Dell Desktop Win32/Heur

Discussion in 'Malware Help (A Specialist Will Reply)' started by bbintxs, Mar 16, 2011.

  1. bbintxs

    bbintxs Private E-2

    Pursuant to AVG Threat Shield Notice of Win32/Heur virus, I went to your site: http://forums.majorgeeks.com/showthread.php?t=35407 and explicitly followed each step. All scans resulted in 0 infection/viruses except my AVG scan (free edition), which resulted in one infection/virus: "";"C:\Windows\System32\perfdisk.dll";"Virus found Win32/Heur";"Object is white-listed (critical/system file that should not be removed)".

    As requested per your site's instructions, I attaching the specified logs. Any assistance would be GREATLY appreciated!!!!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click on the following link and use the below steps to scan a file: Virustotal

    Click the Browse... button.
    Navigate to the file C:\Windows\System32\perfdisk.dll

    Attach the report.
     
  3. bbintxs

    bbintxs Private E-2

    Report attached. Thank you!
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Could you please get this: perfdisk.dll into a zipped file for TimW and attach it for me in your next post? To do this, see the below:

    Please go to start > Run and paste in the following:
    log retrievable @ C:\collect.zip
     
  5. bbintxs

    bbintxs Private E-2

    I was unable to perform below function and attach requested zipped file. Please see attached screen shot for explanation. Thank you!!!
     

    Attached Files:

  6. bbintxs

    bbintxs Private E-2

    I also just tried to use the Filzip program to zip C:\Windows\System32\perfdisk.dll and received the AVG threat shield.
     
  7. bbintxs

    bbintxs Private E-2

    Please see attached zipped file. Hopefully this is what you requested.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    AVG is the only scanner flagging that file. I am sure it is a false positive. You will need to set AVG to ignore it. ;)
     
  9. bbintxs

    bbintxs Private E-2

    That is wonderful news!!!! Are there any certain steps I need to take to set AVG to ignore it? Thank you SO much for your time and assistance!!!!
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You should post in the software forum for that. I don't use AVG so I am not sure how you set it to ignore certain files. ;)
     
  11. bbintxs

    bbintxs Private E-2

    Okay. Is there another anti virus program you recommend?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  13. bbintxs

    bbintxs Private E-2

    I will definitely look into those. Thank you so much for all your time and assistance!! You guys are great!!!!!!!!!!!
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome. Safe surfing. :)

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.We recommend them for doing backup scans when you suspect a malware infection.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:


    Malware removal from a National Chain = $149
    Malware removal from MajorGeeks = $0

    Help Support MajorGeeks
    Buy Discounted Software @ Majorgeeks Store. Giveaways Too!

    Majorgeeks Geek Wear. Hats, T-Shirts, Hoodies

    MajorGeeks on FaceBook
     
  15. bbintxs

    bbintxs Private E-2

    I have tried to contact AVG - to no avail - to set false-positive warning to "ignore." I then started following your final steps instructions and now get the attached warning. Another false-positive????
     

    Attached Files:

  16. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    Yes, that's why we have this note in our guides:
    *You should have held off on enabling/re-installing AVG until you had completed the final steps.

    dr.m
     
  17. bbintxs

    bbintxs Private E-2

    Sorry Dr. M. I realized that immediately after I sent my last post. I am going to completely uninstall AVG at this time and follow the instructions. Is it okay to remain connected to the internet during or after I uninstall AVG ??? and install new anti-virus software???
     
  18. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    bbintxs

    I would have the AVG removal tool and a replacement antivirus program already downloaded, then physically disconnect your machine from the internet before doing the uninstall/re-install, then re-connect to the internet to update the new av's definitions.

    dr.m
     
    Last edited: Mar 17, 2011
  19. bbintxs

    bbintxs Private E-2

    I have now followed all steps through creating a system restore. I have removed CCleaner, RootRepeal and MGTools. I kept SuperAntiSpyware and Malwarebytes, as I had those installed prior to your assistance. Any need to keep any of the ones I removed?? The only step I was unable to take was uninstalling HijackThis from the add/remove programs, as I did not see it there. Please let me know if there are any further steps to take - other than reading/working through your "How to Protect yourself from malware" link. I GREATLY appreciate all of you, and your time and assistance!!!!!!!!! You guys are GREAT!!!!!!!
     
  20. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    You're welcome, bbintxs.

    That I would reccommend that you also keep - CCleaner_Slim is especially useful on a weekly basis, to keep things tidy.
    Not a problem - running MGclean.bat removes quite a few unneeded left-over files & folders from the tools we used.

    Safe surfing! http://i268.photobucket.com/albums/jj5/drmoriarty/Emoticons/char145.gif
     
  21. bbintxs

    bbintxs Private E-2

    Great! I will reinstall/download CCleaner. Much thanks and appreciation to you Dr. M., TimW and Kestrel13 and any others who assisted me in this matter. You guys were so much help and GREAT to work with!!! You made things easy to understand - even for this somewhat computer illiterate woman!!
     
  22. dr.moriarty

    dr.moriarty Malware Super Sleuth Staff Member

    On behalf of the team - "You're Welcome"!

    Personal note: Stick around and "Read 'til your eyes bleed!"...:-D soon your friends will be coming to you for help.

    Take Care,
    dr.m
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds