Browser redirects and AVG not updating - regedit and cmd issues

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bartlett, Apr 18, 2009.

  1. Bartlett

    Bartlett Private E-2

    I am working on my friend's computer. He had the prepurchase version of antivirus2008 a while back and it was deleted manually by myself. All of the tools I have run have found traces of AV2008 and removed them which has not fixed the problem. As best he can recall, the new issue has been happening for about a month, it is as follows:

    Whenever a search is done in google or yahoo, most reliably for spyware removal software, the browser gets redirected. Clicking the back button will bring us back to the page we clicked to. This occurs in both IE7 and FF3. He also had Mcafee installed and it stopped working properly. I uninstalled that and installed AVG, which also will not update. I can visit the avg site with no issue, but the updater constantly fails. As a side note, FF crashes when visiting a site like myspace, but IE does not. I uninstalled, rebooted, then reinstalled a fresh download of FF to no avail.

    When I tried to get a dos prompt (run>cmd and using the program in accessories) the explorer resets. The same thing happens when trying to run regedit. Both conditions exist in safe mode as administrator as well. Before finding this site, I ran adaware, spybot S&D, CCleaner, and did a scan with AVG. Spybot removed 94 wildtangent items and some remnant of AV2008. after the reboot from doing this, explorer stopped booting up. Explorer magically starting opening at boot time after running the diagnostics from your site. The provided tools brought me back to square one and I am toast. combofix could not be run because the forums that it is hosted on will not load in FF or IE. IE opens the page and the progress bar says done but nothing happens. This happens no matter what page of their forum I try to visit. FF tries to download but then says the source is unavailable. I am reluctant to put the file on my thumb drive and then use it in his computer as I don't have any issues of my own and I like it that way.

    Anyway.. here are the logs that I was able to make. Thanks in advance!
     

    Attached Files:

  2. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Welcome to MajorGeeks!

    Can you burn ComboFix to a CD and transfer it to the problem pc?
    I am currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Our queue is working the oldest threads first.

    Thanks for your patience.
    dr.m
     
  3. Bartlett

    Bartlett Private E-2

    There's an idea! I will burn that to a disk and get it to my buddy as soon as possible. I should see him at work tomorrow. Is there an issue with the order that the scans are done? I seem to recall seeing some things about that in other threads while I was trying to answer the issues myself. If you require a full rescan, It will take me a bit to get over there and run them all. I should be able to walk him through combofix on the phone after I give him the cd though. I will get you that log as soon as possible!

    No problem on the wait, I am very grateful that you guys take your time as pros to serve the unwashed masses like this. Let me know if you need anything else, log should be here by Thursday night.

    Thanks
     
  4. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're Welcome!

    If you could have ComboFix ran and then re-run MGTools.zip ... and attach those two logs --- I would have a better idea of what remains to be done.

    Thanks!
    dr.m
     
  5. Bartlett

    Bartlett Private E-2

    I got the disc to my buddy and he attempted to run combofix. The first attempt just caused the computer to hang, on the second attempt after a reboot, he got a dialog box saying that the files could not be written because combofix was only made for 98/2000/me/xp and he has the wrong operating system. He is running windows xp. Not sure what could be going on. The file that I burned to the disc came right from bleepingcomputer.
     
  6. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :confused

    Very puzzling! While I check with my collegues - please verify that you Finalized the CD...and your friend did save combofix.exe to his desktop before running it.

    dr.m
     
  7. Bartlett

    Bartlett Private E-2

    I created the disc on vista and it prompted the finalizing when I attempted to eject the disc, I complied with the finalizing (I think it was more just a notice, not a prompt) after 10-15 seconds it ejected, saying finalization was complete. When I was on the phone walking him through it, I instructed him to drag combofix.exe to the desktop and then close the window from the CD. I then had him remove the disc from the computer (verifies he didn't make a shortcut to the disc) and the first attempt hung with no explanation, attempt two after reboot (as mentioned) said invalid OS. I can't truly verify this info is good since we were on the phone, but as far as I can tell, that is an accurate representation of what happened.

    Lemme know if there is anything more I can do to help you help me while ya'll research it!

    Thanks
     
  8. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    :major

    Hello, Bartlett


    The below fixes are specific to your problem and should only be used for issue(s) on this machine. Also, please do not install any other software while we are still working with you unless instructed. Once we have given you the all clean and final instructions you will be free to install what you want.

    I strongly recommend that you clean up your Desktop immediately leaving only links. Do not store downloads, exe files, iso files....etc on your Desktop. First it is not a safe place to keep them (i.e., you may loose them due to malware, and a cluttered Desktop is an easy hiding place for malware), and last but not least it can have an effect on your PCs performance.

    An observation - Ad-Aware is becoming useless in detecting and removing malware...SAS & MBAM are far better tools.

    You're in need of an increase in your RAM:
    Total Physical Memory --------512.00 MB
    Available Physical Memory ---186.80 MB


    Step 1:
    Please look in Add/Remove Programs for the following and uninstall if found. If you get any errors just make a note and proceed
    Step 2:
    Run this Disable/Remove Windows Messenger to remove Windows Messenger. Do not confuse Windows Messenger with MSN Messenger because they are not the same. Windows Messenger is a frequent cause of popups.


    Step 3:
    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix, exit HJT.

    Step 4:
    Now download The Avenger by Swandog469, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Step 5:
    Run Ccleaner

    Step 6:
    Now install the latest Sun Java Runtime Environment


    Step 7:
    Re-boot the pc and then run ComboFix.

    Step 8:
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, use right click and select Run As Administrator).

    Then attach the below logs to your next reply:
    • C:\MGlogs.zip
    • C:\combofix.txt
    • C:\avenger.txt

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     
  9. Bartlett

    Bartlett Private E-2

    Awesome! I will let him know and get over there as soon as I can to run all this stuff. I am also glad to have a post from a pro telling him to buy more RAM! :-D Thanks again for all your time!
     
  10. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're Welcome!

    By the way -- we normally recommend 1gb of RAM for properly running XP these days.

    dr.m
     
  11. Bartlett

    Bartlett Private E-2

    Sorry so late for the reply. Things got crazy at work for both of us, but i was finally able to get here and run the instructions you gave. It turns out that AVG might have been messing with combofix. It did the same thing it was doing when he tried to run it, but when I ran it in safe mode, it came up and told me to disable avg. I rebooted into normal mode and ran it with avg disabled.. worked fine then. cmd and regedit are both able to be opened now. IE and FF3 have stopped the forwarding issue. AVG and windows update are now able to connect and bleepingcomputer.com opens with no issue. I would say that it is a mission accomplished! I do have the logs for you to review. Thanks for all the help! Awesome service.
     

    Attached Files:

  12. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    ;)

    You're welcome, Bartlett.

    First - I have some concerns about the combination of SpySweeper with AVG 8.5.

    Even if your SpySweeper application is only for blocking and removing spyware (and there are some evidence showing it may have been a version including anti-virus - having 2 AV's would be very bad)- there are known conflicts with using it with AVG 8.5. Please review this:

    http://www.avg.com/faq.num-1214?srch=Spy|Sweeper#faq_1214]

    Now for the removal...

    We need to use The Avenger by Swandog469, previously downloaded and on your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Open Ccleaner - select "Cleaner" > "Run Cleaner" <---use this ONLY

    Then attach C:\avenger.txt to your next reply.

    Make sure you tell me if you had any problems running this procedure and give a description of how things are working now!

    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds