Infections moved to AVG virus vault

Discussion in 'Malware Help (A Specialist Will Reply)' started by happycmpr46, Nov 18, 2008.

  1. happycmpr46

    happycmpr46 Private E-2

    I ran a scan on a friends computer and found 20002 infections, trojan horses, 988 objects were removed or healed 19013 were not removed or healed, were they moved to the virus vault? and if so, will they still be a problem on the computer? also when objects are removed and healed do they even go to the virus vault? there is a button on AVG that says remove all unhealed infections, if I were to use that what exactly happens to the infections, are they put back onto the computer? can anyone please explain it.
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    If you attached a log from AVG it would be alot more helpful.

    If something is healed, it does not need to be put in the vault or delete permanently. Healed means they removed the infection from the file. If there are 19013 files that were not able to be fixed, you could have a very serious infection. It could be one of the types of infections that infects all executable files on a PC. If these are what the 19013 files are then deleting them could potentially make the PC or many applications unusable after the deletion. Removing infections should put them into the Vault.
     
  3. happycmpr46

    happycmpr46 Private E-2

    OK then I should just leave them in the vault then, also the vault is full so no other infections will fit in it, so should I try and delete some? the reason why he got trojans to begin with was because he had limewire on his computer and a pop up came on asking him to update it, well that pop up was actually a trojan, and then it took over from there, I noticed that all the trojans were in C:\Documents and settings\Zack(which is the operating systems owner) so it is confined to that folder, scanning everything else on the computer it finds nothing, so at least it has stayed in one place, for the time being. it is finding Trojan horse Generic_c.MKB if that means anything and they are all pornographic avi files if that means anything also, thankyou for your help you guys are great!
     
    Last edited: Nov 19, 2008
  4. happycmpr46

    happycmpr46 Private E-2

    How would I attach a log from AVG?
     
  5. happycmpr46

    happycmpr46 Private E-2

    How would I attach a log from AVG? I know how to do it with all the other scanners, but trying to figure out AVG is a problem, even looking under the help tab doesnt help, any suggestions?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Infections in the Vault should be removed. However I would like to see a log of what is in the vault before you remove them.
    • Bring up the AVG Test Center and then select the Vault.
    • Then click on the Program menu option.
    • And then select Export List to File
    • Then change the Save As Type selection to Formatted text (space delimited) (*.PRN, *.TXT)
    • Then enter a file name like AVG.log
    • Select the Desktop and then click Save
    • Attach the AVG.log file here.
    AVG is quite annoying to get a proper log from. They really need to simplify things to produce a plain old text log.
    Note if all the infections are coming from AVI file in the C:\Documents and settings\Zack folder, you could just select all the bad files and delete them yourself too. Then empty the Recycle Bin.
     
  7. happycmpr46

    happycmpr46 Private E-2



    Ok I am posting the avg log, please let me know what I can do, you guys are great!tried posting the whole log but it was 4.14mb so I copied and pasted some of it to give you a sample of what avg found, was unable to change the save as type so hopefully this is enough.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What I suggest that you do is empty the Vault completely and then check to see if the below folder with the Exclamation point for a name exists. If it does, then delete it.

    C:\Documents and Settings\Zack\!


    Now reboot and run a full scan with AVG and let me know the results. Don't worry if anything is found in System Volume Information. That is just System Restore which will be fixed during our final steps.
     
  9. happycmpr46

    happycmpr46 Private E-2

    Ok I did what you said, rebooted and did a full scan and I am posting the results, I will be leaving for 2 days so if I dont get right back to you that is why, thank you for all you have done, you guys are great!!!!!
     

    Attached Files:

  10. happycmpr46

    happycmpr46 Private E-2

    Also can I remove malwarebytes,Superantispyware and combofix when the comp. is fixed?
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I did not know you had even started running the cleaning procedure. I would like to see the 4 requested logs since 1 item stands out in your new log from AVG. Please attach the below logs
    • SUPERAntiSpyware
    • Malwarebytes
    • ComboFix
    • MGtools
     
  12. happycmpr46

    happycmpr46 Private E-2

     

    Attached Files:

  13. happycmpr46

    happycmpr46 Private E-2

     
    Last edited: Nov 26, 2008
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not attach anything.

    Note: what AVG is finding is just in System Restore which our final steps (when we get to them) will fix.
     
  15. happycmpr46

    happycmpr46 Private E-2

    hmmmmmmmmm on my end it shows the logs I posted, well here it goes again let me know if you see them, well it wont let me upload because I have already posted them on this thread so look down and see if you can see them. thanks
     
  16. happycmpr46

    happycmpr46 Private E-2

    actually look up, sorry
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Okay I see you had duplicate messages. They were attached to the first but not the second which is what I looked at.
     
  18. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Uninstall the below software:
    J2SE Runtime Environment 5.0 Update 3
    Java 2 Runtime Environment, SE v1.4.2
    Viewpoint Media Player

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O2 - BHO: Installer Class - {1A7793DE-2598-4FA8-9EC5-9442CDE5E1CC} - (no file)
    O2 - BHO: (no name) - {3D923EE1-EA73-48F6-9FB0-7DBD18FF6E11} - (no file)
    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
    O3 - Toolbar: (no name) - {4982D40A-C53B-4615-B15B-B5B5E98D167C} - (no file)
    O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
    O20 - Winlogon Notify: ddcASMfE - ddcASMfE.dll (file missing)
    O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - (no file)
    O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)

    After clicking Fix, exit HJT.


    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment

    Now run Ccleaner!

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator).

    Then attach the below logs:
    • C:\avenger.txt
    • C:\MGlogs.zip
    Make sure you tell me how things are working now!
     
  19. happycmpr46

    happycmpr46 Private E-2

    ok I ran all the necessary steps and everything seems to be running properly, I am attaching the logs you requested, please let me know what you think, HAPPY THANKSGIVING, GOBBLE GOBBLE :)

    P.S.
    would it be ok to uninstall the programs that I needed to install for cleaning the computer like superantispyware,combofix, avenger, ect?
     

    Attached Files:

    Last edited: Nov 27, 2008
  20. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Happy Turkey Day!:)

    Answered in the below.

    Your logs are clean.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. If we had you run Avenger, you can delete all files related to Avenger now.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    9. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  21. happycmpr46

    happycmpr46 Private E-2

    Thank you for all you have done, computer works great, you are awesome!!!! hope you are enjoying your thanksgiving :)



    cheryl
     
  22. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Surf safely.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds