Hi there,
As this post's subject says it all, I can not access any of microsoft.com or avg.com or trendmicro or any anti-virus or any-spyware site. It started since Saturday when my AVG automatic update failed.
Also, when I needed, I tried to open one my hidden data file (which contains my personal data), I could not enable show hidden files/folder option in "Folder Option". I googled it and found a solution where I changed few registry key values for explorer..
Over the past two/three weeks, I did notice strange behavior of explorer.exe. At times, it would stop responding for no apparent reason. Only option left after that was to reboot the system or kill that process (not the explorer.exe process from process list but any explorer/folder window open from Application list tab of task manager) from task manager.
My AVG update were normal until last saturday.. Since then I can not access any anti-virus websites. I can visit all other web sites including secured (SSL) sites. This is I am talking about my desktop. Using same internet connection, I can connect to all these sites from my notebook/laptop.
My hosts file is default and has only one entry
127.0.0.1 localhost
Following is my HijackThis log:
---------------------------------------------------------------------------
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 5:32:54 PM, on 9/7/2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal
Running processes:
F:\WINXPPRO\System32\smss.exe
F:\WINXPPRO\system32\winlogon.exe
F:\WINXPPRO\system32\services.exe
F:\WINXPPRO\system32\lsass.exe
F:\WINXPPRO\system32\svchost.exe
F:\WINXPPRO\System32\svchost.exe
F:\WINXPPRO\system32\ZoneLabs\vsmon.exe
F:\WINXPPRO\system32\spoolsv.exe
F:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
F:\PROGRA~1\AVG\AVG8\avgemc.exe
F:\Program Files\AVG\AVG8\avgcsrvx.exe
F:\PROGRA~1\AVG\AVG8\avgrsx.exe
F:\PROGRA~1\AVG\AVG8\avgnsx.exe
F:\WINXPPRO\system32\wscntfy.exe
F:\WINXPPRO\Explorer.EXE
F:\PROGRA~1\AVG\AVG8\avgtray.exe
F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
F:\WINXPPRO\system32\taskmgr.exe
E:\XP_Installed_programs\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - F:\Program Files\AVG\AVG8\avgssie.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - F:\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [AVG8_TRAY] F:\PROGRA~1\AVG\AVG8\avgtray.exe
O4 - HKLM\..\Run: [ZoneAlarm Client] "F:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"
O17 - HKLM\System\CCS\Services\Tcpip\..\{7F449BA4-28FA-4C93-827E-2545B0F733ED}: NameServer = 208.67.222.222,208.67.220.220
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - F:\Program Files\AVG\AVG8\avgpp.dll
O20 - Winlogon Notify: avgrsstarter - F:\WINXPPRO\SYSTEM32\avgrsstx.dll
O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - F:\PROGRA~1\AVG\AVG8\avgemc.exe
O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - F:\PROGRA~1\AVG\AVG8\avgwdsvc.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - F:\WINXPPRO\system32\ZoneLabs\vsmon.exe
--
End of file - 2070 bytes
---------------------------------------------------------------------------
I have installed most of my applications as portable. I prefer portable applications whenever available.
For internet connection, I have DSL and some times I use ISP's DNS setting and other times I use OpenDNS DNS setting.
Looks like for selected domains, access request is re-routed. At times, My Zone alarm does display alert-log for internet access request from explorer.exe which I obviously deny.
I think that is all. Thanks in advance. Looking forward to resolve my access issues..
Cheers!!
Shailesh.
------------------------------------------------
Small update not sure if relevant...
Using NSLookup, when I try to get IP address for microsoft.com, I get correct IP address i.e 207.46.232.182
When I try http://207.46.232.182 in firefox, instantly it gets replaced by http://microsoft.com in address bar and server not fount error..
If I do the same thing for google.com, I get IP address 74.125.67.100 and when I try http://74.125.67.100 in firefox, I get google search page in firefox and address bar STILL shows http://74.125.67.100 It does not get replaced by http://google.com just like it does for microsoft.com
thought it might be relevant..
Cheers!!
Shailesh.