Author Topic: Antivirus GT  (Read 9624 times)

0 Members and 1 Guest are viewing this topic.

Blue Chip

  • Guest
Antivirus GT
« on: August 05, 2010, 05:54:18 AM »
To all,
   Anyone had a run in with the malware Antivirus GT?  I use the free version of Avast and it did not detect this virus.  Do you know of anyway I can remove it without a lot of pain?
Blue Chip

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Antivirus GT
« Reply #1 on: August 05, 2010, 06:13:27 AM »
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

SafeSurf

  • Guest
Re: Antivirus GT
« Reply #2 on: August 05, 2010, 08:05:06 AM »
You can also check your computer for malware with Malwarebytes’ Anti-Malware (MBAM) and complete disinfection:
·   Download free http://www.malwarebytes.org/ for an on-demand scanner.
·   Double Click mbam-setup.exe to install the application.
·   After install, click update so you have latest database before scanning.
·   Under Settings:
o   General: Automatically Save File After Scan Completes is checked off
o   Scanner SettingsCheck all boxes
o   Updater: Download and install update if available is checked off
·   Once the program has loaded, select "Perform FULL Scan", then click Scan.
·   The scan may take some time to finish, so please be patient.
·   When the disinfection scan is complete, a log will appear in Notepad and you may be prompted to Restart. (See Extra Note).
·   Click the “remove selected” button to quarantine anything found.  You will find the infection details under the Quarantine tab.
·   The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
·   Copy & Paste the entire report in your next reply.  We will analyze the report.

If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts -- Click OK to either and let MBAM proceed with the disinfection process; If asked to restart the computer, please do so immediately.

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Antivirus GT
« Reply #3 on: August 05, 2010, 09:16:46 AM »
Hey SafeSurf, From looking at this thread, It doesn't look like MBAM can find this yet.

http://forums.malwarebytes.org/index.php?showtopic=59451&hl=Antivirus+GT


That's why I suggested The Windows Live OneCare safety scanner 
« Last Edit: August 05, 2010, 09:20:10 AM by Marc57 »
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

SafeSurf

  • Guest
Re: Antivirus GT
« Reply #4 on: August 05, 2010, 09:33:23 AM »
Maybe they haven't updated the definitions yet.  Good catch.  Thanks.  ;)

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Antivirus GT
« Reply #5 on: August 05, 2010, 05:34:38 PM »
No Problem, Glad to help.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76014
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Antivirus GT
« Reply #6 on: August 05, 2010, 05:55:33 PM »
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Blue Chip

  • Guest
Re: Antivirus GT
« Reply #7 on: August 06, 2010, 06:16:53 AM »
To all,
   Thanks.  I was not able to get the Windows Live One Care to work.  I think the malware keeps the software from running the protection and removal modes.  Blue Chip

Offline Marc57

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 1944
  • KISS Rules The World!!!
    • KISS Army
Re: Antivirus GT
« Reply #8 on: August 06, 2010, 07:57:32 AM »
@SafeSurf, You were right, I guess MBAM can get rid of this, Sorry

@Blue Chip, Follow this guide and see if it helps:

http://www.bleepingcomputer.com/virus-removal/remove-antivirusgt

If that doesn't help, I've asked essexboy to take a look at this thread.
You Wanted the Best You Got the Best the Hottest Band in the World KISS!!!

Offline 1tb

  • Jr. Member
  • **
  • Posts: 71
Re: Antivirus GT
« Reply #9 on: September 06, 2010, 05:32:31 PM »
Came across this myself last week on Windows 7 32bit which was protected by Avast 5 Free version. Could not detect it or get rid of it. Downloaded and ran the MBAM anti-malwarebytes tool and while it did remove the virus, MBAM also removed some critical system files and then system would not startup (even in SafeMode).  :( System Restore no use either as it was corrupt/disabled!

Was wondering has anyone forwarded this spyware/virus called AntiVirusGT to Avast virus lab for testing/addition to detection?  ???

Offline polonus

  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 34051
  • malware fighter
Re: Antivirus GT
« Reply #10 on: September 06, 2010, 05:38:29 PM »
Use the following instructions to remove AntivirusGT or Antivirus GT (Uninstall instructions)

Step 1. Disable malicious add-on.

Run Internet Explorer. Click Tools -> Manage Add-ons. Select UpdateCheck.dll addon and you will see an image.

Manage Add-ons

Click disable, click OK and click OK to close Manage Add-ons window. Close Internet Explorer and run it once again.

Step 2. Stop AntivirusGT process.
You need stop a core process of AntivirusGT, after that, you will be able to remove this malicious program and any associated malware without any problem.

Right click to Windows task bar, select Task manager. Task Manager window opens. In the list of processes select the AntivirusGT.exe and you will see a screen similar to the one below.

Task Manager

Click End process button and click Yes for confirm. Close Task Manager.

If Task Manager is blocked, then go to My computer, open your system disk (disk C by defaults), then open System32 folder. Copy file taskmgr to your desktop. Right click to taskmgr icon on your desktop and select Rename. Type explorer and press Enter. Then repeat the step 2 once again.

Step 3. Remove AntivirusGT.

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Double Click mbam-setup.exe to install the application. When the installation begins, keep following the prompts in order to continue with the installation process. Do not make any changes to default settings and when the program has finished installing, make sure a checkmark is placed next to Update Malwarebytes’ Anti-Malware and Launch Malwarebytes’ Anti-Malware, then click Finish.

If an update is found, it will download and install the latest version.

Once the program has loaded you will see window similar to the one below.
malwarebytes-antimalware1
Malwarebytes Anti-Malware Window

Select Perform Quick Scan, then click Scan, it will start scanning your computer for AntivirusGT infection. This procedure can take some time, so please be patient.

When the scan is complete, click OK, then Show Results to view the results. You will see a list of infected items similar as shown below. Note: list of infected items may be different than what is shown in the image below.

Malwarebytes Anti-malware, list of infected items

Make sure that everything is checked, and click Remove Selected for start removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.

Note 1: if you can not download, install, run or update Malwarebytes Anti-malware, then follow the steps: Malwarebytes won`t install, run or update – How to fix it.


AntivirusGT creates the following files and folders

C:\Program Files\AVGT
%Temp%\MICROS~1.DLL
C:\Program Files\AVGT\antivirusGT.exe
AntivirusGT creates the following registry keys and values

HKEY_CLASSES_ROOT\CLSID\{3304F17F-732C-4AC6-BF67-DBDC8B88C11F}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3304F17F-732C-4AC6-BF67-DBDC8B88C11F}
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AVGT

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Antivirus GT
« Reply #11 on: September 06, 2010, 05:47:54 PM »

Offline 1tb

  • Jr. Member
  • **
  • Posts: 71
Re: Antivirus GT
« Reply #12 on: September 06, 2010, 05:49:41 PM »
Step 3. Remove AntivirusGT.

Download MalwareBytes Anti-malware (MBAM). Close all programs and Windows on your computer.

Make sure that everything is checked, and click Remove Selected for start removal process. When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.


Hi Polonus, very detailed post- thank you but unfortunately while I did manage to get MBAM to scan and remove AntiVirusGT- the removal left my system unable to startup. Hence my question as to why Avast 5 did not detect or clean it and has this AntiVirusGT been now added to the Avast virus signature database?

One other thing- I know that Avast it not perfect, but I do find it strange that we are in Avast Forum discussing how to remove malware using a different tool - MBAM? Maybe Alwil will add MBAM to its product range now?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37698
Re: Antivirus GT
« Reply #13 on: September 06, 2010, 05:56:26 PM »
Fake antivirus overwhelming scanners
http://news.techworld.com/security/3203072/fake-antivirus-overwhelming-scanners/


Quote
The reason for the growth in numbers is what is known in technical terminology as ‘polymorphism', an old defence technique which involves changing the binary checksum of every copy (or download) of a piece of malware. This makes it much more difficult for antivirus programs to detect the programs.

Offline 1tb

  • Jr. Member
  • **
  • Posts: 71
Re: Antivirus GT
« Reply #14 on: September 06, 2010, 06:04:06 PM »
This makes it much more difficult for antivirus programs to detect the programs.

Pondus are you basically saying Avast 5 will never be able to stop 'polymorphic' malware? The folks at SAS now appear to have cracked it - so are you indicating that Avast team will not attempt to follow suit?