Cannot access Antivirus sites or see AV programs - Please help

Discussion in 'Malware Help (A Specialist Will Reply)' started by miami, Mar 27, 2010.

  1. miami

    miami Private E-2

    Hello,

    Please.. help. I've been trying to fix this for a week and finally came across your forum. My problem began immediately after I tried installing MagicJack. I started having problems accessing certain websites, first MagicJack's. Then I tried running AVG virus scan and noticed I could not access their site to get an update. Then I noticed I could not get to any AV site. I tried reinstalling Firefox, but could not get to the site to get the download. I deinstalled it and went to IExplorer and had similar problems. Also, it would hang when I went to any site and sometimes would finally work after I hit <cr> a few times.

    I started searching sites (from another computer) for similar problems, and tried a few fix programs, but still had problems. This malware would even prevent me from seeing an AV program I would download, and try to read from CD. I finally found your site and have followed your forum's Read&Run Me First guide and based on that am making this posting since it looks like I'm still having a problem after using the tools and procedure specified.

    Please... can you help?

    Here are the logs I collected:


    Edit by chaslang: Inline SAS log removed. Logs need to be attachments.

    Edit by chaslang: Inline MBAM log removed. Logs need to be attachments.

    Edit by chaslang: Inline ComboFix log removed. Logs need to be attachments.

    =====================================MGTOOLS

    aborted at:
    Running processdll.exe to find loaded DLLs
    window reported:
    The application failed to initialize properly (0xc0000135).
    Click on OK to terminate the application.
     

    Attached Files:

    Last edited by a moderator: Mar 27, 2010
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    Please remember that ALL logs must be attachments.

    Please attach the requested log from RootRepeal.

    Your problems may not be due to malware and MagicJack is not consider malware. Would I recommend using it? No!

    Please do the below.



    Click Start > Run and type in cmd
    • Click OK.
    • This will open a command prompt.
    • Type or copy and paste the following line in the command window:
      ipconfig /flushdns
    • Hit Enter
    • Exit the command window


    Download HostsXpert and then follow the below steps.
    • Unzip HostsXpert.zip
    • It will create a folder named HostsXpert in whatever folder you extract it to.
    • Run HostsXpert.exe by double clicking on it.
    • Click the Make Writeable? button. (if you only see a Make Read-Only selection, it is already writeable so skip this button).
    • Click Restore Microsoft's Hosts File and then click OK.
    • Click the X to exit the program
    Now tell me if you are still having problems. If yes, what happens if you disable/shutdown ZoneAlarm and then AVG and then Ad-Aware's Ad-watch?

    If yes, does it work differently in safe boot mode?
     
  3. miami

    miami Private E-2

    Thank you for replying so quickly. I think your site is great! Sorry about the logs.

    I don't have a log from rootrepeal. When I run it, it displays a window stating: Initializing, please wait....
    then hangs
    in task manager the cpu goes to 99% and virtual mem goes to 2.0GB+, and I have to kill it

    I ran ipconfig /flushdns, then HostsXpert and was still was getting sporadic access to sites even though I could ping them.

    I shutdown zonealarm, avg and ad-aware and now it looks like I can access all of the sites. Do you think something infected these programs? Which programs do you recommend?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! I just think you may have not allowed proper access to some sites. You should enable all of them again and then by process of elimination, figure out which is the problem. I would suspect the firewall first. You may be blocking access to the sites in your firewall or you may have disable cookies, or set protection too high.

    Since this is not a malware problem, I suggest that you post in the Software Forum if you need additional help.



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    8. After doing the above, you should work thru the below link:
     
  5. miami

    miami Private E-2

    Hello,
    I will follow your recommendations, but still am not comfortable with a few things.
    First, is it ok that rootrepeal.exe could not be run and caused cpu usage to go to 99%? Could something be wrong? Should I be concerned about this?

    Also, the firewall and avg had been in use and working fine for a long time, and I never had a problem, then suddenly I began experiencing these problems without having changed anything other that trying to install magicjack. I first began suspecting a virus when I could not update avg, and noticed I could not access their site.

    Thanks.
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    RootRepeal has a high failure rate. Sometimes it is due to various protection software being installed and sometimes it is due to disk emulation software being used, and other times it could be due to not following the instructions exactly.

    The act of installing software can sometimes cause unpredictable changes since changes to the registry and file system are being made. And sometimes, updates to programs like an AV or firewall that occur can also have an effect on their behavior. Sometimes even making it necessary to give permission to programs agaim. Also reinstalling or updating a program (like a browser) can make it necessary to approve the processes in a firewall again. Either way, your problems were not due to malware.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds