system
August 6, 2013, 10:17pm
1
After noticing that my Avast will close every time I click on scan or security I decided to look into it the only thing I have found was this link http://forum.avast.com/index.php?topic=125332.0 . I have completed the steps to get the requested logs and was wondering if any I would I could do to fix this.
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org
Database version: v2013.08.06.01
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
CorruptFate :: CORRUPTED-PC [administrator]
8/6/2013 12:45:55 AM
mbam-log-2013-08-06 (00-45-55).txt
Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 218185
Time elapsed: 5 minute(s), 47 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 8
HKCR\CLSID{67BD9EEB-AA06-4329-A940-D250019300C9} (PUP.Software.Updater) → Quarantined and deleted successfully.
HKCR\TypeLib{A0EE0278-2986-4E5A-884E-A3BF0357E476} (PUP.Software.Updater) → Quarantined and deleted successfully.
HKCR\Interface{9EDC0C90-2B5B-4512-953E-35767BAD5C67} (PUP.Software.Updater) → Quarantined and deleted successfully.
HKCR\Updater.AmiUpd.1 (PUP.Software.Updater) → Quarantined and deleted successfully.
HKCR\Updater.AmiUpd (PUP.Software.Updater) → Quarantined and deleted successfully.
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{EEE6C35C-6118-11DC-9C72-001320C79847} (PUP.Optional.SweetPacks) → Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall{99C91FC5-DB5B-4AA0-BB70-5D89C5A4DF96} (PUP.Software.Updater) → Quarantined and deleted successfully.
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 1
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main|Start Page (PUP.Optional.Conduit) → Bad: (http://search.conduit.com?SearchSource=10&CUI=UN81108171315410325&UM=2&ctid=CT3289847 ) Good: (http://www.google.com ) → Quarantined and repaired successfully.
Folders Detected: 3
C:\ProgramData\Tarma Installer (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B} (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Cache (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
Files Detected: 14
C:\Users\CorruptFate\AppData\Local\Temp\SPStub.exe (PUP.Optional.Conduit.A) → Quarantined and deleted successfully.
C:\Users\CorruptFate\AppData\Local\Temp\Updater.exe (PUP.Optional.Amonetize) → Quarantined and deleted successfully.
C:\Users\CorruptFate\AppData\Local\Temp\ct3289847\chLogic.exe (PUP.Optional.Conduit.A) → Quarantined and deleted successfully.
C:\Users\CorruptFate\AppData\Local\Temp\ct3289847\ctbe.exe (PUP.Optional.Conduit.A) → Quarantined and deleted successfully.
C:\Users\CorruptFate\AppData\Local\Temp\ct3289847\ieLogic.exe (PUP.Optional.Conduit.A) → Quarantined and deleted successfully.
C:\Users\CorruptFate\AppData\Local\Temp\ct3289847\spch.exe (PUP.Optional.Conduit.A) → Quarantined and deleted successfully.
C:\Users\CorruptFate\AppData\Local\Temp\ct3289847\statisticsStub.exe (PUP.Optional.Conduit.A) → Quarantined and deleted successfully.
C:\Windows\Installer\1c3c1a99.msi (PUP.Optional.SweetIM) → Quarantined and deleted successfully.
C:\Windows\Installer\1c3c1a9e.msi (PUP.Optional.SweetIM) → Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.dat (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.exe (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B}\Setup.ico (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B}_Setup.dll (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
C:\ProgramData\Tarma Installer{889DF117-14D1-44EE-9F31-C5FB5D47F68B}_Setupx.dll (PUP.Optional.Tarma.A) → Quarantined and deleted successfully.
(end)
Pondus
August 6, 2013, 10:25pm
2
then you should attach the logs not copy and paste…
run in order listed
AdwCleaner / Malwarebytes / OTL / aswMBR
when done removal experts will be notified, they are most likely all in bed now so you want see them untill tomorrow
system
August 7, 2013, 6:45pm
3
Sorry, these should be the attachments you are looking for.
After this run could you see if Avast now works
Warning This fix is only relevant for this system and no other, using on another computer may cause problems
Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot
Run OTL
[*]Under the Custom Scans/Fixes box at the bottom, paste in the following
https://dl.dropbox.com/u/73555776/OTL_Fix.GIF
:Commands
[CREATERESTOREPOINT]
:OTL
C:\Program Files (x86)\Search Toolbar
IE - HKLM\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {BB231A43-F90A-48EE-82F3-75D9408980B2}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3072253
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6&q={searchTerms}
IE - HKU\S-1-5-21-289605786-4115074822-4268016227-1000\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\7.3\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKU\S-1-5-21-289605786-4115074822-4268016227-1000\..\URLSearchHook: {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
IE - HKU\S-1-5-21-289605786-4115074822-4268016227-1000\..\SearchScopes,DefaultScope = {BB231A43-F90A-48EE-82F3-75D9408980B2}
IE - HKU\S-1-5-21-289605786-4115074822-4268016227-1000\..\SearchScopes\{34610C31-270C-4F4C-8E1F-C67470A53D71}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=100000031&src=crm&q={searchTerms}&locale=en_US&apn_ptnrs=^TV&apn_dtid=^OSJ000^YY^US&apn_uid=3F478507-D52B-42C9-946E-82D0CF9489F5&apn_sauid=BCF8D931-2A55-4F38-AF05-B33FC06B7779
IE - HKU\S-1-5-21-289605786-4115074822-4268016227-1000\..\SearchScopes\{BB231A43-F90A-48EE-82F3-75D9408980B2}: "URL" = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3289847&CUI=UN81108171315410325&UM=2
[2013/03/18 23:19:38 | 000,213,444 | ---- | M] () (No name found) -- C:\Users\CorruptFate\AppData\Roaming\Mozilla\Firefox\Profiles\0\extensions\torntv@torntv.com.xpi
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\7.3\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\7.3\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (uTorrentControl2 Toolbar) - {687578b9-7132-4a7a-80e4-30ee31099e03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (no name) - {EEE6C35B-6118-11DC-9C72-001320C79847} - No CLSID value found.
O3 - HKU\S-1-5-21-289605786-4115074822-4268016227-1000\..\Toolbar\WebBrowser: (uTorrentControl2 Toolbar) - {687578B9-7132-4A7A-80E4-30EE31099E03} - C:\Program Files (x86)\uTorrentControl2\prxtbuTor.dll (Conduit Ltd.)
O3 - HKU\S-1-5-21-289605786-4115074822-4268016227-1000\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files (x86)\Search Toolbar\SearchToolbar.dll ()
[2013/07/24 22:02:51 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Application Updater
[2013/07/24 22:02:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Spigot
[2013/07/24 22:02:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\IObit Toolbar
[2013/08/06 00:55:03 | 000,000,354 | ---- | M] () -- C:\Windows\tasks\ROC_JAN2013_TB_rmv.job
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
system
August 8, 2013, 4:12pm
5
Here it is, thanks for getting back so fast.
system
August 9, 2013, 9:30pm
7
It still runs, but the problem is still the same. When I click on either scan or security (circled in the picture) the window closes before I can have it do anything. I am starting to think that it might be designed this way, though that does seem odd to me.
That is not normal behaviour, first we will try a repair
Go Control Panel > Programmes and features
Select Avast
On the left there should be a repair option select that
Once it has finished reboot and see if Avast now runs properly
system
August 10, 2013, 4:15am
9
Still not working after repairing it today. Still closes when I click those 2 buttons, however it does say that the Avast logo will spin when its scanning and it does spin on my task bar in the bottom right.
OK next option would be a clean install
Lets reinstall Avast
Download Uninstall Utility to your Desktop .
Download the correct version of Avast
Avast Free
Avast Pro
Avast Internet Security
Avast Premier
Disconnect from the net
Uninstall Avast via control panel
[]Run aswClear
[ ]It will offer to reboot to safe mode … Accept that
https://dl.dropbox.com/u/73555776/aswclear.JPG
[*]Once it has rebooted to safe mode
[*]In the Select Product to Uninstall dropdown choose the version of Avast that is on your system.
[*]Press Uninstall
[*]Once complete reboot your system to Normal Mode
[*]Reinstall Avast
system
August 11, 2013, 3:10am
11
It worked, your a genius! Thx for the help
Glad it worked, any further problems ?