
"C:\Documents and Settings\Stephen\Cookies\stephen@ad.yieldmanager[2].txt";"Found Tracking cookie.Yieldmanager";"Moved to Virus Vault"