Help! AVG still finding rootkits!

Discussion in 'Malware Help (A Specialist Will Reply)' started by ThomasAquinas, Feb 10, 2014.

  1. ThomasAquinas

    ThomasAquinas Private E-2

    First, thank you for reading my post and thank you in advance for any assistance you can give me. I understand that the malware removal people work as volunteers and so thank you for taking time to help me with my situation. I have a Dell laptop which runs windows 7 and I believe I have malware on my computer. I am somewhat of a novice computer user so I am sorry in advance for my lack of insight in some of these areas. I followed all the steps laid out in the malware removal sticky to the best of my ability. Nonetheless, when I run my AVG virus scanner it still reports multiple rootkits residing on my computer which it can’t remove. I would really appreciate anybody’s advice or counsel here. I am going to post the logs created from following the Windows 7 Malware removal sticky and hopefully somebody can give me some insight on how to proceed next. Thanks again for taking the time to help me here.
    Thomas
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Re run Hitman Pro and have it remove Malware & Potential Unwanted Programs. (Conduit, Rocketfuel, yontoo etc...)

    Are you deliberately set up to use a proxy?
     
  3. ThomasAquinas

    ThomasAquinas Private E-2

    Hi Kestrel,

    Thanks for responding to my post.

    I am running the hitman pro next.

    No, I never set up my router to act as a proxy or configure my computer to connect to any other proxy servers. I set up my router with the basic security settings such as Mac Authentication, and not to transmit SSID. Should I be running it as a proxy?
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Shop To Win <<< Uninstall this.



    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    • R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;127.0.0.1:9421;<local>
    • O3 - Toolbar: (no name) - {8660E5B3-6C41-44DE-8503-98D99BBECD41} - (no file)
    After clicking Fix exit HJT.




    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  5. ThomasAquinas

    ThomasAquinas Private E-2

    First, Kestrel thank you for taking the time to give me these detailed instructions.

    I ran C:\MGtools\analyse.exe as you said.

    I also added those registry keys you mentioned to the registry and received a message that the registry was updated successfully.

    I also ran the junk ware removal tool. All the logs are on the bottom. I have also re-enabled both Malware Bytes and AVG Internet Security after having disabled them during the scanning.

    My system appears to be running fine. What has happened in the past is whenever I run AVG to do a full system scan multiple rootkits are detected. I have not run a scan since implementing the steps you spelled out and will wait to hear from you if I should do anything else before trying to run my own AVG scan, etc.

    Thanks again for all your help!
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Go ahead and run a full system scan with AVG and let me know how you get on.
     
  7. ThomasAquinas

    ThomasAquinas Private E-2

    Hi Kestrel,

    Sorry it has taken me so long to respond…..let me explain why it has been almost 24 hours.

    This morning around 10 am, I started a full system scan with AVG. It ran until about 2 pm and still hadn’t finished 85% of the system. It also was reporting about a 129 threats at the time and then AVG just stopped responding. It just froze up (AVG/the scan) and wouldn’t respond to anything.

    So I restarted my computer and after several system updates from windows, I decided to try the scan again. I started it at around 4 pm. I left my computer alone and returned maybe 4 hours later. Something again it froze up amid reporting multiple threats. I have been trying to get reports from the scans, but either they are not generated since the scan has not been finished or I don’t know where they are located.

    I have just finished a third scan focusing specifically on rootkits with the AVG. I figured I ought to run this scan which is not a full system scan and hopefully I could give you something more specific by way of a log.

    I actually was able to export the logs from the three scans onto excel files. If there not important disregard, I just thought I would upload them in case they could be of some benefit to you in helping me. If they are useless feel free to disregard them. Thanks again for taking the time to help me here. Malware sucks!
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    They did not attach. But please, put them into a document or notepad instead. Thanks.
     
  9. ThomasAquinas

    ThomasAquinas Private E-2

    Hi Kestrel,

    Sorry, hopefully these work!
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Oh my...that isn't of much use to us at all. AVG fails to actually provide descriptions of exactly which files/or folders, are "infected" :(

    The ONE thing it DID ID was a cookie:
    Obviously not much to worry about with the cookie, but I'm intrigued as to what else it deems to be bad. All those detections of threats.... does it even list one file path to what is infected? :confused
     
  11. ThomasAquinas

    ThomasAquinas Private E-2

    Hi Kestrel,

    I too was really surprised about the lack of information in the scan logs that AVG produced. I spent a while seeing if I could get any more information through looking at each scan which was archived and even then it only said that it could not be fixed and didn’t identify where or what files it was referring too.

    I then tried to contact AVG through some online help line, but haven’t got an answer. Should I run a scan with different anti-virus scanner? Should I download a trial package of Kaspersky and see what it finds? I didn’t purchase AVG and I still have about 5 days left on my free trial. I had a yearlong subscription to Norton which running on my computer when I got all the rootkits and so I moved to AVG. I have the full version of Malwarebytes, but those scans find nothing at all which I know is not correct. I may end up switching to Kaspersky or something else especially if their scans provide more detailed log files to see what is being detected.

    How do you suggest I proceed from here?
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    As long as you only have one antivirus installed and running.

    Remove AVG and run a full system scan with another antivirus and let me know how you get on. :)
     
  13. ThomasAquinas

    ThomasAquinas Private E-2

    Kestrel,
    I am sorry I haven't responded recently. I am running a new scan with another anti-virus scanner and if comes up with rootkit detection, I will post the results. Thanks so much for your help.
     
  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Let me know what's going on whenever possible. :)
     
  15. ThomasAquinas

    ThomasAquinas Private E-2

    Hi Kestrel,

    Sorry it has taken me so long to get back to you. I ended up purchasing Kaspersky's anti-virus program year long liscense. I then completed a total of 3 different scans and nothing came back in terms of rootkits. Only three infected files which were deleted which contained some Trojan horse which Kaspersky seemed to take care of without issue. I really think that whatever you did must have cleaned the malware/rootkits out, although I am still confused as to why AVG came back with so many threats and not information concerning what or where they were located on my system.

    Nonetheless, I want to thank you for helping to clean this computer. I am definitely going to follow the counsels on those sticky's regarding not allowing my computer to stay vulnerable in the future. Thanks again for your help in getting this computer secure and thank you to all the other malware removal specialists at Major Geeks who give their time to help others out here. It is really appreciated!

    Thomas
     
  16. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You had no rootkits to begin with. There was nothing in those AVG logs that indicated a rootkit. Hidden files can be quite normal. There are hundreds of them on PCs. But you AVG log was not showing anything of concern. You should have run a better rootkit tool like the one from Malwarebytes but I would say you did not have any.
     
  17. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)



    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.

    7. After doing the above, you should work thru the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds