AVAST CONSTANTLY BLOCKING URL

Hi!! I´m new at this forum! Sorry for my english as it is not my native language.

About 10 days ago Avast started jumping all the time and the strange thing is that all of a sudden a folder was trying to open itself and then a windows message (i will attach pics in another message).
I scan it several times with the most effective programs and nothing change.
I attached the logs you require.
Thanks!

Here the pics!

Let me know if this stops it

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

HKU\S-1-5-21-229507397-184578654-3858186304-1000\...\Run: [Adworks] => regsvr32.exe C:\Users\Usuario\AppData\Local\Adworks\icuutilinf32.dll <===== ATTENTION HKU\S-1-5-21-229507397-184578654-3858186304-1000\...\Run: [Igsoft] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\Usuario\AppData\Local\YdPack\odbcApiPpm24.dll ShellIconOverlayIdentifiers: [1SecureIconsProvider] -> {FC9D8189-520A-4417-AED7-9EAC810C6FBA} => C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll () CHR HKU\S-1-5-21-229507397-184578654-3858186304-1000\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION HKU\S-1-5-21-229507397-184578654-3858186304-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION SearchScopes: HKLM-x32 -> DefaultScope value is missing. Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKU\S-1-5-21-229507397-184578654-3858186304-1000 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File AlternateDataStreams: C:\Program Files\Common Files\System:TUWuTfwCZOLJu2FXkUunKRWuL AlternateDataStreams: C:\ProgramData\Microsoft:iI75lekBMSwtc4i79Xf1tu AlternateDataStreams: C:\ProgramData\Microsoft:ocgyjstsyzAhR7GMKduDN AlternateDataStreams: C:\ProgramData\TEMP:054B9966 AlternateDataStreams: C:\ProgramData\TEMP:56E2E879 AlternateDataStreams: C:\Users\Usuario\Configuración local:aEnq4DmgPjzcbywsXHUneHz AlternateDataStreams: C:\Users\Usuario\Configuración local:tiuyYDMB3tpVZ8i2JLaC78ja AlternateDataStreams: C:\Users\Usuario\AppData\Local:aEnq4DmgPjzcbywsXHUneHz AlternateDataStreams: C:\Users\Usuario\AppData\Local:tiuyYDMB3tpVZ8i2JLaC78ja AlternateDataStreams: C:\Users\Usuario\AppData\Local\Archivos temporales de Internet:LR7Wm8z3ZEOiHv8J2kYNb89sG AlternateDataStreams: C:\Users\Usuario\AppData\Local\Archivos temporales de Internet:po1vgE6CSn06yukOYDyBXcTZ AlternateDataStreams: C:\Users\Usuario\AppData\Local\Datos de programa:aEnq4DmgPjzcbywsXHUneHz AlternateDataStreams: C:\Users\Usuario\AppData\Local\Datos de programa:tiuyYDMB3tpVZ8i2JLaC78ja C:\Users\Usuario\AppData\Local\YdPack C:\ProgramData\Microsoft\Secure EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

I couldn´t wait and delete the file the program found at temp. Can I still try this procedure? or better not??

Thanks a lot!

Run the fix as they will be regenerated by this :

C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll

Done it!
Fixlog attached!

Anyway, i can´t find this path:

C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll

You won’t find that path now as it was included in essexboy’s fix.

Could not move “C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll” => Scheduled to move on reboot.

??

The machine has reboot already…

then it was moved … as the fix log say :wink:

C:\ProgramData\Microsoft\Secure\Icons\SecureIconsProvider.dll => Is moved successfully.

then it´s over???

Thanks a lot!!!
Hope this works!

Thanks!

not finish yet … essexboy will check log and remove tools used when all is OK

Could you use the computer as normal for a few hours now and if all is well let me know and I will tidy up :slight_smile:

it seems to work well!

some silly questions: why avast was blocking but not deleting this virus?
and why all the scans (many softwares tried) said everything was ok untill the incredible aswMBR appeared?
is there an explanation?

Thanks again!

Avast knew the site it was calling was bad but did not know which programme originated it

As for the other tools, well something new comes out every day and it needs a human eye to see it

right, thank god there are people like you guys!

i believe i´m ready for the cleaning, what should i do?

In that case methinks I will send you on your merry way :slight_smile:

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Remove Combofix

Click Start then Run.
On Windows7 or Vista you may use Start Search field if Run is not available.
In the box copy/paste the following command:

ComboFix /Uninstall

Note that there is a space between " ComboFix " and " /Uninstall " .

Then click OK (or press Enter ).
Wait for the uninstall process to complete.

Remove tools

Download and run Delfix

https://dl.dropboxusercontent.com/u/73555776/delfix.JPG

: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

If you do need to keep Java then download JavaRa
Run the programme and select Remove Java Runtime. Uninstall all versions of Java present
Once done then run it again and select Update Java runtime > Download and install Latest version

https://dl.dropboxusercontent.com/u/73555776/javara.JPG

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG

Malwarebytes.

Update and run weekly to keep your system clean

Unchecky

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme :wink:

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:

Hi essexboy!
I´ve done everything you told me, uninstall java too.
One question: crypto is asking me if I want to whitelist items located in blocked location…
What should I do?

Yes whitelist the current items :slight_smile: