AVG Anti-Spyware Help (Norton STINKS!!)

Discussion in 'Malware Help (A Specialist Will Reply)' started by smartiepants, Jul 7, 2008.

  1. smartiepants

    smartiepants Private E-2

    Hi there,
    I'm new. :wave
    I bought my computer 3 years ago from Dell, it came with an antivirus program which was fine, but on the day I had to renew it I had to download a new version and I got a heap of trojans! Man I was mad!!

    I downloaded AVG, Spybot S&D & AdAware, killed them all and went happily along until one day my computer got slower and slower and I realised there was a problem. I checked and realised I should have downloaded more recent versions of the software as time went along. I downloaded all new free-wear to kill em off, and even paid for Spyware Doctor. I killed all I could find but still something was not right. Everyone in IT at work told me to give up on the freeware and go buy Norton Antivirus. So that is what I did. Norton only made me uninstall AVG & Spybot, so I still had Adaware & Spyware Doc.

    I've had just the very annoying experience of purchasing Norton Antivirus off the shelf, only to find it doesn't protect me at all. It could not find a thing! I am pretty sure I killed all the viruses beforehand anyway with the AVG free. But I've been getting more Trojans since then, which Norton ignores. Only the Ad-Aware & Spyware Doctor find them for me.

    The end result is I've spent an entire weekend removing Norton after their tech support was hopeless. I downloaded the latest versions of AVG free and S&D again and got rid of a heap of trouble, but am still having issues.

    After finding your site I went to your page of must-have freeware and did a bit of downloading. I have joined up for a bit of advice. Will try to ask questions one at a time. :-D

    Along with a load of other stuff, Ive just downloaded the new version of AVG Anti-Spyware and I dont know what this is (pic below).. not sure how to set it up to scan. Can anyone explain? :confused Thanks guys!

    http://i29.tinypic.com/200qmgk.jpg
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That would be a question for the software section ( basically it is where you can create custom scans...as in downloaded files / specific areas / etc.)

    If you think you are having malware issues: Please follow the instructions in the below link and attach the requested logs when you finish these instructions.

    READ & RUN ME FIRST. Malware Removal Guide
     
  3. smartiepants

    smartiepants Private E-2

    Thanks Tim,
    I'll follow the directions & check back if stuck.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Attach the logs when you are ready. :)
     
  5. smartiepants

    smartiepants Private E-2

    Thanks very much Tim,
    guess you’ve noticed computers are definitely not my area of expertise. I found my other post, I think you subscribed me to it as I had not managed before. This here was my first thread, but I lost it, then my second: http://forums.majorgeeks.com/showthread.php?t=164268
    then my third: http://forums.majorgeeks.com/showthread.php?t=164972
    Now I'm back to the original and finally following orders.

    Weird thing is, even after running the programs you recommend I still have trouble at startup with a Windows Installer message completely unrelated to anything I‘ve done recently:
    “the feature you are trying to use is on a CDRom or other removable disk that is not available. Insert the MYOB disk & click OK”
    After clicking “CANCEL” I get:
    “Error 1706. No valid source could be found for product MYOB Acc.v.15”. The Windows Installer cannot continue”
    After clicking “OK” I get:
    “Please wait while Windows Configurates MYOB”
    This continues for a while in circles until it stops.

    Below are the logs for the programs you recommend (and by the way Combofix had a really hard time with the above MYOB problem):

    _________________________________________________________________
    OK, I have run the SUPERAntiSpyware program. Here is the log:


    ____________________________________________________________________________
    Then I ran Malware Bytes:

    ________________________________________________________________________
    Then finally MGTools, but I can't figure out how to attach log.
    BRB :major
     

    Attached Files:

    Last edited by a moderator: Jul 21, 2008
  6. smartiepants

    smartiepants Private E-2

    Just learned how to attach file - MGTools log:
    Thanks
    Bye for now
    :zzz
     

    Attached Files:

  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    This is not a malware issue .....but there are some things for you to do:

    First go to add\remove programs and uninstall:
    MYOB Accounting v15 ---> if it does not uninstall....continue on.

    Use windows explorer to find and delete these:
    C:\Documents and Settings\All Users\Application Data\AVG8
    C:\Documents and Settings\Susan\Desktop\MYOB.lnk
    C:\Documents and Settings\Susan\My Documents\MYOB
    C:\Program Files\AVG
    C:\WINDOWS\E80F62FF5D3C4A1984099721F2928206.TMP
    C:\WINDOWS\MYOB.INI
    C:\WINDOWS\myobp.ini

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.


    Now tell me what problems you are having.
     
  8. smartiepants

    smartiepants Private E-2

    Hi Tim,

    It was initially a malware issue (many Trojans conquered with a Win32 variety Trojan being the most recent), the cleaning process created new problems. I had ditched Norton in favour of AVG 8 but was still having problems - thus the AVG help thread. All went well at first, I think it was the PC Tools Firewall or the Windows Live OneCare safety scanner… it could not complete, kept freezing & after that everything just went nuts. It could have been the combination or the order things were done in.

    Anyhow, thanks for your advice. Things are far more manageable now. In stage 1 - I removed all but the last two as I can’t find them. Did stage 2, using the fixME.. Then re-started and went on to scan again. Logs attached at bottom.

    This from my daughter in between the two stages (we use the same computer with different profiles) not sure if this is malware but we don‘t know this file:

    Before doing a backup I decided to clean up my file folders and in doing so I found A file called Thumbs.db that I have never seen or heard of before, appearing in almost all my file folders, eg. My Music, My Pictures etc. Then I searched for ‘Thumbs.db’ with the windows file search tool and it came up with LOTS of them in different folders, some of which weren’t even folders but files. A lot of them were related to a program I have called Stepmania.
    I deleted some of them and got a warning message telling me that they were system files and asking if I was sure I wanted to delete them and I said yes.. I also thought I should mention that while I was typing this, randomly, a message came up that said ‘the compressed (zipped) folder is invalid or corrupted.’ I hadn’t clicked anything when it came up but I’m thinking it was a delayed response to me trying to delete the file it was referring to?


    If Thumbs.db is a known threat then we will delete them all. Logs from those scans are attached at bottom.

    Question1: Do I need a firewall? I have the windows firewall and have heard that is not enough. Can you recommend?
    Question2: Do I need to check out my start up situation or did you already sort that out with the fixME.reg file?
    Question3: Do you think I should remove any of these programs due to incompatability?
    Question 4: I downloaded Combofix but it did not run, said it was corrupted. Downloaded again but my file shows as: combo-fix.exe.exe So am not sure if I should run it.

    These are the protection programs I now have on my computer:

    SUPERAntiSpyware
    Malwarebytes’ Anti-Malware
    MGTools
    SpywareBlaster
    Ad-Aware 08
    Spyware Doctor
    Secunia PSI (RC3)
    ThreatFire
    Ccleaner
     

    Attached Files:

  9. smartiepants

    smartiepants Private E-2

    Last thing:

    Ad-Aware scan:
    Infections Found
    ===========================
    Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0
    Item Id: 1 Value: MRU Path: C:\Documents and Settings\Susan\Recent Count: 27
    Item Id: 2 Value: MRU Registry Key: S-1-5-21-57989841-790525478-725345543-1004\Software\Microsoft\Search Assistant\ACMru\5603 Count: 1
    Item Id: 3 Value: MRU Registry Key: S-1-5-21-57989841-790525478-725345543-1004\Software\Microsoft\Internet Explorer\TypedURLs Count: 3

    removed.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to dump Ad-aware......it has become basically useless, as it mainly scares you with MRU findings which are almost never a problem.

    When you ran MGTools, it automatically set your system to show hidden files...the thumb.db are just that, system files and should not be removed.

    AVG8 has proved to be problematic on some computers...you may wish to uninstall it and go with Avast. AVG8 has reported many false positives.

    You should post in the software section regarding your startups....You may wish to use a Startup Manager

    And yes you need a firewall...PCTools FIrewall would do nicely.
    The below will answer your questions:

    1. You can uninstall SUPERAntiSpyware now. Though you may wish to keep it in place of Ad-aware.
    2. We recommed you keep Malwarebytes Anti-Malware as a scanner. It uses no resources except a little disk space until you run a scan.
    3. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop & renamed it like we requested.)

    * Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    * "%userprofile%\Desktop\combo-fix" /u
    o Notes: The space between the cf" and the /u, it must be there.
    o This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    * Delete the C:\cf folder from combofix.

    4. If we used SmitFraudFix, you can delete all files and folders related to it now including the c:\rapport.txt log.
    5. If we used VundoFix, you can delete the VundoFix.exe file and the C:\VundoFix Backups folder and C:\vundofix.txt log that was created.
    6. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    7. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    8. Go to add/remove programs and uninstall HijackThis.
    9. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    10. If you are running Vista, Windows XP or Windows ME, do the below:

    * Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    * Then reboot and Enable System Restore to create a new clean Restore Point.
    11. After doing the above, you should work thru the below link:
    How to Protect yourself from malware!
     
  11. smartiepants

    smartiepants Private E-2

    Many thanks Tim,
    I will work through this now.
    Regards
     
  12. smartiepants

    smartiepants Private E-2

    Hmmm.. a few problems I'm afraid:

    - When attempting to uninstall Ad-Aware via Add/Remove Programs I get the following message:
    The Windows Installer Service could not be accessed. This can occur if you are running Windows in safe mode, or if the Windodws Installer is not correctly installed. Contact your support personnel for assistance.

    - When I followed your instructions to uninstall combofix it does not work - I must have done something incorrectly earlier with the install. I have not deleted the C:\cf folder in case there is another way to uninstall combofix.

    - When trying to uninstall HijackThis the following message appeared:
    An error occurred while trying to remove HijackThis 2.0.2. It may have already been uninstalled. Would you like to remove HijackThis from the Add or Remove programs list
    I clicked 'No' for now. Again, apologies, I must have done something wrong.

    I've put off the final 2 steps until I have completed the earlier ones or some alternative.

    :eek:
     
  13. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    For Ad-aware.....have you tried removing it using CCleaner? You can always just delete the whole folder. Then reboot and run CCleaner to remove any left-overs.

    Same thing for HiJackThis....


    For Combo ........you can delete the ComboFix.exe file (or whatever you renamed it) , C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt
     
  14. smartiepants

    smartiepants Private E-2

    I have started a new thread in software forum as it is now a software issue I think.. still having trouble. My thread is called 'stupido'
    Thanks Tim
     
  15. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome ...I'll try to look in on that thread. :)
     
  16. smartiepants

    smartiepants Private E-2

    Hi Tim,

    I really need to work through my issues one at a time. If you could look in on my 'stupido' thread that would be a big help. I've learned the hard way not to take random advice from just anyone.
    ;)
    Thanks again!
     
  17. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are welcome ....good luck.
     
  18. smartiepants

    smartiepants Private E-2

    Well, it looks like I am going to have to stick with this thread as I am not getting any answers on the other one.. besides being told to be more responsible.. rolleyes which is precisely why I am on this forum for goodness sake!!

    It feels stupid having to start all over again explaining the background in a new thread so am giving up on the software thread for the time being.

    So here is my question:

    Question one - The Start up tool:
    I've attached screen shots of the things I have in my startup menu. I unticked most things not long ago, but things have re-instated themselves. Also looks like there are a few duplications. I’m not sure what some of them are and I’d like to know if any of them are bad. (the screen shots are in the 'stupido' thread - it won't let me upload them again).

    PS, Have had trouble with Avira failing to update when requested, so after uninstalling & reinstalling several times, I've downloaded Avast for the time being.

    Thanks:major
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know what all you have done ...downloading, removing, deleting things that may not have been wise to do.....

    Two things to do :

    First go to start / run / type "sfc /scannow" without quotes and have the xp cd handy ...run it twice.

    If this does not help, you may need to do a repair install.

    If you didn't finish the final instructions, and have hidden files still showing (thumbs.db is one) ...just open my computer / tools / folder options / view and check do not show hidden files.

    You need to bump your thread in software and be patient....and perhaps explain exactly what problem you are trying to solve.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds