Avast Found Vbs Malware - Gen.. Or Was It Memory Dying?

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by ellen46240, Feb 22, 2017.

  1. ellen46240

    ellen46240 Private First Class

    Hi to all!
    Nice to not have been here for a while! Vista - Virus problems obvious yesterday. Down-loaded 2 PDFs seemed fine, known source. I used Paint to produce several files as bmg, jpg, etc. I ran topofree.exe, a freeware raster to vector converter program. Had been loaded for some time but not used before yesterday. Generated dxf cad files with it. They didn't load into QuickCad, without some issues (but lacking full documentation.. thought it was MY fault?). I read some online forums from Autodesk. My QuickCad program crashed several times, and it would not save files.. had seriously LONG hangs. Then seemed to be running ok, (but I didn't check if it saved the last files) and Avast Internet Security started a scan. SERIOUS hangs. Opened Task Manager, and Resource Monitor/Overview, which showed 50% CPU (I suspect on Avast alone).. but LOTS of Memory Hard Faults (no previous known mem problems.. but have not run diagnostics yet today either.. because..) Avast found 260+ virus hits, as VBS Malware-Gen. The Auto fix didn't help that. Oddly the AIS firewall said (and still does) that I am not connected to a network(?) I ran MWB Threat scan last night which found nothing! I'm seeing occasional hard fault mem spikes today, with only FF browser open. I run MWB Anti-Malware Home, and Avast Internet Security.

    This morning I logged onto MG, and started the drill. The browser seems to be working fine. The scans all ran fine, but with some issues found.

    I'm not certain if Win updates are Up to date, or not, as I wanted to avoid Win 10 (BS), and hadn't done research as to what to avoid. Not sure if Program Start-up is set as it should be. With virus being recorded, I'm not doing more than the least, to get downloads, and scan logs. But things seemed to be running quite well of recent. Maybe I'm just now having mem issues? Please take a look at the scans, and as always, the assistance here is HIGHLY appreciated. Jerry
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are not having malware issues. I suggest that if you continue to have issues, post in the software forum for additional assistance.

    Since you are not having any malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    3. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If you are running Win 8, Win 7, Vista, Windows XP or Windows ME, do the below to flush restore points:
      • Refer to the instructions for your Windows version in this link: Disable And Enable System Restore
      • For Windows 8 and 8.1 system restore see this link: Win 8 System Restore - How to enable/disable
      • What we want you to do is to first disable System Restore to flush restore points some of which could be infected.
      • Then we want you to Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  3. ellen46240

    ellen46240 Private First Class

     
  4. ellen46240

    ellen46240 Private First Class

    Tim,
    Thanks for the super fast review and reply! I have noticed many recent forum entries, where computer problems were noted, (including VBS malware mention).. and yet no malware was found. And also references to Avast and false positives. Weird! Seems like *something* is happening, that wasn't before.. but I will redirect my focus to Software.

    A few malware(?) related questions here, before proceeding with the follow up..
    Should I rerun those scans and select/delete any of the PUPs or other items that were located? And if Avast scan is run again, and finds more issues, should I auto-fix? Delete? Ignore? (none of those faults were apparent ever before).
    MANY Thanks!!
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    PUP's are potentially unwanted programs.....so use your best judgment as to what to remove. As to additional scans, yes, remove what it finds. However, the VBS malware was probably a false positive.
     
  6. ellen46240

    ellen46240 Private First Class

    Just a few comments relating to the symptoms (and fix), when the AV scan appeared. I had been using QuickCad 8, which had been loaded previously and worked properly, with the properties set to run in virtual XP mode. Two days back, it did open as before, and appeared to be working, but it would not save a file, and crashed several times. After the malware scans, I double checked the start properties which were no longer showing the required virtual mode. I hadn't changed em! Re-applying the VM, the program and computer are running great.. again ..I think.. (famous last words!) SUPER APPRECIATE all the help!!!
     
  7. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds