Please Review Logs - Windows Explorer And Mse Problems

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by drcarl, Feb 9, 2016.

  1. drcarl

    drcarl Staff Sergeant

    Problems

    Lost “Sleep” function months ago - I can live with that, although I miss it.

    Windows Explorer hangs (goes grey, “look for solutions” restores function) – start date unknown: a month? two? and has gotten steadily worse.

    Chrome, MSE, others hang – some can be brought back, some can’t – worsened recently

    MSE hanging during scan. Display freezes yet Resource Monitor looks like it’s still running. Ended process but can’t get MSE running again without restart. – started yesterday

    The rest of these notes are from the last 24-36 hours.

    MSE hang when chrome opened – related or not unknown

    Disastrous failed attempt at uninstalling, the installing MSE

    Went back in time with System Restore.

    Revo (advanced) Uninstaller failed to uninstall Dropbox,. I let it do as much as possible (registry, etc) then removed all “dropbox” anything manually

    Since Malwarebytes (and SuperAntiSpyware & Spybot) are not actually running, I did not “uninstall” them and will if necessary.

    Before starting here with proper instructions, I did let CCleaner scour the registry for fixes.

    'Repair My Computer' is not displayed with the F8 start. Win asks for installation disc (that I don't have) and I don't know if the upgrade disc will do it.
    (Status 0xc000000e Info: boot selection failed because a required device is inaccessible.)

    I got side-tracked, found everything “dropbox” with a search tool called “Everything.” Deleted everything "dropbox" while letting MSE try to scan. It hung, not sure why. I even tried just scanning just the Windows folder with MSE. Got through most of it. Hangs on temp and another folder. No clue if that's a clue or not.

    Now following instructions/outline...

    Re-installed CCleaner so that the default settings are selected. Ran it.

    I have two users that show User Profile Failed. Deleted one and set Guest to off.

    When I ran MalwareBytes, the only Scan Log that was there is dated 4/29/2014. (attached) I’d like to mention that it did quarantine a file Vendor: Rogue.Link Type: File Location C:\Users\Me\Desktop\Nude Girls 3D Model .max .obj .fbx – CGTrader.com url . And that it was the most beautiful computer-generated nude (not porn).

    Just before MGtools finished logging, two dialog boxes appeared.

    First Box:

    ProcessDll.exe – Common Language Runtime Debugging Services

    “Application has generated an exception that could not be handled.

    Process id=0x4e8 (1256), Thread id=0x11b4 (4532)Click OK to terminate application

    CANCEL to debug the app

    I clicked CANCEL


    Second box:

    ProcessDll.exe – No debugger found

    Registred JIT debugger is not available. An attempt to launch a JIT debugger with the following command resulted in error code of 0x2(2). Please check computer settings.

    cordbg.exe !a 0x4e8

    Click on retry to have process wait while attaching debugger manually...I clicked OK to caqncel request.

    Logs attached.

    Thanks for your help

    DrCarl
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't think this is a malware problem. More like a system issue. But let's clean up some junk.

    First, rerun RogueKiller and remove this item:
    ¤¤¤ Registry : 11 ¤¤¤
    [PUP] (X86) HKEY_LOCAL_MACHINE\Software\Conduit -> Found


    Now rerun Hitman and fix these issues.


    Potential Unwanted Programs _________________________________________________

    C:\Users\Carl\AppData\Roaming\Yahoo!\Companion\ (YahooToolbar)
    C:\Users\W W W\AppData\Roaming\Yahoo!\Companion\ (YahooToolbar)
    HKLM\SOFTWARE\Classes\AppID\YMERemote.DLL\ (YahooToolbar)
    HKLM\SOFTWARE\Classes\AppID\{7D831388-D405-4272-9511-A07440AD2927}\ (YahooToolbar)
    HKLM\SOFTWARE\Classes\Wow6432Node\AppID\YMERemote.DLL\ (YahooToolbar)
    HKLM\SOFTWARE\Classes\Wow6432Node\AppID\{7D831388-D405-4272-9511-A07440AD2927}\ (YahooToolbar)
    HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar.1\ (YahooToolbar)
    HKLM\SOFTWARE\Classes\YBrowserToolbar.YBrowserToolbar\ (YahooToolbar)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\18C9E3869A16248439FE3FF9EB02207A\ (Iminent)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\5D8011310B2622942868A458964FFDC5\ (Iminent)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6C63F7979DCC2154CB9591969A5CB89D\ (Iminent)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\6DD31E6C1A73B334383DF186676F4D20\ (Iminent)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\AB3204F747B20694B8D49EF92D8DC94B\ (Iminent)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\C81E33A400B6F814E90C7A3354E2A3A5\ (Iminent)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\EDBF68C5F16790341B7C6FD7C7F8E4FC\ (Iminent)
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\FFA531D0F3A71504DA7AC6A11CE33739\ (Iminent)
    HKLM\SOFTWARE\Wow6432Node\Auslogics\Google Analytics Package\ (TweakBit)
    HKLM\SOFTWARE\Wow6432Node\Conduit\ (Conduit)
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\DefaultTabSearch_RASAPI32\ (DefaultTab)
    HKLM\SOFTWARE\Wow6432Node\Microsoft\Tracing\DefaultTabSearch_RASMANCS\ (DefaultTab)
    HKLM\SOFTWARE\Wow6432Node\Yahoo\Companion\ (YahooToolbar)
    HKU\S-1-5-21-2843507736-2835281995-1909691514-1001\Software\AppDataLow\Software\Yahoo\Companion\ (YahooToolbar)
    HKU\S-1-5-21-2843507736-2835281995-1909691514-1001\Software\Conduit\ (Conduit)
    HKU\S-1-5-21-2843507736-2835281995-1909691514-1001\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration{7F6AFBF1-E065-4627-A2FD-810366367D01}\ (DefaultTab)
    HKU\S-1-5-21-2843507736-2835281995-1909691514-1001\Software\Microsoft\Internet Explorer\ApprovedExtensionsMigration{A1E28287-1A31-4B0F-8D05-AA8C465D3C5A}\ (DefaultTab)
    HKU\S-1-5-21-2843507736-2835281995-1909691514-1001\Software\Yahoo\Companion\ (YahooToolbar)
    HKU\S-1-5-21-2843507736-2835281995-1909691514-1001\Software\Yahoo\YFriendsBar\ (YahooToolbar)

    Reboot and rescan with both RogueKiller and Hitman and save the logs.

    [​IMG] Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.

    Please download AdwCleaner by Xplode and save to your Desktop.
    • Double click on AdwCleaner.exe to run the tool.
      Vista/Windows 7/8 users right-click and select Run As Administrator
    • Click on the Scan button.
    • AdwCleaner will begin...be patient as the scan may take some time to complete.
    • After the scan has finished, click on the Report button...a logfile (AdwCleaner[R#].txt) will open in Notepad for review (where the largest value of # represents the most recent report).
    • The contents of the log file may be confusing. Unless you see a program name that you know should not be removed, don't worry about it. If you see an entry you want to keep, let me know about it.
    • Attach the logfile to your next next reply.
    • A copy of all logfiles are saved in the C:\AdwCleaner folder which was created when running the tool.


    Reboot and do the following:

    Download Windows Repair by Tweaking.com and unzip the contents into a newly created folder on your desktop.
    • Now run Repair_Windows.exe by double clicking on it ( if you are running Vista or Win 7, use right click and select Run As Administrator)
    • Now select the + Repairs tab.
    • Then click the + Open Repairs button down on the bottom right.
    • This will automatically begin a registry backup, so wait for it to complete and when it finishes, you will see a list of many possible different repairs and they are all selected by default. At the bottom of this form there is a not so obvious Unselect All Repairs check box which is to the right of a check box with a green check mark in it. Please click the Unselect All Repairs box. The green check mark box is to Select All Repairs. The ony way you see what these boxes are is when your mouse hovers over them.
    • Now select the following repair options ( the numbers at the begin are the current repair numbers but this is subject to change.)
      • 01 - Reset Registry Permissions
      • 02 - Reset File Permissions
      • 03 - Reset Service Permissions
      • 04 - Register System Files
      • 05 - Repair WMI
      • 06 - Repair Windows Firewall
      • 10 - Remove Policies Set By Infections
      • 13 - Network
      • 14 - Repair Proxy Settings
      • 15 - Repair Windows Updates
      • 21 - Repair MSI (Windows Installer)
      • 23 - Repair File Associations (12 )
      • 26 - Restore Important Windows Services
      • 27 - Set Windows Services To Default Startup
    • Now on the right side under the When Repairs Complete title, check the box for Restart/Shutdown System and then make sure the Restart System radio button is enabled not the Shutdown System button.
    • Shutdown any other programs that you are running now before continuing.
    • Now click the Start Repairs button at the lower right.
    • Be patient while the tool repairs the selected items.
    • It should reboot automatically when finished. If it does not then reboot it yourself.

    Reboot and attach the saved logs. Tell me if anything has improved. We may need to send you to the software forum for additional help.
     
    drcarl likes this.
  3. drcarl

    drcarl Staff Sergeant

    Thanks TimW - on it.

    (I wonder how many system issues will be gone and how many might migrate to Win10 when that finally happens - after Woody Leonhard says it's "OK" - lol)
     
  4. drcarl

    drcarl Staff Sergeant

    Spending hours trying to get HitmanPro to save a log. Did screen shots. Rebooted, re-ran. Stuck at this step. I'll probably continue to the next step...UPDATE- found the logs - will number and attach...then get back to the instructions (and attach again)
     
    Last edited: Feb 10, 2016
  5. drcarl

    drcarl Staff Sergeant

    I'll post these again after I finish all of the other instructions. Posting here now just for your potential interest. I see "ask" wants back...so does Yahoo Toolbar...regardless...I'm sure you'll see that too...moving on....and thanks
     

    Attached Files:

  6. drcarl

    drcarl Staff Sergeant

    Tweaking.com Windows Repair can’t find Adobe Presenter 7. Neither can I. All kinds of dialog boxes that say no can do. Closed them. Moving on.
     
  7. drcarl

    drcarl Staff Sergeant

    Hitman was not interested in saving a log – so I screen-grabbed what was there

    Re-ran it

    Made a second screen grab – “Conduit “is back

    After running ADWCleaner, (or, maybe it was HitmanPro?) I see that my DSClock is gone. <-- I did like that clock.

    I also notice that in AdwCleaner, Services tab is YahooAUService. I have no idea what that is and want nothing to do with Yahoo except occasionally checking some mail on an old Yahoo account

    I did not click the “Cleaning” button

    Chrome Foxtab Speed Dial extension appears to be broken. All my pages of tiles (like bookmarks) are gone. Details: No webpage was found for the web address: chrome-extension://dchmpbaclbiioedakpcldenooikekokm/content/newtab/newtab.html

    Tweaking.com Windows Repair can’t find Adobe Presenter 7. Neither can I. All kinds of dialog boxes that say no can do. Closed them. Moving on.

    “All Repairs” option is now only at the top of the tree. Otherwise I see no option for that.
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You can let ADWcleaner fix / remove what it found. I am not seeing malware and if Windows Repair did not help, I suggest you post in the software forum for additional assistance.
     
    drcarl likes this.
  9. drcarl

    drcarl Staff Sergeant

    Thank you TimW for helping me clean up junk. I let ADW Zhave it's way. May do the same for JRT. DS Clock came back, but it looks like a new speed dial extension is in my future. I'll see how things go and may post over in software. ..again, thank you.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You are most welcome.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep Malwarebytes Anti-Malware for scanning/removal of malware.
    2. Renable your Disk Emulation software with Defogger if you had disabled it in step 4 of the READ & RUN ME.
    3. Go to add/remove programs and uninstall HijackThis. If you don't see it or it will not uninstall, don't worry about it. Just move on to the next step.
    4. If running Vista, Win 7 or Win 8 or 10, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Now goto the C:\MGtools folder and find the MGclean.bat file. Double click ( if running Vista, Win7, or Win 8 Right Click and Run As Administrator ) on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    6. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    7. After doing the above, you should work thru the below link:
     
    drcarl likes this.
  11. drcarl

    drcarl Staff Sergeant

    BTW - problems persist. Regardless, I appreciate your help. I'll post under software. Thanks again.
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You're welcome.
     
    drcarl likes this.
  13. drcarl

    drcarl Staff Sergeant

    For the record, I finally solved the "Sleep function lost" and quite a few other problems.

    In two words: Power supply.

    Went to Best Buy and got me a 750 Corsair. Figured out how to install it.

    Everything works. Like I mean ev-ree-thing, including sleep.

    Got a new 1 TB SSD. Will read other threads and perhaps start one to get replace my C drive with it.

    Acronis might be of help.

    Thanks for all your care!
     
    satrow likes this.
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. :)
     
    drcarl likes this.

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds