BleepingComputer.com: Combofix and AVG

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Combofix and AVG

#1 User is offline   Oldlock15 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 27-January 10

Posted 21 November 2010 - 07:32 AM

I was trying to remove a virus from a computer. I ran Malwarebytes and removed a trojan. The computer still would not open Microsoft Office software. I disabled AVG and tried to run Combofix. I couldn't do it. A message popped up saying I had to remove AVG to allow Combofix to run. So, I tried to remove AVG but couldn't. I did not have access to a registry key, So, I opened the registry editor and found that key. I had to edit the permissions for the HKLM/Software/Microsoft/WindowsNT/CurrentVersion/Windows key. I found there were two entries for everyone that were set to deny. Once I removed the deny and said allow everyone, I could remove AVG and run Combofix. After Combofix ran, the computer appeared normal again. I then installed the Microsoft Security Essentials AV program. Has anyone had this conflict with AVG and Combofix? Is it related to the virus or a conflict. For the record, the version of AVG was 8.5.

#2 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,516
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 21 November 2010 - 07:47 AM

ComboFix will not run until AVG is uninstalled as a protective measure against the anti-virus. This is because AVG "falsely" detects ComboFix (or its embedded files) as a threat and may remove them. If some of ComboFix's files are removed by AVG, it will not perform its routines properly and the developer has determined this can cause damaging or "unpredictable results". This is an issue with AVG and since it cannot be effectively disabled before running ComboFix, the developer has chosen not to allow his tool to run until AVG is uninstalled first in order to avoid any possilbe issues.

Further, no one should be using ComboFix unless specifically instructed to do so by a Malware Removal Expert who can interpret the logs. It is a powerful tool intended by its creator to be "used under the guidance and supervision of an expert. Using this tool incorrectly could lead to disastrous problems with your operating system such as preventing it from ever starting again. When issues arise due to complex malware infections, false detections, problems running ComboFix or with other security tools causing conflicts, experts are usually aware of them and can advise what should or should not be done while providing individual assistance. Those attempting to use ComboFix on their own do not have such information and are at risk when running the tool in an unsupervised environment. Please read the pinned topic ComboFix usage, Questions, Help? - Look here.

This post has been edited by quietman7: 21 November 2010 - 07:59 AM

Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

#3 User is offline   Oldlock15 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 18
  • Joined: 27-January 10

Posted 21 November 2010 - 08:32 AM

I have used Combofix in the past by disabling AVG and removing viruses. This time I had to remove AVG. The computer is now working fine. The bigger question here is why could I not remove AVG? I had tried to remove AVG to install a differnet AV program but was not successful. Since the computer was unable to function properly, I removed AVG, ran Combofix. If this had not worked, or had damaged the OS, I did not care. At that point I was getting ready to wipe the computer clean and reload the OS. I am curious as to why AVG would not uninstall?

#4 User is offline   quietman7 

  • Bleepin' Janitor
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Global Moderator
  • Posts: 25,516
  • Joined: 09-July 05
  • Gender:Male
  • Location:Virginia, USA

Posted 21 November 2010 - 09:37 AM

If is not uncommon for some anti-virus programs to not completely uninstall itself using the usual method of Add/Remove Programs or Programs and Features in Vista/Windows 7. In many cases anti-virus vendors provide clean-up utilities on their web sites to remove remnants left behind after unintalling or for a failed uninstall. In the case of AVG, you can use the uninstall/cleanup utility (AVG Remover) provided in AVG 2011+9.0+8.x Uninstall/Re-Install Instructions.

Other vendors do the same.
Microsoft MVP - Consumer Security 2007-2012 Posted Image
Member of UNITE, Unified Network of Instructors and Trusted Eliminators

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users