Security center problem

Discussion in 'Software' started by psco2007, Oct 8, 2010.

  1. psco2007

    psco2007 Master Sergeant

    Hello all,
    Hope this is the right forum for my question.
    I uninstalled AVG after it expired and installed Avast.
    When I go to the security center (xp home), it says 2 antivirus programs detected and one is ok.
    Why am I getting this message?
    I uninstalled AVG with Revo Uninstaller and it says AVG is gone and add/remove shows no sign of it.
    Thank you
    Paul
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try running CCLeaner to find and delete any leftovers from AVG. You can also run the AVG removal tool:
    Please go here and download and run the AVG Removal Tool.
     
  3. psco2007

    psco2007 Master Sergeant

    Hi Tim,
    I ran both programs and rebooted.
    Getting same message.
    Should I be concerned, since Avast seems to be working?
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There has to be some leftovers that is causing this. If you want, you can run the MGtools and save it to your root folder. So you have:
    C:\MGTools.exe and then attach the C:\MGLogs.zip so we can look to see what is still there.
     
  5. psco2007

    psco2007 Master Sergeant

    Tim,
    Here is the log.
    I hope this is the right one.
    Paul
     

    Attached Files:

    Last edited: Oct 9, 2010
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It will help, but I wanted the entire C:\MGLogs.zip to look for reg keys and other leftovers.

    You can run HJT (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Then you can go to start / run / type:
    services.msc
    In that window, scroll down to AVG Security Toolbar Service and delete it.
     
  7. psco2007

    psco2007 Master Sergeant

    Before I do that, here is the log- if not correct, I'll do the other steps.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Ok, let's do it all in one swoop!! First off, you really need to clean up your desktops!! I strongly advise you to cleanup your Desktop. Remove everything but links to run programs. Do not download and save programs here and definitely do not use it for long term storage. A cluttered Desktop is malware's playground and it can also cause performance degradation especially when you start saving large files here like you are doing.

    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix, exit HJT.

    Now copy just the bold text below to notepad (Do not include any space above the word REGEDIT). Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now use windows explorer to find and delete:
    C:\PROGRAM FILES\AVG
    C:\Documents and Settings\Owner\Application Data\AVG9
    C:\Documents and Settings\Owner\My Documents\AVG DOWN;OAD FREE_files
    C:\Documents and Settings\Owner\My Documents\AVG DOWN;OAD FREE.htm
    C:\AVGTemp

    You should be good to go.
     
  9. psco2007

    psco2007 Master Sergeant

    Tim, I followed all directions and got a "success" message after clicking fixME.reg, but it still shows 2 virus programs in Security Center.
    Unless you feel this is a problem, I'll just leave it as is.
    Thanks for all your time.
    Paul
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I both don't think it is a problem and I don't know what else to do to remove it. That should have removed all leftover traces of AVG. Does anything AVG related show up in CCLeaner ( both the cleaner and the registry )?
     
  11. solaris89

    solaris89 First Sergeant

  12. Caliban

    Caliban I don't need no steenkin' title!

    Agreed. It almost looks like a Security Center reg key got modified somehow (not the normal HKEY_LOCAL_MACHINE \ SOFTWARE \ Microsoft \ Security Center key, and not the normal Override DWORD values) - something deeper, and I don't know the path.

    EDIT: Just saw your link, solaris89 - might fall in line with the reg key idea.
     
  13. oma

    oma MajorGeek

    Googled a bit and found this: http://techrepublic.com.com/5208-11...=186843&messageID=1914136&tag=content;leftCol

    Try this...

    Start -> Run and type in "regedit"

    Browse to branch "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring"

    Expand that branch, and you should see the AntiVirus programs that it is supposed to be monitoring. If you see AVG, delete it.

    Hope the above helps. If not, hopefully someone else will come along and will be able to help out.
     
  14. psco2007

    psco2007 Master Sergeant

    Well guys,
    I thank you all for your help.
    Unfortunately, nothing works.

    Going to registry and checking monitoring, AVG or my current - Avast, but there were many antivirus programs that I tried years ago.
    I deleted them, and followed all instructions, but the pesky message is still there.

    Since this is not a security problem, I will just leave it there.
    I have clicked "thanks" to all.

    Again, I appreciate all the help that was put forward.
     
  15. oma

    oma MajorGeek

    I sincerely hope that you find a solution. While referring our members to another forum is not encouraged, I would make an exception this time and suggest that you visit the Avast forum. http://forum.avast.com/index.php?PHPSESSID=048d556ff22c6dd9d9cc4269edb6764d&board=2.0

    Perhaps they run across your problem more often than here on MG site and will be able to help you?

    Still I hope that in the mean time someone else here will chime in!
     
  16. psco2007

    psco2007 Master Sergeant

    Thanks for the heads-up.
    After all the aggravation of trying to solve this, and being told it is not a security problem, I think I can safely leave it as is.
    Your forum is great and the people who replied had the best of intentions.
     
  17. oma

    oma MajorGeek

    Think I've found the solution to your problem. Please follow the instructions on this link. The procedure should work. http://www.pchell.com/support/multiple_antivirus_in_security_center.shtml

    Sorry about finding the above solution so late but if you decide to change to another AV in the future it may cause you more problems?

    Please try it, you've got nothing to lose. ;)
     
  18. psco2007

    psco2007 Master Sergeant

    Hi Oma,
    You already gave me that solution yesterday.
    Even though I deleted all the anti-virus programs (Norton, AVG or Avast are not on it), they are back.
    This is a real puzzlement.
    Never had this problem before.
    Thanks for all your time.
    Paul
     

    Attached Files:

  19. psco2007

    psco2007 Master Sergeant

    Hello again Oma,
    I ran the Belarc Advisor and it show Lavasoft Antivirus as well as Avast.
    I ran the Revo Uninstaller, but when I run a new Belarc scan, it still shows it is there.
    I never downloaded the Anti-virus portion of Lavasoft, so I don't know why it is there or why I can't get rid of it.
     
  20. oma

    oma MajorGeek

    Try this one as the only solution I have left:

    Right click on MY Computer

    Select Properties

    Select Device Manager

    Click on "View"

    Select "Show Hidden Devices"

    Click on (expand) Non-Plug and Play Drivers

    Look for any antivirus in the list OTHER than AVAST since you chose this one. Ad-aware could be in there as well.

    If found, try DISABLE first. (there may be multiple entries) BE CAREFUL!!!
    If in doubt, post back a thumbnail of the ones you think may belong to another AV. We'll google then to find out to what AV the abbreviations belong to.

    Reboot machine.

    Go to Security Center

    Check if message about more than 1 AV still running

    If not, you're in the clear and then you can UNINSTALL the ones you DISABLED before.

    Reboot after uninstalling.

    If still not fixed, then I throw in MY towel, because that's as far as my knowledge will go. :)

    Please post back about the result, positive or not. :)
     
  21. oma

    oma MajorGeek

    Edit time expired on my previous post.

    Additional info. Just ignore the info of AV's and FW in the MONITOR folder that you attached a picture of in post 18. I've got the EXACT info in my monitor folder as you've got. I'm VERY sure that I never downloaded most of these software programs as shown there. Could be that Windows/Microsoft puts them there? Perhaps an MVP would know the answer to that?
     
  22. psco2007

    psco2007 Master Sergeant

    Hi Oma,
    I did everything and am including a couple of attachments.
    It seems that LavaSoft is still there - according to Belarc and no matter what I do, I can't get rid of it.
    That seems to be the problem, although Revo says it is gone.
    I have gone into Program files and deleted all of LavaSoft.

    I'm sure this has given you grey hairs - me too.
    I will have to live with this, as everyone seems to think that it is not a security problem.

    The non-plug folder only contains Avast.

    Thanks for all your help.
    Paul
     

    Attached Files:

  23. oma

    oma MajorGeek

    It seems that Lavasoft Ad-Watch Live is built into the anniversary edition and a custom stall was required to put the driver on your system. Read this link: http://www.brighthub.com/computing/smb-security/reviews/26025.aspx

    Therefore I THINK that we are in the right place? (software drivers)

    That said, I can see only part of the non-plug in the pic and even that is not readable to me. :(

    Can you start making pics of the non-plug and play folder and start taking pics from the whole list from beginning to the end? Try to make them as readable as possible please? (closeups)

    There is only 1 solution left after the above and that is by posting at the Lavasoft forum (if there is any) and find out what the name of the Ad-Watch Live driver is. They should know and would help us a LOT more than trying to google all of them abbreviations.
     
    Last edited: Oct 10, 2010
  24. psco2007

    psco2007 Master Sergeant

    Sorry about the first pics.
    Hope these are better. I previewed them and they are very clear.
     

    Attached Files:

  25. oma

    oma MajorGeek

    So far I haven't been able to identify anything related to Lavasoft Ad-Watch Live.

    Have you used CCleaner (registry cleaner)? Did it come up clear?

    Did you try to search if you have it in:

    Program Files\Lavasoft\Ad-Aware\ and see if you have a driver\32 there .... or something similar to it? Do a thorough search under documents and settings as well and application data.

    If nothing found, I strongly suggest to make a post on Lavasoft Ad-aware Support Forum to ask where the Ad-Watch Live is located and how to remove it? http://www.lavasoftsupport.com/

    Hope this helps a tiny bit. Good luck!!
     
  26. psco2007

    psco2007 Master Sergeant

    Hi Oma.
    I have been on the phone with ATT support because I thought that Norton might have been causing the problem.
    After it was removed, and my Avast was temporarily disabled, the message in the Security Ctr only showed one Virus Program.
    That [rpgram is Lava Soft Ad-watch.
    So that is the culprit.
    I just registered with Lavasoft forum.
    I'll let you know what I find out.
    Have a great evening.
    Were you able to read the pics?
     
  27. oma

    oma MajorGeek

    Yes, the pics were readable. However, as I said, I can't find anything related to Lavasoft in there. I'm glad that you posted at their forum and that you will update us. :) If you don't get an answer at Lavasoft, perhaps avast forum would be willing to help you out.
     
  28. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    O23 - Service: Lavasoft Ad-Aware Service - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe

    From the HJT log you posted. It should be listed in the services.msc
     
  29. psco2007

    psco2007 Master Sergeant

    Tim,
    Lavasoft is in Services, and is disabled, but it still shows as a second virus program running.
    I have done everything to try to remove it and have failed.
    I know that it is causing the problem in Security Ctr, because if I disable Avast, the message then says " one virus program operating - Lavasoft Ad-Watch
     

    Attached Files:

  30. psco2007

    psco2007 Master Sergeant

    Hi Oma,
    Lavasoft forum is a joke.
    They won't let you post a question and the answers that they give are useless.
    I'll keep trying.
     
  31. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    But the path is no longer there, yes?

    Open notepad and copy and paste the following text in the quote box into the window:
    Save this as fix.bat on your desktop.
    Choose to save as all files.
    Doubleclick fix.bat and let the program run.
    A small black dos window will flash, this is normal.

    Is it gone now?
     
  32. psco2007

    psco2007 Master Sergeant

    Yes, the path is gone.
    I ran the fix.bat and it flashed.
    Message of 2 virus program still there.
     
  33. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Poo......did you check services.msc to see if it was truly gone?:(
     
  34. psco2007

    psco2007 Master Sergeant

    Yes, it is no longer in Services menu.
     
  35. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    How about a reboot? But first run CCleaner ( both cleaner and registry --> make the backup when prompted ).
     
  36. psco2007

    psco2007 Master Sergeant

    I'm in the middle of my Acronis backup, so I don't want to reboot now.
    I will when it ends and let you know the results.
     
  37. psco2007

    psco2007 Master Sergeant

    Tim,
    Did the cc cleaner Registry and said Successful.
    Did a reboot and ran a Belarc Advisor and it still shows Lavasoft Ad-watch as 2nd virus program.
    When I click Fix.bat, it flashes, but nothing after that.
    Is that normal procedure?
    You had me run a fixME.reg yesterday for AVG.
    Since we now know that it is Lavasoft causing the problem, can we use that program for Lavasoft removal?
     
  38. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    We had you run the fix.bat to remove the service, but looking back at your logs, I have not seen the registry key for it. You can open regedit and do a search for lavasoft.
     
  39. psco2007

    psco2007 Master Sergeant

    Hi Tim,

    This problem is FINALLY GONE!!
    After dealing with the Microsoft tech and getting many, many useless fixes, he finally did something right.
    I am enclosing the e-mail that finally got rid of the Lavasoft message and the two anti-virus programs running.
    Thanks for your help.
     

    Attached Files:

    Last edited: Nov 28, 2010
  40. Caliban

    Caliban I don't need no steenkin' title!

    Congratulations - well done! ;)
     
  41. psco2007

    psco2007 Master Sergeant

    Hi Oma,

    I finally got the problem solved after dealing with the somewhat brain-dead Microsoft techs.
    They finally came up with the correct answer.
    I am enclosing the solution.
    Thanks for your help. ( if the pic does not appear, it is also in my reply to Tim)
    Paul
     
  42. tgell

    tgell Major Geek Extraordinaire

    Hello,
    I had this problem and used this utility called Security Center Reset. You have to uninstall your antivirus and then use this utility to reset the Security Center. Then install your antivirus again.
     
  43. psco2007

    psco2007 Master Sergeant

    Hi Tgell,
    My problem was that in the Security Center it said I had 2 antivirus programs and in my Seagate Tools it said my program was Lavasoft, even though the program I have is Avast.
    I never downlaoded Lavasoft Antivirus, so I don't know why it said that.
    The solution (finally) was provided and the pics are in my reply to Tim.
    Thanks for your reply.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds