The stub cannot run installer/updater executable (code 0x3)

Hello,

I have some problems running and updating Avast. I can’t update anything from the program, receiving the message: “The stub cannot run installer/updater executable ‘C:\Program Files\AVAST software\Avast\setup\Sfx\instup.exe’ (code 0x3)”. I’ve tried uninstalling and reinstalling the program, but can’t because of the above error.

I found a very similar problem in the forum (https://forum.avast.com/index.php?topic=168069.0) and the conclusion was that I might need a more tailored fix. I ran a FRST scan and have attached the results. Hopefully, I can find some help!

The FRST fix must be run from safe mode

CAUTION : This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:

CreateRestorePoint: HKU\S-1-5-19\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32 HKU\S-1-5-20\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32 HKU\S-1-5-21-448539723-1677128483-682003330-1003\...\Run: [uTorrent] => C:\Documents and Settings\XRHSTOS\Application Data\uTorrent\uTorrent.exe [1959424 2016-04-10] (BitTorrent Inc.) HKU\S-1-5-21-448539723-1677128483-682003330-1007\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32 HKU\S-1-5-21-448539723-1677128483-682003330-1007\...\RunOnce: [tscuninstall] => %systemroot%\system32\tscupgrd.exe HKU\S-1-5-18\...\RunOnce: [nltide_2] => regsvr32 /s /n /i:U shell32 HKU\S-1-5-18\...\RunOnce: [tscuninstall] => %systemroot%\system32\tscupgrd.exe AppInit_DLLs: c:\docume~1\alluse~1.win\applic~1\surfpr~1\surfpr~1.dll => No File ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => ashShell.dll No File ProxyEnable: [S-1-5-21-448539723-1677128483-682003330-1003] => Proxy is enabled. ProxyServer: [S-1-5-21-448539723-1677128483-682003330-1003] => 127.0.0.1:8118 AutoConfigURL: [S-1-5-21-448539723-1677128483-682003330-1003] => 127.0.0.1:8118 Tcpip\Parameters: [NameServer] 82.163.142.7 95.211.158.134 Tcpip\..\Interfaces\{1E277D8A-9B66-492E-85AA-3283EFF7B053}: [NameServer] 82.163.143.171,82.163.142.173 Tcpip\..\Interfaces\{76E71028-C2BA-44E6-A4AE-654E4794C0AE}: [NameServer] 82.163.143.171,82.163.142.173 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=1452254028&z=9342d1d121ec8691b064c56g0z2w2o4o6w5zae1c1g&from=wpm01073&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=1452254028&z=9342d1d121ec8691b064c56g0z2w2o4o6w5zae1c1g&from=wpm01073&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} HKU\S-1-5-21-448539723-1677128483-682003330-1003\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://yoursites123.com/web?type=ds&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} HKU\S-1-5-21-448539723-1677128483-682003330-1003\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.yoursites123.com/?type=hp&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F HKU\S-1-5-21-448539723-1677128483-682003330-1003\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.yoursites123.com/?type=hp&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F HKU\S-1-5-21-448539723-1677128483-682003330-1003\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://yoursites123.com/web?type=ds&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} URLSearchHook: [S-1-5-21-448539723-1677128483-682003330-1007] ATTENTION => Default URLSearchHook is missing HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs,Tabs: "hxxp://services.eshield.com/general/newhometab.php?hometab=home&partner=11433&guid={73334ADC-B95C-4676-A646-27F60F712E11}&i=" <======= ATTENTION SearchScopes: HKLM -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://yoursites123.com/web?type=ds&ts=1452254028&z=9342d1d121ec8691b064c56g0z2w2o4o6w5zae1c1g&from=wpm01073&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} SearchScopes: HKLM -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://yoursites123.com/web?type=ds&ts=1452254028&z=9342d1d121ec8691b064c56g0z2w2o4o6w5zae1c1g&from=wpm01073&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} SearchScopes: HKLM -> {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XPxdm049YYgr&ptb=AAF46128-D63D-49D4-925B-A08BF2D068D1&psa=&ind=2011101613&ptnrS=XPxdm049YYgr&si=2271&st=sb&n=77def9ad&searchfor={searchTerms} SearchScopes: HKLM -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=499&r=2013/02/24&hid=3829040971&lg=EN&cc=GR SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> DefaultScope {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://yoursites123.com/web?type=ds&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=100582 SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = hxxp://yoursites123.com/web?type=ds&ts=1457703598&z=29e4a86052f18f3c9b0d3d9g2z8w7m0m5eac2qae2e&from=eve0311&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F&q={searchTerms} SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {6679296E-7EA2-4FE2-AF19-F35A7B054894} URL = hxxp://trovi.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3329621&CUI=UN22690802462364312&UM=4 SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {a5b9c0f5-5616-47cd-a95f-e43b488faccf} URL = hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=XPxdm049YYgr&ptb=AAF46128-D63D-49D4-925B-A08BF2D068D1&psa=&ind=2011101613&ptnrS=XPxdm049YYgr&si=2271&st=sb&n=77def9ad&searchfor={searchTerms} SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {BB74DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.pu-results.info/?l=1&q={searchTerms}&pid=499&r=2013/02/24&hid=3829040971&lg=EN&cc=GR SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {BB82DE59-BC4C-4172-9AC4-73315F71CFFE} URL = hxxp://websearch.searchtotal.info/?l=1&q={searchTerms}&pid=24423&r=2015/06/08&hid=17383127931128611931&lg=EN&cc=GR&unqvl=88 SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {D6F10D28-6D2D-4BDF-BE37-C03D54C2274D} URL = hxxp://search.eshield.com/serp?guid={73334ADC-B95C-4676-A646-27F60F712E11}&action=default_search&k={searchTerms} SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {EFE522B3-7ABD-49CB-A5C3-A2AFBBA83B9D} URL = hxxp://www.bing.com/search?q={searchTerms}&form=MSERBM&pc=MSERT1 SearchScopes: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> {F9027F6B-FEC4-4B9E-9873-6480676F0774} URL = hxxp://search.yahoo.com/search?p={searchTerms}&fr=tightropetb&type=11433 Toolbar: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> No Name - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File Toolbar: HKU\S-1-5-21-448539723-1677128483-682003330-1003 -> No Name - {E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} - No File BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-10-03] (AVAST Software) Handler: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\14.0.1\ViProtocol.dll No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files\Internet Explorer\iexplore.exe hxxp://www.yoursearching.com/?type=sc&ts=1450721630&z=41f164ee5c1a8db9220fe6agez8wce8maocg3qbo4b&from=cor&uid=ST380815AS_9QZC1D9FXXXX9QZC1D9F CHR HKLM\...\Chrome\Extension: [cdnkbnlpcblgdhjibkegnkmecmeplafj] - C:\Program Files\Fookgle\Chrome.crx CHR HKLM\...\Chrome\Extension: [dkmjljdbbgogihjcapfhgkonfmccbffp] - hxxps://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - WebRep\Chrome\aswWebRepChrome.crx [2015-11-19] CHR HKLM\...\Chrome\Extension: [jbolfgndggfhhpbnkgnpjkfhinclbigj] - CHR HKLM\...\Chrome\Extension: [lgnbhdnimikkoodkogjlcllngimhlapp] - C:\Program Files\FTDownloader.com\FTDownloader10.crx R2 IhPul; C:\Documents and Settings\XRHSTOS\Application Data\TSv\TSvr.exe [116368 2016-03-17] (tsvr.com) R2 PrivoxyService; C:\Program Files\AFC Secure Net\privoxy.exe [371200 2016-04-26] (The Privoxy team - www.privoxy.org) [File not signed] <==== ATTENTION S2 avast! Antivirus; "AvastSvc.exe" [X] R2 aswHwid; C:\WINDOWS\system32\drivers\aswHwid.sys [24016 2015-11-19] (AVAST Software) R2 aswMonFlt; C:\WINDOWS\system32\drivers\aswMonFlt.sys [81168 2015-11-19] (AVAST Software) R1 aswRdr; C:\WINDOWS\system32\drivers\aswRdr.sys [55200 2015-11-19] (AVAST Software) R0 aswRvrt; C:\WINDOWS\system32\Drivers\aswRvrt.sys [49776 2015-11-19] (AVAST Software) R1 aswSnx; C:\WINDOWS\system32\drivers\aswSnx.sys [794952 2015-11-19] (AVAST Software) R1 aswSP; C:\WINDOWS\system32\drivers\aswSP.sys [435464 2015-11-19] (AVAST Software) S3 aswStmXP; C:\WINDOWS\system32\drivers\aswStmXP.sys [167152 2015-11-19] (AVAST Software) S3 aswTdi; C:\WINDOWS\system32\drivers\aswTdi.sys [57888 2015-11-19] (AVAST Software) R0 aswVmm; C:\WINDOWS\system32\Drivers\aswVmm.sys [209432 2015-11-19] (AVAST Software) S1 avgtp; \??\C:\WINDOWS\system32\drivers\avgtpx86.sys [X] 2016-04-29 14:11 - 2016-02-20 09:33 - 00000450 _____ C:\WINDOWS\Tasks\{6351B84A-D2DD-E080-3018-0FD647D8BD1C}.job 2016-04-29 14:00 - 2016-01-08 16:18 - 00019860 _____ C:\WINDOWS\Tasks\{04790D47-780E-0B7E-0411-09047A7D117D}.job 2016-04-29 09:45 - 2014-07-13 14:51 - 00000364 ____H C:\WINDOWS\Tasks\avast! Emergency Update.job 2016-04-28 18:02 - 2016-02-06 20:59 - 00000312 _____ C:\WINDOWS\Tasks\Win Update.job 2016-04-28 16:07 - 2016-02-12 19:02 - 00000262 _____ C:\WINDOWS\Tasks\System Defender Task.job 2016-04-27 19:02 - 2016-02-06 22:04 - 00000242 _____ C:\WINDOWS\Tasks\AFC Secure Net Task.job 2011-11-12 23:28 - 2011-10-16 20:32 - 0669072 _____ (MindSpark) C:\Program Files\64Uninstall TelevisionFanatic.dll C:\Windows\Tasks\{04790D47-780E-0B7E-0411-09047A7D117D}.job C:\Windows\Tasks\{6351B84A-D2DD-E080-3018-0FD647D8BD1C}.job Task: C:\WINDOWS\Tasks\AFC Secure Net Task.job => C:\Program Files\AFC Secure Net\amjob.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe Task: C:\WINDOWS\Tasks\DNSROSEVILLE.job => C:\Program Files\DNS UnlockerXRHSTOS DNSROSEVILLE-0?!1?!2?!a3?&4?(5?-6?7?8?9?:?;?<?=?a>??? 0? 0? 0? 0? 0?0?0?0?0?0?0?0e?0?0?0?0?a0 ?0!? 0? 0#? 0$? 0%? 0&?0'?0(?0)?0*?0+?0,? <==== ATTENTION Task: C:\WINDOWS\Tasks\System Defender Task.job => C:\Program Files\System Defender\SystemDefender.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\Win Update.job => C:\Documents and Settings\XRHSTOS\Application Data\Win Update\Win Update.exe <==== ATTENTION Task: C:\WINDOWS\Tasks\{04790D47-780E-0B7E-0411-09047A7D117D}.job => powershell exe Task: C:\WINDOWS\Tasks\{6351B84A-D2DD-E080-3018-0FD647D8BD1C}.job => C:\WINDOWS\system32\regsvr32.exeJ /s /n /i:/rt C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\af1e790b\e5f2eb36.dll <==== ATTENTION AV: AVG Anti-Virus Free Edition 2012 (Enabled - Up to date) {17DDD097-36FF-435F-9E1B-52D74245D6BF} C:\Documents and Settings\XRHSTOS\Application Data\TSv C:\Program Files\DNS Unlocker C:\Program Files\AFC Secure Net C:\Program Files\System Defender C:\DOCUME~1\ALLUSE~1.WIN\APPLIC~1\af1e790b Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f RemoveProxy: CMD: netsh advfirewall reset CMD: netsh advfirewall set allprofiles state ON CMD: ipconfig /flushdns CMD: netsh winsock reset catalog CMD: netsh int ip reset c:\resetlog.txt CMD: ipconfig /release CMD: ipconfig /renew CMD: netsh int ipv4 reset CMD: netsh int ipv6 reset EmptyTemp: CMD: bitsadmin /reset /allusers

Save this as fixlist.txt, in the same location as FRST.exe

https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG

Run FRST and press Fix
On completion a log will be generated please post that

THEN
Please download AdwCleaner by Xplode onto your desktop.

[*]Close all open programs and internet browsers.
[*]Double click on AdwCleaner.exe to run the tool.
[*]Click on Scan.
[*]After the scan is complete click on “Clean”
[*]Confirm each time with Ok.
[*]Your computer will be rebooted automatically. A text file will open after the restart.
[*]Please post the content of that logfile with your next answer.
[*]You can find the logfile at C:\AdwCleaner[S0].txt as well.

FINALLY

Download Avast Uninstall Utility to your Desktop.
Download the correct version of Avast
Avast Free
Avast Pro
Avast Internet Security
Avast Premier
Disconnect from the net
Uninstall Avast via control panel

[]Run the uninstall tool and accept the reboot to safe mode
[
]Once complete reboot your system
[*]Reinstall Avast


I think it’s working but I’m sending you the logs as well

How is the computer now ? Try updating Avast

Updated! Current version 11.2.2262. But the icon on the tray doesn’t rotate (internet connection working). Don’t know if that’s a problem

The icon rotation function is off by default - avastUI > Settings > General - Animate the icon when scanning. You may need to reboot before this takes effect.

Even then, it only scans for on-access scanning (web shield, file system shield, etc.) not for on-demand scans.

Thanx a lot both of you! Happy Easter!

Subject to no further problems :slight_smile:

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:

Remove tools

Download and run Delfix
Select the options as shown

https://dl.dropboxusercontent.com/u/73555776/delfix.JPG

: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

If you do need to keep Java then download JavaRa
Run the programme and select Remove Java Runtime. Uninstall all versions of Java present
Once done then run it again and select Update Java runtime > Download and install Latest version

https://dl.dropboxusercontent.com/u/73555776/javara.JPG

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware

https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG

Malwarebytes

Update and run weekly to keep your system clean

Unchecky

Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme :wink:

It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe :wave:

You’re welcome and a Happy Easter to you also.