Un/Re-install Problem

I have (had?) Avast Internet Security. Today I noticed that I couldn’t turn on my Firewall. I googled the error message (something like “Firewall cannot be turned on!” and followed the advice (I think it was a thread on this forum) to uninstall and reinstall. Upon attempting to reinstall, I am getting the message “Please fix this issue to continue the installation: The Base Filtering Engine (BFE) service is not running. Please ensure the service is enabled before installing avast!.”

How do I enable the BFE?

Thanks in advance!

Please, someone, help me as soon as poss because I can’t even turn on Windows Firewall now :frowning: …almost in tears. Also, I’m not hugely technical and don’t even know what a BFE is.

Hi there, what version of windows do you have ?

Download OTL to your Desktop
Secondary link

[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.

https://dl.dropboxusercontent.com/u/73555776/OTL_Main_Tutorial.gif

[*]Select All Users
[]Select LOP and Purity
[
]Under the Custom Scan box paste this in

netsvcs
BASESERVICES
%SYSTEMDRIVE%*.exe
CREATERESTOREPOINT

[*]Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach both logs

Thank You! Rescanning because I forgot to check All Users and None (under Extra Registry)

I have Windows 7

My second scan didn’t produce the Extras.Txt file, but I’ll attach the one from the first scan just in case that’s okay.

Also, I thought to turn on Windows Firewall while I work on this problem, but I can’t even do that! It gives me Error Code 0x80070424

Is there some way to protect my computer while I’m online waiting for an answer?

Hi could you open the OTL logs, save them as ASNI and then re-attach please

Hi Essexboy and thank you for responding. I actually was able to solve my problem by downloading a BFE file (from somewhere on a site called sevenforums) and then turning off my computer completely (not just a restart) and back on again. Then I was able to reinstall avast and turn on its firewall. So far, so good!

I do still have a question, though, because I still get an error message “Windows Firewall can’t change some of your settings. Error Code 0x80070424” when I click “Use recommended settings” under Systems and Security > Windows Firewall. Is this okay? Will the avast firewall be enough protection? I’ve run Malwarebytes AntiMalware and Spybot Search & Destroy several times until no problems existed (that they were able to detect).

Avast firewall is sufficient. It is just that the removal of the BFE service may mean some other services are also disabled which is why I asked for the OTL

Oh! So I’m not out of the woods yet then? Here’s the OTL as ANSI (attached). I appreciate your help!

OK I have found that you have several services missing, these include security centre and BFE among others. This is normally indicative of a zero access infection that was badly cleaned

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

  • IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here

[*]Double click on ComboFix.exe & follow the prompts.
[*]Accept the disclaimer and allow to update if it asks

http://img.photobucket.com/albums/v706/ried7/NSIS_disclaimer_ENG.png

http://img.photobucket.com/albums/v706/ried7/NSIS_extraction.png

[*]When finished, it shall produce a log for you.
[*]Please include the C:\ComboFix.txt in your next reply.

Notes:

  1. Do not mouse-click Combofix’s window while it is running. That may cause it to stall.
  2. Do not “re-run” Combofix. If you have a problem, reply back for further instructions.
  3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

First: Thank you. I appreciate your willingness to help me through this. I downloaded ComboFix, turned off avast (or so I thought) and tried to run ComboFix. ComboFix is giving me this message:

Warning!!! ComboFix has detected the following realtime scanners to be active:
antivirus: avast! Internet Security
antispyware: avast! Internet Security

Please let me know how to turn avast off completely. I’ve been through all the tabs and the only things I saw that I can disable are the shields, the firewall, and antispam. I have a big red box telling me You are Not Protected!!!

Meanwhile, the warning box from ComboFix tells me to “disable all scanners before clicking ok” and that I could seriously damage my machine.

Help! I’m stuck! I’m afraid to turn avast back on, though it’s not completely off apparently, and I’m afraid to click OK because I don’t think avast is completely shut down. The only thing I can think of is ctrl-alt-del. Should I do that? (Edit: I tried ctrl-alt-del on avast but it wasn’t “allowed.”)

Why doesn’t avast have one single command to “disable avast”? Maybe it does and I’m just not seeing it.

From bleepingcomputer:
How to Temporarily Disable your Anti-virus

AVAST
Right-click on the avast! icon in system tray (looks like this: avast.jpg but orange in color starting with v5). Select avast! shields control and there will be options to disable avast for 10 minutes, 1 hour, until the computer is restarted or permanently.

So! It looks like even though I’m getting that warning, avast really is disabled right now. They told someone else to ignore the warnings and just run it, but I’m hesitating as the thread is from 2011. I think I’m just going to back up and x-out the warning box for now and turn avast back on and wait for your reply.

Again, thank you so much!

Edit: Oh GOD! I clicked the x on the warning box (instead of OK, under the assumption that x would close/cancel it) and now I get THIS!

Warning!! The above realtime scanners are still active but ComboFix shall continue to run. Kindly note that this is at your own risk

What?! Are you KIDDING ME??? Kindly note, ComboFix, that you need a CANCEL button! I’m so SICK of this!!!

I’m also reading that no one should use this unless they are under the guidance of a malware removal specialist. Not to be rude, but are you one of those?

Yes essexboy is a malware specialist, he also instructs at Bleepingcomputer :slight_smile:

Please be patient and wait for essexboy to respond, he’ll be back on the forum in probably another 6-7 hours.

Thank you, Craig, I’m sitting here freaking right out. I am in the middle of downloading ArcheAge and wonder if I can continue the download with avast disabled or should I reenable avast and continue the download (it’s huge and taking forever, but now I only have about 6 more hours to go) and just kind of ignore that ComboFix warning box?

Personally I wouldn’t be downloading anything until the system is proven to be clean and avast is back up and working again with the all clear from essexboy, patience is required in these matters otherwise you could end up in more trouble than you started with.

Thank you, CraigB! And thank you, Essexboy! I’ll kill the download and be patient. Appreciate your voices of reason. I am so glad this forum exists or I’d be in dire straits. <3 I’ll check back in the morning. Huge appreciation ~

Ignore the combofix warning once the avast shields are off. Avast should then ignore any files being run

Glad to see you, Essexboy!
Ignored the warning and proceeded…here’s the CombFix log:

How is the computer running now ?