Windows Update and security sites do not open. Secutiry downloads do not start.

D

Dima

Hello!
Windows Update site, www.lavasoft.com and some other security sites do not open.
Windows Update downloads do not start even manually. Google shows adds in the
beginning of search results. Ad-Aware 2008 (definition file 0081.0000) does not
remove the problem. OS is Windows XP SP3. IE 7. Automatically downloaded updates
do not install too.
Office scan 8.710.1002 is not finding any viruses. SFC /scannow does not find
any discrepancies.
Other peer computers in our network do not have the problem.
How to eliminate the problem?
Sincerely,
Dima
 
N

Newell White

Dima said:
Hello!
Windows Update site, www.lavasoft.com and some other security sites do not open.
Windows Update downloads do not start even manually. Google shows adds in the
beginning of search results. Ad-Aware 2008 (definition file 0081.0000) does not
remove the problem. OS is Windows XP SP3. IE 7. Automatically downloaded updates
do not install too.
Office scan 8.710.1002 is not finding any viruses. SFC /scannow does not find
any discrepancies.
Other peer computers in our network do not have the problem.
How to eliminate the problem?
Sincerely,
Dima
If C:\Windows\System32\drivers\etc\hosts and DNS server on this machine
match others which do not suffer, try installing a non-MS browser to download
latest security tools to investigate the problem.
 
D

Dima

Thanks Newell White for your suggestion!
How to know DNS server on my machine?
The Ad-Aware 2008 (definition file 0081.0000) is the latest already.
Regards,
Dima
 
D

Dima

My C:\Windows\System32\drivers\etc\hosts is 239kb and my peer's
C:\Windows\System32\drivers\etc\hosts is 101kb, therefore they are different.
Replacing mine with his file did not change anything.
 
N

Newell White

Dima said:
Thanks Newell White for your suggestion!
How to know DNS server on my machine?
The Ad-Aware 2008 (definition file 0081.0000) is the latest already.
Regards,
Dima

Start... All Programs.. Accessories... Command Prompt

In the window type ipconfig /all

This will give the IP address of one or more DNS servers
 
F

Frank Saunders MS-MVP IE,OE/WM

Dima said:
Hello!
Windows Update site, www.lavasoft.com and some other security sites do not
open. Windows Update downloads do not start even manually. Google shows
adds in the beginning of search results. Ad-Aware 2008 (definition file
0081.0000) does not remove the problem. OS is Windows XP SP3. IE 7.
Automatically downloaded updates do not install too.
Office scan 8.710.1002 is not finding any viruses. SFC /scannow does not
find any discrepancies.
Other peer computers in our network do not have the problem.
How to eliminate the problem?
Sincerely,
Dima

Make sure your firewall is not blocking port 443.
 
P

PA Bear [MS MVP]

Did this problem begin after you installed WinXP SP3?

Was IE7 installed before or after WinXP SP3 was installed?

What anti-virus application or security suite is installed? What
anti-spyware applications (other than Defender)? What third-party firewall
(if any)? Were any of these applications running when you installed WinXP
SP3?
 
D

Dima

Thanks Robear for replying!
This problem began before I installed WinXP SP3.
IE7 was installed before WinXP SP3 was installed.
Office scan 8.710.1002 and Ad-Aware 2008 (definition file 0081.0000) are
installed.
There is no third-party firewall.
Ad-Aware 2008 and Office scan 8.710.1002 were not running when I installed
WinXP SP3.
Regards,
Dima
 
P

PA Bear [MS MVP]

CrystalBall© sez...

Updates are not installed successfully from Windows Update, from Microsoft
Update, or by using Automatic Updates after you repair a Windows XP
installation:
http://support.microsoft.com/kb/943144

NB: Also applies to clean installs, upgrade installs, and Recovery installs.
 
D

Dima

Hello!
localhost [127.0.0.1] blocks windowsupdate.microsoft.com and www.lavasoft.com ,
but not other sites:
C:\Documents and Settings\xxxxxxxxxx>tracert www.mail.ru
ТраÑÑировка маршрута к www.mail.ru [194.67.57.226]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.144.2
2 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 10.254.146.164
3 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.0.12
4 1 ms 1 ms <1 Ð¼Ñ 212.38.108.36
5 1 ms 1 ms 1 ms 10.254.105.100
6 1 ms <1 Ð¼Ñ 1 ms ss-cr02-ge1-2-1500-LUK.msk.stream-internet.net [
195.34.38.49]
7 1 ms 1 ms 1 ms GoldenTelecom-a621.msk-stream-internet.net [195.
34.38.142]
8 1 ms 1 ms 1 ms cat01.Moscow.gldn.net [194.186.158.110]
9 1 ms 1 ms 3 ms mailru-KK12-1-gw.Moscow.gldn.net [195.239.8.10]

10 1 ms 1 ms 1 ms 194.67.57.226
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert www.lavasoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert windowsupdate.microsoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
How to recover from this?
Best regards,
Dima
 
D

Dima

Hello!
Google shows correct search results at first, but then in a second the page
replaces the search results with ads.
Regards,
Dima
 
F

Frank Saunders MS-MVP IE,OE/WM

Dima said:
Hello!
localhost [127.0.0.1] blocks windowsupdate.microsoft.com and
www.lavasoft.com , but not other sites:
C:\Documents and Settings\xxxxxxxxxx>tracert www.mail.ru
ТраÑÑировка маршрута к www.mail.ru [194.67.57.226]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.144.2
2 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 10.254.146.164
3 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.0.12
4 1 ms 1 ms <1 Ð¼Ñ 212.38.108.36
5 1 ms 1 ms 1 ms 10.254.105.100
6 1 ms <1 Ð¼Ñ 1 ms
ss-cr02-ge1-2-1500-LUK.msk.stream-internet.net [
195.34.38.49]
7 1 ms 1 ms 1 ms GoldenTelecom-a621.msk-stream-internet.net
[195.
34.38.142]
8 1 ms 1 ms 1 ms cat01.Moscow.gldn.net [194.186.158.110]
9 1 ms 1 ms 3 ms mailru-KK12-1-gw.Moscow.gldn.net
[195.239.8.10]

10 1 ms 1 ms 1 ms 194.67.57.226
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert www.lavasoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert windowsupdate.microsoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
How to recover from this?


Look on C:\Windows\System32\drivers\etc and rename Hosts (no extension) to
OldHosts
 
P

PA Bear [MS MVP]

As Frank suggested, open Windows Explorer to C:\Windows\System32\drivers\etc
<=this folder | Right-click on the file HOSTS (not LMHOSTS; no extension) |
Rename it to OLDHOSTS | Reboot.

If the behavior persists, you've most likely got a hijackware infection. (I
suspect you may have already done a Repair Install because of this
infection; If so, only a format & reinstall would have fixed it.)

Unexplained computer behavior may be caused by deceptive software
http://support.microsoft.com/kb/827315

Run a /thorough/ check for hijackware, including posting your hijackthis log
to an appropriate forum.

Checking for/Help with Hijackware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_Removal_and_Prevention:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine2.blogspot.com/
http://www.elephantboycomputers.com/page2.html#Removing_Malware

When all else fails, HijackThis v2.0.2
(http://aumha.org/downloads/hijackthis.exe) is the preferred tool to use.
It will help you to both identify and remove any hijackware/spyware with
assistance from an expert. **Post your log to
http://forums.spybot.info/forumdisplay.php?f=22,
http://castlecops.com/forum67.html,
http://forums.subratam.org/index.php?showforum=7,
http://aumha.net/viewforum.php?f=30, or other appropriate forums for review
by an expert in such matters, not here.**

If the procedures look too complex - and there is no shame in admitting this
isn't your cup of tea - take the machine to a local, reputable and
independent (i.e., not BigBoxStoreUSA) computer repair shop.
--
~Robear Dyer (PA Bear)
MS MVP-IE, Mail, Security, Windows Desktop Experience - since 2002
AumHa VSOP & Admin http://aumha.net
DTS-L http://dts-l.net/
 
D

Dima

Thanks Frank for suggesting!
I renamed Hosts a second time today. This have not helped again.
Regards,
Dima
Frank Saunders MS-MVP IE said:
Dima said:
Hello!
localhost [127.0.0.1] blocks windowsupdate.microsoft.com and www.lavasoft.com
, but not other sites:
C:\Documents and Settings\xxxxxxxxxx>tracert www.mail.ru
ТраÑÑировка маршрута к www.mail.ru [194.67.57.226]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.144.2
2 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 10.254.146.164
3 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.0.12
4 1 ms 1 ms <1 Ð¼Ñ 212.38.108.36
5 1 ms 1 ms 1 ms 10.254.105.100
6 1 ms <1 Ð¼Ñ 1 ms ss-cr02-ge1-2-1500-LUK.msk.stream-internet.net
[
195.34.38.49]
7 1 ms 1 ms 1 ms GoldenTelecom-a621.msk-stream-internet.net
[195.
34.38.142]
8 1 ms 1 ms 1 ms cat01.Moscow.gldn.net [194.186.158.110]
9 1 ms 1 ms 3 ms mailru-KK12-1-gw.Moscow.gldn.net
[195.239.8.10]

10 1 ms 1 ms 1 ms 194.67.57.226
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert www.lavasoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert windowsupdate.microsoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
How to recover from this?


Look on C:\Windows\System32\drivers\etc and rename Hosts (no extension) to
OldHosts
 
D

Dima

Thanks Frank for suggesting!
I renamed Hosts a second time today. This have not helped again.
Regards,
Dima
Frank Saunders MS-MVP IE said:
Dima said:
Hello!
localhost [127.0.0.1] blocks windowsupdate.microsoft.com and www.lavasoft.com
, but not other sites:
C:\Documents and Settings\xxxxxxxxxx>tracert www.mail.ru
ТраÑÑировка маршрута к www.mail.ru [194.67.57.226]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.144.2
2 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 10.254.146.164
3 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.0.12
4 1 ms 1 ms <1 Ð¼Ñ 212.38.108.36
5 1 ms 1 ms 1 ms 10.254.105.100
6 1 ms <1 Ð¼Ñ 1 ms ss-cr02-ge1-2-1500-LUK.msk.stream-internet.net
[
195.34.38.49]
7 1 ms 1 ms 1 ms GoldenTelecom-a621.msk-stream-internet.net
[195.
34.38.142]
8 1 ms 1 ms 1 ms cat01.Moscow.gldn.net [194.186.158.110]
9 1 ms 1 ms 3 ms mailru-KK12-1-gw.Moscow.gldn.net
[195.239.8.10]

10 1 ms 1 ms 1 ms 194.67.57.226
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert www.lavasoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert windowsupdate.microsoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
How to recover from this?


Look on C:\Windows\System32\drivers\etc and rename Hosts (no extension) to
OldHosts
 
D

Dima

Thanks Frank for suggesting!
I renamed Hosts a second time today. This have not helped again.
Regards,
Dima
Frank Saunders MS-MVP IE said:
Dima said:
Hello!
localhost [127.0.0.1] blocks windowsupdate.microsoft.com and www.lavasoft.com
, but not other sites:
C:\Documents and Settings\xxxxxxxxxx>tracert www.mail.ru
ТраÑÑировка маршрута к www.mail.ru [194.67.57.226]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.144.2
2 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 10.254.146.164
3 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.0.12
4 1 ms 1 ms <1 Ð¼Ñ 212.38.108.36
5 1 ms 1 ms 1 ms 10.254.105.100
6 1 ms <1 Ð¼Ñ 1 ms ss-cr02-ge1-2-1500-LUK.msk.stream-internet.net
[
195.34.38.49]
7 1 ms 1 ms 1 ms GoldenTelecom-a621.msk-stream-internet.net
[195.
34.38.142]
8 1 ms 1 ms 1 ms cat01.Moscow.gldn.net [194.186.158.110]
9 1 ms 1 ms 3 ms mailru-KK12-1-gw.Moscow.gldn.net
[195.239.8.10]

10 1 ms 1 ms 1 ms 194.67.57.226
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert www.lavasoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert windowsupdate.microsoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
How to recover from this?


Look on C:\Windows\System32\drivers\etc and rename Hosts (no extension) to
OldHosts
 
D

Dima

Thanks Frank for suggesting!
I renamed Hosts a second time today. This have not helped again.
Regards,
Dima
Frank Saunders MS-MVP IE said:
Dima said:
Hello!
localhost [127.0.0.1] blocks windowsupdate.microsoft.com and www.lavasoft.com
, but not other sites:
C:\Documents and Settings\xxxxxxxxxx>tracert www.mail.ru
ТраÑÑировка маршрута к www.mail.ru [194.67.57.226]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.144.2
2 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 10.254.146.164
3 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ 172.31.0.12
4 1 ms 1 ms <1 Ð¼Ñ 212.38.108.36
5 1 ms 1 ms 1 ms 10.254.105.100
6 1 ms <1 Ð¼Ñ 1 ms ss-cr02-ge1-2-1500-LUK.msk.stream-internet.net
[
195.34.38.49]
7 1 ms 1 ms 1 ms GoldenTelecom-a621.msk-stream-internet.net
[195.
34.38.142]
8 1 ms 1 ms 1 ms cat01.Moscow.gldn.net [194.186.158.110]
9 1 ms 1 ms 3 ms mailru-KK12-1-gw.Moscow.gldn.net
[195.239.8.10]

10 1 ms 1 ms 1 ms 194.67.57.226
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert www.lavasoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
C:\Documents and Settings\xxxxxxxxxx>tracert windowsupdate.microsoft.com
ТраÑÑировка маршрута к localhost [127.0.0.1]
Ñ Ð¼Ð°ÐºÑимальным чиÑлом прыжков 30:
1 <1 Ð¼Ñ <1 Ð¼Ñ <1 Ð¼Ñ localhost [127.0.0.1]
ТраÑÑировка завершена.
How to recover from this?


Look on C:\Windows\System32\drivers\etc and rename Hosts (no extension) to
OldHosts
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top