I’m currently trying to fix a PC for a friend and I’m receiving the error that “Avast! is blocked by group policy.” I received this after having the software installed, updated, and running for about 2 days. I’ve done some research and I keep finding that the fixes are for specific machines. So I am starting my own thread. I’ve run FRST and have the 3 logs attached. Any help would be greatly appreciated.
Also, why did this happen? I know the machine is riddled with viruses, malware, spyware, etc. But what exactly happened? Did something alter the system so that I couldn’t run it any longer? Is there a specific virus I should be looking for?
Save this as fixlist.txt, in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Download and Install Combofix
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
Ok, thanks much. Copied fixlist and have run FRST’s fix. It’s been running for about an hour or so, is there a general amount of time it usually takes? Or does it depend on the machine? I can see that it’s using resources from task manager, not frozen.
I think it should be mentioned that I am doing this remotely through TeamViewer. Hope that doesn’t matter.
I’ve run ComboFix. While unpacking I received the error about “hiv-backup.(?)” It got to the second “output folder: c\32788r22fwjfw” and appears to have frozen. It may have rebooted the machine. I’ve never used the program, so I’m not sure if it initiates a reboot.
When I can access the drive I’ll post the ComboFix log.
It appears that the shell has frozen. I can initiate a file transfer via TeamViewer, navigate her file system, and transfer files. But I have a frozen mouse pointer, no response from the OS, no Windows key, etc.
The following happened before “It will need a reboot.” I will have her reboot.
I restarted a session of TeamViewer and was able to remote in. When I did, I received the error I’ve attached. The blue cmd window came up and the program started and tried to create a restore point and froze again. When I tried to remote in again, I was denied.
What do I after it’s rebooted? I see a line above that says to not re-run combofix. Sorry for the flood of posts, I just want to keep you as updated as possible.
She told me that her machine hadn’t frozen, but her internet was disconnected on the machine only. The combofix cmd window didn’t appear to be doing anything. She rebooted and everything started no problem.
Avast and MBAM should now run, we will now clear the adware and take a fresh look with FRST. How is the computer behaving at the moment
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.