First prob was redirect and pop up - now worse...

Discussion in 'Malware Help (A Specialist Will Reply)' started by ravenblackhardt, Jul 9, 2010.

  1. ravenblackhardt

    ravenblackhardt Private E-2

    I was in process of following the Read Me first I did the CC clean (not changing any settings) and it uninstalled part of my AVG - This put me in the same situation I was in a month or so ago... I posted here, regarding the issue... I kept getting this error with several programs...
    "windows can not access the specified device path or file. You may not have the appropriate permissions to access the item."
    Including Incredimail, Nero, art programs, microsoft office etc. Some of the items will work in safe mode, others wont.

    People here were trying everything to help me with this problem and nothing was working. I finally went into safe mode and removed any and every file AVG that was still residual that it would let me remove and finally it let me reinstall and everything started working again and I was able to run the rest of the read and run.

    This time... I was able to properly run the uninstall after the CC cleaner, there are no visible residual AVG files for me to remove... so I dont know what to do to get my functionality back to be able to finish cleaning my computer so I can do a clean reinstall of my antivirus. I dont like my computer being volnurable.

    I also can not open IE when in this state and can only run firefox.

    Please help
     
  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Welcome to Major Geeks!

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator

    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.
    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor
    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.
    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans
    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. ravenblackhardt

    ravenblackhardt Private E-2

    Hi thanks for the reply, Im off to follow your instructions.
    Last night I did a system restore to earlier in the evening and got some functionality back. I was able to open my incredimail again, but explorer still wont work. However Im not getting that errror when trying to run programs... BUT my AVG still shows as functioning, but I cant open the interface to turn it off and when I try to run the CC cleaner as in the run first instructions it gives me an error that AVG is still running and I would be running CC at my own risk of possible damage to my computer.
    I try to uninstall AVG and get this error:
    initialization of languages failed or files count is zero
    so I try to reinstall or repair and it fails.

    So Im going to follow these instructions and see where it leads me.
    I'll report back with results.
     
  4. ravenblackhardt

    ravenblackhardt Private E-2

    I think that's the files you needed.
     

    Attached Files:

  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I do not understand why Ccleaner and avg are clashing. Ccleaner removes temporary files, I have never known it delete anything more than that, and we do not request that you run the registry cleaner aspect of the tool.

    If you want to be completely rid of avg there is a removal tool we can use. Then you can reinstall as per instructions i'd give you, or..you can opt for another AV. Let's deal with that afterwards, for now I shall review your logs and get back to you with a response soon.

    ahhh I see you already have the avgremover...
     
    Last edited: Jul 10, 2010
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    1. Please put this machine into normal start up mode by using MSCONFIG before we continue!

    2. Go to add/remove programs and uninstall the following outdated java:

    • Java(TM) 6 Update 19
    • Java(TM) 6 Update 7

    3. Run SUPERantispyware > let it update > fix all it finds and attach the log it creates.

    4. Go to TDSSKiller and Download TDSSKiller.zip to your Desktop
    • Extract its contents to your Desktop so that you have TDSSKiller.exe directly on your Desktop and not in any subfolder of the Desktop.
    • Click Start > Run and copy/paste the following bold command into Run box and hit Enter.
    "%userprofile%\Desktop\TDSSKiller.exe" -v

    • Follow the instructions to type in "delete" when it asks you what to do when if finds something.
    • When done, a log file should be created on your C: drive named something like TDSSKiller.2.1.1_27.12.2009_14.17.04_log.txt which is based on the program version # and date and time run. Please attach this log to your next reply.

    5. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    6. A leftover service from viewpoint is running, we will deal with that shortly.

    7. Run Combofix at this point which you already have downloaded, as per the instructions.

    8. Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).
    9. Reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    10. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and do not forget the SAS log.

    11. Tell me how things are running now, are you still having redirects??
     
  7. ravenblackhardt

    ravenblackhardt Private E-2

    Thanks,

    I dont know why either...
    CC cleaner in the instructions said to run it as is (not to change any settings) so that is what I did, and when it ran it listed AVG9 in what it was deleting.

    Now AVG9 was only partially deleted... as far as my windows it thinks it is still active, but I cant click it to open the interface control panel or change any settings. If I try to uninstall it I get an error and if I try to reinstall or repair it I get an error.

    Thanks for reviewing my logs. I will await further instructions.

    I just dont want to run combo fix with that error that it can cause permanent damage to my computer as long as it finds avg still running and I cant turn it off.
     
  8. ravenblackhardt

    ravenblackhardt Private E-2

    oops, didnt see you had made a second reply, I will follow your instructions and get back to you.
     
  9. ravenblackhardt

    ravenblackhardt Private E-2

    Ok,
    I dont know where my super anti spyware log saved. It didnt give me an option to save a log, so I assumed it saved somewhere on its own, but I dont know where to locate it. I can attach it if you can tell me where to find it.

    I am attaching all the other logs.
    There was already a mg zip log in my c drive, so I assume, that it either overwrote it, or added the current files to the zip.
    When I did the function it just flashed a little black screen for like a millisecond, so I assume it did what it was supposed to do.

    I think I attached everything I was supposed to. If not let me know and I'll attach it.
    Im going to reboot now and see if everything is functioning and if I'm still getting redirects... and then we can get my residual avg removed and reinstalled... because as long as it is in this state I can not use IE either.

    Im going out for a while with the fam. I'll check your reply when I return.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I think these files belong to DivX but I want to be sure so we will check them out.

    • c:\documents and settings\All Users\Application Data\6375D7699B.sys
    • c:\windows\system32\4FCC7662BC.sys

    The logs for superantiapyware can be found here:


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.

    Now we need to use ComboFix
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
      • If it is not on your Desktop, the below will not work.
    • Also make sure you have shut down all protection software (antivirus, antispyware...etc) or they may get in the way of allowing ComboFix to run properly.
    • If ComboFix tells you it needs to update to a new version, make sure you allow it to update.
    • Open Notepad and copy/paste the text in the below quote box. Ensure you scroll down to select ALL the lines:
    Code:
    KILLALL::
    
    Driver::
    ASKService
    ASKUpgrade
    Viewpoint Manager Service
    
    FileLook::
    c:\documents and settings\All Users\Application Data\6375D7699B.sys
    c:\windows\system32\4FCC7662BC.sys
    
    File::
    c:\windows\system32\REN49.tmp
    c:\windows\system32\REN48.tmp
    c:\windows\system32\REN47.tmp
    C:\WINDOWS\temp\50.tmp
    
    Folder::
    c:\program files\Viewpoint
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://img.photobucket.com/albums/v666/sUBs/CFScriptB-4.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.

    Could you please get this: 6375D7699B.sys into a zipped file and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip

    Please go to Jotti's malware scan

    (If more than one file needs scanned they must be done separately and logs posted for each one)
    • Copy the file path in the below Code box:
      Code:
      c:\documents and settings\All Users\Application Data\6375D7699B.sys
    • At the upload site, click the browse button.
    • Use Windows Explorer to navigate to the file(s) we need scanned and click "submit file"
    • Your file will possibly be entered into a queue which normally takes less than a minute to clear.
    • This will perform a scan across multiple different virus scanning engines.
    • Important: Wait for all of the scanning engines to complete.
    • Once the scan is finished, Copy and then Paste the link in the address bar into your next reply.

    Then do the same for the below file and also let me know the results:

    Code:
    c:\windows\system32\4FCC7662BC.sys
    You did not clean your temp files out last time by the looks so be sure to do this now as instructed;

    Delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Don't forget to install new java

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach those logs from SAS, post the jotti results and attach the collect.zip.


    Are you still getting redirects? Tell me how things are running now.
     
  11. ravenblackhardt

    ravenblackhardt Private E-2

    Hi,
    Sorry for the late response, but Im in worse shape now, I am responding from work.
    After I rebooted from my last response, I can no longer get online. I am still hooked to the internet, but when I click on explorer AND now firefox I get that error:
    "windows can not access the specified device path or file. You may not have the appropriate permissions to access the item."
    I even did a system restore to before we did the work (that I know that likely undid the work we did) then unistalled and reinstalled AVG still no avail.
    I think before we can clear the malware, we need to clear the residual avg file you were speaking of. So I can get online to follow your instructions.
    If you can give me instructions to do this before 5pm EST today when I leave work so I can print them out and take them home. I will try to do this and get back online.
    I know this is an AVG issue. It is the same problem I had last time. And soon as I got AVG completely clear of my computer I was able to get it cleared up. I dont know how the malware got past my avg and malware bytes to begin with.
    Thanks for your help.
    Renee
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Then uninstall avg from add/remove programs if it lets you.

    Then reboot and use the avg removal tool

    Make sure you also delete any AVG folders in Program Files and Documents & Settings/Application Data directories.

    Reboot again and then complete the below:

    Now go to this MGTools and download the new version of MGtools.exe. Overwrite your previous MGtools.exe file with this one.

    Run the new MGTools.exe and attach the C:\Mglogs.zip into your next reply.
     
  13. ravenblackhardt

    ravenblackhardt Private E-2

    it does let me,
    but there is residual files somewhere. I had this problem before.
    AND when I try to use the avg removal tool it says avg isnt installed.
    I believe in a previous response you said there was some file remaining that we would deal with later. What is that file and where can I find it to delete it?
    I can run most things in safe mode, but not in regular mode. I can only uninstall and reinstall avg in safe mode at this point.
    When I try to do anything including open my avg interface in standard mode I get the same error as listed above.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Just get me the latest logs from MGTools please. I am in the middle of getting ready for my shift ast work tonight right now, so just get me those logs and we will deal with any remaining issues afterwards, I will even give you a fix for removing any avg related files/folders (which is something that ought to be dealt with in the software forum really)
     
  15. ravenblackhardt

    ravenblackhardt Private E-2

    Ok, I have printed out your latest instructions prior to my latest reply, I will follow those and hopefully I will be able to get back online. If not, I will save my mgtools log to a thumb drive and bring it to work tomorrow and upload it.
    Thanks for all your help.
    Renee
     
  16. ravenblackhardt

    ravenblackhardt Private E-2

    btw, I did remove all the temp files besides what it wouldnt let me remove...
    and I can't do the jottie maleware scan, because I can't get online. I will do everything else I can do from instructions... unless it clears things up so I can get online. If not, I will report what happens when I get in to work tomorrow.

    Renee
     
  17. ravenblackhardt

    ravenblackhardt Private E-2

    OK,
    I had to perform the combofix drag thing in safe mode, when it rebooted on its own it opened in regular mode and then when it tried to complete the combo fix in regular mode it gave me the error of permissions... so that didnt complete.
    I didnt want to run it again without first checking with you.
    I tried to enter the string in the run file in safe mode, but it gave me no c:collect.zip file to retrieve for you.
    When trying to run it in standard mode, I got the same permissions error I have gotten since things started going downhill on everything.
    I decided to go into my control panel and just start deleting unneeded programs, the first being an amazon unbox and as soon as I did, it opened an explorer window (which I havent been able to open) So I used the opportunity to post here. I will now go to the jotti site, incase I am not able to open this window again.
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As you said, you performed a system restore, so for now get me a new MGlogs.zip and let me see your status. Thanks.
     
  19. ravenblackhardt

    ravenblackhardt Private E-2

    http://virusscan.jotti.org/en/scanresult/fbd462a2508dc47f1bbad259e9f7af7007a21c6b
    Filename: 6375D7699B.sys
    Status: Scan finished. 0 out of 19 scanners reported malware.

    http://virusscan.jotti.org/en/scanresult/d2200ceed3924f8ca46fdcfe9be413ca775bb9a5
    Filename: 4FCC7662BC.sys
    Status: Scan finished. 0 out of 19 scanners reported malware.

    I pasted
    %systemdrive%\MGTools\zip "%systemdrive%\collect.zip" c:\documents and settings\All Users\Application Data\6375D7699B.sys
    into run
    but I could only do it in safe mode.
    It did not produce a C:/collect.zip file
    when I tried it in standard mode I got this error:
    "Windows cannot access the specified device, path, or file. You may not have the appropriate permissions to access the item."
    I am getting this error with pretty much every exe type file at this point, but something had improved since I was momentarily
    able to get online with IE. But it's wierd, because before IE wasnt working and Firefox was. Now Firefox & Google Chrome is giving me the
    same error as listed above.

    So I could download the new version of Java, but not install it, because I also got the same error.
    I ran the mgtools get log in safe mode, because it wouldnt run in standard mode (same error)
    I attached the log.

    I deleted all temp files again that windows would let me delete.

    After I rebooted, I could no longer get on IE. It would open, no errors, but it just gave me a blank
    screen. Never timed out, my internet connection showed as good 100 mpbs, IE just wouldnt load a page.

    This is so frustrating.
    So I saved all these files on a thumb drive and posted them from work.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm sorry but I am not seeing much left to do here in this forum. I think you have problems which are not caused by malware. We can do the below but then you must visit the software forum to resolve any other outstanding issues.

    You have not put this machine into normal start up mode yet by using msconfig. (I am NOT referring to safe mode) Please do this now.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    After clicking Fix exit HJT.

    Use windows explorer to navigate to the following files, right click each of them and tell me what info you can glean from the properties.
    Or perhaps right click and send to > notepad or wordpad and copy and paste what you see for each into notepad.

    c:\documents and settings\All Users\Application Data\6375D7699B.sys
    c:\windows\system32\4FCC7662BC.sys

    Delete using windows explorer:
    • C:\Documents and Settings\All Users\Application Data\avg9
    • C:\Documents and Settings\All Users\Application Data\avg9(2)
    • C:\Program Files\AVG
    • C:\WINDOWS\system32\REN32.tmp
    • C:\WINDOWS\system32\REN33.tmp
    • C:\WINDOWS\system32\REN34.tmp
    • C:\WINDOWS\system32\REN47.tmp
    • C:\WINDOWS\system32\REN48.tmp
    • C:\WINDOWS\system32\REN49.tmp

    Now Reboot your machine and consider using something other than avg ;)

    Run a full system scan with it and let me know if anything crops up. Also let me know about those files which I am positive are legit, I just want to cover all bases for you.
     
  21. ravenblackhardt

    ravenblackhardt Private E-2

    I havent done the standard start up mode because it locks up. The only things I am stopping from starting are windows search, incredimail and mp3 rocket.
    I have printed out your instructions and I will take them home and follow
     
  22. ravenblackhardt

    ravenblackhardt Private E-2

    BTW
    I cant runMGtools analyse in normal start up. I get the permissions error I told you about.
    I cant run any exe files in standard mode at this point in anything but safe mode.
    I will try all the fix in safe mose and deleting the files you listed in safe mode, maybe deleting the avg files will clear up my issues and I can get back online.
    It sucks I just payed for a new year of AVG and I only have these issues when it gets partially deleted.
    Do you reccomend another antivirus?
    I'll get back to you after work if I can get online after instructions, or tomorrow at work if I cant.
     
  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I didn't know your version of avg was paid for. Don't change then, you'll have to visit the software forum I'm afraid :(
     
  24. ravenblackhardt

    ravenblackhardt Private E-2

    I'll still try the things you suggested besides the mgtools in standard mode I cant do and see what happens, maybe I'll be able to post tonight.
     
  25. ravenblackhardt

    ravenblackhardt Private E-2

    Ok I ran the mgtools only in safe mode as that is all I could do.
    I deleted all the files manually as instructed.
    I got the info you requested by checking properties on the files.

    It is attached

    I was still unable to get online.

    I went back into safe mode and cleaned out some more files. Deleted some empty folders, ran avg remover tool again in safe mode and was able to get on explorer again. Im still unable to run any exe files of any kind so Im going to post in the software forum at this time.
    Thanks for all your help.

    Renee
     

    Attached Files:

  26. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Now download and Run exeHelper

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com)

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    Now get us a new C:\MGLogs.zip
     
  27. ravenblackhardt

    ravenblackhardt Private E-2

    Ok wierd,
    If I downloaded it to my desktop, and tried to run it, got the permissions error.
    If I just ran it directly from the post without download, it worked.
    Im posting the results. However, I will have to run an MGlog from safe mode and get back to you. Then I will do the permissions fix thing while Im in safe mode as well.
    Report after reboot to standard mode.
     

    Attached Files:

  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Please attach the new MGLogs.zip.
     
  29. ravenblackhardt

    ravenblackhardt Private E-2

    hi
    I attached it in our thread in the software forum.
    Then I posted a reply that I had the computer fixed... but I spoke to soon.
    I have it mostly fixed... but not quite... the whole story is there. I found a permissions fix for avg... and reinstalled it, but I still get another error, when I try to reinstall. I am able to reinstall it in safe mode, but when I reboot in standard mode it wont update. Every post on avg forums I find just says to do a clean install, but I keep getting the same error over and over.

    I had installed the new version of java as per kestrals instruction, but since it is after the avg reinstall, and things are still kinda hinky it isnt working properly and since my incredimail uses java, well it wont open... so I still cant use it. Im sure my email inbox is exploding.

    It wont let me attach the file again, I tried to attach the file I attached here there as well, but it said it was already here... I was trying to keep everything in one place... but I guess I didnt do such a good job.

    R
     
  30. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Then you need to stay in that software thread to get it all sorted out.

    Since you are not having any malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds