Browser redirects - AVG Icons gone - Task Bar dissappears

Discussion in 'Malware Help (A Specialist Will Reply)' started by Melanie0971, Apr 16, 2009.

  1. Melanie0971

    Melanie0971 Private E-2

    A week ago I upgraded my Family Tree Maker Software to version 9 on my Tablet PC. I had been doing well with my Genealogy research, but as I was searching my FireFox browser didn't see to go where I was supposed to. I had AVG free 8 running, and I noticed the system tray icon was gone. So I restarted. The AVG icon came back, but I've been unable to update ever since. I got the "manual" update, but it has been a "crap shoot" as to getting my system tray / virus checking running.

    I tried to continue with IE, and that would not let me go anywhere. It would not go to any of my bookmarks, and Tools Windows Update would just go to a random web site.

    So I made sure SpyWare Blaster was up to date (16 not protected) and made sure all were at zero. Then I ran SpyBot Seach and Destroy. It, like AVG, would not update. I ran the program anyway, and it found nothing.

    So off to Control Panel / Add-Remove Programs. Just to see what I could see. Turns out there are 2 programs in there that I don't need or want. *Browser Address Error Redirector* and "Google Toolbar for Internet Explorer* neither of which the system will let me remove.

    I tried to look at running processes, and ctrl+alt+del seemed to "refresh" my desktop, but no task manager. I restarted.

    I was able to ctrl+alt+del, and got to task manager, but I was unable to end any processes. There were several processes that start the letters AVG, even though I had no system icon, and running from Start Programs AVG didn't do anything other than "refresh" my desktop.

    I tried run command -- That works, but I don't know what to try there.

    I tried run regedit -- That refreshes the desktop, then removes the taskbar and all the icons, and my ability to get to task manager. I can only hold the power button to shut down the system.

    I have my data saved elsewhere, so I figured I'd do a system restore. I can't. When I press the [F11] key on reboot, the system does not give me any choices, and appears to be 1/2 way through the process asking for a disk that I do not have. (I have two disks - a drivers disk and an applications disk)

    I did run the programs, and they seemed to run smoothly with the following exceptions:

    ComboFix.exe
    -During its run I got a windows error message that said:
    avg is running, and combofix will attempt to continue with AVG running. I had no system try icon for AVG, and could not run Task Manager and don't know of another was to terminate it. I will be glad to run that again if you could advise me on how to terminate AVG.
    -During its run I got a windows error message that said:
    pv.cfexe encountered a problem and needs to close. I got this message twice, once just before combofix insalled Windows Active Recovery and once a little bit after, when the desktop "refreshed" and the desktop icons and taskbar were gone.

    This is all the information I have at this time. If I was not complete, or you have questions, please let me know. I believe I followed the steps in order. I hope you are able to help me out. I have seen that you have been able to help others out. I was afraid to try any further advice from similar posts as my situation may be different enough to warrant different action.

    Thanking you in advance. View attachment 112168
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are running an extremely old version of MGTools. Please go back to the Read and Run First instructions and download the latest version. Just let it overwrite your old version and then double click the C:\MGtools\GetLogs.bat file. Attach the new MGLogs.zip
     
  3. Melanie0971

    Melanie0971 Private E-2

    Opps. I will get the newer version and try again. Thank you for your help.
     
  4. Melanie0971

    Melanie0971 Private E-2

    Weirdness.

    I could NOT download MGtools. It simply refused to download. I downloaded it from my neighbors PC and put it on a thumb drive. Then I copied it to the c:\ directory.

    So that is what I used. I hope this version gives you better/more information.

    After that download copy, I ran everything in order again. Logs are attached.

    Took longer to run this time, but that is fine, just thought it was worth mentioning.

    Things went smoothly until I ran combofix.exe.

    ComboFix.exe told me that AVG resident was still running. I did not have it running, and when I stopped it (near the beginning of the READ/Run ME instructions) got the warning message I was not protected etc. So this was a surprise. I got to task manager and there were 3 processes that started with AVG. avgrsx.exe, avgnsx.exe and avgwdsvc.exe. I was unable to cancel any of these. (before the previous Read/Run ME, I was unable to get to task manager.)

    So I let ComboFix.exe tell me again that these processes were running, and it continued on.

    While running I got 2 messages about pv.cfexe caused a fault and needed to close. I declined to "send error report".

    Beyond that, everything ran. If I need to uninsall AVG, let me know I will do that, or if there are other things I should be doing, please advise. Thank you again for all your help.
     

    Attached Files:

  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I am not seeing any malware on your system..what issues are you still having?
     
  6. Melanie0971

    Melanie0971 Private E-2

    The system does seem better. I still can not uninstall the *Browser Address Error Redirector* and *Google Toolbar for Internet Explorer* in the add/remove programs section.

    I don't know if the MG tools download was a problem.
    I don't know if the AVG in task manager / in memory still for ComboFix is a problem.
    I don't know if pv.cfexe caused a fault and needed to close while running ComboFix is a problem.

    Browser itself seems fine.

    Family Tree Maker is working normally again.

    System does seem fine. Just want to make sure that all is okay. If this is "normal" and "all-clear" then GREAT! and THANK YOU so much. If there is a problem and there is more I need to do, please let me know.
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You just need to check you add-ons and toolbars in IE.

    Your issue with MGTools is a bit of a stumper, but not a problem at this point, so if you are not having malware issues...If you are not having any other malware problems, it is time to do our final steps:

    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They are useful as backup scanners. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.

      • Delete the C:\combofix folder from combofix (if it exists)

    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    8. After doing the above, you should work thru the below link:

     
  8. Melanie0971

    Melanie0971 Private E-2

    Thank You again. I will get the subscription for those running, and I printed the "exit" steps and the Malware prevention instructions to make sure I keep the system clean. I really appreciate all your help. System is running very well. You did a great job, and my system is better for all your advice.
     
  9. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are very welcome. (You do not need to purchase either SAS or MBAM ---> just keep them to do backup scans when you think you may have problems).
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds