Avast failed*...miserably.

I know people shouldn’t get annoyed, but it is a fact that the UAC isn’t user friendly, with no configuration. So it constantly harps in for stuff that really isn’t a problem and won’t remember your decisions, so there is a constant flood of pop-ups.

If it were more user friendly/configurable and remember your decisions then perhaps it would cut down on the number of pop-ups and users would be more likely to pay attention and not disable it in the first place.

I agree. More configurations will be welcome for sure. Like a remember option. Sure.

@ Sir D, Tech

Take a look at this site : http://helpdeskgeek.com/how-to/turn-off-user-account-control-uac-for-a-specific-application/

and this site: http://www.itknowledge24.com/downloads.html

Thanks.

However, all well and good, but this is hardly going to help the average user, as I said before the user doesn’t want all the hassle they just want to be able to use their computer, browse, etc. without having to take have a PHd in computer science.

If the functionality of this UAC Trust Shortcut (and you also need UAC Controller Tool v1.0) were built into UAC. But then if UAC was able to remember your choice. If the executable hasn’t changed since it was last used (MD5) then UAC shouldn’t challenge and these little utilities wouldn’t be needed (as it is unlikely the user will go looking for such utilities).

For such a small utilities, they need .net framework 4.0, this really is overkill to try and make UAC more user friendly. I have been trying to keep .net framework off my win7 netbook.

You’re Welcome.

I am no substitute for Essexboy, and winpatrol is probably no substitute for the tools he will use - but if you have it installed (or can install it), it might just be worth trying to use it to simultaneously kille the multiple instances of the bug (which may be restarting each other).

'Dealing with Stubborn Tasks

Sometimes malicious programs come in pairs or groups that protect each other to prevent you from removing them. In such cases, you will want to find all the suspicious tasks on the Active Tasks list and use the Kill Task feature to shut down each one before removing the suspicious entry from the Startup Programs list.

First, close down all the applications that you know about.
Click the Active Tasks tab to check what programs are still listed.
You may see multiple suspicious programs. Some may have what look to be randomly created filenames.
Hold down the CTRL key to select several tasks at once and click on each suspicious task.
Click on the Kill Task button.

Once the programs are no longer active you should be able to remove them from the Startup Programs list to prevent them from re-starting later.

“Delete File on Reboot”
If after trying to remove a suspicious or dangerous program you find it still will not go away, right-click on the name of the program Module and select “Delete File on Reboot.” This action will not take place until the next time you boot, but the file will be deleted before Windows starts and any other programs that may attempt to prevent its deletion.

There is no way to recover the file once it is deleted, so use this feature only when you are absolutely sure you want to remove the file.’

Just possibly worht a go while you wait?

Hi if it is still running on your system then the first tool will kill it and the second will allow me to find any remnants

Download RogueKiller to your desktop

[]Quit all running programs
[
]For Vista/Seven, right click → run as administrator, for XP simply run RogueKiller.exe
[]When prompted, type 2 and validate
[
]The RKreport.txt shall be generated next to the executable.
[*]If the program is blocked, do not hesitate to try several times. If it really does not work (it could happen), rename it to winlogon.exe

Please post the contents of the RKreport.txt in your next Reply.

THEN

Download OTS to your Desktop and double-click on it to run it

[*]Make sure you close all other programs and don’t use the PC while the scan runs.
[*]Select All Users
[*]Under additional scans select the following
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check

[*]Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
[*]When the scan is complete Notepad will open with the report file loaded in it.
[*]Please attach the log in your next post.

Unforunately, UAC was never disabled on my system, and the malware easily circumvented it.

As for the malware, Avast must have just figured it out this morning. After updating last night and getting nowhere - I booted up this morning and Avast figured it out after updating with a fresh update, so apparently I got a bleeding edge virus that Avast just got protection from. (Either that or they realized it from my post)

Avast did a boot scan, and I deleted the malware this morning. Unfortunately, my .exe association is completely broken, so my system is left in shambles. I’ve been attempting to get it running as we speak, and was able to open firefox by navigating to the directory, and running the executable as administrator (somehow this works).

Thanks for the help, and I’m glad Avast released new definitions to protect against this so that others aren’t left in my situation.

Unfortunate, but true the UAC seems to be more of a problem to users than to malware.

I rather doubt it was just as a result of this topic that avast added this to the detections, they actually need a sample to be able to analyse and add to the virus definitions.

That however, is an ongoing task playing catch-up with new variants.

I would still suggest you follow essexboy’s instructions, at the very least the OTS one which will provide detailed information on your system to ensure all elements are gone, registry entries, etc.

If you run OTS but change the extension to .com or .scr it will run, then I will be able to repair the associations

I downloaded a quick regedit fix for the executable issue.

Everything seems good now.

If you are happy then OK ;D

Heh, I am. I’m glad that avast updated for that as well.

Any other steps you think I should take just to be safe? Everything seems working fine, but do you think I should still do anything else?

Here it is just in case, but all seems well again:

http://pastebin.com/p3QhN3x0

Okay, I just scanned my computer with Malwarebytes and it managed to find 9 infections.

9 infections.

So that means I know of 10 infections that have totally slipped by Avast undetected.

I’m sorry.

I really am…

But Avast is poop. Uninstalled. Kthxbai.

What would have been helpful would have been to post the MBAM log of what was found.

You have two randomly named malware folders on your system. What AV are you going to replace it with ?

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says “Paste fix here” and then click the Run Fix button.

[Unregister Dlls]
[Files/Folders - Modified Within 30 Days]
NY ->  r0t835ni0n1t18aj4n071sa4s7m -> C:\Users\SeeD419\AppData\Local\r0t835ni0n1t18aj4n071sa4s7m
NY ->  r0t835ni0n1t18aj4n071sa4s7m -> C:\ProgramData\r0t835ni0n1t18aj4n071sa4s7m
[Files - No Company Name]
NY ->  r0t835ni0n1t18aj4n071sa4s7m -> C:\Users\SeeD419\AppData\Local\r0t835ni0n1t18aj4n071sa4s7m
NY ->  r0t835ni0n1t18aj4n071sa4s7m -> C:\ProgramData\r0t835ni0n1t18aj4n071sa4s7m
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
  

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here

I will review the information when it comes back in.