Exception Code

Wondering if anyone can help me out. I’ve been having issues with my laptop for a couple months now. Website pages load very slow or don’t load at all, some pictures/links/articles, etc will partially load, when I open any program it opens slower than normal. At 1st I thought this was an internet issue but then I started getting this pop up every so often, see attachment. This started after I installed Avast but I have no clue if it has anything to do with it or not. I have done scan after scan, full scan, boot scan, at the suggestion of a friend I scanned with Malware Bytes and installed another program in the hopes that if it’s a virus and one program didn’t catch it, the other would. I don’t know too much about computers so I have no clue on what else can be done. I am so frustrated with this that I am ready to throw this laptop off my balcony so any help would be appreciated :-\

If you think you are infected, make a topic on the viruses and worms board:

http://forum.avast.com/index.php?topic=53253.0

Before that, I’d try a clean install of avast!

  1. Download Avastclear, Rejzors uninstall tool and the appropriate Avast program edition

Note: It’s important you used the stub online installer from the one I linked… NOT the offline one.

Note: You need to be ONLINE during this install (online installer works in all cases whereas offline sometimes doesn’t)

http://files.avast.com/iavs9x/avast_free_antivirus_setup_online.exe
http://files.avast.com/iavs9x/avast_pro_antivirus_setup_online.exe
http://files.avast.com/iavs9x/avast_internet_security_setup_online.exe
http://files.avast.com/iavs9x/avast_premier_antivirus_setup_online.exe

Avastclear : http://files.avast.com/iavs9x/avastclear.exe
Rejzors Uninstall tool: http://rejzor.wordpress.com/avast-cleanup-tool/

  1. Uninstall Avast by control panel [If you don’t have Avast in control Panel go to #4]
  2. Uninstall in safe mode using Avastclear.
  3. Run Rejzors Uninstall Utility in Normal Mode (removes traces avastclear doesn’t) - reboot.
    Check : Once uninstalled check in device manager>view>show hidden devices if there is anything related to avast with a yellow triangle… if so, uninstall it and reboot.
  4. Install the version you downloaded.
  5. Reboot.

You may want to use Opera instead of your usual browser to visit the pages/get the tools needed:
ftp://ftp.opera.com/pub/opera/win/1216/int/

That appears to be search protection an adware toolbar or its ilk. I would recommend removal using adwcleaner

Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S1].txt as well.

So I have 3 suggestions on what to do, which are appreciated but what’s the easiest way, not sure which one to try ??? … Is this a virus? (Attached is another picture which I meant to attach with the original post and is of the 1st pop up, then it switched to the other one)

Do as Essexboy says.

This?

AdwCleaner v3.018 - Report created 14/02/2014 at 19:58:45

Updated 28/01/2014 by Xplode

Operating System : Windows Vista ™ Home Premium Service Pack 2 (32 bits)

Option : Clean

***** [ Services ] *****

***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\ProgramData\Search Protection
Folder Deleted : C:\ProgramData\WeCareReminder
Folder Deleted : C:\Program Files\Toolbar Cleaner
Folder Deleted : C:\Users\Joshua\AppData\LocalLow\adawaretb
Folder Deleted : C:\Users\Joshua\AppData\LocalLow\PriceGong
Folder Deleted : C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\rir38jm9.default\adawaretb
File Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay.lnk
File Deleted : C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\rir38jm9.default\user.js

***** [ Shortcuts ] *****

***** [ Registry ] *****

Value Deleted : HKCU\Software\Mozilla\Firefox\Extensions [{EC8030F7-C20A-464F-9B0E-13A3A9E97384}]
Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{EC8030F7-C20A-464F-9B0E-13A3A9E97384}]
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtl.1
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary
Key Deleted : HKLM\SOFTWARE\Classes\AxMetaStream.MetaStreamCtlSecondary.1
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components{03F998B2-0E00-11D3-A498-00104B6EB52E}
Key Deleted : HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components{1B00725B-C455-4DE6-BFB6-AD540AD427CD}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{761F6A83-F007-49E4-8EAC-CDB6808EF06F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{76C45B18-A29E-43EA-AAF8-AF55C2E1AE17}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{7E84186E-B5DE-4226-8A66-6E49C6B511B4}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{80922EE0-8A76-46AE-95D5-BD3C3FE0708D}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{96EF404C-24C7-43D0-9096-4CCC8BB7CCAC}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{97720195-206A-42AE-8E65-260B9BA5589F}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{97D69524-BB57-4185-9C7F-5F05593B771A}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{986F7A5A-9676-47E1-8642-F41F8C3FCF82}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{B18788A4-92BD-440E-A4D1-380C36531119}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID{FE9271F2-6EFD-44B0-A826-84C829536E93}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{1631550F-191D-4826-B069-D9439253D926}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{95B7759C-8C7F-4BF1-B163-73684A933233}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats{FD72061E-9FDE-484D-A58A-0BAB4151CAD8}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{DF7770F7-832F-4BDF-B144-100EDDD0C3AE}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Key Deleted : HKCU\Software\pc optimizer pro
Key Deleted : HKCU\Software\wecarereminder
Key Deleted : HKCU\Software\YahooPartnerToolbar
Key Deleted : HKCU\Software\AppDataLow\Software\adawaretb
Key Deleted : HKCU\Software\AppDataLow\Software\DynConIE
Key Deleted : HKCU\Software\AppDataLow\Software\PriceGong
Key Deleted : HKLM\Software\adawaretb
Key Deleted : HKLM\Software\Freeze.com
Key Deleted : HKLM\Software\Toolbar Cleaner
Key Deleted : HKLM\Software\Viewpoint
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner

***** [ Browsers ] *****

-\ Internet Explorer v7.0.6002.18005

-\ Mozilla Firefox v27.0 (en-US)

[ File : C:\Users\Joshua\AppData\Roaming\Mozilla\Firefox\Profiles\rir38jm9.default\prefs.js ]

Line Deleted : user_pref(“extensions.wrc.SearchRules.ask.com.style”, ".WRCN {display:none} #yui-main .tsrc_vnru .title + .WRCN, #yui-main #teoma-results .title + .WRCN {display:inline !important; background: url("I[…]
Line Deleted : user_pref(“extensions.wrc.SearchRules.ask.com.url”, “^hxxp(s)?\:\/\/(.+\.)?ask\.com\/.*”);
Line Deleted : user_pref(“extensions.wrc.SearchRules.rambler.ru.style”, “.WRCN {display:none} .search-results .title + .WRCN {display:inline !important; background: url("IMAGE") right no-repeat}”);
Line Deleted : user_pref(“extentions.y2layers.installId”, “b0f772ca-7e37-4245-b0ae-2cecba04c782”);

-\ Google Chrome v

I think Essexboy is asleep now…he is the expert…looks like the log shows it got it but he really needs to respond.
So he has some feedback in the morning HOW does the machine work now ?

What’s the wow for? LOL…It seems to be ok so far but I have only used it to check my email and this forum so far…if I discover it didn’t work I’ll scream for HELP again :wink:

Sorry, late & typo…I edited…good to hear Essexboy got it for you.

Oh gotcha. Like I said so far so good, but curious on what Essexboy has to say about the log…everyone’s help and suggestions are much appreciated

Me too…

He should see it his morning time in about 4-6 hours away…depending on when we wakes. :slight_smile:

No,not like that but like this.
http://forum.avast.com/index.php?topic=53253.0
Attach the log files to your post.

Just adware files. If there are no further problems then consider it fixed :slight_smile:

I may have spoken too soon, it’s still a bit wonky and then I got this…what’s this mean?

Are you using any cyberlink software

Internet Explorer v7.0.6002.18005 ? Shouldn’t that be version 8?
And please attach the logs as requested.

I have no idea what cyberlink software is and I use Firefox not IE…let me clarify. This laptop was my son’s. His grandfather bought it for him, refurbed and there were some programs on here that I never paid attention to because I didn’t need them and since they never caused any issues I just left them alone. Now that you said that I went into Control Panel and there is something called CyberLink Ucam? I’m sure I can probably get rid of some of these programs but I don’t know which ones are actually needed vs. unnecessary and taking up space.

If you do not use the programme then uninstall it http://www.cyberlink.com/products/youcam/features_en_GB.html?r=1

Otherwise I would recommend that you update it

With regards to IE even if you do not use it, it is embedded in the system and does need to be kept up to date

Lets have a look at it and see what else is there

Download OTL to your Desktop
Secondary link

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif

[*]Select All Users
[]Select LOP and Purity
[
]Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
c:\program files (x86)\Google\Desktop
c:\program files\Google\Desktop
dir “%systemdrive%*” /S /A:L /C
/md5start
rpcss.dll
/md5stop
CREATERESTOREPOINT

[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs