1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Avast Firewall Hijacked? Unable to turn on.

Discussion in 'Malware and Virus Removal Archive' started by kspaulding, 2014/01/14.

  1. 2014/01/16
    kspaulding Lifetime Subscription

    kspaulding Well-Known Member Thread Starter

    Joined:
    2005/08/07
    Messages:
    77
    Likes Received:
    0
    oops, I didn't read carefully and I deleted the OTL log after first run following your last post. I re-ran that script in OTL but the second log may not show what you were looking for. Any way, here it is:

    All processes killed
    ========== OTL ==========
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: Administrator
    ->Temp folder emptied: 0 bytes

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Kevin
    ->Temp folder emptied: 3395 bytes
    ->Temporary Internet Files folder emptied: 3769 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: Susan
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes
    ->Java cache emptied: 0 bytes
    ->Google Chrome cache emptied: 0 bytes
    ->Flash cache emptied: 0 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 17297288 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
    RecycleBin emptied: 0 bytes

    Total Files Cleaned = 17.00 mb


    [EMPTYFLASH]

    User: Administrator

    User: All Users

    User: Default
    ->Flash cache emptied: 0 bytes

    User: Default User
    ->Flash cache emptied: 0 bytes

    User: Kevin
    ->Flash cache emptied: 0 bytes

    User: Public

    User: Susan
    ->Flash cache emptied: 0 bytes

    Total Flash Files Cleaned = 0.00 mb


    [EMPTYJAVA]

    User: Administrator

    User: All Users

    User: Default

    User: Default User

    User: Kevin
    ->Java cache emptied: 0 bytes

    User: Public

    User: Susan
    ->Java cache emptied: 0 bytes

    Total Java Files Cleaned = 0.00 mb

    Restore point Set: OTL Restore Point

    OTL by OldTimer - Version 3.2.69.0 log created on 01162014_234326

    Files\Folders moved on Reboot...
    C:\Users\Kevin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
    C:\Users\Kevin\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
    File move failed. C:\windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.
    File\Folder C:\windows\temp\_avast_\ws157.dat not found!
    File\Folder C:\windows\temp\Secunia PSI Agent\JavaJRE_7u51_64-bit_PSIonlySPS.exe not found!
    File\Folder C:\windows\temp\avast_ash\Flash Player ActiveX\BITD8FF.tmp not found!

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
     
  2. 2014/01/16
    kspaulding Lifetime Subscription

    kspaulding Well-Known Member Thread Starter

    Joined:
    2005/08/07
    Messages:
    77
    Likes Received:
    0
    Broni, thanks again for you time & expertise. My original issue is resolved and I really appreciate the cleaning and advice.

    Kevin S.
     

  3. to hide this advert.

  4. 2014/01/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Yes!! [​IMG]
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.