Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
AVG finding virus win32 heur
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
AVG finding virus win32 heur
Hi, I can't seem to get rid of this win32 heur virus. AVG 8 keeps detecting a threat, first I couldn't turn on my automatic updates, I ran a combofix, and it fixed that problem. but the problem of the 'threat' is still being detected by AVG. it said it was my uniblue spyeraser, so I uninstalled it, which did nothing. Ran virus detector in safe mode- it did nothing. I need help removing this please!
Copy of Virus Vault Resident Shield detection Infection;"Object";"Result";"Detection time";"Object Type";"Process" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP411\A0058563.dll";"Moved to Virus Vault";"5/29/2008, 8:19:57 AM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\system volume information\_restore{97b25540-b35d-443e-bb0e-ff34b8745f05}\rp406\a0058310.dll";"Moved to Virus Vault";"5/29/2008, 6:34:03 AM";"file";"C:\Program Files\Uniblue\SpyEraser\SpyEraser.exe" Potentially harmful program Fake_AntiSpyware.TS;"C:\DOCUME~1\Karen\LOCALS~1\Temp\7zS10.tmp\SpywareRemov er\TCL.dll";"Added to PUP exceptions";"5/29/2008, 6:04:59 AM";"file";"C:\WINDOWS\system32\msiexec.exe" Potentially harmful program Fake_AntiSpyware.TS;"C:\DOCUME~1\Karen\LOCALS~1\Temp\7zS5.tmp\SpywareRemove r\TCL.dll";"Moved to Virus Vault";"5/29/2008, 6:03:08 AM";"file";"C:\WINDOWS\system32\msiexec.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP406\A0058310.dll";"Infected";"5/29/2008, 5:09:09 AM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP406\A0058310.dll";"Infected";"5/29/2008, 4:15:44 AM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP406\A0058310.dll";"Infected";"5/29/2008, 3:55:56 AM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP404\A0058167.dll";"Moved to Virus Vault";"5/29/2008, 1:58:42 AM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP404\A0058167.dll";"Infected";"5/28/2008, 9:09:48 PM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP404\A0058166.dll";"Moved to Virus Vault";"5/28/2008, 8:03:30 PM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\WINDOWS\system32\fccbCRHw.dll";"Moved to Virus Vault";"5/28/2008, 5:56:47 PM";"file";"C:\WINDOWS\system32\winlogon.exe" Virus found Win32/Heur;"C:\WINDOWS\system32\fccbCRHw.dll";"Moved to Virus Vault";"5/28/2008, 5:56:47 PM";"file";"C:\WINDOWS\Explorer.EXE" Virus found Win32/Heur;"C:\WINDOWS\system32\fccbCRHw.dll";"Infected";"5/28/2008, 5:25:16 PM";"file";"C:\WINDOWS\system32\winlogon.exe" Virus found Win32/Heur;"C:\WINDOWS\system32\fccbCRHw.dll";"Infected";"5/28/2008, 5:24:46 PM";"file";"C:\WINDOWS\system32\winlogon.exe" Virus found Win32/Heur;"C:\WINDOWS\SYSTEM32\RGWHWDFT.DLL";"Infected";"5/28/2008, 5:14:40 PM";"file";"" Virus found Win32/Heur;"C:\WINDOWS\SYSTEM32\RGWHWDFT.DLL";"Infected";"5/28/2008, 5:14:39 PM";"file";"" Virus found Win32/Heur;"C:\WINDOWS\system32\yayyAPIX.dll";"Infected";"5/28/2008, 4:56:56 PM";"file";"C:\PROGRA~1\MOZILL~1\FIREFOX.EXE" Virus found Win32/Heur;"C:\WINDOWS\SYSTEM32\RGWHWDFT.DLL";"Infected";"5/28/2008, 4:56:24 PM";"file";"" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP404\A0058167.dll";"Moved to Virus Vault";"5/28/2008, 11:54:18 PM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP404\A0058167.dll";"Moved to Virus Vault";"5/28/2008, 10:54:18 PM";"file";"C:\WINDOWS\System32\svchost.exe" Virus found Win32/Heur;"C:\System Volume Information\_restore{97B25540-B35D-443E-BB0E-FF34B8745F05}\RP404\A0058167.dll";"Moved to Virus Vault";"5/28/2008, 10:42:18 PM";"file";"C:\WINDOWS\System32\svchost.exe" |
|
#2
|
||||
|
||||
|
AVG is getting ridiculous, it detects a number of the tools that we use as malicious. There are bad entries in the above log, but this is one of the downsides to the new AVG -> from their site
" An "ActiveX Compatibility" registry key is a result of the "Immunize" function included in some anti-spyware programs (e.g.: "Spybot search & destroy", "Spyware blaster",...) The key contains the same registry entries as the actual threats, thus preventing them from working correctly. Some anti-spyware programs use this method to prevent launching of the malware. Unfortunately, these parts are still detected by AVG signatures and that is why AVG marks them as infected. To assure protection provided by AVG against these threats, it is not possible to remove such signatures from AVG virus bases. Because of this, "Immunize" function included in above mentioned softwares is NOT compatible with AVG products." ------------------------------------------------------------- Can you attach your combofix log here. Click reply Click the arrow next to the paperclip icon above your reply Navigate to C:\Combofix.txt and upload it here Last edited by Blind Dragon; 05-29-2008 at 04:52 PM.. |
|
|
|
#3
|
|||
|
|||
|
Combofix txt.
|
|
#4
|
||||
|
||||
|
I need a Hijackthis log as well, we are probably going to delete a 020
Highjackthis Instructions
|
|
#5
|
|||
|
|||
|
Okay. I also ran another virus scan and it found a vundo virus. AVG says it removed and healed it though, so I guess that is okay?
|
|
#6
|
||||
|
||||
|
1) Malwarebytes' Anti-Malware
------------------------------------------------------------------------------------- 2)Print out or copy and paste into notepad and save it to your desktop to have while in safe mode Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below. O2 - BHO: (no name) - {129FA2A1-408C-4824-83A4-5001581FD01E} - (no file) O4 - HKLM\..\Run: [LayoutM] KLayMgr.exe O20 - Winlogon Notify: fccbCRHw - fccbCRHw.dll (file missing) Now close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into safe mode. Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode. FileASSASSIN
Malwarebytes' Anti-Malware
After that, Reboot, and post a new HijackThis log with MBAM log here in a reply |
|
#7
|
|||
|
|||
|
Took a while for the scan to complete but I got the results. And removed 4 infections
I also now don't have any icons in my system tray- except for time, volume and MSN messenger....used to have a few more than that AVG, Calendar, and have a few more processes running, used to run around 40, now I am up to 47. And AVG just detected the threat again. Last edited by kimsland; 04-22-2009 at 07:11 PM.. Reason: merged recent posts |
|
#8
|
||||
|
||||
|
When we uninstall combofix that should go back to normal.
Just to be safe lets run Vundofix then an online scan to see if I am missing anything. Please download VundoFix.exe to your desktop.
In this case, VundoFix will run on reboot, simply follow the above instructions starting from "Click the Scan for Vundo button." when VundoFix appears at reboot. ------------------------------------------------------ Run Kaspersky Online AV Scanner Order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
------------------------------ Attach both logs for me and we can go from there |
|
#9
|
|||
|
|||
|
vundo was not found, still trying to update kaspersky though
Okay, here are my results sorry. almost forgot this one Last edited by kimsland; 04-22-2009 at 07:11 PM.. Reason: merged recent posts |
|
|
|
#10
|
||||
|
||||
|
The only signs of it are in your restore points and combofix quarantine.
The kaspersky also showed Nero 8. Which depending how you got that program could just be a false positive or it could infact be infected. So I will list this as an optional removal. To remove it go to add/remove programs and uninstall Nero 8 Then Delete the following folders: C:\Documents and Settings\Karen\My Documents\Karen\Downloads\Nero 8 C:\Program Files\Nero 8 ---------------------------------------- I will post the clean up instructions for you when I get home from work. |
|
#11
|
|||
|
|||
|
K. I thought I saw Nero in there as a virus. Its gone now.
|
|
#12
|
||||
|
||||
|
Uninstall Combofix
* Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter. * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. -------------------------------------------------------------------- OTCleanit! by Oldtimer
-------------------------------------------------------------------- Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
here are some additional utilities that will enhance your safety
__________________
INFECTED? Free Virus and Malware Removal
|
|
#13
|
|||
|
|||
|
THANK YOU!!!
![]() |
|
#14
|
||||
|
||||
|
Your very welcome
BD |
|
#15
|
|||
|
|||
|
Magnificent walk-thru.
I was able to recover a client's computer, which was in total meltdown. It would not even go into safe mode, nor could I boot from the DVD drive. The computer had win32/heur and Vundo. All better! Thanks to both BD for his clear explanations and to KK1, who explained her problem quite intelligently! Keltie |
|
#16
|
|||
|
|||
|
Please Help
BD, good day.
I have tried to follow these instructions but my "hijackthis" log file is different as the specified "O4" file is missing. Can you help? I have attached a copy of my hijackthis log file. |
|
#18
|
|||
|
|||
|
win32 heur threat
I am using the latest vga 8 and tried to cure win 32 heur virus but without success and attached a log file of hijack utility if some one can get me a help before I start formatting my laptop which I don't want to do it at this stage...
Thank you |
|
#20
|
|||
|
|||
|
Hi!
I might have the same problem. Should I just run it like your walkthrough or you would need to see my hijacklog too?? Thanks a lot..I've been goin crazy with 2 of my laptop infected with this virus... |
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Win32/Heur? | Virus & Malware removal | 0 | 05-23-2008 06:53 PM | |
| virus.win32.delf.ak | Virus & Malware removal | 13 | 10-29-2007 04:11 AM | |
| Please elp: Virus.Win32.Delf.ak | Virus & Malware removal | 25 | 05-24-2007 03:30 PM | |
| Virus.Win32.Delf.ak | Virus & Malware removal | 4 | 04-05-2007 01:56 PM | |
| i got win32 virus....help | Software & Utilities in General | 2 | 10-18-2005 03:29 AM | |
All times are GMT -4. The time now is 08:53 PM.





