Author Topic: Avast Blocked by Group Policy - Please help  (Read 10528 times)

0 Members and 2 Guests are viewing this topic.

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #15 on: November 07, 2014, 11:33:08 PM »
No apology necessary.  I am VERY grateful for your help in getting this resolved.  New logs to follow...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast Blocked by Group Policy - Please help
« Reply #16 on: November 07, 2014, 11:40:44 PM »
Ta, the removal of that line would not have affected the programme in any way, just that the taskbar icon would not appear and would need to be reset :)

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #17 on: November 08, 2014, 12:15:39 AM »
We uninstalled Spybot, rebooted, ran the fixlist, and it rebooted again.  The dialogs are still popping up on boot and here is the latest fixlog.txt

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast Blocked by Group Policy - Please help
« Reply #18 on: November 08, 2014, 12:46:05 PM »
That is intriguing as FRST is reporting the keys not found

Download and Install Combofix
 
Download ComboFix from one of the following locations:
Link 1
Link 2
 
VERY IMPORTANT !!! Save ComboFix.exe to your Desktop
 
* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks




  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.[/b]
Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.

3.  If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.


Please make sure you include the combo fix log in your next reply as well as describe how your computer is running now

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #19 on: November 09, 2014, 06:05:39 AM »
I may not be able to get the latest instructions carried out for another 1-2 days.  I have not given up on your help and I will report back when I get a chance to run ComboFix.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast Blocked by Group Policy - Please help
« Reply #20 on: November 09, 2014, 12:27:01 PM »
No problem

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #21 on: November 10, 2014, 04:39:42 AM »
So we tried to disable Avast, but get an error that it is blocked by Group Policy again.  I tried to have her kill the Avast process in Task Manager, but got an error that it could not be stopped.

We then tried to run ComboFix.exe, but got a dialog error that Avast was running and to "please disable these scanners before clicking ok"....

The problem is that I can't disable the scanners and there is no apparent way to cancel ComboFix and the only option is to click the "ok" button or the "X" at the top of the dialog box.

I told my mother to just leave the computer alone until I get word back from you about what to do at this point.

Help! :)

Thank...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast Blocked by Group Policy - Please help
« Reply #22 on: November 10, 2014, 04:20:31 PM »
OK could you run a fresh FRST scan for me please and I will try to locate the miscreant

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #23 on: November 10, 2014, 04:26:13 PM »
Is it safe to hit "ok" on the warning screen that is still up from ComboFix?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast Blocked by Group Policy - Please help
« Reply #24 on: November 10, 2014, 04:33:38 PM »
Yes Avast should not affect the running of combofix

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #25 on: November 11, 2014, 05:11:34 AM »
Ran ComboFix.

Ran FRST.

The logs are attached.


Current Status:
The computer did not auto-reboot itself.  We tried to run Avast and Malwarebytes but both still get a "blocked by group policy" error.

I had her reboot the computer manually.

The five error dialogs are gone!  Yay.

She still couldn't run Avast or Malwarebytes; it still gives the group policy errors.

*sigh*

Sorry for all the trouble.  We had the group policy issue resolved at one point back there temporarily, but it got reverted upon a reboot somehow (probably Teatimer).


Please advise the next steps...


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast Blocked by Group Policy - Please help
« Reply #26 on: November 11, 2014, 04:35:31 PM »
OK lets now see if this sticks :)

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Download the attached fixlist.txt  to the same location as FRST.exe
Run FRST and press Fix
On completion a log will be generated please post that

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #27 on: November 12, 2014, 12:02:53 AM »
Here is today's fixlog...


I'll get you an update on how the computer is running as soon as I hear from my mother. :)


UPDATE:

Both Avast and Malwarebytes run now.  There are no error messages upon booting.

We did try to update Malwarebytes and it gave an error that it "could not properly uninstall the prior version, please uninsatll it manuallY".  I'm not overly concerned about that and can deal with it later unless you think it still has something to do with the infection we are/were dealing with.

Thank you again for your help.
« Last Edit: November 12, 2014, 12:32:12 AM by mhe4 »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Avast Blocked by Group Policy - Please help
« Reply #28 on: November 12, 2014, 04:17:47 PM »
There is an MBAM removal tool and instructions for such cases here https://forums.malwarebytes.org/index.php?/topic/122284-mbam-clean-removal-process/

If you could run MBAM when it is up and running again just to make sure I did not miss anything

REDACTED

  • Guest
Re: Avast Blocked by Group Policy - Please help
« Reply #29 on: November 12, 2014, 05:33:15 PM »
The saga continues...

Downloaded MBAM removal tool

Disabled Avast

Ran MBAM removal tool

Rebooted

Downloaded MBAM

Tried to go disable Avast again before installing MBAM, but the tray icon was not there, so I tried to run Avast from the program icon on the Windows Menu, but get a "blocked by Group Policy" error once again.

Awaiting further recommendations...