AVG anti-virus help............. | FerrariChat

AVG anti-virus help.............

Discussion in 'Technology' started by kizdan, Oct 2, 2008.

This site may earn a commission from merchant affiliate links, including eBay, Amazon, Skimlinks, and others.

  1. kizdan

    kizdan F1 Veteran

    Dec 31, 2003
    5,505
    I bought AVG anti-virus, anti-spyware software. I run a virus scan almost every day. Each time I run it, I get 10 -25 threats found, that either get deleted or moved to a vault. It seems to be the same ones every time I run it.

    This only happens when the computer has been shut down in between scans.

    I looked at the list of viruses found and opened the folder where they were originating from. I tried to delete what was in there, and got a warning saying something like this was part of the core Windows programming, or something along those lines.

    My impression is that there is some kind of seed that is not erasable, and it keeps regenerating itself every time I turn the computer on.

    How do I get rid of it for good?!?!?!?
     
  2. Etcetera

    Etcetera Two Time F1 World Champ
    Silver Subscribed

    Dec 7, 2003
    24,011
    Full Name:
    C6H14O5
    Try booting Windows in safe mode and running the AV from there.
     
  3. Wade

    Wade Three Time F1 World Champ
    Owner

    Mar 31, 2006
    32,793
    East Central, FL
    Full Name:
    Wade O.
    Got a screen grab?

    BTW, I'm using AVG and hate it. I doing an evaluation and can't wait till it's over.
     
  4. taber

    taber Formula 3

    Mar 4, 2005
    1,582
    San Francisco
    Full Name:
    Norman
    no complaints with the free version.

    v8.0 sucks though, make sure you don't install the toolbar and link scanner. It only slows down everything.
     
  5. Whisky

    Whisky Three Time F1 World Champ
    Silver Subscribed

    Jan 27, 2006
    31,938
    In the flight path to Offutt
    Full Name:
    The original Fernando
    I have AVG and have no problems.

    I would do this:

    Download all the latest updates for it, then download and install SPYBOT, update it, then download and install HIJACK THIS and update it,(don't run the scans yet)

    THEN:

    Unplug your computer from the Internet (pull the wire, turn off the wireless router, THEN boot into safe mode, and run all the virus checks from there.
    Everyone should try this, you would be amazed how many things you find when not physically not connected to the internet, because some trojan horses
    'talk to' your computer and they are not detected, but when that connection is cut, they get found and flagged.
     
  6. Schatten

    Schatten F1 World Champ
    Owner

    Apr 3, 2001
    11,238
    Austin, TX
    Full Name:
    Randy
    Need to know the items that are being removed. It seems they are sneaky and reloading themselves or you have some application that you are unaware of which fetches more applications to the same directory.
     
  7. kizdan

    kizdan F1 Veteran

    Dec 31, 2003
    5,505
    I'll give this a shot.

    What is the difference running anti virus in "safe mode" vs standard mode?
     
  8. bpu699

    bpu699 F1 World Champ
    Owner Silver Subscribed

    Dec 9, 2003
    17,720
    wisconsin/chicago
    Full Name:
    bo
    Fascinating...

    Half the crap viruses on my computer I can get rid off...

    My 6 year old kids have a dedicated PC they use. They load on free games, surf Youtube, and load in Poke-mon movies. Their computers are teaming with viruses every time I run a check, even though AVG is on there...

    Their pc is on the same router as another PC in our house...

    Quite frankly, anything that requires a password/financial info/credit card info... I do on the MAC. No problems whatsoever...
     
  9. Etcetera

    Etcetera Two Time F1 World Champ
    Silver Subscribed

    Dec 7, 2003
    24,011
    Full Name:
    C6H14O5
    Safe Mode does not load anything but the most basic drivers, nor does it load programs that automatically start up. Many types of malware will not allow themselves to be deleted if they are already running. Since Safe Mode disables autorun of programs, viruses are not loaded, and can be deleted by the AV program.
     
  10. Etcetera

    Etcetera Two Time F1 World Champ
    Silver Subscribed

    Dec 7, 2003
    24,011
    Full Name:
    C6H14O5
    Except that Safe Mode has more than one mode. Safe Mode does not load NIC drivers unless you tell it to do so by selecting Safe Mode with Network Support option.
     
  11. Schatten

    Schatten F1 World Champ
    Owner

    Apr 3, 2001
    11,238
    Austin, TX
    Full Name:
    Randy
    Viruses aren't just about destruction and infection these days. They gotta do something and they gotta bring in the dollars.

    And most likely, your kids' computer has been turned into a drone computer, sending out spam like other heavily infected pcs.
     
  12. Wade

    Wade Three Time F1 World Champ
    Owner

    Mar 31, 2006
    32,793
    East Central, FL
    Full Name:
    Wade O.
    No kidding, the only thing worse than a zombie computer relaying spam is a porn proxy.

    Zombie computer
    Hijacked Windows PCs Spread Porn
     
  13. kizdan

    kizdan F1 Veteran

    Dec 31, 2003
    5,505
    Okay, tried your recommendation this weekend.

    When I ran "Hijack This", it came up with quite a few things that I don't know what to have deleted, and what to keep.
     
  14. Schatten

    Schatten F1 World Champ
    Owner

    Apr 3, 2001
    11,238
    Austin, TX
    Full Name:
    Randy
    You don't want to delete everything. Hijackthis only provides you with information to look into, it doesn't provide you with a list of things to remove. Just copy and paste the log file here in this thread or email it to one of us.
     
  15. kizdan

    kizdan F1 Veteran

    Dec 31, 2003
    5,505
    Here's what came up;

    Logfile of HijackThis v1.99.1
    Scan saved at 12:06:31 PM, on 10/5/2008
    Platform: Windows XP SP3 (WinNT 5.01.2600)
    MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)

    Running processes:
    C:\WINDOWS\System32\smss.exe
    C:\WINDOWS\system32\winlogon.exe
    C:\WINDOWS\system32\services.exe
    C:\WINDOWS\system32\lsass.exe
    C:\WINDOWS\system32\svchost.exe
    C:\WINDOWS\system32\svchost.exe
    C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
    C:\WINDOWS\Explorer.EXE
    C:\Program Files\HijackThis\HijackThis.exe

    R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
    R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.dellnet.com
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.dellnet.com
    O2 - BHO: IDM Helper - {0055C089-8582-441B-A0BF-17B458C2A3A8} - C:\Program Files\Internet Download Manager\IDMIECC.dll
    O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
    O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
    O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
    O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
    O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
    O4 - HKLM\..\Run: [DVDSentry] C:\WINDOWS\System32\DSentry.exe
    O4 - HKLM\..\Run: [PCMService] "C:\Program Files\Dell\Media Experience\PCMService.exe"
    O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
    O4 - HKLM\..\Run: [DwlClient] C:\Program Files\Common Files\Dell\EUSW\Support.exe
    O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
    O4 - HKLM\..\Run: [UpdateManager] "C:\Program Files\Common Files\Sonic\Update Manager\sgtray.exe" /r
    O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack
    O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
    O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
    O4 - HKLM\..\Run: [mmtask] "C:\Program Files\MUSICMATCH\MUSICMATCH Jukebox\mmtask.exe"
    O4 - HKLM\..\Run: [WD Button Manager] WDBtnMgr.exe
    O4 - HKLM\..\Run: [RetroExpress] C:\PROGRA~1\RETROS~1\RETROS~1.0\RetroExpress.exe /h
    O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
    O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
    O4 - HKCU\..\Run: [IDMan] C:\Program Files\Internet Download Manager\IDMan.exe /onboot
    O4 - HKCU\..\Run: [TomTomHOME.exe] "C:\Program Files\TomTom HOME 2\HOMERunner.exe"
    O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe
    O4 - Startup: Forget Me Not.lnk = C:\Program Files\Mindscape\AGCraft\PMREMIND.EXE
    O4 - Startup: V CAST Music Monitor.lnk = C:\Program Files\Verizon Wireless\V CAST Music\V CAST Music Monitor.exe
    O4 - Global Startup: Acrobat Assistant.lnk = C:\Program Files\Adobe\Acrobat 6.0\Distillr\acrotray.exe
    O4 - Global Startup: Digital Line Detect.lnk = ?
    O4 - Global Startup: Distiller Assistant 3.0.lnk = C:\Acrobat3\Distillr\DISTASST.EXE
    O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
    O4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exe
    O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
    O4 - Global Startup: Wireless Network Monitor.lnk = C:\Program Files\Linksys\WUSB600N\WUSB600N.exe
    O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
    O8 - Extra context menu item: Download all links with IDM - C:\Program Files\Internet Download Manager\IEGetAll.htm
    O8 - Extra context menu item: Download FLV video content with IDM - C:\Program Files\Internet Download Manager\IEGetVL.htm
    O8 - Extra context menu item: Download with IDM - C:\Program Files\Internet Download Manager\IEExt.htm
    O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll (file missing)
    O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll
    O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
    O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)
    O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
    O16 - DPF: {3BFFE033-BF43-11D5-A271-00A024A51325} (iNotes6 Class) - https://sctcdm07.extra.daimlerchrysler.com/iNotes6W.cab
    O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,96/mcinsctl.cab
    O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
    O16 - DPF: {BCC0FF27-31D9-4614-A68E-C18E1ADA4389} - http://download.mcafee.com/molbin/shared/mcgdmgr/1,0,0,26/mcgdmgr.cab
    O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} (GpcContainer Class) - https://vistaprintwebinars.webex.com/client/T25L/event/ieatgpc.cab
    O20 - Winlogon Notify: avgwlntf - C:\WINDOWS\SYSTEM32\avgwlntf.dll
    O20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)
    O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
    O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
    O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
    O23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exe
    O23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exe
    O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    O23 - Service: Intel NCS NetService (NetSvc) - Intel(R) Corporation - C:\Program Files\Intel\NCS\Sync\NetSvc.exe
    O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
    O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
    O23 - Service: Retrospect Express HD Helper (RetroExp Helper) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.0\rthlpsvc.exe
    O23 - Service: Retrospect Express HD Launcher (RetroExpLauncher) - EMC Corporation - C:\PROGRA~1\RETROS~1\RETROS~1.0\retrorun.exe
    O23 - Service: Roxio UPnP Renderer 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUPnPRenderer9.exe
    O23 - Service: Roxio Upnp Server 9 - Sonic Solutions - C:\Program Files\Roxio\Digital Home 9\RoxioUpnpService9.exe
    O23 - Service: RoxMediaDB9 - Sonic Solutions - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    O23 - Service: USB2.0 VIDBOX NW01 Service (StkASSrv) - Syntek America Inc. - C:\WINDOWS\System32\StkASv2K.exe
    O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe
     
  16. Fenivision

    Fenivision Formula Junior

    Sep 25, 2008
    486
    SoCal
    Full Name:
    Alexander
    I used to run Nod32 when I still had a PC and was really impressed.
    Now I'm waiting for their Mac version.

    Hope you can solve that though.
     
  17. thecarreaper

    thecarreaper F1 World Champ
    Silver Subscribed

    Sep 30, 2003
    18,076
    Savannah
    nod32 is excellent. i was a fan of zone alarm, but they changed something, and it really slowed everything down. i also had avg on 2 computers in my network, and never had issues with it. i do want to try the safe mode scan.... be neat to see if i missed anything.
     
  18. bpu699

    bpu699 F1 World Champ
    Owner Silver Subscribed

    Dec 9, 2003
    17,720
    wisconsin/chicago
    Full Name:
    bo
    Ok... how do you boot in safe mode???

    Shut the computer off, waited for the message to press F8 or is it F10 during start up... it flashed so quickly I couldn't get it into safe mode. Tried 3 times, and gave up...

    Is it different on Vista?!

    Do any of those optimization programs work? I swear to god it takes my wife's laptop 15 minutes to boot... Once running, it is tsill ungodly slow...
     
  19. Gran Drewismo

    Gran Drewismo F1 Rookie

    Jan 24, 2005
    3,778
    Idaho
    Full Name:
    Andrew
    What I usually do is start hitting F8 repeatedly after powering the machine on until it comes to the Windows boot menu.
     
  20. PAP 348

    PAP 348 Ten Time F1 World Champ
    Lifetime Rossa Owner

    Dec 10, 2005
    100,220
    Mount Isa, Australia
    Full Name:
    Pap
    How do you boot your computer in safe mode again?? :D:D

    I forget how to do it. :eek::eek:
     
  21. Etcetera

    Etcetera Two Time F1 World Champ
    Silver Subscribed

    Dec 7, 2003
    24,011
    Full Name:
    C6H14O5
    F8 after BIOS sequence.
     
  22. PAP 348

    PAP 348 Ten Time F1 World Champ
    Lifetime Rossa Owner

    Dec 10, 2005
    100,220
    Mount Isa, Australia
    Full Name:
    Pap

    Cheers brother. I just got it. :D:D
     
  23. kizdan

    kizdan F1 Veteran

    Dec 31, 2003
    5,505
    Well, I've tried everything, and the problem keeps getting worse and worse. Now every time I run both Spybot and AVG, the amount of viruses and spyware increases each and every time. I think I am getting to the point where I'll have to wipe my hard drive clean and start from scratch again. I e-mailed AVG about the problem and they never even bothered to respond.
     
  24. Schatten

    Schatten F1 World Champ
    Owner

    Apr 3, 2001
    11,238
    Austin, TX
    Full Name:
    Randy
    They don't need to respond, it is a free app.

    Regarding your problem - looks like you have an app that downloads various apps at will. There's no telling what your computer is doing when you are not tending to it. Do you have a list of apps that are being downloaded, or more importantly, where they are found?
     
  25. kizdan

    kizdan F1 Veteran

    Dec 31, 2003
    5,505
    #25 kizdan, Oct 27, 2008
    Last edited: Oct 27, 2008
    I have a paid version of AVG, so they should be supporting it.

    When I run AVG, I do a "detailed user" scan, and it does provide a list of everything found. It seems a lot of them are traced back to a folder called "Application Data" (which is a hidden folder), within an Earthlink folder (I don't even have Earthlink anymore). If I try to erase this folder, it tells me that it is part of Windows, and that it cannot be deleted.
     

Share This Page