Monday, November 23rd 2009, 2:15am UTC+1

You are not logged in.

  • Login
  • Register

Date of registration:
Nov 1st 2009


Version: AntiVir Premium


Operating System: Dell Windox XP Professional


Location: NYC, USA



1

Tuesday, November 3rd 2009, 6:44pm

Using MalwareBytes with Avira

I read in a different thread here that someone with serious infections was advised as a method of last resort to boot in SAFE mode ( F8 ) and run Avira Antivir first, and then MalwareBytes.

I had been leary of Malwarebytes because AVG gave what was probably a false positive (or perhaps I retrieved a version of MalwareBytes from some malicious link).

Anyway, I followed the link posted here in this forum, installed MalwareBytes and did the quick initial scan (which took about 30 minutes).

It did catch and remove one infection.

QUESTION: Is it ok to have MalwareBytes resident on the machine along with Avira: I am under the impression that MalwareBytes is not a resident program, but is active only if I invoke it, at which times I could deactivate Avira.

I am now curious to reboot in safe mode and do a complete Avira scan, followed by a complete MalwareBytes scan.

Here is log from MalWareBytes:

Malwarebytes' Anti-Malware 1.41
Database version: 3092
Windows 5.1.2600 Service Pack 3

11/3/2009 12:38:42 PM
mbam-log-2009-11-03 (12-38-42).txt

Scan type: Quick Scan
Objects scanned: 166753
Time elapsed: 21 minute(s), 42 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\typelib (Fake.Dropped.Malware) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

This post has been edited 1 times, last edit by "WilliamBuell" (Nov 3rd 2009, 6:45pm)

  • Go to the top of the page

Farger

Community member

Date of registration:
Jul 10th 2009


Version: AntiVir Personal


Operating System: Windows XP PRO SP2


Location: Ukraine



2

Tuesday, November 3rd 2009, 7:07pm

Hi WilliamBuel,

QUESTION: Is it ok to have MalwareBytes resident on the machine along with Avira: I am under the impression that MalwareBytes is not a resident program, but is active only if I invoke it, at which times I could deactivate Avira.


I also use MBAM since version 1.35 and still under high impression :love: . Seriously, MBAM is very powerful software and can catch what others can't. I use MBAM only as on-demand scanner. MBAM is antimalware software that is designed to fill in the gaps left by antivirus software. Using Avira and now combine it with MBAM pro, I can say with confidence: No conflicts between the two running side by side, a marriage made in heaven. :D (plus its easy to use)
  • Go to the top of the page

Date of registration:
Nov 1st 2009


Version: AntiVir Premium


Operating System: Dell Windox XP Professional


Location: NYC, USA



3

Tuesday, November 3rd 2009, 10:34pm

Two clean safe mode scan logs: 1 from Avira & 1 from MalwareBytes

Thanks to everyone's help here, I finally got two clean logs in safe mode (F8) one from Malware Bytes and one from Avira:

Malwarebytes' Anti-Malware 1.41
Database version: 3092
Windows 5.1.2600 Service Pack 3 (Safe Mode)

11/3/2009 2:37:53 PM
mbam-log-2009-11-03 (14-37-53).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 252209
Time elapsed: 1 hour(s), 41 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)

++++++++++++++++++++



Avira AntiVir Personal
Report file date: Tuesday, November 03, 2009 14:39

Scanning for 1862073 virus strains and unwanted programs.

Licensee : Avira AntiVir Personal - FREE Antivirus
Serial number : 0000149996-ADJIE-0000001
Platform : Windows XP
Windows version : (Service Pack 3) [5.1.2600]
Boot mode : Save mode
Username : William
Computer name : PC1

Version information:
BUILD.DAT : 9.0.0.410 18074 Bytes 9/25/2009 11:56:00
AVSCAN.EXE : 9.0.3.7 466689 Bytes 7/21/2009 19:36:14
AVSCAN.DLL : 9.0.3.0 40705 Bytes 2/27/2009 16:58:24
LUKE.DLL : 9.0.3.2 209665 Bytes 2/20/2009 17:35:49
LUKERES.DLL : 9.0.2.0 12033 Bytes 2/27/2009 16:58:52
ANTIVIR0.VDF : 7.1.0.0 15603712 Bytes 10/27/2008 18:30:36
ANTIVIR1.VDF : 7.1.4.132 5707264 Bytes 6/24/2009 15:21:42
ANTIVIR2.VDF : 7.1.6.160 5413376 Bytes 10/28/2009 21:40:39
ANTIVIR3.VDF : 7.1.6.184 206848 Bytes 11/3/2009 15:46:41
Engineversion : 8.2.1.53
AEVDF.DLL : 8.1.1.2 106867 Bytes 11/2/2009 21:42:28
AESCRIPT.DLL : 8.1.2.43 528764 Bytes 11/2/2009 21:42:25
AESCN.DLL : 8.1.2.5 127346 Bytes 11/2/2009 21:42:15
AERDL.DLL : 8.1.3.2 479604 Bytes 11/2/2009 21:42:03
AEPACK.DLL : 8.2.0.2 422263 Bytes 11/2/2009 21:41:54
AEOFFICE.DLL : 8.1.0.38 196987 Bytes 7/23/2009 15:59:39
AEHEUR.DLL : 8.1.0.173 2064760 Bytes 11/2/2009 21:41:45
AEHELP.DLL : 8.1.7.0 237940 Bytes 11/2/2009 21:41:15
AEGEN.DLL : 8.1.1.70 364917 Bytes 11/2/2009 21:41:13
AEEMU.DLL : 8.1.1.0 393587 Bytes 11/2/2009 21:41:03
AECORE.DLL : 8.1.8.1 184693 Bytes 11/2/2009 21:40:55
AEBB.DLL : 8.1.0.3 53618 Bytes 10/9/2008 20:32:40
AVWINLL.DLL : 9.0.0.3 18177 Bytes 12/12/2008 14:47:59
AVPREF.DLL : 9.0.3.0 44289 Bytes 11/3/2009 15:46:43
AVREP.DLL : 8.0.0.3 155905 Bytes 1/20/2009 20:34:28
AVREG.DLL : 9.0.0.0 36609 Bytes 12/5/2008 16:32:09
AVARKT.DLL : 9.0.0.3 292609 Bytes 3/24/2009 21:05:41
AVEVTLOG.DLL : 9.0.0.7 167169 Bytes 1/30/2009 16:37:08
SQLITE3.DLL : 3.6.1.0 326401 Bytes 1/28/2009 21:03:49
SMTPLIB.DLL : 9.2.0.25 28417 Bytes 2/2/2009 14:21:33
NETNT.DLL : 9.0.0.0 11521 Bytes 12/5/2008 16:32:10
RCIMAGE.DLL : 9.0.0.25 2438913 Bytes 5/15/2009 21:39:58
RCTEXT.DLL : 9.0.37.0 86785 Bytes 4/17/2009 16:19:48

Configuration settings for the scan:
Jobname.............................: Complete system scan
Configuration file..................: c:\program files\avira\antivir desktop\sysscan.avp
Logging.............................: low
Primary action......................: interactive
Secondary action....................: ignore
Scan master boot sector.............: on
Scan boot sector....................: on
Boot sectors........................: C:, D:,
Process scan........................: on
Scan registry.......................: on
Search for rootkits.................: on
Integrity checking of system files..: off
Scan all files......................: All files
Scan archives.......................: on
Recursion depth.....................: 20
Smart extensions....................: on
Macro heuristic.....................: on
File heuristic......................: medium

Start of the scan: Tuesday, November 03, 2009 14:39

Starting search for hidden objects.
The driver could not be initialized.

The scan of running processes will be started
Scan process 'avscan.exe' - '1' Module(s) have been scanned
Scan process 'avcenter.exe' - '1' Module(s) have been scanned
Scan process 'explorer.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'svchost.exe' - '1' Module(s) have been scanned
Scan process 'lsass.exe' - '1' Module(s) have been scanned
Scan process 'services.exe' - '1' Module(s) have been scanned
Scan process 'winlogon.exe' - '1' Module(s) have been scanned
Scan process 'csrss.exe' - '1' Module(s) have been scanned
Scan process 'smss.exe' - '1' Module(s) have been scanned
11 processes with 11 modules were scanned

Starting master boot sector scan:
Master boot sector HD0
[INFO] No virus was found!

Start scanning boot sectors:
Boot sector 'C:\'
[INFO] No virus was found!
Boot sector 'D:\'
[INFO] No virus was found!

Starting to scan executable files (registry).
The registry was scanned ( '2055' files ).


Starting the file scan:

Begin scan in 'C:\'
C:\pagefile.sys
[WARNING] The file could not be opened!
[NOTE] This file is a Windows system file.
[NOTE] This file cannot be opened for scanning.
Begin scan in 'D:\' <Backup>


End of the scan: Tuesday, November 03, 2009 16:14
Used time: 1:35:38 Hour(s)

The scan has been done completely.

8639 Scanned directories
412411 Files were scanned
0 Viruses and/or unwanted programs were found
0 Files were classified as suspicious
0 files were deleted
0 Viruses and unwanted programs were repaired
0 Files were moved to quarantine
0 Files were renamed
1 Files cannot be scanned
412410 Files not concerned
4291 Archives were scanned
1 Warnings
1 Notes
  • Go to the top of the page

Farger

Community member

Date of registration:
Jul 10th 2009


Version: AntiVir Personal


Operating System: Windows XP PRO SP2


Location: Ukraine



4

Tuesday, November 3rd 2009, 10:38pm

Hi WilliwamBuel,

Thanks to everyone's help here, I finally got two clean logs in safe mode (one from Malware Bytes and one from Avira:


My congratulations :thumbup:
  • Go to the top of the page

avon

Community member

Date of registration:
Apr 15th 2008


Version: AntiVir Premium


Operating System: Vista Home Premium SP2 & Win XP Home XP SP3


Location: 7 Seas



5

Tuesday, November 3rd 2009, 11:04pm

Hi Farger,
Regarding MBAM, please read post #17 & #18 =
http://forum.avira.com/wbb/index.php?page=Thread&postID=867980#post867980

avon.
  • Go to the top of the page

Farger

Community member

Date of registration:
Jul 10th 2009


Version: AntiVir Personal


Operating System: Windows XP PRO SP2


Location: Ukraine



6

Tuesday, November 3rd 2009, 11:13pm

Hi avon,

Thank you for info...I've already read your post 10 minutes ago ;) . About MBAM and IObit - circle ?(
  • Go to the top of the page