system
October 25, 2014, 3:06pm
1
Long story short-
Frustrations with AGV’s constant request to shutdown to complete update lead me to uninstall it and attempt to install Avast free since it runs so nicely on my wife’s computer. Upon attempt to install Avast the process was stopped with the message- The base filtering engine (BFE) service is not running. A search of the service -local files does not show the BFE in residence there.
When the Avast installation when awry, I then attempted to reinstall AGV but was unsuccessful with that attempt as well. So now I’m without any antivirus protection what so ever. I’m not at all certain that the problem is virus related but came to this forum first as it seems to be a likely culprit.
I’m a 60 years old and not especially computer savvy so please bear with me.
Below are the results of several scans I’ve done.
Thanks for any informed advice!
Pondus
October 25, 2014, 3:25pm
2
according to log AVG is installed
AV: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}
AS: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}
a log expert will take a look when online …
First could you run the AVG removal tool from here http://www.avg.com/gb-en/utilities
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
HKU\S-1-5-21-3248977499-1159942530-1925479633-1000\...\Run: [AVG-Secure-Search-Update_1113a] => C:\Users\Hugh\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=41c40dd1f8189edbc97f4de61a06fb32-43a05bf02a6740cbc0124bd4b03d4b328d668e73 /CMPID=1113a
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files\AVG\AVG2012\avgssie.dll No File
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File
FF HKLM\...\Firefox\Extensions: [avg@igeared] - C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF Extension: AVG Security Toolbar - C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2011-09-17]
S3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [947528 2011-03-18] ()
C:\Users\Hugh\msgr11us.exe
2014-10-25 05:57 - 2013-05-31 12:08 - 00000350 _____ () C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2014-10-24 19:24 - 2010-10-15 20:25 - 00000000 ____D () C:\ProgramData\MFAData
2014-10-24 18:57 - 2010-09-23 21:16 - 00000000 ____D () C:\Program Files\AVG
2014-10-24 18:20 - 2013-09-21 14:12 - 00000000 ____D () C:\ProgramData\AVG2014
Task: {F0CD200D-6181-4D30-9CD0-041342D3254F} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\windows\TEMP\{106ADD5C-348D-4F41-8D86-54BA2BB9AD76}.exe
Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\windows\TEMP\{106ADD5C-348D-4F41-8D86-54BA2BB9AD76}.exe
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt , in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Download and run farbar service scanner
https://dl.dropboxusercontent.com/u/73555776/fssscan.JPG
Tick “All ” options.
Press “Scan ”.
It will create a log (FSS.txt ) in the same directory the tool is run.
Please copy and paste the log to your reply.
Eddy
October 25, 2014, 4:23pm
4
system
October 25, 2014, 6:41pm
5
Thanks to all who replied! The more sophisticated extraction tools dragged the last bits of AVG out that the basic uninstall had obviously left behind. Suddenly the BFE showed back up and I was able to install Avast with no further problem. Things appear to be ship shape once again and it’s great not to be hassled with the constant requests of AVG to do a restart.
I promise to pass some form of help forward.
Hugh
Pondus
October 25, 2014, 6:55pm
6
Did you also run the fix essexboy made for you… follow his instructions and attach requested logs
system
October 25, 2014, 11:38pm
7
First could you run the AVG removal tool from here http://www.avg.com/gb-en/utilities
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
HKU\S-1-5-21-3248977499-1159942530-1925479633-1000\...\Run: [AVG-Secure-Search-Update_1113a] => C:\Users\Hugh\AppData\Roaming\AVG 1113a Campaign\AVG-Secure-Search-Update-1113a.exe /PROMPT /mid=41c40dd1f8189edbc97f4de61a06fb32-43a05bf02a6740cbc0124bd4b03d4b328d668e73 /CMPID=1113a
BHO: No Name -> {02478D38-C3F9-4efb-9B51-7695ECA05670} -> No File
BHO: AVG Safe Search -> {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} -> C:\Program Files\AVG\AVG2012\avgssie.dll No File
BHO: No Name -> {5C255C8A-E604-49b4-9D64-90988571CECB} -> No File
Toolbar: HKLM - No Name - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG2012\avgpp.dll No File
FF HKLM\...\Firefox\Extensions: [avg@igeared] - C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared
FF Extension: AVG Security Toolbar - C:\Program Files\AVG\AVG10\Toolbar\Firefox\avg@igeared [2011-09-17]
S3 AVG Security Toolbar Service; C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe [947528 2011-03-18] ()
C:\Users\Hugh\msgr11us.exe
2014-10-25 05:57 - 2013-05-31 12:08 - 00000350 _____ () C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job
2014-10-24 19:24 - 2010-10-15 20:25 - 00000000 ____D () C:\ProgramData\MFAData
2014-10-24 18:57 - 2010-09-23 21:16 - 00000000 ____D () C:\Program Files\AVG
2014-10-24 18:20 - 2013-09-21 14:12 - 00000000 ____D () C:\ProgramData\AVG2014
Task: {F0CD200D-6181-4D30-9CD0-041342D3254F} - System32\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv => C:\windows\TEMP\{106ADD5C-348D-4F41-8D86-54BA2BB9AD76}.exe
Task: C:\windows\Tasks\AVG-Secure-Search-Update_JUNE2013_TB_rmv.job => C:\windows\TEMP\{106ADD5C-348D-4F41-8D86-54BA2BB9AD76}.exe
EmptyTemp:
CMD: bitsadmin /reset /allusers
Save this as fixlist.txt , in the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that
THEN
Download and run farbar service scanner
https://dl.dropboxusercontent.com/u/73555776/fssscan.JPG
Tick “All ” options.
Press “Scan ”.
It will create a log (FSS.txt ) in the same directory the tool is run.
Please copy and paste the log to your reply.
Here goes my best attempt. Thanks for the time and effort.
That looks good … Any further problems
system
October 26, 2014, 5:09pm
9
Everything seems to be working smoothly and it’s so nice to not be constantly asked to restart the computer.
Thanks so much for the help!!!
Hugh
In that case methinks I will send you on your merry way
Subject to no further problems
I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems
Now the best part of the day ----- Your log now appears clean
A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:
Download and run Delfix
https://dl.dropboxusercontent.com/u/73555776/delfix.JPG
: Keep Java Updated :
WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article
I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser )
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
CryptoPrevent install this programme to lock down and prevent crypto ransome ware
https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG
Malwarebytes .
Update and run weekly to keep your system clean
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe