I typically install Avast on any computer that I do repairs on and I’ve never had any issues with it whatsoever. I use it on my own system (Purchase version) but the free version works great for every other system I’ve encountered. Recently I started to work on my brother-in-law’s system for him to try and fix it. After finally getting it to a point where it would run programs again I ran a malwarebytes scan. It came up with 822 infected objects (I am not even joking.) And I removed them. Now here’s the problem:
I installed Avast perfectly, no issues whatsoever.
When I click on the icon, even when running it as admin nothing happens. Nada. No error message or loading symbol at all. The process isn’t running and I cannot even do a manual start through the services menu. I tried completely uninstalling it with the utility in safe mode then reinstalling but it still didn’t work.
Any suggestions or help would be welcome, I’m about at my wits end here. I’ve done everything else but I refuse to give the computer back to him without having it scanned by Avast and able to use it easily.
It came up with 822 infected objects (I am not even joking.) And I removed them.
maybe the computer is still not clean....
see the guide at top in virus and worms forum section “logs to assist in cleaning malware”
attach the requested logs and a removal expert will help you
Mostly basic toolbar adware and registry changing stuff. I double checked to see and I haven’t noticed any lingering effects but I’ll double check with the guide posted above and get back to you guys.
:Commands
[CREATERESTOREPOINT]
:OTL
O2 - BHO: (no name) - {1036AD63-AEAC-460B-9060-C96005D4DC86} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found
O27:64bit: - HKLM IFEO\avastSvc.exe: Debugger - C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
O27:64bit: - HKLM IFEO\avastUI.exe: Debugger - C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avastSvc.exe: Debugger - C:\Windows\SysWow64\svchost.exe (Microsoft Corporation)
O27 - HKLM IFEO\avastUI.exe: Debugger - C:\Windows\SysWow64\svchost.exe (Microsoft Corporation)
O33 - MountPoints2\{9e4541d0-d07a-11de-a3ba-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{9e4541d0-d07a-11de-a3ba-806e6f6e6963}\Shell\AutoRun\command - "" = D:\install.EXE id= ver=1.0.0.0
:Commands
[resethosts]
[emptytemp]
[Reboot]
[*]Then click the Run Fix button at the top
[*]Let the program run unhindered, reboot the PC when it is done
[*]Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
OK the IFEO’s are still there, lets try a stronger tool
Download and Install Combofix
Download ComboFix from one of the following locations: Link 1 Link 2
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks
It’s still running fine although explorer.exe and related processes seem to have slowed immensely. Also I suddenly can’t connect to the internet on that computer. I had to put the log onto a thumbdrive to get it here. It seems that the laptop can no longer detect proxy settings. Anyway, here’s the log from the last program, still no avast though.
Also new Malwarebytes log. It was at 0 threats last night but 3 as of today.
Please downloadThe Avenger by Swandog46 to your Desktop.
[*]Right click on the Avenger.zip folder and select “Extract All…”
[*] Follow the prompts and extract the avenger folder to your desktop
Copy all the text contained in the code box below to your Clipboard by highlighting it and pressing (Ctrl+C):
Begin copying here:
Registry keys to delete:
HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\avastUI.exe
HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\image file execution options\avastSvc.exe
Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.
Now, open the avenger folder and start The Avenger program by clicking on its icon.
[*] Right click on the window under Input script here:, and select Paste.
[*] You can also click on this window and press (Ctrl+V) to paste the contents of the clipboard.
[*] Click on Execute
[*] Answer “Yes” twice when prompted.
The Avenger will automatically do the following:
[*]It will Restart your computer. ( In cases where the code to execute contains “Drivers to Delete”, The Avenger will actually restart your system twice.)
[*]On reboot, it will briefly open a black command window on your desktop, this is normal.
[*]After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
[*] The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
Please copy/paste the content of c:\avenger.txt into your reply along with a freshOTL log .
OK do you feel confident enough to do this manually ?
Go Start and in the search box type regedit
Regedit.exe will appear in the list
Right click this and select "Run as Administrator "
Navigate to the following keys using the little arrows to open each major group