Author Topic: Malware-gen infection Avast service disabled.  (Read 6845 times)

0 Members and 1 Guest are viewing this topic.

enigma_lhn

  • Guest
Malware-gen infection Avast service disabled.
« on: November 21, 2010, 11:30:46 PM »
I have a Malware-gen infection according to Avast, avast can't delete it  When windows rebooted it became really a huge problem.  After the reboot multiple services are disabled and can not be started including Avast. Windows installer  Windows Update, and the Security Center. Most of the 32bit programs can also not be started. The OS is Win7 64 bit and help would really be appreciated.
I have been locking all over for a solution but not even a clue and since avast can not be started I am really in a mess.

Help is needed.

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Malware-gen infection Avast service disabled.
« Reply #1 on: November 21, 2010, 11:40:32 PM »
So i guess you are using another computer to post this ?

Try this  Dr.Web® LiveCD
Emergency System Recovery Disk http://www.freedrweb.com/livecd/?lng=en
How does it work? http://www.freedrweb.com/livecd/how_it_works/?lng=en


enigma_lhn

  • Guest
Re: Malware-gen infection Avast service disabled.
« Reply #2 on: November 22, 2010, 12:01:51 AM »
Yes, the problem is on my private laptop and I am posting from a work computer. I'll try the CD tomorrow,
Maybe I should add that system restore is also disabled as well as Shadow Copy

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37533
  • Not a avast user
Re: Malware-gen infection Avast service disabled.
« Reply #3 on: November 22, 2010, 12:14:11 AM »
I have sendt a PM to our malware remover expert Essexboy, he may be in bed now, if so he wont show until late uk time tomorrow

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Malware-gen infection Avast service disabled.
« Reply #4 on: November 22, 2010, 08:28:22 PM »
Can you get to the safe mode menu ?  If so select the repair my computer option

enigma_lhn

  • Guest
Re: Malware-gen infection Avast service disabled.
« Reply #5 on: November 22, 2010, 10:13:54 PM »
I can go to safe mode and I can start repair, but it ed end with an errormessaga saying that some files can not be opened because of som antivirus app is running. but that message is not correct, avast is diabled and doesn't  run It can not be started.
If I go to system reset, I can run reset, but only restor from the latest (last) restore point if I select a previous reotore point i get the same errormessage as I do when I run repair, antivirus is loocking some file...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Malware-gen infection Avast service disabled.
« Reply #6 on: November 22, 2010, 10:23:17 PM »
OK then lets have a look see

Download OTL  to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Select All Users
  • Under the Custom Scan box paste this in
netsvcs
%SYSTEMDRIVE%\*.exe
/md5start
explorer.exe
winlogon.exe
/md5stop
%systemroot%\*. /mp /s
CREATERESTOREPOINT




  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

enigma_lhn

  • Guest
Re: Malware-gen infection Avast service disabled.
« Reply #7 on: November 23, 2010, 08:27:00 AM »
Didn't do anything. As I said before it is nott possible to run a 32 bit program, so when Itry to run the program only see this little rotating circle for a few seconds and then nothing.



Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Malware-gen infection Avast service disabled.
« Reply #8 on: November 23, 2010, 10:06:46 PM »
Do you have the facility to burn a live CD ? If so

Please print these instruction out so that you know what you are doing

OTLPENet.exe
MD5=C2629B6D6FA189EA92FF6FD1FFA2A81D
127,353,979bytes / 121.4MB
  • Download OTLPENet.exe to your desktop
  • Download the attached scan.txt to a USB
  • Ensure that you have a blank CD in the drive
  • Double click OTLPENet.exe and this will then open imgburn  to burn the file to CD

  • Reboot your system using the boot CD you just created.
Note : If you do not know how to set your computer to boot from CD follow the steps here
  • As the CD needs to detect your hardware and load the operating system, I would recommend a nice cup of tea whilst it loads  :) 
  • Your system should now display a Reatogo desktop.
Note : as you are running from CD it is not exactly speedy
  • Double-click on the OTLPE icon.
  • Select the Windows folder of the infected drive if it asks for a location
  • When asked "Do you wish to load the remote registry", select Yes
  • When asked "Do you wish to load remote user profile(s) for scanning", select Yes
  • Ensure the box "Automatically Load All Remaining Users" is checked and press OK
  • OTL should now start.
  • Double click the Custom scans and fixes box
  • In the dialogue locate the scan.txt you have on the USB
  • Press Run Scan to start the scan.
  • When finished, the file will be saved  in drive C:\OTL.txt
  • Copy this file to your USB drive if you do not have internet connection on this system.
  • Right click the file and select send to : select the USB drive. 
  • Confirm that it has copied to the USB drive by selecting it
  • You can backup any files that you wish from this OS
  • Please post the contents of the C:\OTL.txt file in your reply.

enigma_lhn

  • Guest
Re: Malware-gen infection Avast service disabled.
« Reply #9 on: November 24, 2010, 10:00:23 AM »
Im starting to think that the Gods are against me. When I open the downloaded file to my second pc, the file opens nicely, I get the question if I would like to burn a CD, answer "Yes" get a message Extracting, then it hangs on extracting forever. and the program can't be cancelled normayyl, after 2 hours of waiting (more than one cup of tea) then I cancelled via the task manager.

Tried again with a fresh download just in case, but same result.

I am now closer than ever to just reformatting the hard drive an start fresh. Thank God I have a fresh backup of my files...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Malware-gen infection Avast service disabled.
« Reply #10 on: November 24, 2010, 08:57:38 PM »
This appears to be one of those cases where we can chase it around for a few days and not get a satisfactory resolution... Or bite the bullet and do a full reformat - much quicker

enigma_lhn

  • Guest
Re: Malware-gen infection Avast service disabled.
« Reply #11 on: November 24, 2010, 09:37:57 PM »
Agree reformat seems to be the way to go. But it would be nice to know what the virus is but nos I guess I'll never nev
er know