Cannot install Avast (BFE service is not running)

Hello,

On this laptop it had AVG installed as well as some McAfee scan tools. I removed the McAfee products using the removal tool and uninstalled AVG as I always use Avast. When trying to install Avast it states the BFE service is not running and quits the installation. I ran MBAM as well as the other tools in the Avast forum sticky thread and am attaching all logs requested.

Thank you for your much needed help!

Hello,

Is this your PC?

Hi TwinHeadedEagle,

This is my mothers laptop I am trying to get running smoothly for her as it had/has some viruses and malware.

1. Open notepad and copy/paste the text present inside the code box below.
To do this highlight the contents of the box and right click on it. Paste this into the open notepad.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to the operating system

createrestorepoint:
closeprocesses:
emptytemp:
Task: C:\windows\Tasks\SmartPCFix Task.job => C:\Program Files\SmartPCFix\SmartPCFix.exe <==== ATTENTION
Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\windows\TEMP\{6265F8A6-5686-4876-807C-C049E8AD6A35}.exe <==== ATTENTION
Task: {85CC3B0C-ED1A-4778-BD34-B4E159457E91} - System32\Tasks\SmartPCFix Task => C:\Program Files\SmartPCFix\SmartPCFix.exe <==== ATTENTION
AlternateDataStreams: C:\ProgramData\TEMP:2CFBE2D1
HKU\S-1-5-21-1573421710-2260934194-1118575729-1000\Software\Classes\.exe: exefile =>  <===== ATTENTION
C:\Program Files\SmartPCFix
C:\windows\TEMP\{6265F8A6-5686-4876-807C-C049E8AD6A35}.exe
HKU\S-1-5-21-1573421710-2260934194-1118575729-1000\...\Run: [Google Update**.d<*>] => "C:\Users\Karen\AppData\Local\Google\Desktop\Install\{be1f210f-21a5-f63b-4dc0-a7621a0988cb}\❤≸⋙\Ⱒ☠⍨\<U+202E>ﯹ๛\{be1f210f-21a5-f63b-4dc0-a7621a0988cb}\GoogleUpdate.exe" > <===== ATTENTION (Value Name with invalid characters)
Winsock: Catalog5 01 mswsock.dll No File ATTENTION: LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
cmd: netsh winsock reset
HKU\S-1-5-21-1573421710-2260934194-1118575729-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.att.net/
HKU\S-1-5-21-1573421710-2260934194-1118575729-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com/ig/redirectdomain?brand=TSNA&bmod=TSNA
SearchScopes: HKLM -> DefaultScope {47DEE0AE-81BF-4362-80A3-CFCBA40FB61D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA
SearchScopes: HKLM -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKLM -> {47DEE0AE-81BF-4362-80A3-CFCBA40FB61D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA
SearchScopes: HKU\S-1-5-21-1573421710-2260934194-1118575729-1000 -> DefaultScope {47DEE0AE-81BF-4362-80A3-CFCBA40FB61D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA_enUS358
SearchScopes: HKU\S-1-5-21-1573421710-2260934194-1118575729-1000 -> {074E99B1-3CC4-45E9-AC20-7643A39FBC49} URL = hxxp://search.avg.com/route/?d=4cc8dd3b&v=6.10.6.4&i=26&tp=chrome&q={searchTerms}&lng={language}&iy=&ychte=us
SearchScopes: HKU\S-1-5-21-1573421710-2260934194-1118575729-1000 -> {47DEE0AE-81BF-4362-80A3-CFCBA40FB61D} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSNA_enUS358
CHR HomePage: Default -> hxxp://www.att.net/
CHR StartupUrls: Default -> "hxxp://www.att.net/"
CHR DefaultSearchURL: Default -> hxxp://isearch.avg.com/search?cid={B779EF59-5098-4A46-A806-2A33B6925C5D}&mid=4287e2cc744347d19388d16f640e235e-8aa7601d0d92e27c167dcd98ae491b30ec9c42f2&lang=en&ds=AVG&pr=pr&d=2012-01-18 18:05:38&v=15.3.0.11&pid=avg&sg=0&sap=dsp&q={searchTerms}
CHR DefaultSearchKeyword: Default -> isearch.avg.com
CHR DefaultSuggestURL: Default -> hxxp://toolbar.avg.com/acp?q={searchTerms}&o=1
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
2014-02-18 21:58 - 2014-02-18 21:58 - 0000000 _____ () C:\Program Files\GUT6882.tmp
2013-05-16 14:40 - 2013-05-16 14:40 - 4167680 _____ () C:\Program Files\GUTE777.tmp
2012-01-15 15:07 - 2012-01-21 10:49 - 0009626 _____ () C:\Users\Karen\AppData\Roaming\40a64e26
2013-02-17 18:05 - 2013-02-17 18:05 - 0018609 _____ () C:\Users\Karen\AppData\Roaming\UserTile.png
2011-01-19 15:14 - 2015-09-15 23:07 - 0005738 _____ () C:\Users\Karen\AppData\Roaming\wklnhst.dat
2012-01-15 15:07 - 2012-01-21 10:49 - 0009603 _____ () C:\Users\Karen\AppData\Local\62e24a56
2014-03-30 17:46 - 2014-03-30 17:46 - 0000057 _____ () C:\ProgramData\Ament.ini
2012-01-15 15:07 - 2012-01-21 10:49 - 0009540 _____ () C:\ProgramData\f68339ff
C:\Users\Karen\AppData\Local\Google\Desktop\Install

2. Save notepad as fixlist.txt to your Desktop.
NOTE: => It’s important that both files, FRST and fixlist.txt are in the same location or the fix will not work.

3. Run FRST/FRST64 and press the Fix button just once and wait.
If the tool needed a restart please make sure you let the system to restart normally and let the tool completes its run after restart.

The tool will make a log on the Desktop (Fixlog.txt). Please attach it to your reply.
Note: If the tool warned you about the outdated version please download and run the updated version.

https://sites.google.com/site/cannedfixes/eset-services-repair/servicerepairico.png
Fix with ESET Services Repair

Please download Services Repair by ESET and save it to your desktop.

[*]Right-click on
https://sites.google.com/site/cannedfixes/eset-services-repair/servicerepairico.png
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
[*]If security notifications appear, click Continue or Run.
[*]Accept the prompt about restoring services.
[*]Once the tool has finished, you will be prompted to restart your computer. Click Yes to restart.
[*]A log will be saved in the CCSupport folder the tool created on your desktop.

Please include that logfile in your next reply.

I have attached the requested files.

Please note that for some reason when I open google and type in “avast forums” to come here it is now dreadfully slow. This is only occurring when searching. Going directly to the page loads fine.

How is the situation now?

My apologies for not being able to reply sooner. I had an emergency to tend to and was not at the computer.

The computer itself seems sluggish (for example shutting down or browsing folders) and when trying to search the internet it is normally very slow now. It is not my internet connection as I have computers and the internet is fine on them.

Please note the only other thing I have done other than your instructions was used the AVG Remover utility which came directly from the AVG website.

https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
Scan with Farbar Recovery Scan Tool

Please re-run Farbar Recovery Scan Tool to give me a fresh look at your system.

[*]Right-click on
https://sites.google.com/site/cannedfixes/farbar-recovery-scan-tool/FRST.gif
icon and select
https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg
Run as Administrator to start the tool.
(XP users click run after receipt of Windows Security Warning - Open File).
[*]Make sure that Addition option is checked.
[*]Press Scan button and wait.
[*]The tool will produce two logfiles on your desktop: FRST.txt and Addition.txt.

Please include their content into your next reply.

I have re-ran FRST as instructed. Before I ran FRST I did the following:

Ran MBAM again which found 0 threats.
Ran the Windows 7 System File Checker Tool which stated it found some problems and fixed them.
Ran Disk Defrag
Used CCleaner to delete all temporary files, etc.

The computer is still slow however it is intermittent. Even typing this sentence I have to wait for the text to appear on the screen as I am typing (up to 10 seconds). Other issues are when restarting the computer I get the “Waiting for processes to shutdown” prompt but there is nothing displayed.

I am attaching the FRST.txt and Addition.txt as posting their contents exceeds the message limit.