Author Topic: avast blocked by group policy  (Read 2023 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
avast blocked by group policy
« on: December 03, 2014, 02:17:12 PM »
hi

I have the avast blocked by group policy issue.

Malwarebytes sees no issue, I cannot delete AVAST to try reinstalling it.

- I have run malwarebytes and FARBAR - logs attached, can anyone suggest what  I need to be looking at?


« Last Edit: December 03, 2014, 03:22:35 PM by lewisij »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: avast blocked by group policy
« Reply #1 on: December 03, 2014, 03:41:42 PM »
I'll pass this on. But, do not be surprised if you recieve no answer. You have an extreme amount of torrents, and anyone trained by UNITE, follow UNITE rules.

Torrenting is bad. I very much so recommend you stop torrenting now.

Edit: OK. So, assuming no one posts here to assist you, I've confirmed with someone, who shall remain unnamed, that I can post a fixlist that'll remove Avast! restrictions, MBAM and Chrome restrictions. I'll give the removers who have yet to read it 24-36 hours before I post :-)
« Last Edit: December 03, 2014, 06:20:55 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: avast blocked by group policy
« Reply #2 on: December 04, 2014, 01:49:11 PM »
OK, enough waiting for me.

First off: Your FRST is running from a TEMP folder. Please DOWNLOAD it onto your Desktop (Instructions below)

Firstly:

P2P WARNING!
It appears that there is at least one Peer to Peer(P2P) program on your computer:

uTorrent

Whilst some P2P programs themselves may be harmless, we at Avast! do not recommend their use due to the extremely high likelyhood of obtaining an infection from files that have been downloaded. This may range from annoying adware to malicious trojans stealing your passwords and other personal information.

There is also the risk of inadvertently sharing information that wasn't intended due to incorrectly configured software.

It is highly likely that this is the source of the issue that brought you here today. And if not, probably what will bring you back at a later date.

Here are some useful links regarding the dangers of P2P software.
FBI: http://www.fbi.gov/scams-safety/peertopeer/oeertopeer
ITPro: http://www.itpro.co.uk/195672/file-sharing-infects-500000-computers

It is your choice of course, but if you do decide to keep this program installed, please refrain from using it whilst we are performing your clean up.
If you need assistance in removing the program(s), do not hesitate to ask.

Step 1

FRST Fix
  • If FRST64.exe is not on your desktop, please download Farbar Recovery Scan Tool and save it to your desktop.
  • Download the attached Attachment fixlog and save it to your desktop <<< very important - it must be in the same location as FRST64.exe
  • Right click frst.png and run as administrator. When the tool opens click Yes to the disclaimer.
  • Press the Fix button.
  • It will produce a log called fixlog.txt on your Desktop.
  • Please copy and paste the contents of that log back here.

NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

Step 2

Download Adwcleaner Save the file to the desktop.


NOTE: If you are using IE 8 or above you may get a warning that stops the program from downloading. Just click on the warning and allow the download to complete.

Close all open windows and browsers.
Vista/7/8 users: Right click the AdwCleaner icon on the desktop, click Run as administrator and accept the UAC prompt to run AdwCleaner.

  • Click the Scan button and wait for the scan to finish.
  • After the Scan has finished the window may or may not show what it found and above, in the progress bar, you will see: Pending.
  • Please uncheck elements you don't want to remove. Please Do Not delete anything at this time.
  • Click the Report button to get the log.
  • Copy and Paste it into your next reply. This report is also saved to C:\AdwCleaner\AdwCleaner[R0].txt.
  • Click the X in the upper right corner of the program or click the File menu and click Exit to close the program.


Items I need to see in your next post:
  • FRST Fixlog
  • ADWcleaner Scan Only log

Notes: I have told FRST to clear your Temps and to reboot. If FRST sits still for 30 minutes reboot... Ensure you save all of your work!
« Last Edit: December 05, 2014, 11:25:32 AM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: avast blocked by group policy
« Reply #3 on: December 04, 2014, 03:56:35 PM »
Sorry, one more note. Avast! tends to warn users about FRST and adwcleaner. Please disable Avast! whilst running Adwcleaner and FRST so there isn't a chance of interference.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline magna86

  • Anti Malware Fighter
  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4235
    • Ambulanta MyCity Forum - ASAP Member
Re: avast blocked by group policy
« Reply #4 on: December 05, 2014, 09:39:20 AM »
Hello lewisij and welcome to avast!. I will be working on your Malware issues.

Please note that these fixes are not instantaneous. Most infections require more than one round to properly eradicate.

Please stay with me until given the 'all clear' even if symptoms seemingly abate.

Kindly follow my instructions and please do no fixing on your own or running of scanners unless requested by a helper

Note that Michael (alan1998) despite his good will and desire is not qualified to provide assistance. For this reason I will take your case under my supervision.


---     ---     ---     ---     ---



Recommendation to remove & uninstall 'iolo technologies' System Mechanic' and jZip app from control panel>programs and features. They are not malicius per se.
Download fresh FRST to your desktop, do not run it through a browser. Run it by yourself via FRST icon ().

Follow Michael's guide for creating and running FixList and execute it via FRST tool. Post here FixLog.txt for my analysis. Same goes for Adware Cleaner (AdwCleaner AdwCleaner[R0].txt).

Then, post me the fresh FRST.txt logfile by re-running FRST tool and wait for my future directions.