0000135 %hs missing

Discussion in 'Malware Help (A Specialist Will Reply)' started by whatthe, Oct 12, 2013.

  1. whatthe

    whatthe Private E-2

    I am running Windows 7 on my laptop. The incident happened after I restarted my computer to finalize updates the computer had. During reboot, I got the the blue screen and it said "0000135 error, %hs missing". It didn't say that word for word but it was in the lines of that.

    My key under \ControlSet001\Control\SessionManager\SubSystems is already in "winsrv", didn't have to change it from "consrv". I have looked at other threads and found out that I must perform FRST64.exe and then create a fix for it. However I do not know how to do this. So I was hoping someone could create this fix for me. I have done the FRST64 and have performed the search for "services.exe;winsrv". If someone could help me out, that would be great! I have attached the files. Thanks in advance!
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

  3. whatthe

    whatthe Private E-2

    So the weird thing is that my computer seems to be running fine now, but it's on and off. It seems like the problem may have risen from a Windows update. After I would get the blue screen, I did a restore to a point before the problem. It was able to fix it. Then once I got logged in and everything, I had restarted again because of the Windows update(thinking it might have been gone). Same thing happened so I did another restore. A day later, Windows said to restart again, so I thought I'd give it another shot. So today I had restarted my computer and I did not encounter the blue screen.

    To be safe though, I ran the tests that you gave me. I followed the instructions and did the restart like it told me after I have removed the infections from MalwareBytes. After the restart, I got the blue screen again but it wasn't saying anything about the %hs missing. Instead it was much longer, to long and quick for me to read, but I did notice that it said something about HKEY.

    I was able to get a log of RogueKiller and MalwareBytes before the system restore. I performed the tests again but I did not remove this time or restart my computer. Here are my logs.
     
  4. whatthe

    whatthe Private E-2

    Here are the files for logs I obtained after the system restore. I was not able to perform the tasks from MGTools because it wouldn't go through once I clicked yes to allow it to access RegEdit.
     

    Attached Files:

  5. whatthe

    whatthe Private E-2

    Sorry, here are the logs from before the system restore.
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you make sure when running MGTools that antivirus is temporarily disabled, that you run it as admin, and that you have indeed got UAC turned off.

    Try again please, it's the most important set of logs to review.
     
  7. whatthe

    whatthe Private E-2

    I have my anti-virus turned off and I most definitely can not turn the UAC off without having to restart. And when I restart, that's when I get the blue screen and then I have to system restore back to a point before the incident. Here's a picture of what keeps happening. I click yes but then the same pop-up comes again and again. Even if I click no, it keeps coming. I had to ctrl-alt-delete to end the process in order for it to stop.
     

    Attached Files:

  8. whatthe

    whatthe Private E-2

    Like I said in my before post, I had removed the infections from MalwareBytes like it told me to and did a restart. Ever since then I have been experiencing another problem. This(attached image) keeps popping up every time I try to open anything(for instance Google Chrome). After clicking 'ok' several times, Google Chrome will open up like nothing was wrong. But it's annoying to keep receiving the pop-up every time I try to open something.
     

    Attached Files:

  9. whatthe

    whatthe Private E-2

    Ok so I'm not exactly sure what I did, but I messed with it a little and I believe I have the log file. The file was too large so I split them in half.
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    There should be many more logs than that in the MGlogs.zip, can you please attach the MGlogs.zip as is? There's no need to seperate the logs from out of the compressed folder.
     
  11. whatthe

    whatthe Private E-2

    Ok, I'm so sorry. Because I had to click so many times because of the pop-up, I thought that it was done on the first one. Here are the MGlogs.
     

    Attached Files:

  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Uninstall the below softwares:

    • SaveAs 1.66
    • SaveAs
    • SaveShare 1.74
    • Search Assistant 1.74




    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    • O20 - AppInit_DLLs: c:\progra~2\saveas\sprote~1.dll c:\progra~2\websea~1\sprote~1.dll c:\progra~2\savesh~1\sprote~1.dll
    • O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Unknown owner - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (file missing)
    NOTE: HJT may popup an error about the AppInit_DLLs line. Ignore it and click OK to continue.

    After clicking Fix exit HJT.




    Download and run OTM.

    Download OTM by Old Timer and save it to your Desktop.


    Code:
    :reg
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=-
    [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows]
    "AppInit_DLLs"=""
    
    :files
    C:\ProgramData\SaveAs
    C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SaveAs
    C:\Program Files (x86)\SaveAs
    C:\Program Files (x86)\SaveShare
    C:\Program Files (x86)\SearchProtect
    C:\Program Files (x86)\WebSearch
    C:\Program Files (x86)\Common Files\Spigot
    C:\Windows\SysWOW64\ntoskrnl(51).exe
    C:\Windows\SysWOW64\user(56).exe
    C:\Windows\SysWOW64\wow32(57).dll
    C:\Windows\tasks\AutoKMS.job
    C:\Windows\tasks\Driver Robot.job
    c:\progra~2\websea~1\sprote~1.dll
    
    :Commands
    [emptytemp]
    [Reboot]
    • Return to OTM, right click in the Paste List of Files/Folders to Move window (under the yellow bar) and choose Paste.
    • Push the large http://farm3.static.flickr.com/2782/4174320048_f01c448b32_o.png button.
    • OTM may ask to reboot the machine. Please do so if asked.
    • Copy everything in the Results window (under the green bar), and paste it into notepad, save it as something appropriate and attach it into your next reply.

    NOTE: If you are unable to copy/paste from this window (as will be the case if the machine was rebooted), open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTM\MovedFiles folder, and open the newest .log file present, and attach the contents of that document back here in your next post.




    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.



    Re run Hitman and have it delete the Potential Unwanted Programs.
    Re run RogueKiller, just a scan and attach the log.
    Does MBAM find anything else when you rescan with it?
    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  13. whatthe

    whatthe Private E-2

    Ok so I was able to uninstall:
    SaveAs 1.66
    SaveAs
    SaveShare 1.74
    Search Assistant 1.74

    I also ran the analyse.exe and removed
    O20 - AppInit_DLLs: c:\progra~2\saveas\sprote~1.dll c:\progra~2\websea~1\sprote~1.dll c:\progra~2\savesh~1\sprote~1.dll
    O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Unknown owner - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (file missing)

    Then I ran the OTM, copy and paste, moved it, and did the restart. Then I encountered the blue screen once again. Had to do a system restore again as well. So basically, I can't restart my computer without encountering the bluescreen at startup.
     

    Attached Files:

  14. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you run FRST again please and attach the log.
     
  15. whatthe

    whatthe Private E-2

    Here is the log from FRST.
     

    Attached Files:

    Last edited: Oct 16, 2013
  16. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)

    -----------------

    Any better?
     

    Attached Files:

  17. whatthe

    whatthe Private E-2

    Could I get some more help on how to do this?
     
  18. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Certainly. :)

    I gave you some instructions, which part are you struggling with?
     
  19. whatthe

    whatthe Private E-2

    Ok so I'm able to get to the system recovery options which looks like this right? Then I don't know how to run a exe file when the closest thing says "recover from image". I clicked on that and all it said was there is no image saved onto your hard drive.
     

    Attached Files:

  20. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.
     
  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This was already done which is how the snapshot was obtained. The Command Prompt needs to be selected just like what was done when the first post in the thread was attached with the first FRST log which was run from the Recover Environment. The second FRST log in this thread was not run from the Recovery Environment. It was run from Normal Startup.
     
  22. whatthe

    whatthe Private E-2

    Oh ok. Sorry for my ignorance in not remembering on how to run an exe through command prompt. Anyways, I did that through the recovery page but it did not fix my computer. Once the fix was applied and computer had to be restarted, upon startup I hit the same blue screen again. Then had to do a system restore once again. Here is my fixlog.

    Can I also mention that my usb was not connecting with my computer? Or is that a different problem? When I insert my usb to my laptop it makes the sound that it is connected but does not appear on my computer nor can I access it though command prompt when logged in. I am for some reason able to access my usb through the recovery system options, but I won't be able to post or upload anything through that way. I had to upload the fixlog from a different computer.
     

    Attached Files:

  23. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I am beginning to think that you will have to post about this in the software forum. Before you do, please run FRST again. No fix, just run it normally. (like you did the very first time) and attach it's log.
     
  24. whatthe

    whatthe Private E-2

    Here are the FRST logs for both a normal boot and recovery mode.
     

    Attached Files:

  25. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt > Save fixlist.txt to your desktop. Also save a copy of FRST64.exe on your desktop.


    Double click FRST64 to run it.
    Click on the FIX button.
    Logs should be produced on your desktop.
    Attach them please.
     

    Attached Files:

  26. whatthe

    whatthe Private E-2

    I tried it out but I still got the blue screen. I chose to restore from 2 days ago, but surprisingly there was a fixlog.txt on my desktop. I have attached it.
     

    Attached Files:

  27. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Our progress is being hindered by the system restores. I understand you have used it so that you can indeed follow some of my instructions but it's now messy, and I believe you have problems which ought to be resolved in the software forum. Then you can return here afterwards. Hang in there, I am seeking advice about all this in the background.

    Thanks for your patience. :)
     
  28. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there. Can you please go thru what you can of the R&R again. And attach the requested logs. I want a fresh look at what's going on.
     
  29. whatthe

    whatthe Private E-2

    Here are the fresh new logs!
     

    Attached Files:

  30. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    SaveAs <--- uninstall this rubbish.


    Re run Hitman and have it delete all Potential Unwanted Programs.


    Delete these if you see them:

    • C:\ProgramData\CloudSoft
    • C:\ProgramData\SaveAs
    • C:\Program Files (x86)\Conduit
    • C:\Windows\SysWOW64\ntoskrnl(51).exe
    • C:\Windows\SysWOW64\user(56).exe
    • C:\Windows\SysWOW64\wow32(57).dll


    Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:


    • R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchingissme.info/?unqvl=23
    • O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Unknown owner - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (file missing)
    After clicking Fix exit HJT.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.

    Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now!
     
  31. whatthe

    whatthe Private E-2

    Well....

    I was not able to uninstall SaveAs because it kept saying that it was being used by another program.

    Ran Hitman and deleted potential problems.

    I was able to delete only this:
    C:\ProgramData\SaveAs
    C:\Program Files (x86)\Conduit

    Ran C:\MGtools\analyse.exe and was only able to delete:
    R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://websearch.searchingissme.info/?unqvl=23

    Ran C:\MGtools\GetLogs.bat and here are the logs.



    Should I restart my computer??
     
  32. whatthe

    whatthe Private E-2

    I see what happened last post. Here are the new logs.
     

    Attached Files:

  33. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Before we continue I would like for you to use MSConfig to put this machine back into normal start up mode


    SaveAs <--- uninstall this garbage using Revo Uninstaller.


    Delete these:
    • C:\Windows\SysWOW64\ntoskrnl(51).exe
    • C:\Windows\SysWOW64\user(56).exe
    • C:\Windows\SysWOW64\wow32(57).dll
    • C:\Windows\tasks\AutoKMS.job


    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    http://imageshack.us/a/img841/7292/thisisujrt.gif Please download Junkware Removal Tool to your desktop.
    • Shut down your protection software now to avoid potential conflicts.
    • Run the tool by double-clicking it. If you are using Windows Vista or Seven, right-mouse click it and select Run as Administrator.
    • The tool will open and start scanning your system.
    • Please be patient as this can take a while to complete depending on your system's specifications.
    • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
    • Attach JRT.txt to your next message.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.


    How are things running?
     
  34. whatthe

    whatthe Private E-2

    I was able to change the computer back to normal startup using MSConfig.

    Revo Uninstaller was of no help to uninstall SaveAs because it didn't exist.(attached)

    Was able to only delete C:\Windows\tasks\AutoKMS.job

    Created a fixMe.reg and was able to successfully merge with registry.

    Downloaded and got the logs from JRT.

    Ran C:\MGtools\GetLogs.bat


    Nothing seems to be changed. Should I restart computer?
     

    Attached Files:

  35. whatthe

    whatthe Private E-2

    RevoUninstaller
     

    Attached Files:

  36. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Clearly, it's still left a mess across your machine and you can see it's entry listed in the newfiles.txt along with all the other installed programs.


    Download The Avenger by Swandog469, and save it to your Desktop.

    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Do not change any check box options!!
    • Copy everything in the Quote box below, and paste it into the Input script here: part of the window:
    • Now click the Execute button.
    • Click Yes to the prompt to confirm you want to execute.
    • Click Yes to the Reboot now? question that will appear when Avenger finishes running.
    • Your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt and it will popup for you to view when you login after reboot.


    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. (Right click and run as admin if using Vista, Windows7 or Win8) Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  37. whatthe

    whatthe Private E-2

    So what happened was, I was not able to postpone the restart any longer. My computer had restarted on its own and once again, started hitting the blue screen. None of the system restores left on my computer were working anymore. So, I had to make a painful decision. I did a factory reset. My computer is now up and running good as new, only problem is my files are gone.
     
  38. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You will have to ask about that in the software forum. :) Did you back anything up at all?
     
  39. whatthe

    whatthe Private E-2

    Yup everything is running smoothly. I'm currently in the process of reinstalling softwares. I was able to transfer over te files I needed. The only thing missing is the software, which I can reinstall easily. Thank you for all your help!
     
  40. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    You are most welcome. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds