Hi All,
Just wandering if anyone can help me with these two possibly unrelated problems regarding avast.
First a bit of history;
I am running windows xp home edition on a dell dimension 3100 and have been using avast 4.8 free for a few years with absolutely no problems. I am a self taught computer amateur with limited skills and knowledge.
One day, about a month ago I suddenly got infected with the malware xp 2010 virus and it completely locked me out of my computer.
luckily, I have an old laptop and after a lot of research and a usb drive, I managed to disable the virus with malwarebytes and then eventually regain control using some script to restart task manager and give me back administrator rights and re-enable the exe files and a bunch of other stuff that it had done, bit by bit.
I have since run several anti virus scans using, among others superantispyware, hitman pro, TDSS killer (which incidentley always finds the same rootkit, asks for a re-boot and then does exactly the same thing on the next run - don’t recall the name of it but will research and repost).
These all picked up various things and, I assume, got rid of them, although it seemed to take many passes of each.
The most difficult problem was a google re-direct but that has cleared up now following one of the many scans.
It also stopped avast auto update which I managed to fix by using the ‘no proxy’ setting in program options. I hope it isn’t a problem to leave it like that but its the only setting that lets it auto update.
Most scans now come up clean except that if I scan with avast (or I think, even if I just use the computer for some time) it will eventually find something called win32:Alureon-FZ. When the warning screen comes up, it doesn’t matter weather you delete or move to chest the warning screen immediately returns forever. If I then restart I am greeted with the infamous BSOD with the error STOP:0x0000007B(0xBA4C3524, 0x0000…etc) and must revert to the last known stable configuration that worked on reboot. Then I can use the computer as before.
I’m not sure if this is related but if I schedule a boot time scan, it detects something but then freezes on the screen where you have the option to press 1 to delete etc. and I must shutdown by holding the power button and revert to last stable config. on re-boot again.
I hope someone can make sense of it for me. I didn’t want to bother anyone about this but I have been battling it for so long on my own that I am wandering if I shouldn’t have re-installed weeks ago as a friend first suggested.
I could provide other scan logs but here is the Avast boot time scan log:
06/17/2008 21:58
Scan of all local drives
Scanning aborted
Number of searched folders: 2188
Number of tested files: 43048
Number of infected files: 0
04/25/2010 10:23
Scan of all local drives
File C:\System Volume Information_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP2\A0000049.exe is infected by Win32:Trojan-gen
05/12/2010 18:02
Scan of all local drives
File C:\Documents and Settings\NetworkService\Local Settings\Temporary Internet Files\Content.IE5\S0NA9AAR\us1[1].htm is infected by JS:Prontexi-AV [Trj]
Here is the relevant resident protection notepad (the whole lot is too big too post):
- avast! Report
- This file is generated automatically
- Task ‘Resident protection’ used
- Started on 06 May 2010 21:06:23
- VPS: 100501-1, 01/05/2010
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\pci.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\pci.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
C:\WINDOWS\system32\drivers\pci.sys [L] Win32:Alureon-FZ (0)
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\pci.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
File was successfully deleted…
C:\WINDOWS\system32\drivers\PCI.sys [L] Win32:Alureon-FZ (0)
*
- avast! Report
- This file is generated automatically
- Task ‘Resident protection’ used
- Started on 11 May 2010 20:58:38
- VPS: 100501-1, 01/05/2010
-
Task stopped: 11 May 2010 21:16:41
-
Run-time was 18 minute(s), 3 second(s)
-
avast! Report
-
This file is generated automatically
-
Task ‘Resident protection’ used
-
Started on 11 May 2010 21:17:35
-
VPS: 100501-1, 01/05/2010
-
Task stopped: 11 May 2010 21:52:49
-
Run-time was 35 minute(s), 14 second(s)
-
avast! Report
-
This file is generated automatically
-
Task ‘Resident protection’ used
-
Started on 11 May 2010 21:58:20
-
VPS: 100511-1, 11/05/2010
-
Task stopped: 11 May 2010 22:05:19
-
Run-time was 6 minute(s), 59 second(s)
-
avast! Report
-
This file is generated automatically
-
Task ‘Resident protection’ used
-
Started on 12 May 2010 17:55:14
-
VPS: 100511-1, 11/05/2010