Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Generic User Avatar

AVG finds malware/virus upon pc starting. playing games turns off PC


  • Please log in to reply
38 replies to this topic

#31 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 20 April 2024 - 08:40 PM

Greetings.

Thank you for all the uploads. We are going to start with clearing out AVG/Avast remnants.

It would be helpful to take a cellphone picture of, or print out the instructions for reference.

===================================================

Farbar Recovery Scan Tool Fix - Safe Mode Command Prompt with Attached File

--------------------
  • If necessary, download Farbar Recover Scan Tool for 64 bit systems and save it to a USB device
  • Download Attached File  Fixlist.txt   47.79KB   3 downloads and save it in the same USB device
  • Click Start, type msconfig, then select Run as administrator
  • Click on the Boot tab
  • Check Safe boot, then select Alternative shell
  • Click Apply, then OK
  • Click Restart and allow the black Command Prompt window to appear
  • Insert the USB device into your compromised computer
  • In the command window type in Notepad and press Enter.
  • Under File menu select Open
  • Locate and and left click on your USB drive letter
  • Near the lower right hand corner of the Open window change Text Documents (*.txt) to All Files (*.*)
  • Right click on the FRST icon and select Run as administrator
  • Click Yes to disclaimer that may appear
  • Press Fix button
  • Click OK to restart your computer
  • A fixlog.txt file will be saved on the USB drive. Please attach it to your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Attached Fixlog

Edited by Oh My!, 21 April 2024 - 05:15 PM.

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

BC AdBot (Login to Remove)

 


#32 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 21 April 2024 - 06:37 AM

It states

Warning:
Looks you don't know what to do. To prevent damage to the system the tool will exit.

#33 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 21 April 2024 - 07:49 AM

Are both FRST64.exe and the Fixlist.txt file on the same USB? That warning means they are not in the same location.


Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#34 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 21 April 2024 - 01:32 PM

Yes both on usb. I tried it without the txt file and it said fixlist.txt not found for muddy be in same directory as Frst64.exe

Is there an error in the text file somewhere?

Edited by Dustin77, 21 April 2024 - 02:37 PM.


#35 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 21 April 2024 - 05:16 PM

Please try the instructions again. I modified the Fixlist.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#36 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 22 April 2024 - 04:34 AM

Finally. lol. here is the fixlogAttached File  Fixlog.txt   102.1KB   1 downloads



#37 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 22 April 2024 - 08:55 AM

Great, thanks.

I would like us to test for the Plex/.js file detection you previously experienced with AVG. Launch Plex, turn on Windows Defender, then run a scan. Let me know the results.
Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69

#38 Dustin77

Dustin77
  • Topic Starter

  •  Avatar image
  • Members
  • 22 posts
  • OFFLINE
  •  
  • Local time:02:30 PM

Posted 22 April 2024 - 02:26 PM

i have no real time protection in defender. it states that virus and threat protection is managed by your organization.

 

where do i do the scan?



#39 Oh My!

Oh My!

    Adware and Spyware and Malware


  •  Avatar image
  • Malware Response Instructor
  • 57,428 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:09:30 PM

Posted 22 April 2024 - 04:05 PM

Please run this then attempt to access and run a Windows Defender Full Scan.

===================================================

Farbar Recovery Scan Tool Fix

--------------------
  • Right click on the FRST64 icon and select Run as administrator
  • Highlight the below information then hit the Ctrl + C keys at the same time and the text will be copied
  • There is no need to paste the information anywhere, FRST64 will do it for you
Start::

Powershell: Set-MpPreference -EnableControlledFolderAccess Disabled
Powershell: Set-MpPreference -DisableRealtimeMonitoring $true


ExportKey: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender
[-HKLM\SOFTWARE\Policies\Microsoft\Windows Defender]

StartRegedit: 

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender]
"DisableAntiSpyware"=dword:00000000

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender\Policy Manager]

EndRegedit:

ExportKey: HKLM\SOFTWARE\Policies\Microsoft\Windows Defender

Powershell: Set-MpPreference -EnableControlledFolderAccess Enabled
Powershell: Set-MpPreference -DisableRealtimeMonitoring $false
Powershell: Get-MpComputerStatus
End::
  • Click Fix
  • When completed the tool will create a log on the desktop called Fixlog.txt. Please copy and paste the contents of the file in your reply.
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it.
  • Fixlog
  • Defender Scan detections?

Gary 

Lord, to whom shall we go? You have the words of eternal life. We have come to believe and to know that you are the Holy One of God.

John 6:68-69




1 user(s) are reading this topic

0 members, 1 guests, 0 anonymous users