I think I’ve been hit by some type of malware attack. Avast was switched off and I was getting an error message about group policy settings when I tried to start Avast.
Am on Win 7 Home.
After much web searching and scans and installing and uninstalling of programs I have got to a stage where I can run Avast again.
But, Avast will not auto-start on boot-up! Also, the context menu scan feature seems not to work. :-[ :-\
Okay it was that the Avast icon was not in my system tray. I then went to Start: all Programs and tried to start Avast there. That is when I got the Group Policy type of error saying I didn’t have permission to start Avast.
I uninstalled avast from control panel then used avastclear in safe mode, booted to normal and used Rejzors uninstall. I have done this a few times now.
I had zonealarm and spybot s&d wen this all first happened. I now have malwarebytes installed and have just run a scan which showed as clear.
AswMBR though may be wrong. It took over 12 hours before I it save log and exited. Should I run it again? Not sure why the ‘quick scan’ took sooo long?
Note: You need to run the version compatibale with your system. If you are not sure which version applies to your system download both of them and try to run them.
Only one of them will run on your system, that will be the right version.
[*]Double-click to run it. When the tool opens click Yes to disclaimer.
[*]Press Scan button.
[*]It will make a log (FRST.txt) in the same directory the tool is run. Please attach it to your reply.
[*]The first time the tool is run, it makes also another log (Addition.txt). Please attach it to your reply.
1. Open notepad and copy/paste the text present inside the code box below. To do this highlight the contents of the box and right click on it. Paste this into the open notepad. NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system
Start
HKU\S-1-5-21-3722593541-308869362-1513390712-1004\...\MountPoints2: {11947c5c-04b8-11e3-bd8a-81689a2c6413} - D:\LaunchU3.exe -a
HKU\S-1-5-21-3722593541-308869362-1513390712-1004\...\MountPoints2: {1ff0c034-6e72-11e1-9a54-9fa5d182a443} - F:\PcOptions.exe
HKU\S-1-5-21-3722593541-308869362-1513390712-1004\...\MountPoints2: {3ea37072-b9d4-11df-9389-705ab64cd207} - F:\LaunchU3.exe -a
URLSearchHook: HKCU - (No Name) - {91da5e8a-3318-4f8c-b67e-5964de3ab546} - No File
Toolbar: HKCU - No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
Toolbar: HKCU - No Name - {91DA5E8A-3318-4F8C-B67E-5964DE3AB546} - No File
C:\Users\Mitul\AppData\Roaming\RegFree.ini
CMD: DEL %TEMP%\*.* /F /S /Q
CMD: RD /S /Q %TEMP%
End
2. Save notepad as fixlist.txt to your Desktop. NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.
3. Run FRST/FRST64 and press the Fix button just once and wait. If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.
The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply. Note: If the tool warned you about the outdated version please download and run the updated version.
[*] Please download ComboFix by sUBs and save it to your Desktop. You may read how Combofix works here.
[*] Temporarily disable your AntiVirus program, usually via a right click on the System Tray icon. They may interfere with Combofix. If you are unsure how to do this please read this or this Instruction.
[*] Run ComboFix. Click on I Agree! & follow the prompts. Note: If you see a message like “Illegal operation attempted on a registry key that has been marked for deletion” just restart your computer.
[*] When finished, it will produce a report for you. Please attach log reports (ComboFix.txt) back to topic. (typical log location: C:\ComboFix.txt )
Okay so this is odd… Even though there was no Avast icon in my system tray, when I turned on comboFix - it said avast was running. So I started Avast from he Start menu and then turned it off before running combofix.
Close all browser windows and refering to the picture above.
Referring to the screenshot above, drag CFScript.txt into ComboFix.exe.
ComboFix will will re-run. When finished, it will produce a log for you.
Attach the contents of the log in your next reply. (typical location: C:[b]ComboFix.txt[/b] )
Okay so I uninstalled zonealarm, rebooted, got nothing.
Removed spybot s&d also, rebooted, got nothing.
Uninstalled Avast, used avast cleaner and avast cleaner.
Re-installed Avast from online installer.
Rebooted…
And still no icon in systray. Context menu scan also still not working, in fact it gives me an error “AvastUI is currently not running. Please run the application before starting a scan”.