Author Topic: avast blocked by group policy URGENT  (Read 1406 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
avast blocked by group policy URGENT
« on: March 27, 2015, 12:22:18 AM »
Hello,
please my PC is infected and avast is blocked by group policy
I used Farbar Recovery Scan Tool Download and I got this 3 files.

Please help ASAP.

Best.
Mem


REDACTED

  • Guest
Re: avast blocked by group policy URGENT
« Reply #1 on: March 27, 2015, 01:06:10 AM »
My windows 7 today has been attacked  today and has turned OFF my avast so that it is unprotected , it will not restore to an earlier time , e-mail has also been corrupted , avast is a paid version ,writing this on another notebook , any suggestions please

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: avast blocked by group policy URGENT
« Reply #2 on: March 27, 2015, 06:18:35 AM »
My windows 7 today has been attacked  today and has turned OFF my avast so that it is unprotected , it will not restore to an earlier time , e-mail has also been corrupted , avast is a paid version ,writing this on another notebook , any suggestions please
Start a new topic in V&W and post your logs there: https://forum.avast.com/index.php?action=post;board=4.0
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: avast blocked by group policy URGENT
« Reply #3 on: March 27, 2015, 01:53:41 PM »
Avast will restart after the FRST fix has rebooted

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
CreateRestorePoint:
HKLM-x32\...\Run: [eduv] => C:\Users\mem\AppData\Local\eduv\eduv.exe [313379 2015-03-26] (DigestionsBillionDelivery)
HKLM Group Policy restriction on software: C:\Program Files\AVAST Software <====== ATTENTION
HKLM\...\Policies\Explorer\Run: [eduv] => C:\Users\mem\AppData\Local\eduv\eduv.exe [313379 2015-03-26] ( (DigestionsBillionDelivery))
HKU\S-1-5-21-1290630191-3579848777-760491292-1000\...\Run: [fastclean] => "C:\Program Files (x86)\FastClean PRO\fastcleanpro.exe"
HKU\S-1-5-21-1290630191-3579848777-760491292-1000\...\Run: [YdPack] => C:\Windows\SysWOW64\regsvr32.exe C:\Users\mem\AppData\Local\Ahbworks\Test.dll
ShellIconOverlayIdentifiers: [0WinSecurityProvider] -> {F76FA5C2-3B6A-451E-8CA5-34C8D0AE0637} =>  No File
ProxyServer: [S-1-5-21-1290630191-3579848777-760491292-1000] => http=127.0.0.1:51757;https=127.0.0.1:51757
Toolbar: HKU\S-1-5-21-1290630191-3579848777-760491292-1000 -> No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
Task: {211C6347-5E89-4849-A7DE-56668DD07855} - \Mext Guard FBE8818C-5B13-48C2-A93E-AD731167DBF2 No Task File <==== ATTENTION
Task: {3A1FC8F8-A936-4014-AC46-33EAA3444F3E} - \TidyNetwork Update No Task File <==== ATTENTION
Task: {56E873DF-62D4-4B19-8F8A-4217E02F2DFC} - \FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl No Task File <==== ATTENTION
C:\Program Files (x86)\FastClean PRO
C:\Users\mem\AppData\Local\eduv
C:\Users\mem\AppData\Local\Ahbworks
Reg: reg delete HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
Reg: reg add HKLM\SOFTWARE\Policies\Microsoft\Windows\IPSec\Policy\Local /f
RemoveProxy:
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Double click on AdwCleaner.exe to run the tool.
  • Click on Scan.
  • After the scan is complete click on "Clean"
  • Confirm each time with Ok.
  • Your computer will be rebooted automatically. A text file will open after the restart.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S0].txt as well.