AV Security Suite info

Discussion in 'Malware Help (A Specialist Will Reply)' started by boarder428, Jul 11, 2010.

  1. boarder428

    boarder428 Private E-2

    I appologize for creating another post on this topic but the existing threads would not allow me to post.

    I am trying to educate myself on the AV Security Suite virus/malware as I seem to have come in contact with this numerous times over the years on my pc's and friends and families pc. Or something similar. I am currently going thru the steps of removing this on one of my laptops right know and am wondering where this program enters the pc from and why virus protection never seems to catch it coming in?
    Thanks foany info you can supply!
    Corey
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!


    Correct. In the Malware Forum, only the originator of a thread and authorized malware fighters can post to that thread. This prevents
    • getting incorrect answers from novices
    • thread hijacking
    • and keeps the thread on topic and flowing smoothly
    The people who get their PCs infected with this would know best how they received these infections but the typical places they may occur from are any of the below and this is not necessarily the only way:
    • torrent or P2P downloading
    • surfing questionable websites especially porn, sites with illegal software for download, and possibly some gambling sites
    • video download sites including big name ones who don't police the stuff they have available for downloading
    • installing codecs to view various online videos (very common cause)
    • also online sites like FaceBook, MySpace....etc are also possible causes
    And many people do not have their PCs properly protected with an antivirus, antispyware, and a real software firewall (not the Windows firewall) and they also allow Windows and many other programs to remain out of date with updates leaving hundreds of security holes.

    If your goal is to learn to be a malware fighter, see the below thread:

    Becoming A Malware Forum Helper

    It takes a significant amount of time and dedication.
     
  3. boarder428

    boarder428 Private E-2

    thanks for the response, I'm currently still going thru the cleaning process but I beleive that I saw an alert on my av while using facebook. (Why did my Av only alert me to the infection vs. stop it from coming in?) I did notice that it only seemed to infect the current profile that I was logged in to. I did reboot into safe mode and was able to use system restore to roll the pc back a few days and the problem seems to be gone but I'm not 100% convinced yet. If anything I still probably have a restore point that contains the infection as I have not deleted restore points yet. I plan to continue the cleaning process but it may take a few days to complete and get logs posted!
    Thanks again,
    Corey
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    How do you know it did not stop it? Did the notice you received say you were still infected? Perhaps it did block it and was just telling you it did. I would not know without seeing a log or the actually message. In fact I don't even know what it was finding or whether it was even valid without a log showing exactly what and where.


    Performing a Restore can sometimes just mask the effects of the malware without fully removing the malware. For example, it the malware starts its dirty work by have adding a startup entry to your registry, doing a restore could remove the startup entry from the registry since an older copy of the registry is restored. But it does not necessarily remove all of the files the infection may have put on your PC and it may not fix other problems created by the infection since a System Restore is not a 100% backup.
     
  5. boarder428

    boarder428 Private E-2

    I don't know if it stopped or not. I was tired, it was late and I was exiting my browser at the time. I did'nt think much of it until my wife said the computer was flipping out. I may even of just clicked ok on the AV notice since I was ready for bed! I don't have the log file cause I paniced after the fact and replaced my AV. I was using the free Avast AV at the time and replaced it With the Mcaffee Security Suite provided by my ISP

    So far the cleaning process is comming up without any threats. I forgot to mention that I did purchase Spy Hunter and ran it after the restore, before finding this Forum I had read that it was successfull in removing the AV Security Suite Virus. I am running 64 bit windows so was not able to run the programs that were not 64 bit capable. I noticed when running SUPERAntiSpyware you recommend leaving "Ignore System Restore/Volume Information on ME/XP" checked. Does this keep SUPERAntiSpyware from checking the restore files on Vista?
     
  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Are you an expert at reading MGtools logs?

    If you do not attach the 3 logs from SAS, MBAM and MGtools, we cannot help you determine your status for sure.

    Not a recommended program. Never was and likely never will be. Was even considered a rogue at one point.

    Yes! We don't care about seeing anything in System Restore since they will be cleaned when System Restore is disabled but only after we have deemed a PC to be clean. Having even infected restore points could be better than none at all.
     
  7. boarder428

    boarder428 Private E-2

    Absolutely not, Just taking my time to make sure I get all the steps completed correctly. I did'nt post logs yet because I was not thru running all the software and had a question.

    Logs are ready now.
    Did not run combo fix & root repeal since they were not fot 64 bit os's
    Had an error initializing MGTools stating it was'nt 64 bit compatible but seemed to run after clicking ok.
     

    Attached Files:

  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are in pretty good shape. You just have a few minor things to do.

    I do however question the use of PageRage Toolbar from FaceBook which is not recommended and has cause many people problems. We recommend uninstalling.

    Also Yontoo Layers has been considered malware (re the below)

    O2 - BHO: Yontoo Layers - {FD72061E-9FDE-484D-A58A-0BAB4151CAD8} - C:\Program Files (x86)\Yontoo Layers Client for Internet Explorer\YontooIEClient.dll

    And this was installed when you installed PageRage, probably without even telling you it was installing.



    Uninstall the below old versions of software:
    Java(TM) 6 Update 20

    Now install the current version of Sun Java from: Sun Java Runtime Environment

    Delete the below folder:
    C:\ProgramData\Viewpoint

    Also delete all files and subfolders in the below folders except ones from the current date (Windows will not let you delete the files from the current day).
    C:\Windows\TEMP
    C:\Users\Register\AppData\Local\Temp

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    Now run Ccleaner. Only use the Run Cleaner button. Do not run anything else on any other forms.


    Are you currently having any malware problems?
     
  9. boarder428

    boarder428 Private E-2

    Thanks alot chaslang, everything went well, all steps completed with no problems! :celebrate
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.




    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds