blocked access to malicious site

Avast pops up an On-Access Scanner message every 5 minutes or so and reports:

“Network Shield: blocked access to malicious site

I can’t detect what’s triggering this event.

That looks like a bad site, are you trying to get the genuine windows update site,or is something taking you to that site


Please could you modify your post to remove the active hyperlink (change www to wXw) to prevent others potentially bcoming infected.

How did you get to this site?

When I click on Microsoft update (through the start menu) I am taken to this site:

This is the official Microsoft update site.


Something is trying to take me there all on it’s own. I’ve run a full avast scan, ccleaner, spyware dr, malwaresbytes, and superantispyware. I get reoccurring infections after reboot and my system (XP sp2) hangs on “Windows is shutting down” screen if windows automatic update is turned on.

spyware dr keeps finding…
Threat Name - Application.Windows_File_Protection_Disabled
Type - Modified Registry Value
Risk Level - Info & PUAs
Infection - HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, SFCDisable

ccleaner shows me wuauclt.exe gets added to my startup file after every reboot.

Problem started occuring a few days ago after a AntiVirus Pro attack.


Post a HijackThis log, run the program, choose,scan and save a logfile. Copy/paste the txt log

Also post your last Malwarebytes and superantispyware logs please

I have to post the logfiles in two posts because the HJT file was a little big.

(begin part1)

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 4:01:00 AM, on 7/13/2009
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Malwarebytes’ Anti-Malware 1.38
Database version: 2415
Windows 5.1.2600 Service Pack 2

7/13/2009 4:08:15 AM
mbam-log-2009-07-13 (04-07-58).txt

Scan type: Quick Scan
Objects scanned: 97294
Time elapsed: 5 minute(s), 57 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.Userinit) → Bad: (C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wuauclt.exe,) Good: (Userinit.exe) → No action taken.

Folders Infected:
(No malicious items detected)

Files Infected:
c:\documents and settings\Owner\Start Menu\Programs\Startup\wuauclt.exe.lnk (Trojan.Agent) → No action taken.

SUPERAntiSpyware Scan Log

Generated 07/13/2009 at 04:27 AM

Application Version : 4.26.1006

Core Rules Database Version : 3989
Trace Rules Database Version: 1929

Scan type : Quick Scan
Total Scan Time : 00:16:28

Memory items scanned : 558
Memory threats detected : 0
Registry items scanned : 536
Registry threats detected : 0
File items scanned : 14815
File threats detected : 2

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@chitika[1].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.techguy[2].txt

While I have a look at the HJT log,I notice on the MBAM log it says ’ no action take ’ Did you not fix those items ?

Not Yet. I was waiting for your advice. I fixed them in the past but these are the ones that regenerate on reboot.

Well you have two entries in HJT they are

F2 - REG:system.ini: UserInit=C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\wuauclt.exe,

O4 - Startup: wuauclt.exe.lnk = C:\WINDOWS\system32\wuauclt.exe

I think the first one is bad, Im not sure about the other,

First and most important, you must be running HJT from its own folder, I see yours is on E drive.Your not running it from a pen drive are you. If you fix any entries,they can be reversed if HJT is running from its own folder.

I would fix the first entry, using HJT, then fix it with MBAM then reboot and do fresh scans, and post back with new logs.

Windows Service Pack 3 has been available for a year and contains several Critical Security updates plus performance improvements you need to start Internet Explorer then go to Tools then Windows Update and download all of the available updates.

Also you should enable Automatic Updates or at least be notified that Updates are available.

Go to Control Panel then Automatic Updates then select Automatic (recommended) or at least Notify me but don’t automatically download or install them.

Adobe Acrobat 7.0 is down level and has security exposures.

Go to Secunia Online Software Inspector then run it to see what other applications are vulnerable:

After a bit of googling, its my opinion that both HJT entries are bad

HJT is installed on a partitioned internal HD (e:) c drive/partition was getting full (trying to make run to install XP SP3 - I tried upgrading yesterday but install failed. Possible problem was not enough room on c drive 1.47G free).

Should I reinstall HJT on the c drive? Since I ran a through ccleaner I now have 4.6G free.

I’ll run the the fixes you recommended and post the results.

Hi TheyGotMe,

wuauclt.exe - Here is the scoop on Cult Trojan as it pertains to computer network security. The big question: what is wuauclt.exe and is it spyware, a trojan and if so, how do I get rid of Cult Trojan?
wuauclt.exe (Cult Trojan) - Details
Many viruses will appear in the task list with the process name ‘wuauclt.exe’. One such example is the CultB trojan. You should treat this process with caution as it may be a virus.
wuauclt.exe is considered to be a security risk, not only because antivirus programs flag Cult Trojan as a virus, but also because a number of users have complained about its performance.
Cult Trojan is likely a virus and as such, presents a serious vulnerability which should be fixed immediately! Delaying the removal of wuauclt.exe may cause serious harm to your system and will likely cause a number of problems, such as slow performance, loss of data or leaking private information to websites.
To establish that the executable you have is a virus or a legit file please upload the file to for analysis and report back here.

Many spyware / malware programs use filenames of usual, non-malware programs. If here I have included information about wuauclt.exe that is inaccurate, we would greatly appreciate your help by updating the avast process information database and they will do their best to correct it,


polonus provided the missing link. The wuauclt.exe was the problem. I replaced it with a clean copy and after a few rounds of using HJT, MWB, spyware dr and file assassin I finally have a stable copy of wuauclt.exe running. There was something in the system that kept reinfecting the file.

I can now run all programs listed in this topic and all report zero infections and my system is running as smooth as expected.


btw - I did remove acrobat 7 and reinstalled HJT on the c drive. And I can also turn auto-update back on without a problem. I believe auto-update uses the wuaucklt.exe file.

I’m going to upgrade to XP sp3 tomorrow for added protection. Thanks again.