PDA

View Full Version : AVG is uninstalling Malwarebytes


robinb
September 13th, 2009, 11:43 AM
I got a phone call yesterday from one of my clients and lots of email messages.
Seems when trying to run Malwarebytes, AVG pop up and says it is a virus and totally removes the program from Add/remove programs.
I checked 10 computers that tried to run their malwarebytes and all of them running xp home or pro had the same problem.
If you try to go to malwarebytes.org and download the program, AVG pops up and says it is a threat? HUH?????
None of these computers including my own 7 have viruses or trojans on them. AVG needs to fix this asap. Seemed this happened in the last update.

I sent an email off to avg

has anyone else running avg seen this?

robin

robinb
September 13th, 2009, 02:27 PM
just so you know this is only happening on AVG Internet Security
it is not happening on AVG free or AVG Pro Antivirus Program

robin

JRViejo
September 13th, 2009, 04:21 PM
robinb, I'm running AVG Free 8.5.409 ( DB 270.13.94/237 ) and I can confirm that running and/or downloading MBAM, I don't get a pop-up. However, I did a Shell Extension Scan of mbam-setup.exe, and it messed up the GUI, displaying an AVG has encountered a problem and needs to close message. After that, I could not access the GUI via the Desktop, Tray Icon and/or Start menu.

I did a Repair Installation and regained the GUI. In the meantime, AVG had updated their Virus DB ( 270.13.95/2368 ) and after performing an update, ran a Shell Extension Scan of mbam-setup.exe without any problems. Perhaps it was a fluke, but decided to post an FYI, in case someone else experiences this problem with the old Virus DB.

robinb
September 13th, 2009, 05:35 PM
-{ Quote: "robinb, I'm running AVG Free 8.5.409 ( DB 270.13.94/237 ) and I can confirm that running and/or downloading MBAM, I don't get a pop-up. However, I did a Shell Extension Scan of mbam-setup.exe, and it messed up the GUI, displaying an AVG has encountered a problem and needs to close message. After that, I could not access the GUI via the Desktop, Tray Icon and/or Start menu.

I did a Repair Installation and regained the GUI. In the meantime, AVG had updated their Virus DB ( 270.13.95/2368 ) and after performing an update, ran a Shell Extension Scan of mbam-setup.exe without any problems. Perhaps it was a fluke, but decided to post an FYI, in case someone else experiences this problem with the old Virus DB." }-


i have the same VB update on the pro version Internet Security- and this is the one that has the problems.

I am awaiting AVG to figure this out. I was on the phone with them because i am an affiliate and get free tech support- and they have no idea what is going on and asked me to send to virus@avg.com both mbam.exe and setup files .

Right now I have 3 clients with a screwed up Malwarebytes that cannot be uninstalled because it is not in add remove programs and worse i cannot get it to install because AVG keeps popping up and saying it is a threat and then Malwarebytes aborts the install because it seems it is getting strangled by AVG

I just hope they fix this asap so i can reinstall malwarebytes on these 3 computers

What really bothers me is why AVG removed the program from Add/Remove Software in Windows and made it impossible to uninstall.

robin

JRViejo
September 13th, 2009, 07:09 PM
-{ Quote: "i have the same VB update on the pro version Internet Security- and this is the one that has the problems.

What really bothers me is why AVG removed the program from Add/Remove Software in Windows and made it impossible to uninstall.

robin" }-
robin, I assume you are talking about Virus DB 270.13.95/2368 on your AVG IS?

Have you tried something other than Add/Remove, like a Revo Uninstaller (http://www.revouninstaller.com/index.html) or similar program, to see if there are any existing remnants of MBAM that can be uninstalled?

Brocke
September 14th, 2009, 01:25 AM
i remember reading about AVG attacking Itunes and removing it. i wonder if this is the same case.

AVG as of late have had these type of issue and i dont know why,

TonyKlein
September 14th, 2009, 02:29 AM
According to MBAM staff AVG did fix this FP within a few days

robinb
September 14th, 2009, 11:31 AM
-{ Quote: "robin, I assume you are talking about Virus DB 270.13.95/2368 on your AVG IS?

Have you tried something other than Add/Remove, like a Revo Uninstaller (http://www.revouninstaller.com/index.html) or similar program, to see if there are any existing remnants of MBAM that can be uninstalled?" }-

yes that database and the new data base today does it too which is 270.13.95/2370

MBAM folder is there but if you even try to use its own uninstaller AVG pops up with a threat and will not allow it to continue
MBAM suggestion is just to reinstall the program
Only I cannot do it- AVG will not allow it to download
So i went to another computer- downloaded the setup for MBAM, put it on one of the computers with this problem and AVG still popped up stating it is a threat.
I then renamed the setup file to something else and AVG still sees it as a threat
So
AVG needs to fix this
I received an email this morning from AVG telling me they are analyzing the files and will email me when they figure this all out
robin

robinb
September 14th, 2009, 11:33 AM
-{ Quote: "According to MBAM staff AVG did fix this FP within a few days" }-

not this one- this just happened yesterday
robin

TonyKlein
September 14th, 2009, 11:39 AM
I guess you'll have to keep reporting it to them... ::)

JRViejo
September 14th, 2009, 01:30 PM
-{ Quote: "I received an email this morning from AVG telling me they are analyzing the files and will email me when they figure this all out
robin" }-
robin, thanks and keep us posted!

dawgg
September 14th, 2009, 02:01 PM
-{ Quote: "According to MBAM staff AVG did fix this FP within a few days" }-
Superfast!

AVG has been very unfortunate over the last few years with the high number of FPs on popular software. Yes, all AVs get FPs, but AVG more often gets FPs which affect more users - should really sort out its Quality Control by increasing the size of its whitelist or something.

Popular software such as MBAM, iTunes, Flash, Windows core files and Adobe Reader should be priority to be added to whitelistes.

robinb
September 14th, 2009, 07:35 PM
-{ Quote: "Superfast!

AVG has been very unfortunate over the last few years with the high number of FPs on popular software. Yes, all AVs get FPs, but AVG more often gets FPs which affect more users - should really sort out its Quality Control by increasing the size of its whitelist or something.

Popular software such as MBAM, iTunes, Flash, Windows core files and Adobe Reader should be priority to be added to whitelistes." }-

Not necessarily true, Norton Security messed up superantispyware pro, Kapersky messed up Malwarebytes so AVG is really not the only one that does this.

btw this is the fix that malwarebytes told me to do in the meantime until AVG fixes this:

Right-click the AVG icon in the system tray.
On the shortcut menu selectLaunch Control Center.
Click the 'Tools' tab, select Advanced settings...'
Scroll down or select 'Exceptions'
Click 'Add List' and copy and paste the following list of

files:
C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\rules.ref
C:\WINDOWS\system32\drivers\mbam.sys
C:\WINDOWS\system32\drivers\mbamswissarmy.sys
C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\mbam-setup.exe
Click OK 3 times.
Reboot your PC.

I did this on all 3 computers and it worked 99%. The 1% was where when malwarebytes asked for an upgrade as it was doing it - AVG popped up again and said it was a threat but when you clicked on "allow" mbam installed with no issues.

Hopefully they will fix this so you do not have to add exceptions

robin

JRViejo
September 14th, 2009, 09:50 PM
robin, thank you for providing the AVG temporary fix. :thumb: Let us know as soon as you are alerted, regarding their final fix.

robinb
September 16th, 2009, 11:14 AM
i just got this email from AVG as you will see below- seems the problem is in the AIP part of AVG Internet Security since this program is the only thing different (besides the firewall part) in all the other versions of AVG
Some of my clients who saw this problem did NOT install the firewall and are using xp's firewall, some did so it is not a problem in the firewall
I emailed AVG to find out what version database the fix is in
I will post it when they answer me but this is what they wrote:


"Unfortunately, the current AVG Identity Protection database version
may detect the mentioned virus on some legitimate applications. We can
confirm that it is a false alarm. We would like to inform you that the
false positive will be removed in the next database update.


Please update your AVG and check the situation again."

JRViejo
September 16th, 2009, 01:49 PM
robin, that explains why the Free version is not affected, because Identity Protection is a purchase option, but it has left me wondering if some remnants of ID Protection are/were in the Free version, thus my previous GUI disappearance, which has not happened since. Thanks for keeping us posted.

robinb
September 16th, 2009, 05:58 PM
AVG said they were going to issue an update to the AIP but i have not seen it yet
robin

robinb
September 17th, 2009, 06:51 PM
AVg claims they updated the AIP toConfiguration version: 245
Product Version: 8.5.2.718

only one little problem with that- on the 6 computers that have this problem none of them will do the update. They all have the prior version and when clicking on "check for updates" on the AIP it says "you already have the latest update"

I sent some files AVG requested but i think the problem lies on their end.
I asked for a manual download of where i can get this so i can fix it on the other computers. I am still awaiting for an answer

robin

tactful
September 21st, 2009, 08:15 PM
Hi Robin,long ago I had AVG paid.instead of using tickets or emails try this number to their Office in SC I think(maybe NC) to talk to a human.866-833-5727 that stinks when a good program like MBAM gets caught up in their game.it's not funny especially if it was paid for.used to use that number to renew but no more since ESS was put on.when KIS was had MBAM installed no problem.they just do not like anythng not kaspersky even when it caught things it didn't,reported a Trojan to them it found. I could not believe they did not care?and so it goes they are now history but MBAM remains in tact.sorry for all the info that's not needed.toll free call.try it who knows it just might work.
cheerz,
Mark

robinb
September 22nd, 2009, 12:26 PM
i called that number and it is not AVG so they will not talk to me but i emailed AVG this from these findings

i have now gone on 6 computers running AVG Internet Security
None of them will update the AIP to the newest version
All of them are in separate locations owned by separate individuals
I told them they need to fix this part of AVG
They need to put an update through AVG to update the AIP
4 of them have the AVG firewall
2 of them did not install the AVG firewall
All of them i tried all their suggestions in changing the config files they asked and all of them will not allow me to do so with following all their instructions which tends to tell me that something is wrong on their end and with the AIP part of the program
Nothing is wrong with AVG doing regular updates.
This is totally ridiculous!
If they cannot figure this out I will just uninstall the AIP from all their computers and just stick with the rest of the program
I am also a reseller of AVG and after all this nonsense I doubt if I will ever sell the AVG Internet Security Suite again. It has caused me nothing but countless hours of frustration and loss of funds. I will only sell the AVG Pro because i actually like the Antivirus part of the program

If any of you have AVG Internet Security with AIP the newest version is Configuration version: 245
Product Version: 8.5.2.718

You need to open AVG Identity Protection and click on the settings tab and click on "check for updates"
Please report back here if you can or cannot update to the latest version

Maybe if they see that others cannot in here too maybe they will realize it is a function of the program and not on our side

robin

tactful
September 22nd, 2009, 03:21 PM
Got it Robin it is their 3rd party distrubutor but the number stiil stands as shown below.you would think they would have a direct line for support but no like eveyone else they farm it out or resource it ESS does not.another option here:http://www.avg.com/support-newbetter still here:http://www.avg.com/support-existing if email is insisted listed numbers too for you.one of em as to work?could be why I dropped them
too.communication breakdown,KIS was no better,worse in fact if that's possible.happy with Smart Security here.they're there if you need them
they do call you if a case is submitted at the number you give on the form That I Like. they even answer emails another +
walling data is their go between
AVG Technical Support - 828-459-5422
Free AVG Support - 828-459-5422
Fax - 828-459-7341


Support Extensions
AVG Home Support - Ext. 414
AVG Business Support - Ext. 410
Local Home Support - Ext. 407
National Home Support - Ext. 414

1 Executive Drive, 3rd Floor
Chelmsford, MA 01824
USA
Customer services
USA

Walling Data Systems, Inc.
Education, Government Sales and Support Specialists
2105 Northwest Blvd.
Newton, NC 28658
USA
Tel. 866-833-5727

robinb
September 22nd, 2009, 05:33 PM
I have talked to them on the phone. I get free on phone tech support because i am a reseller but talking to them is like talking to deaf ears. That is why i would like to see here who ever installed the AIP in the Internet Security version can or cannot update their version.

robin

tactful
September 23rd, 2009, 03:17 PM
lots of luck robin getting hold of or hearing/seeing anyone to fix or change their protocols.if it's programmed in it is not going to happen.like the KIS issue it will be like talking to a wall. #1 reason they are history.more but details not needed,bigger the company seems less they care about their customers.at least from my decade of dealing with sec apps,still many not tried out there.not enough machines or time