Avast WEBforum
Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: 14wolfe88 on April 07, 2011, 10:18:47 PM
-
Everytime I try to uninstall or upgrade it always says it wouldn't work due to an error and eventually I got this message"
07.04.2011 13:53:05 general: Started: 07.04.2011, 13:53:05
07.04.2011 13:53:05 general: Running setup_ais-3e8 (1000)
07.04.2011 13:53:05 system: Operating system: WindowsXP ver 5.1, build 2600, sp 3.0 [Service Pack 3]
07.04.2011 13:53:05 system: Memory: 40% load. Phys:1874156/2097151K free, Page:3266052/4194303K free, Virt:2067104/2097024K free
07.04.2011 13:53:05 system: Computer WinName: HOME-DD5CF14473
07.04.2011 13:53:05 system: Windows Net User: HOME-DD5CF14473\****
07.04.2011 13:53:05 general: Cmdline: /sfx /sfxstorage "C:\DOCUME~1\****\LOCALS~1\Temp\_av_sfx.tm~a01412" /brandcode "A" /srcpath "C:\DOCUME~1\Ryan\MYDOCU~1\DOWNLO~1" /sfxname "setup_av_free" /spawnfordeleter
07.04.2011 13:53:05 general: DldSrc set to sfx
07.04.2011 13:53:05 general: Old version: 2a5 (677)
07.04.2011 13:53:05 registry: Deleted registry: Software\AVAST Software\Avast\UpdateReady
07.04.2011 13:53:05 general: SGW32AIS::CheckIfInstalled set m_bAlreadyInstalled to 1
07.04.2011 13:53:05 system: Installed in: C:\Program Files\Alwil Software\Avast5 (15865M free)
07.04.2011 13:53:05 internet: SYNCER: Type: use IE settings
07.04.2011 13:53:05 internet: SYNCER: Auth: another authentication, use WinInet
07.04.2011 13:53:05 package: Part prg_ais-3e8 is installed
07.04.2011 13:53:05 package: Part vps_win32-11040701 is installed
07.04.2011 13:53:05 package: Part setup_ais-3e8 is installed
07.04.2011 13:53:05 package: Part jrog-a7 is installed
07.04.2011 13:53:05 package: Part jrog2-1b5 is installed
07.04.2011 13:53:05 general: LoadState: Edition=1
07.04.2011 13:53:05 general: Old version: 2a5 (677)
07.04.2011 13:53:05 file: SetExistingFilesBitmap: 811->88->33
07.04.2011 13:53:05 general: GUID: 0407a450-e0f7-494c-93c5-de4700d388cd
07.04.2011 13:53:05 general: SelectCurrent: selected server 'tmp sfx storage' from 'sfx'
07.04.2011 13:53:05 internet: SYNCER: Type: use IE settings
07.04.2011 13:53:05 internet: SYNCER: Auth: another authentication, use WinInet
07.04.2011 13:53:05 package: sfx edition: 1
07.04.2011 13:53:05 package: LoadProductVpu: C:\DOCUME~1\****\LOCALS~1\Temp\_av_sfx.tm~a01412\prod-ais.vpx
07.04.2011 13:53:05 package: LoadPartInfo: jrog = jrog-a7 returned 00000000
07.04.2011 13:53:05 package: LoadPartInfo: jrog2 = jrog2-160 returned 00000000
07.04.2011 13:53:05 package: LoadPartInfo: program = prg_ais-3e8 returned 00000000
07.04.2011 13:53:05 package: LoadPartInfo: setup = setup_ais-3e8 returned 00000000
07.04.2011 13:53:05 package: LoadPartInfo: vps = vps_win32-11022400 returned 00000000
07.04.2011 13:53:05 package: LoadProductVpu: C:\DOCUME~1\Ryan\LOCALS~1\Temp\_av_sfx.tm~a01412\prod-ais.vpx ended with 00000000
07.04.2011 13:53:08 general: Operation set to INST_OP_UNINSTALL
07.04.2011 13:53:08 general: Entered SetupProcessAIS::Do( INST_OP_UNINSTALL )
07.04.2011 13:53:08 general: Entered SetupProcessWin32Avast::Do( INST_OP_UNINSTALL )
07.04.2011 13:53:09 package: Transferred: files 0, bytes 0, time 0 ms
07.04.2011 13:53:09 package: Retries: total 0, files 0, servers 1
07.04.2011 13:53:09 general: DldSrc set to inet
07.04.2011 13:53:09 general: Server definition(s) loaded for 'main': 299 (maintenance:0)
07.04.2011 13:53:09 general: SelectCurrent: selected server 'Download746 AVAST5 Server' from 'main'
07.04.2011 13:53:09 internet: SYNCER: Type: use IE settings
07.04.2011 13:53:09 internet: SYNCER: Auth: another authentication, use WinInet
07.04.2011 13:53:10 internet: Sending stats 'http://download746.avast.com/cgi-bin/iavs4stats.cgi': 00000000 204
07.04.2011 13:53:10 file: NeedReboot=false
07.04.2011 13:53:10 general: Return code: 0x000004C7 [The operation was canceled by the user.]
07.04.2011 13:53:10 general: Stopped: 07.04.2011, 13:53:10
Tried just about everything. Any help would be greatly appreciated!
-
have you tried the uninstall tool? http://www.avast.com/en-no/uninstall-utility
-
...and have you tried it in safe mode? ;)
-
...and have you tried it in safe mode? ;)
My computer isn't able to go into safemode manually. I've tried but nothing works.
As for the tool it only runs in safemode and i can't do that.
-
Try disabling the avast self-defence module, avastUI, Troubleshooting and reboot.
Then try running the uninstall utility again.
-
My computer isn't able to go into safemode manually.
When the machine is booting up, hit the F8 key repeatedly until it goes into Safe Mode. You may be given several options while in Safe Mode, like Safe Mode with Networking which is fine to use as well...just stay off-line.
-
My computer isn't able to go into safemode manually.
When the machine is booting up, hit the F8 key repeatedly until it goes into Safe Mode. You may be given several options while in Safe Mode, like Safe Mode with Networking which is fine to use as well...just stay off-line.
I've actually just tried this 6 times in a row. It told me to hit enter, didn't give me any commands about safe mode and after try 4 I tried hitting F8 then F12 and nothing worked. This is frustrating because my computer doesn't have an AV an i can't uninstall it properly to get a new version. :(
-
Do you have a rescue/restore disk that came with the machine?
You do not have an AV on your machine currently?
-
You can try running the uninstall tool in normal mode, what other security software is on the system ?
-
Do you have a rescue/restore disk that came with the machine?
You do not have an AV on your machine currently?
Nope. I bought it refurbished 3 years ago and the dicks never gave me anything.
I've got an unregistered, outdated AV that doesn't work nor want to uninstall for me so I can get something new and updated.
-
Can you get into normal mode? If so, download and install MBAM (Malwarebytes) to check for malware that may be causing your problems.
· Download free http://www.malwarebytes.org/ (http://www.malwarebytes.org/) (the blue button) for an on-demand scanner.
· Double Click mbam-setup.exe to install the application.
· After install, click update so you have latest database before scanning.
· Under Settings:
o General: Automatically Save File After Scan Completes is checked off
o Scanner Settings: Check all boxes
o Updater: Download and install update if available is checked off
· Once the program has loaded, select "Perform FULL Scan", then click Scan.
· The scan may take some time to finish, so please be patient.
· When the disinfection scan is complete, a log will appear in Notepad and you may be prompted to Restart. (See Extra Note).
· Click the “remove selected” button to quarantine anything found. You will find the infection details under the Quarantine tab.
· The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
· Copy & Paste the entire report in your next reply.
-
Have you tried REVO UNINSTALLER??
-
Have you tried REVO UNINSTALLER?
Revo is not recommended for uninstalling security software, especially antivirus.
I still need to find out from the OP if he/she can get into normal mode, and if so run an MBAM scan since he/she is using outdated AV and could possibly have malware.
-
Have you tried REVO UNINSTALLER??
No good idea at this point.
Please let SafeSurf continue his support uninterrupted as he suspects some malware infection.
Thx.
-
Ok sorry guys.....jsut try to help here :-[ :-X
-
Ok sorry guys.....jsut try to help here :-[ :-X
No problem, anybody's help is highly appreciated. 8)
But it's not advisable at this stage in this particular thread.
Keep it up!
Zyndstoff
-
ok no problem bro , I know how frustrating it can be when someone is trying to help another person with there problems and everybody else is trying to interfere....But If anybody has any malware problems ; I just wanted everybody here to know ; At your service!!!! ;D
-
Have you tried REVO UNINSTALLER?
Revo is not recommended for uninstalling security software, especially antivirus.
I still need to find out from the OP if he/she can get into normal mode, and if so run an MBAM scan since he/she is using outdated AV and could possibly have malware.
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6330
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
4/11/2011 9:41:10 AM
mbam-log-2011-04-11 (09-41-10).txt
Scan type: Full scan (C:\|)
Objects scanned: 375618
Time elapsed: 2 hour(s), 32 minute(s), 42 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 1
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> Value: (default) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\secfile\shell\open\command\(default) (Rogue.MultipleAV) -> Value: (default) -> Quarantined and deleted successfully.
Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
c:\program files\image-line\Shared\DSP_IPP\uninstall.exe (Rootkit.Agent) -> Quarantined and deleted successfully.
-
So, MBAM did find and quarantine some stuff.
Is the problem solved now or do problems persist?
-
So, MBAM did find and quarantine some stuff.
Is the problem solved now or do problems persist?
I still can't get it to uninstall. I just noticed that when I take the checkmark off the self defence module for Avast! and apply the settings, and go back to it, the box is still checked off.
-
Rerun MBAM (Do an update first in the GUI! Quick Scan is good enough and it only takes minutes).
Rerun it, until the log is clear.
Try again then.
Did that help?
I notified the forum expert malware fighter. He'll look into this. Nick is "essexboy". Wait for his assistance please.
-
Hi we will need to fix the no safe boot problem first
Download OTS (http://oldtimer.geekstogo.com/OTS.exe) to your Desktop and double-click on it to run it
- Make sure you close all other programs and don't use the PC while the scan runs.
- Select All Users
- Under additional scans select the following
Reg - Disabled MS Config Items
Reg - Drivers32
Reg - NetSvcs
Reg - SafeBoot Minimal
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check
- Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
Userinit.exe
svchost.exe
/md5stop
%systemroot%\*. /mp /s
hklm\software\clients\startmenuinternet|command /rs
CREATERESTOREPOINT
- Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
- When the scan is complete Notepad will open with the report file loaded in it.
- Please attach the log in your next post.
-
First part
-
Second part.
-
Ok, thanks for the logs.
Please be patient, as essexboy can't be around here 24 hrs. 8)
He will further assist you. Do not follow anyone else's proposals until then.
Cheers
Zyndstoff
-
@ 14wolfe88,
I didn't abandon you and I'm glad Zyndstoff stepped in as I had no electricity due to storms. Thank you Zyndstoff for notifying Essexboy. ;)
Essexboy is on late UK time zone, so please check this thread at least daily and he will give you further instructions. Please do not make any further changes to your machine now that you have provided the logs (MBAM and OTS). Thank you.
-
@ 14wolfe88,
I'm glad Zyndstoff stepped in as I had no electricity due to storms. Thank you Zyndstoff for notifying Essexboy. ;)
No sweat. 8)
-
Here you go
Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.
[Unregister Dlls]
[Registry - Safe List]
< Run [HKEY_USERS\S-1-5-21-343818398-2049760794-725345543-1003\] > -> HKEY_USERS\S-1-5-21-343818398-2049760794-725345543-1003\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "Desura" -> [C:\Program Files\Desura\Desura\desura.exe -autostart]
[Registry - Additional Scans - Safe List]
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > ->
*netsvcs* -> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\\netsvcs
YY -> RPCQT -> C:\WINDOWS\system32\Rpcqt.dll
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost > ->
[Files/Folders - Modified Within 30 Days]
NY -> At1.job -> C:\WINDOWS\tasks\At1.job
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix. Post that information back here
I will review the information when it comes back in.