Avast says I’m unprotected.
It says the background service is not started, and nothing happens when I click “Start Now”
It says the firewall is not running. I click “turn on” and it says that it is “unable to start firewall!”
I try to login, says “Internal server error!”
I’m a paid user of AIS.
I’ve tried to uninstall, it won’t let me.
I’ve tried to repair and reboot.
I’ve installed the 2016 version.
What’s going on?
What do I do next?
Thanks!
Forgot to mention, it won’t run a scan, says there are no endpoints.
When I try to uninstall, I get the “just switch to free” screen, which leads nowhere, and there’s no other button that I can see on my monitor in Safe Mode.
Windows 7, 64 bit.
Just tried to reset to factory settings. Error message reads:
“Error during resetting to default settings. The AAVM subsystem detected a RPC error.”
Did you just install avast?
What antivirus did you use before avast, and was it uninstalled according to vendors instructions before installing avast?
No, been using Avast for years. Paid, all that.
I downloaded some crappy ISO burner from FileHippo, seems to be what started the problems.
see here https://forum.avast.com/index.php?topic=53253.0
scroll down to second picture … Farbar Recovery Scan Tool … run as instructed and attach the two diagnostic logs
Thanks!!! Please see attached.
Now you wait for the log expert to arrive
Is there hope for me?
Please also attach the mbam log.
I don’t see where such a file was generated, do I need to run that same program in a different way? I reopened that program, its not apparent to me which buttons I should be clicking.
there is no need for it yet, if Essexboy (log expert) need it he will ask for it and give you instructions
Since it soon midnight here in europe he may not reply before tomorrow
Is there hope for me?I just spoke to your doctor and he said no. But the good news is, there is hope for your system ;D
OK a question first… Did you install Norton VIP access ?
Also are you unable to run a repair on Avast ?
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: HKU\S-1-5-21-1706253155-2584530251-1239189411-1002\...\Run: [C:\Users\JAMIEM~1\AppData\Local\Temp\BoxForOutlook.exe] => C:\Users\JAMIEM~1\AppData\Local\Temp\BoxForOutlook.exe /exenoupdates /exelang 0 /prereqs "0" <===== ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggUJQoAUFpBQBgbIQoITA1BEAUOIg0AUxQVGFcSc18NVQgTGFYFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg== HKU\S-1-5-21-1706253155-2584530251-1239189411-1002\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggUJQoAUFpBQBgbIQoITA1BEAUOIg0AUxQVGFcSc18NVQgTGFYFIk0FA1ADB0VXfVBdFElXTwhwJVhKAlE8TkdGC1dXFg== SearchScopes: HKLM -> DefaultScope {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ5dUgFAQgVCbQFZUglcFQUScBRaVQFDDFEaIggLBwxFEFcaIx9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms} SearchScopes: HKLM -> OldSearch URL = hxxp://www.bing.com/search?q={searchTerms}&form=CMNTDF&pc=CMNTDF&src=IE-SearchBox SearchScopes: HKLM -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM -> {ec29edf6-ad3c-4e1c-a087-d6cb81400c43} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ5dUgFAQgVCbQFZUglcFQUScBRaVQFDDFEaIggLBwxFEFcaIx9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms} SearchScopes: HKLM-x32 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKU\S-1-5-21-1706253155-2584530251-1239189411-1002 -> DefaultScope {D97053E8-8FA8-4725-9D95-9FB338F3DD01} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ5dUgFAQgVCbQFZUglcFQUScBRaVQFDDFEaIggLBwxFEFcaIx9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms} SearchScopes: HKU\S-1-5-21-1706253155-2584530251-1239189411-1002 -> OldSearch URL = hxxps://www.google.com/search?q={searchTerms} SearchScopes: HKU\S-1-5-21-1706253155-2584530251-1239189411-1002 -> {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://search.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKU\S-1-5-21-1706253155-2584530251-1239189411-1002 -> {D97053E8-8FA8-4725-9D95-9FB338F3DD01} URL = hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ5dUgFAQgVCbQFZUglcFQUScBRaVQFDDFEaIggLBwxFEFcaIx9aFQQTSEcFME0FCFwEURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms} Toolbar: HKU\S-1-5-21-1706253155-2584530251-1239189411-1002 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File FF Homepage: hxxp://searchinterneat-a.akamaihd.net/h?eq=U0EeCFZVBB8SRggUJQoAUFpBQBgbIQoITA1BEAUOIg0AUxQVGFcSc18NVQgTGFYFIk0FA18DB0VXfV9eFElXTwhwJVhKAlE8TkdGC1dXFg== FF NewTab: hxxp://searchinterneat-a.akamaihd.net/t?eq=U0EeFFhaR1oWHAJGcwEJAgkQDA1CcwkVVQlAERhBdAEKTF1IQwQQJgwMUFtIQhNBNARaB0tXUUEeJl9NER8fHGZGIUtbCXQeU1BoLlZP FF Keyword.URL: hxxp://searchinterneat-a.akamaihd.net/s?eq=U0EeE1xZE1oZB1ZEfQ5dUgFAQgVCbQFZUglcFQUScBRaVQFDDFEaIggLBwxFEFcaIx9aFQQTR0cFME0FB18EURNNfWpdAEsSSXhMMlxzD1YG&q={searchTerms} FF SearchPlugin: C:\Users\Jamie McGloin-King\AppData\Roaming\Mozilla\Firefox\Profiles\eu3v7m7t.default\searchplugins\search-simple.xml [2015-11-24] R0 MfeEpeOpal; C:\Windows\System32\Drivers\MfeEpeOpal.sys [100808 2012-04-05] (McAfee, Inc.) R0 MfeEpePc; C:\Windows\System32\Drivers\MfeEpePc.sys [158920 2012-04-05] (McAfee, Inc.) 2015-11-23 14:42 - 2015-11-23 14:42 - 00003276 _____ C:\windows\System32\Tasks\{6FD0237F-F932-40B9-BB40-EA62356604ED} Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Please download AdwCleaner by Xplode onto your desktop.
[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.
Regarding Norton VIP Access:
- it was on my computer when I started having this problem. Not sure how long I’ve had it or where it came from, didn’t interact with it much.
- yesterday, when casting about for solutions, I uninstalled it. I had to use the Windows thing where you say you’re having trouble uninstalling things and it takes you to a windows website and you download something and run it.
Correct, I was unable to repair Avast in any way that fixed anything.
Does anything about those answers affect your instruction set?
Many thanks!!!
Nope, but I have also removed two McAfee drivers so we will see if that makes a difference