Needing some help please

Discussion in 'Malware Help (A Specialist Will Reply)' started by kbosch, Jul 12, 2007.

  1. kbosch

    kbosch Private E-2

    I have been continuing to get AVG warnings about viruses. Some of them seem to be normal programs according to doing a search in Google about the program it found.

    I have followed all of the recommendations and ran all of the programs required before posting in this forum with these results:

    *I have went through all of the programs in "add/remove software" and didn't see anything that was on the list of things to look for.

    *I have selected "Normal Startup" from msconfig

    *Booted in SAFE mode and ran CCleaner - it found a few things

    *Ran SPYBOT S&D - it found a few things too

    *I ran CounterSpy but when I run it in SAFE mode I can't save the log file. But it ran clean and didn't find anything

    *Ran AVG and saved the log file and am posting it here

    *I ran Bitdefender but I had to do it in normal boot mode as I was having problems with internet - will include log

    *I ran Panda Active Scan (againn in normal boot mode) - will include log
     

    Attached Files:

  2. kbosch

    kbosch Private E-2

    I couldn't find how to save AVG results. I pulled up the test results and the tab with the problems found but can't find a way to save it. I went to "Program" at the top and then selected "Export Lists" and saved it as a Tab Space dilemeted file but it won't let me upload in here. So I printed it as a PDF File and will try uploading that now here
     

    Attached Files:

  3. kbosch

    kbosch Private E-2

    Here is my HiJackThis Log.

    Thanks in advance for looking at all of this and helping me.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You need to attach the logs from GetRunKey and ShowNew that were requested in step 6.

    Also you MUST rename HijackThis as requested in step 7 and then attach a new HJT log.

    Your log (rather incomplete) from AVG Antivirus shows valid files being deleted. Since your log is incomplete, I have to ask what were they supposedly infected with. You may want to restore them from the vault. What version of AVG Antivirus are you running and does it have the current updates?
     
  5. kbosch

    kbosch Private E-2

    Sorry for not including the two other log files. Here they are
     

    Attached Files:

  6. kbosch

    kbosch Private E-2

    Here is the new HijackThis log with running it as analyse.exe

    The version of AVG I am running is AVG Free Edition version 7.5.476. Every day that I boot up my laptop it automatically downloads an update from AVG so I am current on those.

    I am also including another screen shot from AVG showing what virus it supposedly found.

    Thank you
     

    Attached Files:

  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your logs are not showing any malware problems. I still wonder if those detections by AVG are valid. It is possible that the below files which it removed were somehow infected but it seems unlikely:
    You may want to consider restoring them from the vault and then running each of them thru the below online file scanner (it will use many different antivirus programs to test it):

    http://virusscan.jotti.org/


    Also you should do the below.

    Uninstall the Sunbelt CounterSpy trial since we are finished with it now! Then delete the below two folders which may be left behind by the uninstall:
    C:\Documents and Settings\Keith & Melissa\Application Data\Sunbelt Software
    C:\Documents and Settings\All Users\Application Data\Sunbelt Software
    C:\Program Files\Sunbelt Software

    Uninstall the below old versions of software:
    J2SE Runtime Environment 5.0 Update 10
    J2SE Runtime Environment 5.0 Update 6
    Java(TM) SE Runtime Environment 6 Update 1

    Make sure you reboot after uninstalling the above!

    After reboot, now install the current version of Sun Java from: Sun Java Runtime Environment


    Run HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:
    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime

    After clicking Fix, exit HJT.
     
  8. kbosch

    kbosch Private E-2

    Just thought I'd give you an update.

    I did everything you suggested in your recent post.

    When I tried to restore each individual file I would get a notice from AVG immediately saying that there was a virus found. I tried to restore it as a different name in a different directory and once again AVG warned me that a virus was found. When I went to the site you recommended to upload the individual file for scanning it says that the file is 0 bytes and that either some malware or a firewall was keeping it from being scanned. Then I would get another message from AVG recognizing the file again as a virus. I went ahead and let it put it in the vault. I tried this with one other file that was over 1mb in size and got the same results.

    I think I might just leave those files in the vault...
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Based on other info I have seen since your posting, other people are having similar problems (even with other files). This seems to be a recent detections problem with AVG and as I suspected it is a false detection. Hopefully an update will correct this very soon. Do you have this update installed? AVG Anti-Virus Updates July 16, 2007
     
  10. kbosch

    kbosch Private E-2

    At the time you asked the last question, I had an update dated 7/17/07 when I checked the next day. The current date that I have is 7/21/07 and the version is 7.5.476

    Thank you.
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  12. kbosch

    kbosch Private E-2

    Loaded the newest update this afternoon before trying and as soon as I restore one of the files from the vault it comes up with the "Virus Detected" and it is the same virus as I reported earlier.

    confused
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well that just means that they have not addressed the problem yet. You can convince yourself that they are not problems by disabling AVG active protection and then scan those files using the Jotti website I gave to you.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds