AntiVir Not Recognizing Firefox and error Logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by cpbunch, Nov 28, 2012.

  1. cpbunch

    cpbunch Private E-2

    I had very weird activity with my Firefox and AntiVir. AntiVir was saying Firefox was trying to change settings and control keyboards and access parts of the operating system it shouldn't. I uninstalled and reinstalled Firefox then came here to see what I could do. I followed the Start Here thread and ran all the scans. I just would like someone to look them over. I believe they found a few things.

    I can't seem to find the MgTools log file I do have a .zip file though. Does that mean it did not run?
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What ZIP file are you saying you have?

    Are you looking for C:\MGlogs.zip as stated? It is not in the C:\MGtools folder

    The logs you have attach thus far do not show any problems. I have a feeling you are misinterpreting what Avira is telling you. Every program you use has to make changes to the file system and registry at some point. MGtools does this too. Did Avira complain/block MGtools? We do tell you to disable protection software before running just for these reasons.
     
  3. cpbunch

    cpbunch Private E-2

    Yes I have a C:\MGlogs.zip but I have no MGtools folder at all. The issue I had with Avira was with Firefox and that was after I had Firefox and Avira for over a year. Just happened one day without any updates to start kicking about it saying it was trying to gain control over my keyboard and various other placed on the computer. This was definitely not normal so it raised a red flag for me.

    Anything else I can check? Computer has been running well but when I run Spybot it does pick up a few things but not sure how reliable that program is.

    Thanks
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then please attach it.

    Not possible. The MGlogs.zip file cannot be created unless there had been an MGtools folder to run the scans that create MGlogs.zip.

    The logs you have attached thus far are not showing any malware problems so it is not very likely that MGlogs.zip will either.

    Avira can update several times per day. Spybot is not very useful anymore any mostly picks up trivial leftovers that are insignificant.
     
  5. cpbunch

    cpbunch Private E-2

    Okay I went back through and you are correct. There is a folder called MGTools. I just missed it when I first looked.

    Here's the zip for you.

    Thank you.
     

    Attached Files:

  6. cpbunch

    cpbunch Private E-2

    Sorry to double post but I just ran an CLoud Panda scan and it said I was infected with malware adware/fakeav
    Malware. FILE: C:\USERS\CPBUNCH\DOWNLOADS to be deleted.

    Malware. FILE: C:\Users\cpbunch\Desktop\Downloads.lnk to be deleted.

    Suspicious Policy. POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[SHOWSUPERHIDDEN] to be changed to: 1

    Suspicious Policy. POLICY: HKCU\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXPLORER\ADVANCED[HIDEFILEEXT] to be changed to: 0
     
  7. cpbunch

    cpbunch Private E-2

    Sorry if I ran something I should not have but I feel like you think I do not have an infection and I really feel strongly that I do. I'm sorry if I did something wrong.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The log is very incomplete. Did you wait for it to finish running before attaching the log? See the command prompt window that opens. It will tell you when it is fiished. It can take 10 or 15 minutes sometimes. Shutdown all other applications ( including your antivirus and browsers ) while running so you can see everything and also it will run faster.
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    The first item is just a link that you put on your Desktop. Possibly per the name for downloading.

    The last two are just changed to default settings to allow you to view hidden files, folders and file extensions which are required and part of the READ & RUN ME. They are not problems.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No problems yet but I need the complete MGlogs.zip first to say for sure.
     
  11. cpbunch

    cpbunch Private E-2

    Okay I will follow your instructions and run the MGTools after I shutdown the other programs you mentioned and post the files. I did wait for it to finish last time but I will rerun.

    On a side note my weekly boot scan ran this morning when I booted the computer up. I haven't looked to see the results. Do you want that log too?

    Thanks
     
  12. cpbunch

    cpbunch Private E-2

    I was able to run the tool MgTools.exe. I did get a pop-up but failed to see there were additional instructions in the C:prompt. I can't remember if I x'd out of it like the instructions said or if I just clicked ok or cancel.

    Thanks again for your help.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to download and run the current version of MGtools. You are using a version of MGtools that is 20 months old. Please attach the new log.

    ALso please do not put it where you did before ( C:\Users\cpbunch\Documents\Spyware\MGtools.exe ). It is not a document and it is not spyware.
     
  14. cpbunch

    cpbunch Private E-2

    Hi . . I didn't put that one there. I downloaded it yesterday from the link and put it in the C: drive as instructed. I believe that one was left over from when I was helped here back in June. It was still on the desktop so I moved it to that folder back then. I didn't realize it was still there.

    I'll delete that one, redownload, and try again. It took 3 hours to run the first time so I'll be back much later in the day with the results.

    Thanks so much.
     
  15. cpbunch

    cpbunch Private E-2

    Just tried redownloading it in the correct spot. Made sure antivirus and firewall and all other programs were closed and/or deactivated. It says it cannot run because it failed to run getlogs.bat.
     
  16. cpbunch

    cpbunch Private E-2

    Was able to get it going by right clicking and running as admin.

    Attached are the log files. Hope it worked for me this time.

    Thanks for your patience.
     

    Attached Files:

  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    That may be, but it is also what you ran last time. Your logs showed it was what you were running. So while you may have downloaded to the new version, you did not run it.

    I still don't see any malware in your new logs. Perhaps you are just having an issue that you need to reverify Firefox in your Comodo Firewall. This will happen anytime you update and program including Firefox.
     
  18. cpbunch

    cpbunch Private E-2

    Okay thanks for checking it. I finally got around to checking the Avast Boot Scan and it said it found one infection:

    avast java deployment/chache/6.0 threat: java: malware-gen [Trj]

    It says that it is cleaned and deleted. Could this be a false positive or could it have taken care of it. I'm not having any issues with my mouse or with firefox any longer and my Java is up-to-date.

    Are there cleanup instructions I need to follow?

    Thanks again.
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just some junk laying around. Avast probably cleaned it up.

    Yes.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Go back to step 4 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    5. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    6. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    7. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    8. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 6 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    9. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds