My personal machine now has issues

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by axlmastr, Jan 6, 2012.

  1. axlmastr

    axlmastr Private E-2

    I routinely run the malware scanners and SAS found some things in a program I use for managing pre-payroll info. Not good! Also ran RootRepeal and found issues with my MBR and disk sectors. RootRepeal recommended I raise the disk access level. I will admit I did not "remove" AVG Free 2012 before running combofix. I disabled it for the duration of the scan and combofix did its job without throwing up the usual AV warning. I also shutdown my Zonealarm software firewall. I have reinstalled AVG 2010 thru 2012 a couple of times each previously because when I am in the user interface there seems to be something wrong with it. I see HTML-type language in the right pane of the window and the lower notification (can provide screenshot). My other machines display this correctly with the graphical equivalent of the code shown in mine. I am wondering if something is on my machine that is causing this anomaly. I can find no other reference to this odd behavior of the AVG user interface. Malwarebytes found some things that I legitimately downloaded from the MG site to use on office machines but I let it quarantine them anyway. Logs attached.
     

    Attached Files:

  2. axlmastr

    axlmastr Private E-2

    Additional reports attached

    RRreport.txt is with disk access level at default setting
    RRreport(1).txt is after disk access level was increased
     

    Attached Files:

  3. thisisu

    thisisu Malware Consultant

    Go ahead and provide screenshot :)

    Also run the below:

    http://img684.imageshack.us/img684/6489/aswmbr.gif Please download aswMBR to your desktop.
    • Double-click aswMBR.exe to run (Vista/7 right-click and select Run as Administrator)
    • Select No when asked "Would you like to download latest Avast! virus definitions?"
    • Click the [Scan] button.
    • On completion of the scan click [Save log], save it to your desktop and attach this log to your next message. (How to attach)
     
  4. axlmastr

    axlmastr Private E-2

    Not a noob at this but I admit I missed the part about NOT downloading the defs. My bad. Attached are the logs and screenshots. When I ran the Avast scan the I chose quick scan though it was not that quick. I forgot to disable ZA and AVG so the machine BSOD with 0x0000008E. After disabling the ZA and AVg the scan went through though slow as mentioned. The screenshots reflect what I described of AVG UI in previous post. One of them just happens to show my extended desktop to the right but exhibits how the lower notification in the UI is acting like the right pane.
     

    Attached Files:

  5. thisisu

    thisisu Malware Consultant

    I am not sure to be honest. Your concerns would be best addressed in the Software forum.

    A few things that come to mind would be to completely uninstall all versions of Java, and .NET framework.

    And the below:

    http://img406.imageshack.us/img406/3189/windowsrepair.gif Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now open Repair_Windows.exe
    • Go to Start Repairs tab.
    • Choose "Custom Mode" and press "Start".
    • Create a System Restore point if prompted.
    • In the Custom Mode window, select the following repair options:
      • Register System Files
      • Repair Internet Explorer
    • Now click the Start button.
    • Be patient while the tool repairs the selected items.
    • If asked to reboot the computer for the changes to take affect, make sure other tasks in the program are not still running before accepting to restart.

    aswMBR reports an "unknown" MBR. Unknown does not necessarily mean infected. If your only problem is with AVG, I doubt it's actually infected. Attempting to repair the MBR may be more trouble than what it's worth and we would recommend that you make sure you have your data backed up first just in-case things do not go as planned.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis if it present
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work through the below link:
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds