Author Topic: Please Help  (Read 6932 times)

0 Members and 1 Guest are viewing this topic.

Mr. Week

  • Guest
Please Help
« on: December 31, 2012, 12:46:02 PM »
My Avast Free Anti-Virus could not automatically update when I turned my computer on so I clicked on it and I clicked the Update button. It would start updating and after about 1 second it stops and says that its finished but on the Summary tab says that my Virus Definitions Versions is outdated. When I try to update it just does the same thing again and again so I tried to look up on the internet what to do and then a Windows Action Center message has popped out saying '1 important message' and under that it said 'Turn on avast! Antivirus (Important)'. So I clicked on it and then it asked me 'Do you want to run this program? You should only run programs that come from publishers you trust.' So i clicked 'Yes, I trust the publisher and want to run this program'. After that nothing has happened, so I tried again few more times but  the Windows Action Center message was still there about turning on Avast, and my Avast was still outdated and this happened to me few times now. Each time I reinstalled Avast again and it would work for about a month and then the same thing would happen. How can I fix this?

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Please Help
« Reply #1 on: December 31, 2012, 12:58:56 PM »
did you just install it?
what antivirus did you use before avast?
did you uninstall it before installing avast?
did you run the vendors removal tool to clear any leftover conflicting files    http://singularlabs.com/uninstallers/security-software/


try avast repair:  controlpanel > ad/remove programs > avast > uninstall > repair option > wait 2 minutes and reboot

Mr. Week

  • Guest
Re: Please Help
« Reply #2 on: December 31, 2012, 01:02:19 PM »
No I installed it about a month ago
I always used Avast and it worked fine before its just like that in the last few months
Yes
No but I might use it now because I am just about the install it again

Mr. Week

  • Guest
Re: Please Help
« Reply #3 on: December 31, 2012, 01:03:54 PM »
And I tried Avast Repair but it didn't work

Mr. Week

  • Guest
Re: Please Help
« Reply #4 on: December 31, 2012, 01:14:31 PM »
I reinstalled it and used the Vendors Removal Tool and so far it works but I'll find out if its going to stop working again in about a month because thats about how long it lasts but if there is another was of fixing this other than reinstalling please reply if anyone knows how to. Thank You

Offline Gopher John

  • Avast Evangelist
  • Super Poster
  • ***
  • Posts: 2098
Re: Please Help
« Reply #5 on: December 31, 2012, 09:25:06 PM »
AMD A6-5350M APU with Radeon HD Graphics, 8.0GB RAM, Win7 Pro SP1 64bit, IE11
i7-3610QM 2.3GHZ, 8.0GB Ram,  Nvidia GeForce GT 630M 2GB, Win7 Pro SP1 64bit, IE 11
Common to both: Avast Premium Security 19.7.2388, WinPatrol Plus, SpywareBlaster 5.5, Opera 12.18, Firefox 68.0.2, MBam Free, CCleaner

Mr. Week

  • Guest
Re: Please Help
« Reply #6 on: December 31, 2012, 11:51:02 PM »
Yes I am

Mr. Week

  • Guest
Re: Please Help
« Reply #7 on: January 02, 2013, 02:16:46 PM »
Is there a way to fix this because it just stopped working again after only few days

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Please Help
« Reply #8 on: January 02, 2013, 02:29:48 PM »
Is there a way to fix this because it just stopped working again after only few days
strange.......

you may post a OTL diagnosis log for one of the experts to look at

see this guide  http://forum.avast.com/index.php?topic=53253.0   scroll down to OTL and follow the instructions

attach the log here...not copy and paste

when done the experts will be notified and have a look at it later today


Mr. Week

  • Guest
Re: Please Help
« Reply #9 on: January 02, 2013, 05:30:25 PM »
Like this?
« Last Edit: January 02, 2013, 05:32:17 PM by Mr. Week »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Please Help
« Reply #10 on: January 02, 2013, 05:59:54 PM »
Hi, lets see what I can do

 Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:OTL
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=IE&userid=04d3dd2d-d9fe-4553-b147-502cc9442d9c&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-4244098424-3650855318-2149262391-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=IE&userid=04d3dd2d-d9fe-4553-b147-502cc9442d9c&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-4244098424-3650855318-2149262391-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=IE&userid=04d3dd2d-d9fe-4553-b147-502cc9442d9c&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-4244098424-3650855318-2149262391-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=IE&userid=04d3dd2d-d9fe-4553-b147-502cc9442d9c&searchtype=hp&exp=true
IE - HKU\S-1-5-21-4244098424-3650855318-2149262391-1000\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=IE&userid=04d3dd2d-d9fe-4553-b147-502cc9442d9c&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-4244098424-3650855318-2149262391-1000\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=IE&userid=04d3dd2d-d9fe-4553-b147-502cc9442d9c&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-4244098424-3650855318-2149262391-1000\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snap.do/?publisher=SnapdoOpenCandy&dpid=SnapdoOpenCandy&co=IE&userid=04d3dd2d-d9fe-4553-b147-502cc9442d9c&searchtype=ds&q={searchTerms}
IE - HKU\S-1-5-21-4244098424-3650855318-2149262391-1000\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://www.claro-search.com/?q={searchTerms}&affID=116696&tt=4212_2&babsrc=SP_ss&mntrId=0a85a78600000000000000064f9bee38
O3:64bit: - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {ae07101b-46d4-4a98-af68-0333ea26e113} - No CLSID value found.
O4 - HKLM..\Run: [ROC_roc_ssl_v12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_ssl_v12.exe" / /PROMPT /CMPID=roc_ssl_v12 File not found

:Commands
[resethosts]
[emptytemp]
[CREATERESTOREPOINT]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.
THEN

Download AdwCleaner from here to your desktop
Run AdwCleaner and select Delete



Once done it will ask to reboot, allow this
On reboot a log will be produced please attach that

FINALLY

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

Mr. Week

  • Guest
Re: Please Help
« Reply #11 on: January 02, 2013, 08:01:54 PM »
So far its all running fine. I wonder for how long.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Please Help
« Reply #12 on: January 02, 2013, 08:17:44 PM »
As it stands I can see no reason why Avast would fail.  The only errors I can see are to do with the Nvidia files

UserA789

  • Guest
Re: Please Help
« Reply #13 on: January 30, 2013, 01:34:30 PM »
...and then it asked me 'Do you want to run this program? You should only run programs that come from publishers you trust.'

I was just wondering about the dialog pop up, did you get a chance to screnshot it?  Did it look like this or was it a bonafied actual Avast Warning Dialog Box (said Avast on it somewhere, usually at the top):

***I am aware this is a warning from Java to let me know the app/website is not signed, or signed properly but the site has a FULLY SIGNED cert... even Java dot com elevates the prompt.  Every Java app signed or not.  I removed the website name as my ISP is checking this out***

If this is the same dialog box then there is something going on with Java and your Avast not updating was a mere symptom.  If you were being victim of the ZERODAY java hole just re-found (it was pointed out a while ago but Oracle did nothing), it would be smart to intefere with a valid update to Avast in case Avast caught it first.  That I know of, Avast doesnt Utilise Java (..is this correct modds?) so it may have been an attempt to get you to allow an illicit users Java protocoling rights in your system.  Its an old tactic.

There is a couple of spots where someone is trying to add this line:

permission java.lang.RuntimePermission "queuePrintJob";`

Manually to file:
C:\program files\Java\jre.1.5.0\lib\security
No more message displays..

How can I solve this? Like signed applet?


The answer given: "Digitally sign the code and then convince the user to OK it when prompted at (before) load, and the applet should be able to do further secure actions (print, access personal information, trash the user's disks or install the slave-bot..) unprompted." -its obvious the point of the intial request is getting a user to unknowningly allow bad Java on their system and think nothing is strange, as my recent occurences have been on VALID java signed sites but still get the warning of a Java app NOT being verifiable.  This would be a solid work around for the covering of the Java ZERODAY exploit just fixed.  I dont care really what its all about, I only care about it reporting one site as not signed.

Now, I have had the problem with Windows saying Avast is turned off multiple times and no one has answered why this notification from the security center happens and assure me that Avast is still running.  Iv been told its a 'conflict' with the Windows Security Center on occassion, but the smoothness the Avast FW has intergrated with Windows Firewall Services makes me doubt the Avast team would be so sloppy they didnt insure conflict resolution with Windows Security Center.  Iv also been told its probably a GUI, to remove Avast (including using the aswclear tool.  Iv been told many things but nothing narrowed down.  Although it hasnt happened for a few weeks now after a few clever adjustments of MSTaskSchedulerEvents, GPEDIT.MSC, and some 'hidden services' being unhidden, Im still waiting for it to happen again.

Also, in November and December, I would be told my Anti-virus was not turned on Windows.  My Avast icon on the bottom would be fine, or it wouldnt have the 'EXCLAMATION' on it in the task bar.  But, when I would open Avast it would show me that either my WEB SHIELD or my MAIL SHIELD or my SCRIPT SHIELD was turned off and I couldnt turn it back on through the GUI or the notification.  I would re-start and try a repair and end up with the following 'repaired' GUI (after another restart):


Iv heard of people creating their own stripped down versions of programs but thats going overboard  :o

Windows Security Center would also have an Alert listed, but no notification pop-up that Windows Defender needed to scan my computer as though it was a scheduled TaskEvent  but wasnt.  One of the times I had Windows Defender turned off completly!


Here, have some logs from Avast when it did the cool stripped down GUI (attached).  Im lost.