Cannot uninstall AVG on XP PRO laptop

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by BoredOutOfMyMind, Jun 26, 2011.

  1. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    I am working through the Malware Removal Steps to remove a trojan from a friends XP Laptop.

    I cannot get AVG to uninstall as the registry cannot be referenced to continue past and to step 2.

    :-o

    I don't want to turn the beast loose on my network and have already chanced infecting a thumb drive to install the tools. SuperSpyware and Malwarebytes come back clean and AVG found trojans quaranteed and removed at scan.
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Thanks Kestrel13

    I tried that and get a message that the registry cannot be read. Let me fire up and see about cell phone photo of error.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Go ahead and attach the log from AVG so Kes can look at it and then get us the C:\MGLogs.zip. We may need to remove it manually.
     
  5. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Screenprint of error

    Error: Action failed for registry key HKLM\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Windows: Access is denied
     

    Attached Files:

  6. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU


    I run MGTools from the desktop, correct?
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGTools can be run from the desktop, but it would be better to put it directly on the root folder -- C:\MGTools.exe.
     
  8. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    I kept the MGMalware in a folder on the icon cluttered desktop, and remembered directions said to run from desktop. Thanks Tim.

    C:\MGLogs.zip attached.
     

    Attached Files:

  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download The Avenger by Swandog469, and save it to your Desktop.

    * Extract+ avenger.exe from the Zip file and save it to your desktop

    Please use add/remove programs to uninstall:
    Java 2 Runtime Environment, SE v1.4.2_03
    Java(TM) 6 Update 2
    Java(TM) 6 Update 3

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now download and install:
    Java Runtime 6

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
    • C:\Avenger.txt

    Make sure you tell me how things are working now!
     
    Last edited: Jun 26, 2011
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boom, hang on a sec. then hit F5 to refresh as I need to edit that last posts.
     
  11. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU


    Not good- Blue Screen after reboot request by The Avenger... :confused

    Reboot and select Last Known Configuration booted.

    (I am typing this on the Linux box as the Virus Box is offline)
     

    Attached Files:

  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Will it boot up? We didn't remove anything that should have stopped it from booting.
     
  13. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    I still have the AVG icon running in task bar, logs attached.
    Error on Avenger was my mistake in typing script- I ran program again with no errors after seeing what the log contains about script error.
     

    Attached Files:

  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    The log you attached from Avenger shows a script error, so I am assuming you ran it with the correct script the second time as most of what was in it is removed.

    Now we can concentrate on AVG:

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix, exit HJT.

    * Run avenger.exe by double-clicking on it.
    * -Do not change any check box options!!
    * Copy everything in the Quote box below, and paste it into the Input script here: part of the window:

    * Now click the Execute button.
    * Click Yes to the prompt to confirm you want to execute.
    * Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    * Your PC should reboot, if not, reboot it yourself.
    * A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip
    • C:\Avenger.txt

    Make sure you tell me how things are working now!
     
  15. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU


    ON SECOND attempt it ran and rebooted.

    I will have to attempt next steps after church tonight.

    Thanks for the help so far TimW!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yeah, forgot about that. LOL

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  17. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    No errors found with reg add.
    Files attached.
     

    Attached Files:

  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: (no name) - CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
    O2 - BHO: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll

    After clicking Fix exit HJT.


    Now download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista or Windows7) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  19. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Kes,

    I am not sure why, but MGTools seemed slow to run.

    Do you want the C:\Avenger.txt file snipped?

    Thanks!

    ;)
     

    Attached Files:

  20. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Use windows explorer to manually find and delete:
    C:\WINDOWS\uoxfp.txt
    C:\WINDOWS\system32\drivers\avgtdix.sys
    C:\WINDOWS\system32\drivers\orsjot.sys


    Then see if you can't run CCLeaner to remove any vestiges of AVG.

    Tell me what issues you are still having with this rig.
     
  21. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    AVG found a trojan. Since AVG was running and system developed Trojan, needed cleansing. User advised to visit forum and user could not connect due to searchbar hijacks and system slowdown. I was working through Malware removal and was stumped at remove AVG.

    I did not get to next step of running combofix. I am thinking that is maybe not needed due to the great help from Kes and TimW.:)

    I need to now install AV again.
     
  22. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You could try installing the XP version of MSE for XP.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  23. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    The box is sluggish as if there is something running. I disabled iTunes, Gtalk, Gmail notifier, and Adobe/Java phone-home programs with no speed improvement.

    I installed Avast and already am getting popups of Malware found. Just as well as I cannot find how to dl MSE with Linux.... I will run a full scan, and report what I find.
     
  24. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, get me a log.
     
  25. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    I am having a terrible time finding WHERE Avast keeps the bootscan log.

    C:\Documents and Settings\All Users\Application Data\

    Finds log that is HUGE and shows this entry which does not include all that AVAST found and I moved to chest.
    Should I simply delete all found and re-run the scan?

    The GOOD news is one trojan is an iPod file, so user Desktop is most likely infected also! LOL

    Code:
    Device \Driver\atapi -> DriverStartIo 874dc53b
    
    Disk 0 MBR:Alureon-G [Rtk]
    
    Disk 0 TDL4@MBR code has been found
    
    Disk 0 MBR [TDL4]  **ROOTKIT**
    :confused
     
  26. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you still had AVG installed in any form, you should not have installed Avast. So if AVG is still showing on the system, uninstall Avast now and then reboot. After reboot:

    • Make sure that the C:\avenger.txt log you previously had has been deleted.
    • Uninstall Advanced SystemCare 4
    • redownload MGtools.exe and run it and then attach a new MGlogs.zip file.
     
  27. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Log attached.
     

    Attached Files:

  28. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay now complete the instructions in the below:

    Resetting Registry and File Permissions

    Make sure to reboot after doing the above. Then continue on to the below.



    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    Now goto the below link and follow the instructions for running TDSSKiller from Kaspersky

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista or Win7, don't double click, use right click and select Run As Administrator).


    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  29. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    I cannot find avenger.txt
    Attached is TDSS Killer and MGLogs

    Do you want TDSSKiller removed from desktop now?
     

    Attached Files:

  30. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run the fix properly? Did it reboot your PC after running the fix?


    No! Let's make sure it fixed the problem. Run it again and attach the new log.
     
  31. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on your logs Avenger was not run. At least not properly. And one of the infected files has renamed itself now to C:\WINDOWS\system32\drivers\hdhekm.sys
     
  32. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    I did run it prior. I ran again and file attached.

    This remains, do I delete from Explorer? Headed out for about 1 hour.

    Thank you chaslang for your help!
     

    Attached Files:

  33. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then I will need a new MGlogs.zip file after you run C:\MGtools\GetLogs.bat to create the new log.



    See if it let's you delete it.


    Also remember I need you to rerun TDSSKiller and get a new log.
     
  34. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  35. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    I was able to delete (held shift to bypass recycle bin) with no errors..
    TDSSKiller found 0 errors -
    Registry fix no errors seen.

    VB will not allow upload avenger.txt and MGLogs.zip
     

    Attached Files:

    Last edited: Jun 28, 2011
  36. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    VB will not allow upload avenger.txt and MGLogs.zip

    Uploaded to Dropbox

    Av.txt

    MG.zip
     
  37. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Let's see if Combo will now remove the left overs:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    If it is not on your Desktop, the below will not work.
    * Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    * If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    Driver::
    hdhekm
    File::
    C:\WINDOWS\wfwxfnvy.txt
    C:\WINDOWS\system32\tueugv.txt
    C:\WINDOWS\system32\drivers\hdhekm.sys
    C:\WINDOWS\Tasks\Ad-Aware Update (Weekly).job
    C:\WINDOWS\Tasks\McAfee.com Scan for Viruses - My Computer (SERF1-Sylvia).job
    C:\Documents and Settings\Sylvia\Local Settings\Temp\avg9inst_2011-06-28_01-56.xml
    C:\Documents and Settings\Sylvia\Local Settings\Temp\avglng.log
    C:\Documents and Settings\Sylvia\Local Settings\Temp\avglng.log.lock
    
    Folder::
    C:\$AVG
    C:\WINDOWS\Temp\slhnnv
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    If it asks you to overide the previous file with the same name, click YES.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below log:

    • C:\MGlogs.zip

    Make sure you tell me how things are working now!
     
  38. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Combofix and MGlogs attached.

    Thank you TimW
     

    Attached Files:

  39. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay so are things working now?
     
  40. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Actually after you told me to reverse what I had done yesterday (install Avast) I was waiting to see if you had advise from the last logs uploaded, and follow your direction.

    Are we needing to complete the steps in post #22?
     
  41. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes it is time for final instructions if everything is working okay now.
     
  42. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    It seems to run fine.

    Microsoft Security Essentials - Is that Antivirus? (remember I am primarily a Linux user now)
     
  43. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes it is and there is a version that works on XP.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  44. BoredOutOfMyMind

    BoredOutOfMyMind Picabo, ICU

    Installed and updated MSE. Seemed no errors and I gave it back to the user today.

    Thank you again to the MG Malware Team (Kes, TimW and chaslang) for the help. :cool
     
  45. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Hope she/he finds all is well. ;)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds