AVG Nation and loss of file/folder permissions

Pete21

New Member
Thread author
Feb 12, 2014
7
A few days ago my PC seemed to get infected with the AVG Nation toolbar.
The AVG virus checker came installed with this relatively new PC and it seems to have behaved itself quite well since then.
Then a couple of days ago, turned on PC, desktop wallpaper gone, lots of desktop shortcuts gone, no connection on email (Outlook 2010) and the web browser (IE10) displayed a big "AVG NATION".
Lots of odd behaviour.
Managed to reconnect email to ISP but lost address book and old PST files.
Googled for "AVG Nation" and tried to follow the MalwareTips instructions to remove it:
tried to un-install it from Control Panel but it ran and ran for 30+ minutes apparently doing nothing.
Disabled IE add-ons, installed and ran Adwcleaner, downloaded and installed Junkware Removal Tool. It said it was installed to desktop but not there. Tried twice - suspect this is related to "permissions problem, see below.
Ran MalwareBytes - no threats but it fails to create a log file (see below)
Installed and ran HitmanPro. No threats, log below.
None of these showed many suspicious entries or files but cleaned things where advised.
Now AVG Nation appears to be gone from IE.
Occasionally when IE starts, get a pop-up dialogue asking about "use recommended security and compatibility settings". This is new.
Full scan using Microsoft Security Essentials - no threats detected.
Another full scan by Malwarebytes - No malicious items detected.
Full scan by Spybot Search & Destroy - found 2 "BrowseFox" adware entries. Removed using SpyBot. Re-ran, no threats.
Uninstalled AVG (the virus checker) using Control Panel. The Infospace "AVG Nation toolbar" still appears in Control Panel's list of programs.
BUT some odd file access problems remain - maybe someone can please help?
For example, all my Favorites have gone from IE. They are all in the expected folder:
C:\Users\Pete\Favorites
but in IE there's nothing. If I create a new favorite in IE it gets stored to
C:\Windows\SysWOW64\config\systemprofile\Favorites
Why is this?
In IE all the sites I had blocked from storing cookies have gone (tools, internet options, privacy, sites, managed websites).
All my desktop shortcuts are in the expected folder C:\Users\Pete\Desktop but this clearly isn't read when Windows starts.
When MalwareBytes completes it tries to create its text log file but it says "the specified path cannot be found". Notepad opens with a blank page.
If I try to associate a file extension with a particular application (say .txt with Notepad++) I can browse to and select the relevant exe but the option to "always use the selected program" is greyed out and it remains associated with the default MS-Notepad.
Help in MS-Word, Excel & PowerPoint all say "There is a problem with one or more installed help files. Please repair your Office installation".
If I set a different desktop theme, say Windows Classic, it gets set but is gone on the next restart. The background is just black (same set of shortcuts remain).
I guess there are other things although as far as I can tell all my files and folders appear to be present.
So on the face of it AVG Nation has gone bit there seems to be some loss of file or folder permissions or access. Can I/we confirm this and/or fix it?
For info:
Windows 7 Professional, 64bit, SP1, 16Gb RAM. Intel Core i5, 3.4GHz

Thanks
Pete

# AdwCleaner v3.018 - Report created 12/02/2014 at 21:41:57
# Updated 28/01/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Pete - PETE-PC
# Running from : F:\AVGNation removal\adwcleaner.exe
# Option : Scan
***** [ Services ] *****

***** [ Files / Folders ] *****

***** [ Shortcuts ] *****

***** [ Registry ] *****
Key Found : HKLM\SOFTWARE\Classes\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
***** [ Browsers ] *****
-\\ Internet Explorer v10.0.9200.16750

*************************
AdwCleaner[R0].txt - [5886 octets] - [11/02/2014 20:23:43]
AdwCleaner[S0].txt - [6062 octets] - [11/02/2014 20:26:35]
AdwCleaner[R1].txt - [1064 octets] - [11/02/2014 20:30:29]
AdwCleaner[S1].txt - [1159 octets] - [11/02/2014 20:31:40]
AdwCleaner[R2].txt - [814 octets] - [12/02/2014 21:41:57]
########## EOF - \AdwCleaner\AdwCleaner[R2].txt - [873 octets] ##########

Code:
HitmanPro 3.7.9.212
www.hitmanpro.com
  Computer name . . . . : PETE-PC
  Windows . . . . . . . : 6.1.1.7601.X64/4
  User name . . . . . . : Pete-PC\Pete
  UAC . . . . . . . . . : Disabled
  License . . . . . . . : Trial (29 days left)
  Scan date . . . . . . : 2014-02-12 21:54:53
  Scan mode . . . . . . : Normal
  Scan duration . . . . : 3m 14s
  Disk access mode  . . : Direct disk access (SRB)
  Cloud . . . . . . . . : Internet
  Reboot  . . . . . . . : No
  Threats . . . . . . . : 0
  Traces  . . . . . . . : 0
  Objects scanned . . . : 1,444,763
  Files scanned . . . . : 31,144
  Remnants scanned  . . : 337,245 files / 1,076,374 keys
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Hi,


Please download Farbar Recovery Scan Tool and save it to your desktop.

Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.


  • Double-click to run it. When the tool opens click Yes to disclaimer.
  • Press Scan button.
  • It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
  • The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
 

Pete21

New Member
Thread author
Feb 12, 2014
7
Thanks for the prompt reply. FRST run as requested. The two logs are attached. Hope you can make some sense of them.
Thanks
Pete
 

Attachments

  • FRST.txt
    23.2 KB · Views: 108
  • Addition.txt
    22.3 KB · Views: 173

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
PC seems clean, let's make another search.


Please download aswMBR and save it to your desktop.

Double click aswMBR.exe to start the tool.
  • Select Yes if prompted to download the Avast database.
  • Click Scan
  • Upon completion of the scan ( Scan finished successfully ) click Save log and save it to your desktop, and post that log in your next reply for review.
    Note: do NOT attempt any Fix yet.



Please download AdwCleaner by Xplode and save to your Desktop.

Double click on AdwCleaner.exe to run the tool.
  • Click on the Scan button.
  • After the scan has finished click on the Clean button.

Press OK when asked to close all programs and follow the onscreen prompts.
Press OK again to allow AdwCleaner to restart the computer and complete the removal process.

  • After rebooting, a logfile report (AdwCleaner[S0].txt) will open automatically.
  • Post logfile will also be saved in the C:\AdwCleaner folder.
 

Pete21

New Member
Thread author
Feb 12, 2014
7
Hi TwinHeadedEagle,
Difficulty downloading the 2 tools. Click on your links, the expected dialogue pop-ups at the bottom of IE with "do you want to open or save aswMBR.exe (4.52mb) from public.avast.com" and OPEN/SAVE/CANCEL buttons. Click SAVE - nothing happens. There's a dropdown on the SAVE with option to SAVE AS. Tried saving to USB drive, still failed to do anything. Googled for aswMBR.exe and found it at: http://public.avast.com/~gmerek/aswMBR.htm - tried to do a "save target as" to USB drive. All I got was a 0Kb file called aswmbr_exe.5e4o2s3.partial.
Even the CANCAL button doesn't remove the dialogue. Same with adwCleaner. Same after rebooting PC. Something to do with the folder permissions problem?
BUT...
Managed to download both to my android tablet, plug in tablet to PC and copy tools to desktop!
So ran aswMBR, downloaded Avast database, did scan, log attached - had to save it twice - it said it was saved on desktop. It wasn't and it wasn't even in C:\Windows\system32\config\systemprofile\Desktop\aswMBR.txt. So saved it 2nd time to USB drive (F:).
Tried to run the downloaded adwCleaner from desktop. Get Error box "Autolt error unable to open script file". Ran adwcleaner.exe direct from USB drive that I downloaded a couple of days ago (11-feb-2014, 1139kb). Started scan. Log attached.
Thanks
Pete
 

Attachments

  • aswMBR.txt
    755 bytes · Views: 86
  • AdwCleaner[R3].txt
    989 bytes · Views: 94

Pete21

New Member
Thread author
Feb 12, 2014
7
Well that's good news, but any thoughts about why various folders seem inaccessible? Favorites, desktop, downloads etc.
A Windows corruption or hard disk failure? Certainly there AVG Nation toolbar was present though now thankfully gone. Can you recommend another forum that might help?

And many thanks for your help today. I don't know who you are or where you are but I have been very impressed with your speed of response and the array of tools you can call on.
Pete in the UK
 

TwinHeadedEagle

Level 41
Verified
Mar 8, 2013
22,627
Open your topic here and someone will help you about your issues. As I've said, there is no malware

http://malwaretips.com/forums/troubleshooting-software-hardware-issues.18/



The following will implement some post-cleanup procedures:

=> Please download DelFix by Xplode to your Desktop.

Run the tool and check the following boxes below;
checkmark.png
Remove disinfection tools
checkmark.png
Create registry backup
checkmark.png
Purge System Restore

Click Run button and wait a few seconds for the programme completes his work.
At this point all the tools we used here should be gone. Tool will create an report for you (C:\DelFix.txt)

The tool will also record healthy state of registry and make a backup using ERUNT program in %windir%\ERUNT\DelFix
Tool deletes old system restore points and create a fresh system restore point after cleaning.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top