Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: Shinigamisenpai on October 19, 2012, 02:34:54 AM

Title: Avast! Stopped working!!
Post by: Shinigamisenpai on October 19, 2012, 02:34:54 AM
(http://i180.photobucket.com/albums/x222/Enma_Ai_00/001.jpg)
One day just stopped. It began to read, insecure system, with a red cross and all. I uninstalled it in safe mode, and re-install, repair from the control panel, and all the solutions I found in this forum and I`m still having this problem.
My version is registered.
Thanks for any help you can give me.

- Which avast!: Free
- Which version: 7.0.1466
- OS: Windows Vista Home Basic, 32 bits, SP 1
- Other security related software installed: None
- Which AV did you use before avast!: After the problem I tried: AVG, Avira, Eset, Panda. But before, none. Avast! was my first AV.



Title: Re: Avast! Stopped working!!
Post by: Asyn on October 19, 2012, 06:55:27 AM
First, be sure to get rid of all remnants of your prior installed AVs.
-> https://support.avast.com/index.php?_m=knowledgebase&_a=viewarticle&kbarticleid=574
-> http://singularlabs.com/uninstallers/security-software/

1. Download avast! Free Antivirus: http://files.avast.com/iavs5x/avast_free_antivirus_setup.exe
2. Follow instructions: http://www.avast.com/uninstall-utility (Run this tool for all prior installed avast! versions..!!)
3. Reinstall avast! with the downloaded installer from point 1.
4. Reboot.
Title: Re: Avast! Stopped working!!
Post by: Shinigamisenpai on October 20, 2012, 01:28:52 AM
Done.... and still having the same problem.... :'(
Title: Re: Avast! Stopped working!!
Post by: Nesivos on October 20, 2012, 02:11:54 AM
Take a look here

https://forum.avast.com/index.php?topic=56896.0 (https://forum.avast.com/index.php?topic=56896.0)

also here

https://forum.avast.com/index.php?topic=90543.0 (https://forum.avast.com/index.php?topic=90543.0)

You could also do a Internet search for "avast in inconsistent state" to see if you can find other posts on this forum regarding your issue and how to possibly solve it.
Title: Re: Avast! Stopped working!!
Post by: Shinigamisenpai on October 20, 2012, 03:02:44 AM
Ok, done a clean reinstall, like it said on those post, and nothing changed. This´s my HijackThis log....

Title: Re: Avast! Stopped working!!
Post by: iroc9555 on October 20, 2012, 03:49:57 AM
Shinigamisenpai.

If you ran uninstallers from here: http://singularlabs.com/uninstallers/security-software/
for all those AV that you named above.

Uninstalled Avast! with  aswclear.exe (http://translate.google.es/translate?sl=en&tl=es&js=n&prev=_t&hl=es&ie=UTF-8&layout=2&eotf=1&u=http%3A%2F%2Fwww.avast.com%2Fes-es%2Funinstall-utility) in safe mode.

Reinstalled Avast! with a fresh copy downloaded from here: http://files.avast.com/iavs5x/avast_free_antivirus_setup.exe

and still having problems.

Better to follow this guide: http://forum.avast.com/index.php?topic=53253.0

and attach ( Do not copy/paste ) logs for AdwCleaner, Malwarebytes' (MBAM), OTL, and aswMBR.exe here where and specialist will review the logs.

FYI HijackThis is no longer used.
Title: Re: Avast! Stopped working!!
Post by: Shinigamisenpai on October 21, 2012, 11:10:34 PM
Ok, done all the stuff from the guide....

FYI HijackThis is no longer used.

Sorry, I just posted because that´s what the guy from these post had done

Take a look here
https://forum.avast.com/index.php?topic=56896.0 (https://forum.avast.com/index.php?topic=56896.0)
also here
https://forum.avast.com/index.php?topic=90543.0 (https://forum.avast.com/index.php?topic=90543.0)
You could also do a Internet search for "avast in inconsistent state" to see if you can find other posts on this forum regarding your issue and how to possibly solve it.
Title: Re: Avast! Stopped working!!
Post by: iroc9555 on October 22, 2012, 02:13:07 PM
Malware specialists notified. Wait please.
Title: Re: Avast! Stopped working!!
Post by: Pondus on October 22, 2012, 02:17:22 PM
i see lots of files from Panda Cloud Antivirus in there....   ::)
Title: Re: Avast! Stopped working!!
Post by: magna86 on October 22, 2012, 03:51:36 PM
Preparation ...


Multiple Antivirus Programs

You are running more than 1 Antivirus program!


(AVAST Software)
(Panda Security, S.L.)


Running - more than one - antivirus program is not recommended because:[list=1]
I strongly suggest you uninstall one of them.  Which one, is your decision.


Then go here adn download uninstaller tool to remove antivirus remains:
http://singularlabs.com/uninstallers/security-software/

----------------------------------------------

To make sure nothing left behind ...

Download   AppRemover  (http://www.appremover.com/) (~ 6MB) on Desktop .
Run it by double-clicking

Click Next, choose the second option (Clean Up a Failed Uninstall), confirm with Continue, go to Next, wait to be finished, choose If something is listed, scan and remove it by clicking on the Next .

*************************************
Malware Removal


Step#1 

Download TDSSKiller (http://support.kaspersky.com/downloads/utils/tdsskiller.exe)  and save it to your desktop

    Execute TDSSKiller.exe by doubleclicking on it.

Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.

******************************


Step#2 





> Download ComboFix from here (http://download.bleepingcomputer.com/sUBs/ComboFix.exe) and save it to your Desktop.
If you are unsure how ComboFix works please read this guide (http://www.bleepingcomputer.com/combofix/how-to-use-combofix) carefully.
note: ComboFix must be downloaded to your Desktop.

> Temporarily disable your AntiVirus program.
If you are unsure how to do this please read this (http://www.techsupportforum.com/forums/f50/how-to-disable-your-security-applications-490111.html) or this (http://www.bleepingcomputer.com/forums/topic114351.html) Instruction.

How to disable avast:

Note: Do not forget to turn on this option after the cleaning.



> Run ComboFix. Click on I Agree!
ComboFix will check if there is a newer version of ComboFix available.
Click Yes if prompted to download.

ComboFix will display DISCLAIMER OF WARRANTY ON SOFTWARE.
Click Yes to allow ComboFix to continue.

If Recovery Console is not installed, ComboFix will offer download & installation.
Click Yes to allow ComboFix to install Recovery Console.
Note:Do not mouse-click Combofix's window while it is running.
If you see a message like "Illegal operation attempted on a registry key that has been marked for deletion" just restart computer once more.


> When the tool is finished, it will produce a log report for you. (typical location: C:\ComboFix.txt )
  Attach log reports ( ComboFix.txt) back to topic.



***************************************



Step#3 



> Check USB storage devices / removable drives


Download MCShield from one of the following links:

MyCity -  Official download link (http://amf.mycity.rs/mcshield/)
Softpedija - Mirror download link (http://www.softpedia.com/get/Antivirus/MCShield.shtml)

Recommendation to under General and Scanner tab you click on Defaults button to choose recommended options.
When all scanning is done, you need to attach a logreport that has made MCShield.

Start -> All Programs -> MCShield -> Logs

Attach here -> AllScans.txt

Explanation: USB storage devices are all the USB devices that get their own partition letter at connecting to the PC,
e.g. flash drives (thumb/pen drives, USB sticks), external HDDs, MP3/MP4 players, digital cameras,
memory cards (SD cards, Sony Memory Stick, MultiMedia Cards etc.), some mobile phones, some GPS navigation devices etc.



Title: Re: Avast! Stopped working!!
Post by: Shinigamisenpai on October 26, 2012, 06:57:12 PM
This is what happened:
*AppRemover doesn´t find anything about Panda....
* I executed TDSSKiller.exe...here´s the log
*Combofix: downloaded the exe, Avast doesn´t let me turn off the shields, the program is still running "at my own risk." Then Windows will not boot, 5 blue deaths later,  I restored the system before ComboFix.
*I considered throwing the notebook against the wall and set it on fire
* I don´t have any usb stuff, just a cellphone with a memory card.... I connected it anyway and the log off McShield is empty...

And... Avast is working again!!! I don´t know in what part of this disaster that happened! So is finished? I need anything else? Final advice?
Thank you so much for your help!!!!
Title: Re: Avast! Stopped working!!
Post by: magna86 on October 26, 2012, 08:32:39 PM
Hm hard one ... Ok.

We will repet TDSSKiller scan. If you have old copy of TDSSKiller, please delete adn download fresh one:


>>  Step#1 
Download TDSSKiller (http://support.kaspersky.com/downloads/utils/tdsskiller.exe)  and save it to your desktop

    Execute TDSSKiller.exe by doubleclicking on it.

Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please post the contents of that log in your next reply.

********************************


>>  Step#2


Note:It will also create a log in the C:\ directory. 


*********************

>>  Step#3
Re-run OTL, click on RunScan and attach here fresh OTL.txt logreport

**********************

>>  Step#4

Download  AVZ Antiviral Toolkit   from the following link:

http://support.kaspersky.com/downloads/utils/avz4.zip

Attach file virusinfo_syscheck.zip contained in folder AVZ \ Log on the forum.

Title: Re: Avast! Stopped working!!
Post by: Shinigamisenpai on October 30, 2012, 10:51:13 PM
Hi again! Sorry for the delay.... Here`re the files you asked me!

*virusinfo_syscheck.zip.
You cannot upload that type of file. The only allowed extensions are txt,jpg,gif,png,log.

So here´s the file on mediafire...
http://www.mediafire.com/?nnxmg9a6fpx051j
Title: Re: Avast! Stopped working!!
Post by: magna86 on October 31, 2012, 11:07:21 AM
Hi,
I still see driver modules by two active antivirus that may cause real problem to your system.


DRV - [2012/08/21 06:13:15 | 000,355,632 | ---- | M] (AVAST Software) [Kernel | System | Running] -- C:\Windows\System32\drivers\aswSP.sys -- (aswSP)
DRV - [2012/06/27 15:51:06 | 000,153,000 | ---- | M] (Panda Security, S.L.) [Kernel | System | Running] -- C:\Windows\System32\drivers\NNSPrv.sys -- (NNSPRV))


>> Please, read again "Multiple Antivirus Programs" and warning.

You need to uninstall one AntiVirus. Than download uninstaller tool to remove remaining leftovers.
http://singularlabs.com/uninstallers/security-software/

******************************

Re-run OTL.exe.

Code: [Select]

:OTL
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://eis.esnips.com/page/search/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d
IE - HKU\S-1-5-21-2712004474-2089528838-1624444860-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.babylon.com/?AF=108976&babsrc=HP_ss&mntrId=04ec29e10000000000000015afb0ef47
IE - HKU\S-1-5-21-2712004474-2089528838-1624444860-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}&AF=108976&babsrc=SP_ss&mntrId=04ec29e10000000000000015afb0ef47
IE - HKU\S-1-5-21-2712004474-2089528838-1624444860-1000\..\SearchScopes\{25477387-2310-45df-933D-E9416D3D0303}: "URL" = http://eis.esnips.com/page/search_provider/?client_uuid=bda82ac0-85c3-4b48-b0d2-41fde8d1391d&q={searchTerms}
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (no name) - {B530A9A4-1722-4D16-AAD6-AA85E3AD2ADE} - No CLSID value found.
O33 - MountPoints2\{19558f4f-9bf0-11de-a53a-0015afb0ef47}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE      .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{19558f58-9bf0-11de-a53a-0015afb0ef47}\Shell\AutoRun\command - "" = E:\em8tqm.cmd
O33 - MountPoints2\{19558f58-9bf0-11de-a53a-0015afb0ef47}\Shell\open\Command - "" = E:\em8tqm.cmd
O33 - MountPoints2\{19558f77-9bf0-11de-a53a-0015afb0ef47}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\update.exe
O33 - MountPoints2\{19558f77-9bf0-11de-a53a-0015afb0ef47}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-1482476501-1644491937-682003330-1013\update.exe
O33 - MountPoints2\{19558f7f-9bf0-11de-a53a-0015afb0ef47}\Shell\AutoRun\command - "" = E:\WIN\DOWS\LAX.exe
O33 - MountPoints2\{19558f7f-9bf0-11de-a53a-0015afb0ef47}\Shell\open\command - "" = E:\WIN\DOWS\LAX.exe
O33 - MountPoints2\{1ad99163-77b5-11df-b1e0-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{1ad99163-77b5-11df-b1e0-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{1ad99168-77b5-11df-b1e0-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{1ad99168-77b5-11df-b1e0-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{2bd3f48c-b11d-11e0-a278-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{2bd3f48c-b11d-11e0-a278-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{4101fd19-3015-11df-b56d-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{4101fd19-3015-11df-b56d-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{4101fd25-3015-11df-b56d-0090f5812f32}\Shell - "" = AutoRun
O33 - MountPoints2\{4101fd25-3015-11df-b56d-0090f5812f32}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{50808b0a-f3c2-11de-9a0a-0090f5812f32}\Shell\AutoRun\command - "" = E:\rRYEyv.Exe
O33 - MountPoints2\{50808b0a-f3c2-11de-9a0a-0090f5812f32}\Shell\opEn\coMmaNd - "" = E:\rryEyV.exE
O33 - MountPoints2\{517d9a49-9bba-11df-8ce4-0015afb0ef47}\Shell\AutoRun\command - "" = p9rs.exe
O33 - MountPoints2\{517d9a49-9bba-11df-8ce4-0015afb0ef47}\Shell\open\Command - "" = p9rs.exe
O33 - MountPoints2\{551217e2-8a6f-11df-869d-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{551217e2-8a6f-11df-869d-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{55121801-8a6f-11df-869d-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{55121801-8a6f-11df-869d-0015afb0ef47}\Shell\AutoRun\command - "" = F:\AutoRun.exe
O33 - MountPoints2\{55d1bcd6-9be9-11de-88b9-0015afb0ef47}\Shell\AutoRun\command - "" = RECYCLER\autorun.exe
O33 - MountPoints2\{55d1bcd6-9be9-11de-88b9-0015afb0ef47}\Shell\open\command - "" = RECYCLER\autorun.exe
O33 - MountPoints2\{61fff5cb-c565-11df-abeb-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{61fff5cb-c565-11df-abeb-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{61fff5ea-c565-11df-abeb-0090f5812f32}\Shell - "" = AutoRun
O33 - MountPoints2\{61fff5ea-c565-11df-abeb-0090f5812f32}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{648e2de0-ca2e-11df-92ca-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{648e2de0-ca2e-11df-92ca-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{648e2de1-ca2e-11df-92ca-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{648e2de1-ca2e-11df-92ca-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{77c5a420-d067-11de-b7f8-0015afb0ef47}\Shell\AutoRun\command - "" = E:\RECYCLER\autorun.exe
O33 - MountPoints2\{77c5a420-d067-11de-b7f8-0015afb0ef47}\Shell\open\command - "" = E:\RECYCLER\autorun.exe
O33 - MountPoints2\{80bab5dd-13f5-11e0-9336-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{80bab5dd-13f5-11e0-9336-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{80bab5fc-13f5-11e0-9336-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{80bab5fc-13f5-11e0-9336-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{84da45d8-fc61-11e1-8dd7-0090f5812f32}\Shell - "" = AutoRun
O33 - MountPoints2\{84da45d8-fc61-11e1-8dd7-0090f5812f32}\Shell\AutoRun\command - "" = E:\setup.exe -a
O33 - MountPoints2\{85ffa9d3-8a85-11df-ad08-0090f5812f32}\Shell - "" = AutoRun
O33 - MountPoints2\{85ffa9d3-8a85-11df-ad08-0090f5812f32}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{8d2a725e-bc6a-11e1-862a-0090f5812f32}\Shell\AutoRun\command - "" = E:\urDrive.exe
O33 - MountPoints2\{8dfc310f-0ba8-11e2-87f7-0015afb0ef47}\Shell\AutoRun\command - "" = autorun.exe\autorun.exe\autorun.exe
O33 - MountPoints2\{8dfc310f-0ba8-11e2-87f7-0015afb0ef47}\Shell\open\command - "" = autorun.exe\autorun.exe\autorun.exe
O33 - MountPoints2\{ab9efd5d-9c13-11e0-be6c-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{ab9efd5d-9c13-11e0-be6c-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{ab9efd62-9c13-11e0-be6c-0015afb0ef47}\Shell - "" = AutoRun
O33 - MountPoints2\{ab9efd62-9c13-11e0-be6c-0015afb0ef47}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{cb322842-1801-11df-8334-0090f5812f32}\Shell - "" = AutoRun
O33 - MountPoints2\{cb322842-1801-11df-8334-0090f5812f32}\Shell\AutoRun\command - "" = F:\start.exe
O33 - MountPoints2\{d63da928-f680-11e1-a5ee-0015afb0ef47}\Shell\AutoRun\command - "" = E:\RunClubSanDisk.exe
O33 - MountPoints2\F\Shell - "" = AutoRun
O33 - MountPoints2\F\Shell\AutoRun\command - "" = F:\start.exe
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:1CE11B51
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:8CE646EE

:Files
C:\Program Files\mozilla firefox\searchplugins\babylon.xml
C:\Users\Bangho\AppData\Local\Babylon
C:\ProgramData\Babylon
C:\Users\Bangho\AppData\Roaming\Babylon
ipconfig /flushdns /c
netsh int ip reset c:\resetlog.txt /c
ipconfig /release /c
ipconfig /renew /c

:commands
[CREATERESTOREPOINT]
[emptytemp]


***********************


> Re-run OTL, click on RunScan and attach here fresh OTL.txt log
Title: Re: Avast! Stopped working!!
Post by: Shinigamisenpai on November 19, 2012, 08:47:23 PM
Hi, I want to thank the help and patience you gave me with this problem, but after many difficulties, I wiped my drive and installed Windows 7. Thanks anyway! You were very kind.
Kisses!! :D