1. Computer problem? Tech Support Guy is completely free -- paid for by advertisers and donations. Click here to join today! If you're new to Tech Support Guy, we highly recommend that you visit our Guide for New Members.

Win32/HostBlock

Discussion in 'Virus & Other Malware Removal' started by pottre11, Apr 27, 2010.

Thread Status:
Not open for further replies.
  1. pottre11

    pottre11 Thread Starter

    Joined:
    Apr 27, 2010
    Messages:
    2
    Hi guys,

    I've seen a few with this issue but each fix seems to be very bespoke to each specific user/computer so I thought i'd give a post a try!

    The machine is Windows Server 2003 with a Citrix overlay, people are logging in and are able to use it, however we are getting live reports of Hostblock being on the system, I am also unable to modify/view the host file.

    Unfortunately AVG/MBAM can't find or remove it.

    Please find below the logs from HiJackThis, ComboFix isn't compatible with Win2k3 server apparently.

    Code:
    Logfile of Trend Micro HijackThis v2.0.4
    Scan saved at 10:41:28, on 27/04/2010
    Platform: Windows 2003 SP2 (WinNT 5.02.3790)
    MSIE: Internet Explorer v7.00 (7.00.6000.16735)
    Boot mode: Normal
    Running processes:
    C:\Documents and Settings\administrator.HWCC\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\spoolsv.exe
    c:\altiris\aclient\aclient.exe
    C:\WINDOWS\system32\cisvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
    C:\Program Files\Citrix\System32\Citrix\Ima\IMAAdvanceSrv.exe
    C:\Program Files\CA\eTrustITM\InoRT.exe
    C:\Program Files\CA\eTrustITM\InoTask.exe
    C:\Program Files\LogMeIn\x86\RaMaint.exe
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\System32\snmp.exe
    C:\Program Files\UPHClean\uphclean.exe
    C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe
    C:\Program Files\Citrix\system32\cdmsvc.exe
    C:\WINDOWS\System32\svchost.exe
    C:\Program Files\Citrix\ICA Client\ssonsvr.exe
    C:\WINDOWS\Explorer.EXE
    c:\altiris\aclient\AClntUsr.EXE
    C:\Program Files\CA\eTrustITM\realmon.exe
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\avs\bin\avscc.exe
    Y:\Entrprse\FAXSRV\FAXCLNT.EXE
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\System32\svchost.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
    C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\HPBOID.EXE
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\dllhost.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\cidaemon.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\Program Files\Citrix\ICA Client\SSONSVR.EXE
    C:\Program Files\Citrix\System32\wfshell.exe
    C:\WINDOWS\Explorer.EXE
    c:\altiris\aclient\AClntUsr.EXE
    C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe
    C:\Program Files\CA\eTrustITM\realmon.exe
    C:\Program Files\LogMeIn\x86\LogMeInSystray.exe
    C:\Program Files\LogMeIn\x86\LMIGuardian.exe
    C:\Documents and Settings\All Users\Application Data\8b2b1c7\CU8b2b.exe
    C:\Program Files\avs\bin\avscc.exe
    Y:\Entrprse\FAXSRV\FAXCLNT.EXE
    C:\Program Files\LogMeIn\x86\LogMeIn.exe
    C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
    c:\program files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\scrnsave.scr
    c:\program files\internet explorer\iexplore.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\Program Files\Trend Micro\HiJackThis\HiJackThis.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    C:\WINDOWS\system32\cmd.exe
    C:\WINDOWS\system32\ping.exe
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://shdoclc.dll/softAdmin.htm
    R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://www.hwchamber.co.uk[/URL]
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = [URL]http://go.microsoft.com/fwlink/?LinkId=54896[/URL]
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = [URL]http://go.microsoft.com/fwlink/?LinkId=69157[/URL]
    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\system32\blank.htm
    R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [URL]http://go.microsoft.com/fwlink/?LinkId=74005[/URL]
    F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,
    O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O4 - HKLM\..\Run: [AClntUsr] c:\altiris\aclient\AClntUsr.EXE
    O4 - HKLM\..\Run: [Realtime Monitor] "C:\Program Files\CA\eTrustITM\realmon.exe" -s
    O4 - HKLM\..\Run: [IcaBar] "C:\Program Files\Citrix\system32\icabar.exe" /adminonly
    O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
    O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_09\bin\jusched.exe"
    O4 - HKLM\..\Run: [LogMeIn GUI] "C:\Program Files\LogMeIn\x86\LogMeInSystray.exe"
    O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-19\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'LOCAL SERVICE')
    O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-20\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'NETWORK SERVICE')
    O4 - HKUS\S-1-5-21-2235087172-104979336-3292247462-1008\..\RunOnce: [tscuninstall] %systemroot%\system32\tscupgrd.exe (User 'ctx_cpsvcuser')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1129\..\Run: []  (User 'd.hardman')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1129\..\Run: [winnt4] P:\winnt_\winnt4.exe (User 'd.hardman')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1129\..\Run: [winnt5] P:\winnt_\winnt5.exe (User 'd.hardman')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1129\..\Run: [winnt6] P:\winnt_\winnt6.exe (User 'd.hardman')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1139\..\Run: []  (User 'g.woodman')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1142\..\Run: []  (User 'h.king')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1143\..\Run: []  (User 'J.cook')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1147\..\Run: []  (User 'k.ward')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1156\..\Run: []  (User 'n.griffiths')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1157\..\Run: []  (User 'p.thompson')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1158\..\Run: []  (User 'p.turvey')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1213\..\Run: []  (User 'c.armistead')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1258\..\Run: []  (User 'k.betts')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1288\..\Run: []  (User 'l.sanders')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1322\..\Run: []  (User 'A.Imray')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-1339\..\Run: []  (User 'r.smith')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-2174\..\Run: []  (User 'L.Lessimore')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-2177\..\Run: []  (User 'c.braun')
    O4 - HKUS\S-1-5-21-76959124-2956176113-1521454009-2178\..\Run: []  (User 't.grabovcic')
    O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'SYSTEM')
    O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe (User 'Default user')
    O4 - S-1-5-21-76959124-2956176113-1521454009-1157 Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe (User 'p.thompson')
    O4 - S-1-5-21-76959124-2956176113-1521454009-1157 User Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe (User 'p.thompson')
    O4 - S-1-5-21-76959124-2956176113-1521454009-1213 Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe (User 'c.armistead')
    O4 - S-1-5-21-76959124-2956176113-1521454009-1288 Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe (User 'l.sanders')
    O4 - S-1-5-18 Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe (User 'SYSTEM')
    O4 - .DEFAULT Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe (User 'Default user')
    O4 - .DEFAULT User Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe (User 'Default user')
    O4 - Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe
    O4 - Global Startup: client.lnk = ?
    O4 - Global Startup: Exchequer Fax Client.lnk = ?
    O4 - Global Startup: PhoneManager.lnk = C:\Program Files\Avaya\IP Office\Phone Manager\PhoneManager.exe
    O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_09\bin\ssv.dll
    O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL
    O10 - Broken Internet access because of LSP provider 'c:\documents and settings\administrator.hwcc\windows\system32\mswsock.dll' missing
    O15 - ESC Trusted Zone: [URL]http://runonce.msn.com[/URL]
    O16 - DPF: {01A88BB1-1174-41EC-ACCB-963509EAE56B} (SysProWmi Class) - [URL]http://support.euro.dell.com/systemprofiler/SysPro.CAB[/URL]
    O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - [URL]http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab[/URL]
    O16 - DPF: {493ACF15-5CD9-4474-82A6-91670C3DD66E} (LinkedIn ContactFinderControl) - [URL]http://www.linkedin.com/cab/LinkedInContactFinderControl.cab[/URL]
    O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [URL]http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1209460808109[/URL]
    O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [URL]http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1224496644570[/URL]
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - [URL]https://iris.webex.com/client/T25L/support/ieatgpc.cab[/URL]
    O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - [URL]http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab[/URL]
    O16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - [URL]https://secure.logmein.com/activex/ractrl.cab?lmi=100[/URL]
    O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = hwcc.local
    O17 - HKLM\Software\..\Telephony: DomainName = hwcc.local
    O17 - HKLM\System\CCS\Services\Tcpip\..\{0C091C15-1273-49DA-9576-423FCB898FE3}: NameServer = 10.30.1.1,10.30.1.2
    O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = hwcc.local
    O17 - HKLM\System\CS1\Services\Tcpip\..\{0C091C15-1273-49DA-9576-423FCB898FE3}: NameServer = 10.30.1.1,10.30.1.2
    O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = hwcc.local
    O17 - HKLM\System\CS2\Services\Tcpip\..\{0C091C15-1273-49DA-9576-423FCB898FE3}: NameServer = 10.30.1.1,10.30.1.2
    O20 - AppInit_DLLs:  mfaphook.dll
    O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\Documents and Settings\administrator.HWCC\WINDOWS\system32\browseui.dll (file missing)
    O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Documents and Settings\administrator.HWCC\WINDOWS\system32\browseui.dll (file missing)
    O23 - Service: Altiris Client Service (AClient) - Altiris, Inc. - c:\altiris\aclient\aclient.exe
    O23 - Service: Avamar Client Agent - Unknown owner - C:\Program Files\avs\bin\avagent.exe (file missing)
    O23 - Service: Backup Exec Remote Agent for Windows Systems (BackupExecAgentAccelerator) - Symantec Corporation - C:\Program Files\Symantec\Backup Exec\RAWS\beremote.exe
    O23 - Service: Citrix Diagnostic Facility COM Server (CdfSvc) - Citrix Systems, Inc. - C:\Program Files\Common Files\Citrix\System32\CdfSvc.exe
    O23 - Service: Citrix Client Network (CdmService) - Citrix Systems, Inc. - C:\Program Files\Citrix\system32\cdmsvc.exe
    O23 - Service: Citrix Encryption Service - Citrix Systems, Inc. - C:\Program Files\Citrix\system32\encsvc.exe
    O23 - Service: Citrix SMA Service - Citrix Systems Inc. - C:\Program Files\Citrix\Sma\SmaService.exe
    O23 - Service: Citrix Virtual Memory Optimization - Citrix Systems, Inc. - C:\Program Files\Citrix\Server Resource Management\Memory Optimization Management\Program\CtxSFOSvc.exe
    O23 - Service: Citrix Health Monitoring and Recovery (CitrixHealthMon) - Citrix Systems, Inc - C:\Program Files\Citrix\HealthMon\HCAService.exe
    O23 - Service: Citrix XTE Server (CitrixXTEServer) - Citrix Systems, Inc. - C:\Program Files\Citrix\XTE\bin\XTE.exe
    O23 - Service: Citrix Print Manager Service (cpsvc) - Citrix Systems, Inc. - C:\Program Files\Citrix\system32\CpSvc.exe
    O23 - Service: Citrix ActiveSync Service (CtxActiveSync) - Citrix Systems, Inc. - C:\Program Files\Citrix\System32\CtxActiveSync.exe
    O23 - Service: Citrix CPU Utilization Mgmt/CPU Rebalancer (CTXCPUBal) - Aurema Pty Limited - C:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpubal.exe
    O23 - Service: Citrix CPU Utilization Mgmt/Resource Mgmt (ctxcpuSched) - Aurema Pty Limited - C:\Program Files\Citrix\Server Resource Management\CPU Utilization Management\bin\ctxcpusched.exe
    O23 - Service: Citrix XML Service (CtxHttp) - Citrix Systems, Inc. - C:\Program Files\Citrix\System32\ctxxmlss.exe
    O23 - Service: HP Port Resolver - Hewlett-Packard Company - C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\HPBPRO.EXE
    O23 - Service: HP Status Server - Hewlett-Packard Company - C:\WINDOWS\system32\spool\DRIVERS\W32X86\3\HPBOID.EXE
    O23 - Service: iTechnology iGateway 4.2 (iGateway) - CA, Inc. - C:\Program Files\CA\SharedComponents\iTechnology\igateway.exe
    O23 - Service: Citrix Services Manager (IMAAdvanceSrv) - Citrix Systems, Inc. - C:\Program Files\Citrix\System32\Citrix\Ima\IMAAdvanceSrv.exe
    O23 - Service: Citrix Independent Management Architecture (IMAService) - Citrix Systems, Inc. - C:\Program Files\Citrix\System32\Citrix\Ima\ImaSrv.exe
    O23 - Service: eTrust ITM RPC Service (InoRPC) - Unknown owner - C:\Program Files\CA\eTrustITM\InoRpc.exe (file missing)
    O23 - Service: eTrust Antivirus Realtime Service (InoRT) - CA - C:\Program Files\CA\eTrustITM\InoRT.exe
    O23 - Service: eTrust ITM Job Service (InoTask) - CA - C:\Program Files\CA\eTrustITM\InoTask.exe
    O23 - Service: LogMeIn Maintenance Service (LMIMaint) - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\RaMaint.exe
    O23 - Service: LogMeIn - LogMeIn, Inc. - C:\Program Files\LogMeIn\x86\LogMeIn.exe
    O23 - Service: Citrix MFCOM Service (MFCom) - Citrix Systems, Inc. - C:\Program Files\Citrix\System32\mfcom.exe
    --
    End of file - 19429 bytes
    
    The virus/real time alert came from eTrust in C:\Windows\System32\Drivers\Etc\.....

    Cure failed, the file was simply renamed, hence the multiple host files named Host_New.ext

    Thanks in advance,

    Chris
     
  2. pottre11

    pottre11 Thread Starter

    Joined:
    Apr 27, 2010
    Messages:
    2
    Update : Safe mode still won't allow edits/changes to the host file.
     
As Seen On
As Seen On...

Welcome to Tech Support Guy!

Are you looking for the solution to your computer problem? Join our site today to ask your question. This site is completely free -- paid for by advertisers and donations.

If you're not already familiar with forums, watch our Welcome Guide to get started.

Join over 733,556 other people just like you!

Loading...
Similar Threads - Win32 HostBlock
  1. Olddog20
    Replies:
    0
    Views:
    366
  2. Sumfeg
    Replies:
    0
    Views:
    1,224
Thread Status:
Not open for further replies.

Short URL to this thread: https://techguy.org/919528

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice