Avast WEBforum
Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: jayjay76 on June 03, 2011, 10:11:51 PM
-
I have a new install of Avast that I've started the boot-time scan on and it finds a Win32:Netsky-AF[Win] virus ... I choose REPAIR and it says it cannot repair it. I choose MOVE TO CHEST and the scan 'crashes' and Windows loads. This repeats every time I try a boot-time scan. Also, since this happened, I cannot load/view any NON-secure websites in IE8 nor in Chrome... I can view any https:// site, but not a single http:// site. I've tried re-registering the .DLLs and that doesn't work.
Not sure what to do short of an OS reinstall
This is on Windows XP SP3
Thanks for any help anyone can provide.
-
Please post the file
c:\Documents and Settings\All Users\Application Data\AVAST Software\Avast\log\aswBoot.log
-
There are not files in the /avast software/ folder.
It ends with c:\Documents and Settings\All Users\Application Data\Avast Software\ with no files or folders there.
-
If you have updated avast! from version 5, maybe it's not "AVAST Software\Avast", but rather "ALWIL Software\Avast5" ?
-
have you scanned with Malwarebytes ?
Malwarebytes Anti-Malware 1.50.1 http://filehippo.com/download_malwarebytes_anti_malware/
always update before you scan so you have latest signatures
click on the remove selected button to quarantine anything found
Post scan log here
-
This is a new download and install of Avast from today.
I uninstalled it and reinstalled it after this happened but to no avail. Avast won't put up real-time shields since this initial finding of a virus and immediately rebooting after trying to quarantine it.
I am scanning with Malware bytes ... found 3 items; all are in an "old harddrive" folder so none should be hurting the OS.
Here is the MBytes log:
Malwarebytes' Anti-Malware 1.51.0.1200
www.malwarebytes.org
Database version: 6765
Windows 5.1.2600 Service Pack 3
Internet Explorer 8.0.6001.18702
6/3/2011 4:51:45 PM
mbam-log-2011-06-03 (16-51-33).txt
Scan type: Full scan (C:\|)
Objects scanned: 269339
Time elapsed: 1 hour(s), 15 minute(s), 39 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\old harddrive\documents and settings\Owner\application data\spywarebot\quarantine\23-12-2007-09-38-28\15.qit (PUP.FunWebProducts) -> No action taken.
c:\old harddrive\documents and settings\Owner\application data\spywarebot\quarantine\23-12-2007-09-38-28\16.qit (Adware.MyWebSearch) -> No action taken.
c:\old harddrive\documents and settings\Owner\application data\spywarebot\quarantine\23-12-2007-09-38-28\17.qit (Adware.MyWebSearch) -> No action taken.
-
Files Infected:
c:\old harddrive\documents and settings\Owner\application data\spywarebot\quarantine\23-12-2007-09-38-28\15.qit (PUP.FunWebProducts) -> No action taken.
c:\old harddrive\documents and settings\Owner\application data\spywarebot\quarantine\23-12-2007-09-38-28\16.qit (Adware.MyWebSearch) -> No action taken.
c:\old harddrive\documents and settings\Owner\application data\spywarebot\quarantine\23-12-2007-09-38-28\17.qit (Adware.MyWebSearch) -> No action taken.
Why did you select "No action taken" instead of quarantine the infected items?
You may want to update MBAM again and run a Quick scan and select the correct action.
-
I did rerun MBytes and quaranteened those 3 files.
I reran a scan just now and it is not finding anything.
However, I still cannot connect to do an update for anything... it appears I can get to the outside world by specifying an IP address, but not by a FQDN. Avast, also, will not run real-time shields. I also cannot do a boot-time scan with AVast as it "chokes" on the Win32:Netsky-AF[Win] virus that it finds and then stops the scan and loads windows. I've uninstalled and reinstalled AVast with the exact same result.
-
Do you have MsnMsgrs.exe running (TaskManager)