Malware-gen infection Avast service disabled.

I have a Malware-gen infection according to Avast, avast can’t delete it When windows rebooted it became really a huge problem. After the reboot multiple services are disabled and can not be started including Avast. Windows installer Windows Update, and the Security Center. Most of the 32bit programs can also not be started. The OS is Win7 64 bit and help would really be appreciated.
I have been locking all over for a solution but not even a clue and since avast can not be started I am really in a mess.

Help is needed.

So i guess you are using another computer to post this ?

Try this Dr.Web® LiveCD
Emergency System Recovery Disk http://www.freedrweb.com/livecd/?lng=en
How does it work? http://www.freedrweb.com/livecd/how_it_works/?lng=en

Yes, the problem is on my private laptop and I am posting from a work computer. I’ll try the CD tomorrow,
Maybe I should add that system restore is also disabled as well as Shadow Copy

I have sendt a PM to our malware remover expert Essexboy, he may be in bed now, if so he wont show until late uk time tomorrow

Can you get to the safe mode menu ? If so select the repair my computer option

I can go to safe mode and I can start repair, but it ed end with an errormessaga saying that some files can not be opened because of som antivirus app is running. but that message is not correct, avast is diabled and doesn’t run It can not be started.
If I go to system reset, I can run reset, but only restor from the latest (last) restore point if I select a previous reotore point i get the same errormessage as I do when I run repair, antivirus is loocking some file…

OK then lets have a look see

Download OTL to your Desktop

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select All Users
[*]Under the Custom Scan box paste this in

[b]netsvcs
%SYSTEMDRIVE%*.exe
/md5start
explorer.exe
winlogon.exe
/md5stop
%systemroot%*. /mp /s
CREATERESTOREPOINT

[/b]

[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.

[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Didn’t do anything. As I said before it is nott possible to run a 32 bit program, so when Itry to run the program only see this little rotating circle for a few seconds and then nothing.

Do you have the facility to burn a live CD ? If so

Please print these instruction out so that you know what you are doing

OTLPENet.exe
MD5=C2629B6D6FA189EA92FF6FD1FFA2A81D
127,353,979bytes / 121.4MB

[*]Download OTLPENet.exe to your desktop
[*]Download the attached scan.txt to a USB
[*]Ensure that you have a blank CD in the drive
[*]Double click OTLPENet.exe and this will then open imgburn to burn the file to CD

[*]Reboot your system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
[*]As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads :slight_smile:

[*]Your system should now display a Reatogo desktop.
Note : as you are running from CD it is not exactly speedy
[*]Double-click on the OTLPE icon.
[*]Select the Windows folder of the infected drive if it asks for a location
[*]When asked “Do you wish to load the remote registry”, select Yes
[*]When asked “Do you wish to load remote user profile(s) for scanning”, select Yes
[*]Ensure the box “Automatically Load All Remaining Users” is checked and press OK
[*]OTL should now start.
[*]Double click the Custom scans and fixes box
[*]In the dialogue locate the scan.txt you have on the USB
[*]Press Run Scan to start the scan.
[*]When finished, the file will be saved in drive C:\OTL.txt
[*]Copy this file to your USB drive if you do not have internet connection on this system.
[*]Right click the file and select send to : select the USB drive.
[*]Confirm that it has copied to the USB drive by selecting it
[*]You can backup any files that you wish from this OS
[*]Please post the contents of the C:\OTL.txt file in your reply.

Im starting to think that the Gods are against me. When I open the downloaded file to my second pc, the file opens nicely, I get the question if I would like to burn a CD, answer “Yes” get a message Extracting, then it hangs on extracting forever. and the program can’t be cancelled normayyl, after 2 hours of waiting (more than one cup of tea) then I cancelled via the task manager.

Tried again with a fresh download just in case, but same result.

I am now closer than ever to just reformatting the hard drive an start fresh. Thank God I have a fresh backup of my files…

This appears to be one of those cases where we can chase it around for a few days and not get a satisfactory resolution… Or bite the bullet and do a full reformat - much quicker

Agree reformat seems to be the way to go. But it would be nice to know what the virus is but nos I guess I’ll never nev
er know