スパイウェアの侵入を疑ったらhostsファイルを確認するべし

知り合いでWindowsUpdateが出来なくなったという問い合わせが来た。
スパイウェアの侵入も考えられるのでc:\windows\system32\drivers\etc\hostsを確認したら・・・


# Copyright (c) 1993-1999 Microsoft Corp.
#
# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.
#
# This file contains the mappings of IP addresses to host names. Each
# entry should be kept on an individual line. The IP address should
# be placed in the first column followed by the corresponding host name.
# The IP address and the host name should be separated by at least one
# space.
#
# Additionally, comments (such as these) may be inserted on individual
# lines or following the machine name denoted by a '#' symbol.
#
# For example:
#
# 102.54.94.97 rhino.acme.com # source server
# 38.25.63.10 x.acme.com # x client host

127.0.0.1 localhost
0.0.0.0 avp.ch
0.0.0.0 avp.com
0.0.0.0 avp.ru
0.0.0.0 awaps.net
0.0.0.0 ca.com
0.0.0.0 dispatch.mcafee.com
0.0.0.0 download.mcafee.com
0.0.0.0 download.microsoft.com
0.0.0.0 downloads.microsoft.com
0.0.0.0 engine.awaps.net
0.0.0.0 fastclick.net
0.0.0.0 f-secure.com
0.0.0.0 ftp.f-secure.com
0.0.0.0 ftp.sophos.com
0.0.0.0 go.microsoft.com
0.0.0.0 liveupdate.symantec.com
0.0.0.0 mast.mcafee.com
0.0.0.0 mcafee.com
0.0.0.0 media.fastclick.net
0.0.0.0 msdn.microsoft.com
0.0.0.0 my-etrust.com
0.0.0.0 nai.com
0.0.0.0 networkassociates.com
0.0.0.0 office.microsoft.com
0.0.0.0 phx.corporate-ir.net
0.0.0.0 secure.nai.com
0.0.0.0 securityresponse.symantec.com
0.0.0.0 service1.symantec.com
0.0.0.0 sophos.com
0.0.0.0 spd.atdmt.com
0.0.0.0 support.microsoft.com
0.0.0.0 update.symantec.com
0.0.0.0 updates.symantec.com
0.0.0.0 us.mcafee.com
0.0.0.0 vil.nai.com
0.0.0.0 viruslist.ru
0.0.0.0 windowsupdate.microsoft.com
0.0.0.0 housecall-t.activeupdate.trendmicro.com
0.0.0.0 liveupdate.symantecliveupdate.com