Error Messages On Boot

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by msidea, Aug 5, 2018.

  1. msidea

    msidea Private First Class

    I have been receiving boot errors about my power supply not being compatible, experienced lagging, and freezing of software for about 2 months now so I have run a variety of scans, including Avast root kit scan. Still the problems are continue intermittently.

    About 3 weeks ago, I received a "ransom" email with an old password that I used to use for everything in the header. In the email, the sender told me that he would know when I opened it. I don't know if it was a bluff like the rest of his email, but my son who is in high school and does programming told me that just because I didn't open an attachment does not mean that he could not have attached a pixel something or other.

    Tonight, I ran the scans as per Read & Run document. Here are my results.

    Thank you so much for everything that you do!
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    It is highly unlikely that you would get infected by looking at an email. I am certain the attachment was the bomb.

    Please open Hitman and remove these two items:
    Potential Unwanted Programs _________________________________________________

    HKLM\SOFTWARE\Classes\Software.OneClickProcessLauncherMachine.1.0\ (BoxoreOU)
    HKLM\SOFTWARE\Classes\Software.OneClickProcessLauncherMachine\ (BoxoreOU)

    Reboot and rerun Hitman and also please run ADWCleaner and attach the logs.
     
  3. msidea

    msidea Private First Class

    Hi Tim,

    Thanks for your fast response.

    I did what you said. I ran Hitman and deleted the 2 items that showed up. Then I ran ADW Cleaner. It found the legacy pup. I had it clean and repair it, and it asked me to restart. When I did that to go in and access the logs to send them to you, something happened. The error message says that Windows can't access SENS.

    Please advise.
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Click on the Start button and select Control Panel, Administrative Tools, Services. Locate System Event Notification Manager in the list and check that the StartUp type is Automatic. If it is not set to Automatic right click and select Properties, General tab. There is a box after StartUp type. The options are available on a drop down by clicking on the arrow down to the right of the box. After making the change click on Apply and OK. Restart the computer and check whether it has started.
     
  5. msidea

    msidea Private First Class

    Hello again Tim.

    We - my son who's helping me and me - tried following your instructions. The event viewer didn't open.

    He looked on a couple of web sites to see how to open it. I'm attaching some of the error message that we got. He confirmed that the SENS, the Event Log Registry folder, and the Schedule Registra folder have full admin rights.

    When we tried force starting the Windows Event Log service. That's when we got the authorization unknown error. The other one was when we tried running the Event Viewer.

    Awaiting your command.
     

    Attached Files:

    Last edited: Aug 6, 2018
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Press the Windows + R keys at the same time, then type services.msc and hit OK

    Now locate System event notification service and double-click it.

    Make sure the blue boxes match your settings, Startup Type should be set to Automatic and the Service should be running.
     
  7. msidea

    msidea Private First Class

    Those are the current settings. We were working in Safe Mode with CMD.

    So I tried restarting again. It did ask for the password and accepted it. It took a long time to boot and when it finally did, it showed a blue box with an error message but I was too far to read it before it disappeared. It restarted. When I tried logging in again as Admin, it said "Handle invalid". I tried using my user account with the same result. It then rebooted on its own.

    Is this situation because of a virus or could it have been caused by the clean up?
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Neither virus or clean up. What about any of the other accounts? Can you log in with those?
     
  9. msidea

    msidea Private First Class

    No.

    I was able to get into my Admin account briefly. It seemed to be booting Windows. Then it showed an error message saying that something went wrong and that it needed to restart. When I leave it alone, it puts itself in a perpetual loop of reboot.

    Why do you think that it's doing this?
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I don't know. I suggest you post in the software forum for additional assistance. The Malware forum is not the place to pursue this issue. :)
     
  11. msidea

    msidea Private First Class

    Ok, but if I didn't have this issue before the malware, then how do I know that it's not a result of the malware?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Because this was the only thing found:
    HKLM\SOFTWARE\Classes\Software.OneClickProcessLauncherMachine.1.0\ (BoxoreOU)
    "The software will modify the user's web browser and display advertisements in Internet Explorer, Chrome and Firefox as well as modify the home and search pages. - Read more at https://www.shouldiremoveit.com/Boxore-Client-41982-program.aspx"

    It has no effect on your core systems.
     
  13. msidea

    msidea Private First Class

    Ok.

    I guess I'm just wondering if there's some other malware that we haven't found.

    In any case, thanks Tim! If I can't solve it through the forums, my son is going to take my info from my hard drive and we'll reformat.

    Question on this. My computer is a Dell Windows 8, everything legit. When Windows 10 came out, I upgraded through the link that I sent. If I reformat it, do you know how I would get Windows 10 again?
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MG's has a link for the ISO file. If you need help with doing that, ask in the software forum. :)
     
  15. msidea

    msidea Private First Class

    Great Tim! Again, thanks so much!
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    No problem. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds