Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: AVG detection was going crazy  (Read 7198 times)

0 Members and 1 Guest are viewing this topic.

Veltas

    Topic Starter


    Intermediate

    Thanked: 7
    • Yes
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Linux variant
AVG detection was going crazy
« on: June 30, 2014, 09:19:55 AM »
AVG detection was going crazy, but now after running the software in the stickyed forum topic and following the instructions I am not getting the messages anymore.

I wish I had taken some screenshots before running this software because now certain suspicious programs are no longer starting when logging in, and have probably been removed from the computer. I think names such as "PC Speedup" and "PC Health kit" or things along those lines were there.

I'm afraid I can only guess how this malware was introduced because my family uses this laptop and not me. If anyone has any tips for getting less of this malware I can pass onto them that would also be greatly appreciated.

Logs are attached
Malwarebytes XML log: http://www.filedropper.com/mbam-log-2014-06-3015-41-00

EDIT: I should probably mention the computer has Windows 8 64-bit installed, uses AVG for virus security, Windows Firewall, and most accounts are administrator accounts.

[recovering disk space, attachment deleted by admin]

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: AVG detection was going crazy
« Reply #1 on: June 30, 2014, 01:04:10 PM »
Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer.

1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
2. The fixes are specific to your problem and should only be used for this issue on this machine.
3. If you don't know or understand something, please don't hesitate to ask.
4. Please DO NOT run any other tools or scans while I am helping you.
5. It is important that you reply to this thread. Do not start a new topic.
6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
7. Absence of symptoms does not mean that everything is clear.

If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
*************************************************************************
Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

Quote
I'm afraid I can only guess how this malware was introduced because my family uses this laptop and not me. If anyone has any tips for getting less of this malware I can pass onto them that would also be greatly appreciated.
This sort of malware usually is loaded along with other programs. That's why it's important to pay attention when downloading and installing certain free programs of the net. I will give more instructions at the end about how to protect your computer.
*********************************************
Please run MBAM again and see if it picks up anything else. Only post the log if there is something else.
*************************************************
Please download Junkware Removal Tool to your desktop.

Warning! Once the scan is complete JRT will shut down your browser with NO warning.

Shut down your protection software now to avoid potential conflicts.

•Temporarily disable your Antivirus and any Antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.

•Run the tool by double-clicking it. If you are using Windows Vista or Windows 7, right-click JRT and select Run as Administrator

•The tool will open and start scanning your system.

•Please be patient as this can take a while to complete depending on your system's specifications.

•On completion, a log (JRT.txt) is saved to your desktop and will automatically open.

•Copy and Paste the JRT.txt log into your next message.
************************************************
Windows 8 comes with its own AV called Windows Defender. If you wish to use another AV such as AVG, you will need to disable Windows Defender.

Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.


First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
***************************************************
Malwarebytes' Anti-Rootkit

Please download Malwarebytes' Anti-Rootkit and save it to your desktop.
  • Be sure to print out and follow the instructions provided on that same page for performing a scan.
  • Caution: This is a beta version so also read the disclaimer and back up all your data before using.
  • When the scan completes, click on the Cleanup button to remove any threats found and reboot the computer if prompted to do so.
  • Perform another scan with Malwarebytes Anti-Rootkit to verify that no threats remain. If they do, then click Cleanup once more and repeat the process.
  • If there are problems with Internet access, Windows Update, Windows Firewall or other system issues, run the fixdamage tool located in the folder Malwarebytes Anti-Rootkit was run from and reboot your computer.
  • Two files (mbar-log-YYYY-MM-DD, system-log.txt) will be created and saved within that same folder.
  • Copy and paste the contents of these two log files in your next reply.
Windows 8 and Windows 10 dual boot with two SSD's

Veltas

    Topic Starter


    Intermediate

    Thanked: 7
    • Yes
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Linux variant
Re: AVG detection was going crazy
« Reply #2 on: July 01, 2014, 02:47:06 PM »
Ran malwarebytes again and got one result (attached file scan2.txt).

Ran JRT with AV disabled, a few results (attached file JRT.txt).

Windows Defender is disabled (albeit I'm considering removing AVG and just using Windows Defender).

Updated Java.

Removed older Java versions (logfile available at request).

While attempting malwarebytes anti-rootkit scan: first thing that happens is an error message appears in the stage "Scan System" with title "Could not load DDA driver" and message details "DDA driver was not installed which may be caused by rootkit activity. Do you want to reboot the computer to install DDA driver (Scan will continue after reboot)?" with options Yes and No. Selecting Yes results in another error message: "Error" "Could not install driver on boot. Scan can't continue". This topic https://forums.malwarebytes.org/index.php?/topic/127463-could-not-load-dda-driver/ suggested disabling AV, but this didn't fix the problem. Selecting No also fails the scan.

Running fixdamage.exe and restarting fixed the problem and it performed its scan. Logfiles attached (mbar-log-??? and system-log.txt).

Also, if it helps, the model of the laptop is a Lenovo G580 (2689).

Thanks a lot for the help so far.

[recovering disk space, attachment deleted by admin]

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: AVG detection was going crazy
« Reply #3 on: July 01, 2014, 05:54:26 PM »
Quote
Windows Defender is disabled (albeit I'm considering removing AVG and just using Windows Defender).
Good decision. WD is efficient and not a resource hog. If you can't uninstall AVG you can use this tool below.

AVG Antivirus - AVG Anti-virus Removal Tool

Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan

•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
  • Leave the check mark next to Remove found threats.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Windows 8 and Windows 10 dual boot with two SSD's

Veltas

    Topic Starter


    Intermediate

    Thanked: 7
    • Yes
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Linux variant
Re: AVG detection was going crazy
« Reply #4 on: July 02, 2014, 07:52:24 AM »
Please do not attach your logs unless absolutely necessary. Copy and paste them in your reply(ies)

Whoops, sorry.

Ran ESET and got the results:


C:\$Recycle.Bin\S-1-5-21-1678877460-1370999422-2246632477-1004\$R4AF2EV.exe   a variant of Win32/Toolbar.SearchSuite.A potentially unwanted application   deleted - quarantined
C:\$Recycle.Bin\S-1-5-21-1678877460-1370999422-2246632477-1004\$RVBI11E.exe   a variant of Win32/Toolbar.SearchSuite.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Buzz-it Corp\Buzz-it_wd.exe.vir   a variant of Win32/AdWare.AddLyrics.AJ application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Buzz-it Corp\Buzzi.exe.vir   a variant of Win32/AdWare.AddLyrics.AI application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Buzz-it Corp\Uninstall.exe.vir   a variant of Win32/AdWare.AddLyrics.AH application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll.vir   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll.vir   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe.vir   a variant of Win32/Toolbar.SearchSuite.D potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe.vir   a variant of Win32/Toolbar.SearchSuite.O potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_DLL_nsw2732.dll.vir   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_EXE_nsw2732.exe.vir   a variant of Win32/Toolbar.SearchSuite.O potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_LL_nsw2732.dll.vir   Win32/Toolbar.SearchSuite.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_mg_nsw2732.dll.vir   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\Helper.dll.vir   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\IEBHO.dll.vir   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\Internet Explorer Settings.exe.vir   a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll.vir   a variant of Win32/Toolbar.SearchSuite.S potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe.vir   a variant of Win32/Toolbar.Visicom.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\__searchresultsDx.dll.vir   a variant of Win32/Toolbar.Visicom.B potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\__searchresultstb.dll.vir   a variant of Win32/Toolbar.Visicom.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll.vir   a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\Datamngr.dll.vir   a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\del_DM_LL_nsw2732.dll.vir   a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\IEBHO.dll.vir   a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\Internet Explorer Settings.exe.vir   a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\mgrldr.dll.vir   a variant of Win64/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Nosibay\Bubble Dock\extensions\axSurfMatch.dll.vir   Win32/BubbleDock.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Nosibay\Bubble Dock\extensions\GCSurfMatch.crx.vir   Win32/BubbleDock.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Health Kit\PCHealthKit.exe.vir   a variant of Win32/SpeedingUpMyPC application   cleaned by deleting - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir   a variant of Win32/Conduit.SearchProtect.H potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir   a variant of Win32/Conduit.SearchProtect.H potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir   a variant of Win32/Conduit.SearchProtect.H potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir   a variant of Win64/Conduit.SearchProtect.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir   a variant of Win32/Conduit.SearchProtect.I potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe.vir   Win32/SpeedUpMyPC potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win32cert.dll.vir   Win32/Toolbar.SearchSuite.M potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win32prop.dll.vir   Win32/Toolbar.SearchSuite.M potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win64cert.dll.vir   Win64/Toolbar.SearchSuite.B potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win64prop.dll.vir   Win64/Toolbar.SearchSuite.B potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialApp.dll.vir   a variant of Win32/Toolbar.Montiera.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialEng.dll.vir   probably a variant of Win32/Toolbar.Montiera.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialsrv.exe.vir   a variant of Win32/Toolbar.Montiera.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll.vir   a variant of Win32/Toolbar.Montiera.F potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\bh\mysearchdial.dll.vir   a variant of Win32/Toolbar.Escort.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\SaveSense\SaveSenseIE.dll.vir   Win32/SaveSense.A potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\SaveSense\SaveSenseUpdateVer.exe.vir   a variant of Win32/DealPly.M potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\torch\Helper.dll.vir   a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Roaming\Mysearchdial\UpdateProc\UpdateTask.exe.vir   a variant of Win32/DealPly.S potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\George\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe.vir   a variant of Win32/DealPly.S potentially unwanted application   deleted - quarantined
C:\AdwCleaner\Quarantine\C\Users\Julie\AppData\Roaming\Nosibay\Bubble Dock\Bubble Dock Update.exe.vir   Win32/BubbleDock.A potentially unwanted application   deleted - quarantined
C:\Program Files (x86)\Savevid\Helper.dll   a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\11E43AM6\Installer_20130403[1].exe   a variant of Win32/Toolbar.Linkury.E potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6E332VDT\DefaultTabSetup_1500[1]   a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EYVU3Y80\iTunes.exe   Win32/OutBrowse.M potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK7PX2ME\Cloud_Backup_Setup[1]   Win32/MyPCBackup.A potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK7PX2ME\SavevidSetupV2.exe   a variant of Win32/Toolbar.SearchSuite.A potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\ezdtcehM.exe.part   a variant of Win32/InstallCore.D potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\xJjYYo1T.exe.part   Win32/InstallCore.BN potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\is357113909\158716626_stp\wajam_validate.exe   Win32/Wajam.F potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\is357113909\158716978_stp\uninstaller.exe   Win32/InstallCore.AZ potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsg21EE.tmp\Helper.dll   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsg21EE.tmp\Starter.exe   Win32/Toolbar.SearchSuite.M potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsl1732.tmp\Helper.dll   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsl1732.tmp\Starter.exe   Win32/Toolbar.SearchSuite.M potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsl1732.tmp\~nso786F.tmp   Win32/Toolbar.SearchSuite.M potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsl9BC5.tmp\Helper.dll   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsl9BC5.tmp\Starter.exe   Win32/Toolbar.SearchSuite.M potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsx35BC.tmp\Helper.dll   a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsxDDFC.tmp\Helper.dll   a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application   deleted - quarantined
C:\Users\George\AppData\Local\Temp\nsxDDFC.tmp\~nsl32BC.tmp   a variant of Win32/Toolbar.SearchSuite.M potentially unwanted application   deleted - quarantined
C:\Users\George\Downloads\FastDownload.exe   Win32/InstallMate.A potentially unwanted application   deleted - quarantined
C:\Users\George\Downloads\pivot_setup.exe   Win32/Somoto.F potentially unwanted application   deleted - quarantined

[/quote]

and:

Quote from: log.txt

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.7587
# api_version=3.0.2
# EOSSerial=d0c8b59bce97264fa2c0cb0066175468
# engine=18977
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-07-02 04:24:05
# local_time=2014-07-02 05:24:05 (+0000, GMT Daylight Time)
# country="United Kingdom"
# lang=1033
# osver=6.2.9200 NT
# compatibility_mode_1='AVG AntiVirus Free Edition 2013'
# compatibility_mode=1044 16777213 100 87 35571 91376629 0 0
# compatibility_mode_1=''
# compatibility_mode=5893 16776574 100 94 3863563 35847975 0 0
# scanned=231519
# found=72
# cleaned=72
# scan_time=4640
sh=2C3E6F0BAD4EFB0F44F70392809F316D7B7A25A8 ft=1 fh=be84e9cff61cc62f vn="a variant of Win32/Toolbar.SearchSuite.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\$Recycle.Bin\S-1-5-21-1678877460-1370999422-2246632477-1004\$R4AF2EV.exe"
sh=2C3E6F0BAD4EFB0F44F70392809F316D7B7A25A8 ft=1 fh=be84e9cff61cc62f vn="a variant of Win32/Toolbar.SearchSuite.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\$Recycle.Bin\S-1-5-21-1678877460-1370999422-2246632477-1004\$RVBI11E.exe"
sh=22179EF610F4B2EB51B0DCE4D6EB0116654764E4 ft=1 fh=e5161ae672e3be7a vn="a variant of Win32/AdWare.AddLyrics.AJ application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Buzz-it Corp\Buzz-it_wd.exe.vir"
sh=B60B8A2BB15D5BA67982A03F145FE94455679EDA ft=1 fh=c71c00115bf86cbd vn="a variant of Win32/AdWare.AddLyrics.AI application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Buzz-it Corp\Buzzi.exe.vir"
sh=5CF7AE59EEE2A82DBD2195D9168258C7A793EEE5 ft=1 fh=aa85274350b73ff1 vn="a variant of Win32/AdWare.AddLyrics.AH application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Buzz-it Corp\Uninstall.exe.vir"
sh=EF1E359782475F4EC9EB3B5194EF321EF98FCEF0 ft=1 fh=c1c82c5b6a45b692 vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\apcrtldr.dll.vir"
sh=9E5BC8A0B37E814F209C42185A29C2ACF406D8AB ft=1 fh=ff5608a60d96ce45 vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\Datamngr.dll.vir"
sh=6AB6F7E34CAFBE27EDA2380C39E3FF1A2ED8BCF2 ft=1 fh=718133fd69ff057b vn="a variant of Win32/Toolbar.SearchSuite.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrCoordinator.exe.vir"
sh=3B041A73B7630948FEEC897B8990A0CDA4348633 ft=1 fh=67a78b00bc20bc32 vn="a variant of Win32/Toolbar.SearchSuite.O potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\DatamngrUI.exe.vir"
sh=2F0DA3C0C1EF884EDF9F1559392307DE6AEF32A9 ft=1 fh=ae5ed1c8e5c2e778 vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_DLL_nsw2732.dll.vir"
sh=2B0B04C6637690BD0F36DAFFB724A872F134275F ft=1 fh=bd25ca2916b50071 vn="a variant of Win32/Toolbar.SearchSuite.O potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_EXE_nsw2732.exe.vir"
sh=5DA5144C6032C44EF0E2A9F1B760BA62048C7D59 ft=1 fh=2120e33d18b8ebef vn="Win32/Toolbar.SearchSuite.F potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_DM_LL_nsw2732.dll.vir"
sh=FCF0BEB6D4FC3A856CCEB3AF3D4E075F7E5E370C ft=1 fh=58ceb130a0eabad4 vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\del_mg_nsw2732.dll.vir"
sh=23B5076A4E341E0BAAF9375E178E721787B6839E ft=1 fh=4c03f5ce5d12121f vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\Helper.dll.vir"
sh=62B8083EED333E7154DD49D46C5C44E66E739656 ft=1 fh=098eec8aa1cbc68f vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\IEBHO.dll.vir"
sh=D46E54E60B68ABF5299AFF55CB49375991BAA787 ft=1 fh=4a5300a0700faf17 vn="a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\Internet Explorer Settings.exe.vir"
sh=95D58DE86C4A6D42D6CCC490D5366AE5BC8968FF ft=1 fh=4090a01dc2b97419 vn="a variant of Win32/Toolbar.SearchSuite.S potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\mgrldr.dll.vir"
sh=BFDC3839ACE19D582651CBDBCA401D85ACB87CEE ft=1 fh=c71c0011ea55d4ef vn="a variant of Win32/Toolbar.Visicom.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\dtUser.exe.vir"
sh=E02E52D8D6D4809A43A0747AD2D43EA571EFAF81 ft=1 fh=28dc55d634c41655 vn="a variant of Win32/Toolbar.Visicom.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\__searchresultsDx.dll.vir"
sh=AEE777C33B56057601631AB4644C0978BCA2A1C8 ft=1 fh=42e798c3bb668ec2 vn="a variant of Win32/Toolbar.Visicom.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\SRTOOL~1\IE\__searchresultstb.dll.vir"
sh=CFB95664F285F96C14A256B9DD099037C83DD0CD ft=1 fh=26bdc9859ac5874e vn="a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\apcrtldr.dll.vir"
sh=266CEA783ABDF8359FC692BB7BCDD21CAE5BF51E ft=1 fh=a6d892f0c7bcd98a vn="a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\Datamngr.dll.vir"
sh=AF52E069218609F6BD938ABC68374E99EACD4B65 ft=1 fh=7a2c456fb1281cd6 vn="a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\del_DM_LL_nsw2732.dll.vir"
sh=CCAE3D0D944F56B2A8D0D8C693F6A625781F6676 ft=1 fh=22551674c4f08135 vn="a variant of Win64/Toolbar.SearchSuite.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\IEBHO.dll.vir"
sh=0D37E10C3776170FBAC3954E1B46492575F2CDE3 ft=1 fh=1adfbc2e3fdcbace vn="a variant of Win32/Toolbar.SearchSuite.Q potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\Internet Explorer Settings.exe.vir"
sh=95EE0DBCCA0EADC45CEF1F608A2904AF90571066 ft=1 fh=d19d1bc22c9ed3f8 vn="a variant of Win64/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Movies Toolbar\Datamngr\x64\mgrldr.dll.vir"
sh=AAABC4DCD137FD5FA7A262B8946562362DA4B87B ft=1 fh=67aa170b9ae6a09a vn="Win32/BubbleDock.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Nosibay\Bubble Dock\extensions\axSurfMatch.dll.vir"
sh=E31170FB27C4B768CAB91E1ED34DA518A629A2AC ft=0 fh=0000000000000000 vn="Win32/BubbleDock.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Nosibay\Bubble Dock\extensions\GCSurfMatch.crx.vir"
sh=7300AECAF125F863577FF0C9994B4F55D8BD5ED1 ft=1 fh=d0789cb125174225 vn="a variant of Win32/SpeedingUpMyPC application (cleaned by deleting - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\PC Health Kit\PCHealthKit.exe.vir"
sh=68BF1E0437E11832B4DC5E9923DCA5FFB92914AC ft=1 fh=fe3fcc60a0369b2a vn="a variant of Win32/Conduit.SearchProtect.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\SPTool.dll.vir"
sh=74ADF35C3A3456993B5D72F70AE1EDEB28987C80 ft=1 fh=90d7e36e3b85c7e4 vn="a variant of Win32/Conduit.SearchProtect.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\Main\bin\uninstall.exe.vir"
sh=8A0819C25BB2568FF451BED451955B4E69E724D7 ft=1 fh=7bc6a5dd57c41934 vn="a variant of Win32/Conduit.SearchProtect.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32.dll.vir"
sh=01E8A066B023DAACD6FE9CBC35372A56BE6EC5B1 ft=1 fh=832dcd421f4cfd2d vn="a variant of Win64/Conduit.SearchProtect.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll.vir"
sh=FB7948E63D42672E50D4A521CDB6DBACD615D773 ft=1 fh=fc81cec60cf9c6da vn="a variant of Win32/Conduit.SearchProtect.I potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\SearchProtect\UI\bin\cltmngui.exe.vir"
sh=7F986BDBD7AFD6AE68CC9FFE045A4924D28B5CFF ft=1 fh=aeeeb867773cd084 vn="Win32/SpeedUpMyPC potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Program Files (x86)\Uniblue\SpeedUpMyPC\speedupmypc.exe.vir"
sh=E15DF75E5B81A209E0E453092C9610C3F8DC7073 ft=1 fh=8918dac93ad3a346 vn="Win32/Toolbar.SearchSuite.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win32cert.dll.vir"
sh=9B56D5787C88CF939DABA1E9273775A1D33EF25F ft=1 fh=8aacdf233e2d6e39 vn="Win32/Toolbar.SearchSuite.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win32prop.dll.vir"
sh=2FA019C3D1CC2BC1905FBD6765DA3CFBE851DD64 ft=1 fh=f275e610e24fd946 vn="Win64/Toolbar.SearchSuite.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win64cert.dll.vir"
sh=34ABB88310B01A075382292FDE9F2B6E727E5D66 ft=1 fh=1bef8d0f51d0bf3a vn="Win64/Toolbar.SearchSuite.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\wincert\win64prop.dll.vir"
sh=31D0B125962639ACC9DF9F39782A3207099DD924 ft=1 fh=ca95fc211bc2fbc3 vn="a variant of Win32/Toolbar.Montiera.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialApp.dll.vir"
sh=6857BD88EA938B705EFC3FD46D5C91D2C1B3EDE9 ft=1 fh=a2f65d85debd6839 vn="probably a variant of Win32/Toolbar.Montiera.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialEng.dll.vir"
sh=7ABB587B2A0D80E1EC4B2F1E8BB0E2C194FBB4A0 ft=1 fh=9074270edfd38722 vn="a variant of Win32/Toolbar.Montiera.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialsrv.exe.vir"
sh=3407FB00757C71D9CB28AEC2EC7855FF5D3A6609 ft=1 fh=67364266c19decdd vn="a variant of Win32/Toolbar.Montiera.F potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\mysearchdialTlbr.dll.vir"
sh=89DC63472DE94DF3F12DBAE15B7EBE6C04263369 ft=1 fh=7fb9e45e0079471d vn="a variant of Win32/Toolbar.Escort.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\Mysearchdial\1.8.21.0\bh\mysearchdial.dll.vir"
sh=882681090DD5A8A870CE9C88E50FF27CC3B87329 ft=1 fh=015b93fe230fa0e5 vn="Win32/SaveSense.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\SaveSense\SaveSenseIE.dll.vir"
sh=E465456F417ACF3A43FE496EA3E186E6B1FBE7C4 ft=1 fh=295bbdbd63d089cd vn="a variant of Win32/DealPly.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\SaveSense\SaveSenseUpdateVer.exe.vir"
sh=BCFF5E97D1B7D6A0C9DAD30F821BD4B8ADE0514D ft=1 fh=4aaaf7525beb5905 vn="a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Local\torch\Helper.dll.vir"
sh=41C64A74B69F1A74EFE8A5DDE9FF59551E42B205 ft=1 fh=fb35a249052591d3 vn="a variant of Win32/DealPly.S potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Roaming\Mysearchdial\UpdateProc\UpdateTask.exe.vir"
sh=8E84B3369C409B88BFF2F167495B5BDA08485065 ft=1 fh=cea6bc5b1fc91d53 vn="a variant of Win32/DealPly.S potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\George\AppData\Roaming\SaveSense\UpdateProc\UpdateTask.exe.vir"
sh=4CC503EE104508E451343C93E0909BAA24B3EE6C ft=1 fh=341716b8c60f84b9 vn="Win32/BubbleDock.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\Users\Julie\AppData\Roaming\Nosibay\Bubble Dock\Bubble Dock Update.exe.vir"
sh=DD6FA78845D318BE658EFBE29AA64F46B141C3D5 ft=1 fh=fcd8e3d0cc9ffeb6 vn="a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\Savevid\Helper.dll"
sh=AB665E668DE9A986EFB8830DC2DE6BB460A93BC1 ft=1 fh=81e6d9125ab0b147 vn="a variant of Win32/Toolbar.Linkury.E potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\11E43AM6\Installer_20130403[1].exe"
sh=2FD529A338D9A6A4C99FF9F4C64EAC196805D909 ft=1 fh=2703e97b60143d57 vn="a variant of Win32/Toolbar.DefaultTab.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6E332VDT\DefaultTabSetup_1500[1]"
sh=93BF87AF97FD6AB7F0C9B29756B874154C5853DD ft=1 fh=c262713358c3c39c vn="Win32/OutBrowse.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\EYVU3Y80\iTunes.exe"
sh=EEDA63CB3651F4EE4C739B0393FEB686605DB575 ft=1 fh=0dc95380111b3368 vn="Win32/MyPCBackup.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK7PX2ME\Cloud_Backup_Setup[1]"
sh=2C3E6F0BAD4EFB0F44F70392809F316D7B7A25A8 ft=1 fh=be84e9cff61cc62f vn="a variant of Win32/Toolbar.SearchSuite.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\ZK7PX2ME\SavevidSetupV2.exe"
sh=9945D0B5FCE78D5D7BE42B38AEB049640161ADF5 ft=1 fh=c34cb1051b91d273 vn="a variant of Win32/InstallCore.D potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\ezdtcehM.exe.part"
sh=6B1C34E83572B648D78B96611B53C29A42FF938D ft=1 fh=a5b0591b2d6bee7b vn="Win32/InstallCore.BN potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\xJjYYo1T.exe.part"
sh=A836A8346F791EC8A83B51BC78E84B2F6659E6DA ft=1 fh=0a2e45c370149901 vn="Win32/Wajam.F potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\is357113909\158716626_stp\wajam_validate.exe"
sh=9F82BB5DC8D4EC6B8B2BB47CB6C329B8AF1C14CE ft=1 fh=c92ed1f3ca58c043 vn="Win32/InstallCore.AZ potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\is357113909\158716978_stp\uninstaller.exe"
sh=23B5076A4E341E0BAAF9375E178E721787B6839E ft=1 fh=4c03f5ce5d12121f vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsg21EE.tmp\Helper.dll"
sh=3E16AFD8556490C746AF0E1B5183B0AEBFF3A723 ft=1 fh=9e04c8d30ddd55c9 vn="Win32/Toolbar.SearchSuite.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsg21EE.tmp\Starter.exe"
sh=23B5076A4E341E0BAAF9375E178E721787B6839E ft=1 fh=4c03f5ce5d12121f vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsl1732.tmp\Helper.dll"
sh=3E16AFD8556490C746AF0E1B5183B0AEBFF3A723 ft=1 fh=9e04c8d30ddd55c9 vn="Win32/Toolbar.SearchSuite.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsl1732.tmp\Starter.exe"
sh=CC7EBD4BA7795FD75313069A1DC445B27F3914CE ft=1 fh=f16081f84df83856 vn="Win32/Toolbar.SearchSuite.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsl1732.tmp\~nso786F.tmp"
sh=23B5076A4E341E0BAAF9375E178E721787B6839E ft=1 fh=4c03f5ce5d12121f vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsl9BC5.tmp\Helper.dll"
sh=3E16AFD8556490C746AF0E1B5183B0AEBFF3A723 ft=1 fh=9e04c8d30ddd55c9 vn="Win32/Toolbar.SearchSuite.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsl9BC5.tmp\Starter.exe"
sh=BCFF5E97D1B7D6A0C9DAD30F821BD4B8ADE0514D ft=1 fh=4aaaf7525beb5905 vn="a variant of Win32/Toolbar.SearchSuite.P potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsx35BC.tmp\Helper.dll"
sh=DBD55B6771FA154307F2EE370ECAB332429131C6 ft=1 fh=a0d23fff5c9a7968 vn="a variant of Win32/Toolbar.SearchSuite.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsxDDFC.tmp\Helper.dll"
sh=8D154A0A55941DFE19D0341858880AB6F42594DB ft=1 fh=42131fd8e5ca6b40 vn="a variant of Win32/Toolbar.SearchSuite.M potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\AppData\Local\Temp\nsxDDFC.tmp\~nsl32BC.tmp"
sh=E278BCCC0C5649E741CE885C04B8A158724B8CC6 ft=1 fh=429fd215ef5a3712 vn="Win32/InstallMate.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\Downloads\FastDownload.exe"
sh=CDE950F0AF79750E52BA0B4DAF3DA81908472030 ft=1 fh=31688d3353222c47 vn="Win32/Somoto.F potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\George\Downloads\pivot_setup.exe"

« Last Edit: July 02, 2014, 12:45:58 PM by SuperDave »

Veltas

    Topic Starter


    Intermediate

    Thanked: 7
    • Yes
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Linux variant
Re: AVG detection was going crazy
« Reply #5 on: July 02, 2014, 08:30:02 AM »
Have uninstalled AVG, activated Windows Defender.

I want to upgrade my computer to Windows 8.1 but I'm guessing I should wait until we've finished cleaning the system? Or am I okay to do that?

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: AVG detection was going crazy
« Reply #6 on: July 02, 2014, 12:47:56 PM »
Before you upgrade to 8.1 tell me how your computer is working now?
Windows 8 and Windows 10 dual boot with two SSD's

Veltas

    Topic Starter


    Intermediate

    Thanked: 7
    • Yes
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Linux variant
Re: AVG detection was going crazy
« Reply #7 on: July 02, 2014, 01:35:18 PM »
Well it seems to be working fine, in fact it has been seemingly fine since the scans I did before making my initial post.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: AVG detection was going crazy
« Reply #8 on: July 03, 2014, 12:28:12 PM »
Ok, let's do some clean up and then you can install 8.1

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create Registry backup
  • Purge System Restore Points
  • Re-set system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.
**********************************************
Click Start> Computer> right click the C Drive and choose Properties> enter
Click Disk Cleanup from there.



Click OK on the Disk Cleanup Screen.
Click Yes on the Confirmation screen.



This runs the Disk Cleanup utility along with other selections if you have chosen any. (if you had a lot System Restore points, you will see a significant change in the free space in C drive)
************************************************
Go to Microsoft Windows Update and get all critical updates.

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Windows 8 and Windows 10 dual boot with two SSD's

Veltas

    Topic Starter


    Intermediate

    Thanked: 7
    • Yes
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Linux variant
Re: AVG detection was going crazy
« Reply #9 on: July 04, 2014, 10:05:53 AM »
Okay, ran the cleanup tools and upgraded to Windows 8.1.

Anything else I need to do? When you give the okay I will mark the topic as closed and be on my way. Thanks for everything, you've been a great help.

SuperDave

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: AVG detection was going crazy
« Reply #10 on: July 04, 2014, 01:27:18 PM »
Quote
Anything else I need to do? When you give the okay I will mark the topic as closed and be on my way. Thanks for everything, you've been a great help.
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
Windows 8 and Windows 10 dual boot with two SSD's