Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

Web Browser Hanging Up and Shutting Down [Solved]


  • This topic is locked This topic is locked

#16
LiquidTension

LiquidTension

    Expert

  • Expert
  • 1,151 posts

Hello cloroxmartini,
 

Reset Classic Shell and the menu options and file explorer work fine now

I'm glad to hear. 
 
Please provide an update on your issues after carrying out the following instructions. Are you still experiencing issues with Outlook and your browsers?

xlK5Hdb.png Farbar Recovery Scan Tool (FRST) Script

  • Press the Windows Key pdKOQKY.png + r on your keyboard at the same time. Type Notepad and click OK.
  • Copy the entire contents of the codebox below and paste into the Notepad document.
    2014-06-30 09:05 - 2014-06-30 09:05 - 04489040 _____ (Systweak Inc )
    C:\Users\Donnapc\Downloads\rcp_dcomnew_sec_728.exe
    2014-06-30 09:07 - 2014-06-30 09:07 - 00000000 ____D () C:\Users\Donnapc\AppData\Roaming\amazon
    2014-06-30 11:02 - 2014-06-30 11:02 - 00001162 _____ () C:\Users\Donnapc\Desktop\Live PC Help.lnk
    AlternateDataStreams: C:\Users\Donnapc\Downloads\Change of Info Form For Area Team.eml:OECustomProperty
    AlternateDataStreams: C:\Users\Donnapc\Downloads\Fw_ Matt Harding dances around the world.email.eml:OECustomProperty
    AlternateDataStreams: C:\Users\Donnapc\Downloads\mime-attachment.eml:OECustomProperty
    AlternateDataStreams: C:\Users\Donnapc\Downloads\RE Prayer Request.eml:OECustomProperty
    AlternateDataStreams: C:\Users\Donnapc\Downloads\Word for 2014 from Doug Addison.eml:OECustomProperty
    AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_0OLFavIE91284348923
    AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_1OCalFavIE91545382048
    AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_2PeopleFav-510560096
    AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_3SkyDriveFav-324886575
    AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_4OLFavIE91410631431
    HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
    HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
    HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
    SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
    SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
    SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
    SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
    SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
    SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
    HKLM-x32\...\Run: [] => [X]
  • Click FileSave As and type fixlist.txt as the File Name
  • Important: The file must be saved in the same location as FRST64.exe. 

NOTICE: This script is intended for use on this particular machine. Do not use this script on any other machine; doing so may cause damage to your Operating System.

  • Right-Click FRST64.exe and select AVOiBNU.jpg Run as administrator to run the programme.
  • Click Fix.
  • A log (Fixlog.txt) will open on your desktop. Copy the contents of the log and paste in your next reply.

  • 0

Advertisements


#17
cloroxmartini

cloroxmartini

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

After deleting Spybot, the problems with Outlook links and load time for Chrome went away.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 28-06-2014 02
Ran by Donnapc at 2014-07-01 11:50:48 Run:1
Running from C:\Users\Donnapc\Desktop
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
2014-06-30 09:05 - 2014-06-30 09:05 - 04489040 _____ (Systweak Inc )
C:\Users\Donnapc\Downloads\rcp_dcomnew_sec_728.exe
2014-06-30 09:07 - 2014-06-30 09:07 - 00000000 ____D () C:\Users\Donnapc\AppData\Roaming\amazon
2014-06-30 11:02 - 2014-06-30 11:02 - 00001162 _____ () C:\Users\Donnapc\Desktop\Live PC Help.lnk
AlternateDataStreams: C:\Users\Donnapc\Downloads\Change of Info Form For Area Team.eml:OECustomProperty
AlternateDataStreams: C:\Users\Donnapc\Downloads\Fw_ Matt Harding dances around the world.email.eml:OECustomProperty
AlternateDataStreams: C:\Users\Donnapc\Downloads\mime-attachment.eml:OECustomProperty
AlternateDataStreams: C:\Users\Donnapc\Downloads\RE Prayer Request.eml:OECustomProperty
AlternateDataStreams: C:\Users\Donnapc\Downloads\Word for 2014 from Doug Addison.eml:OECustomProperty
AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_0OLFavIE91284348923
AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_1OCalFavIE91545382048
AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_2PeopleFav-510560096
AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_3SkyDriveFav-324886575
AlternateDataStreams: C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website:TASKICON_4OLFavIE91410631431
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK13/1
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK13/1
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://www.bing.com/...0TR&pc=HPDTDFJS
HKLM-x32\...\Run: [] => [X]
*****************

"2014-06-30 09:05 - 2014-06-30 09:05 - 04489040 _____ (Systweak Inc )" => File/Directory not found.
C:\Users\Donnapc\Downloads\rcp_dcomnew_sec_728.exe => Moved successfully.
C:\Users\Donnapc\AppData\Roaming\amazon => Moved successfully.
C:\Users\Donnapc\Desktop\Live PC Help.lnk => Moved successfully.
C:\Users\Donnapc\Downloads\Change of Info Form For Area Team.eml => ":OECustomProperty" ADS removed successfully.
C:\Users\Donnapc\Downloads\Fw_ Matt Harding dances around the world.email.eml => ":OECustomProperty" ADS removed successfully.
C:\Users\Donnapc\Downloads\mime-attachment.eml => ":OECustomProperty" ADS removed successfully.
C:\Users\Donnapc\Downloads\RE Prayer Request.eml => ":OECustomProperty" ADS removed successfully.
C:\Users\Donnapc\Downloads\Word for 2014 from Doug Addison.eml => ":OECustomProperty" ADS removed successfully.
C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website => ":TASKICON_0OLFavIE91284348923" ADS removed successfully.
C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website => ":TASKICON_1OCalFavIE91545382048" ADS removed successfully.
C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website => ":TASKICON_2PeopleFav-510560096" ADS removed successfully.
C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website => ":TASKICON_3SkyDriveFav-324886575" ADS removed successfully.
C:\Users\Donnapc\AppData\Roaming\Microsoft\Windows\Start Menu\Outlook.website => ":TASKICON_4OLFavIE91410631431" ADS removed successfully.
HKCU\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Default_Page_URL => Value was restored successfully.
HKLM\Software\\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}' => Key deleted successfully.
'HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}'=> Key not found.
HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => Value was restored successfully.
'HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}' => Key deleted successfully.
'HKCR\Wow6432Node\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}'=> Key not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
'HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}' => Key deleted successfully.
'HKCR\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}'=> Key not found.
HKLM\Software\WOW6432Node\Microsoft\Windows\CurrentVersion\Run\\ => value deleted successfully.

==== End of Fixlog ====


  • 0

#18
LiquidTension

LiquidTension

    Expert

  • Expert
  • 1,151 posts

Hi cloroxmartini,
 

After deleting Spybot, the problems with Outlook links and load time for Chrome went away.

Thank you for letting me know. 
 
Lets check for leftovers, and we will be done shortly after. 
 
STEP 1
GfiJrQ9.png Malwarebytes Anti-Malware (MBAM)

  • Launch Malwarebytes Anti-Malware and click Update Now.
  • Once updated, click the Settings tab and tick Scan for rootkits.
  • Click the Scan tab, ensure Threat Scan is checked and click Scan Now.
  • Note: You may see the following message, "Could not load DDA driver". Click Yes, allow your PC to reboot and continue afterwards. 
  • If threats are detected, click the Apply Actions button. You will now be prompted to reboot. Click Yes.
  • Upon completion of the scan (or after the reboot), click the History tab.
  • Click Application Logs and double-click the Scan Log.
  • Click Copy to Clipboard and paste the log in your next reply. 
     

STEP 2
GzlsbnV.png ESET Online Scan
Note: This scan will take a significant amount of time to complete. Please do not browse the Internet whilst your resident protection is disabled.

  • Please download ESET Online Scan and save the file to your desktop.
  • Temporarily disable your anti-virus software. For instructions, please refer to the following link.
  • Double-click esetsmartinstaller_enu.exe to run the programme. 
  • Agree to the EULA by placing a checkmark next to Yes, I accept the Terms of Use. Then press Start.
  • Agree to the Terms of Use once more and click Start. Allow components to download.
  • Click Hide advanced settings. Your settings should match that of the image below.
  • Ensure Remove found threats is unchecked.
    3Crnyln.png
  • Allow virus signature database to download and for the scan to finish. Please be patient as this can take some time.
  • Upon completion, click esetListThreats.png. If no threats were found, skip the next two bullet points. 
  • Click esetExport.png and save the file to your desktop, naming it something unique such as MyEsetScan.
  • Push the Back button.
  • Place a checkmark next to KN1w2nv.png and click SzOC1p0.png.
  • Re-enable your anti-virus software.
  • Copy the contents of the log and paste in your next reply.
     

======================================================
 
STEP 3
pfNZP4A.png Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • MBAM Scan log
  • ESET Online Scan log

  • 0

#19
cloroxmartini

cloroxmartini

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 7/1/2014
Scan Time: 1:46:02 PM
Logfile: MBAM log.txt
Administrator: Yes

Version: 2.00.2.1012
Malware Database: v2014.07.01.07
Rootkit Database: v2014.07.01.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 8.1
CPU: x64
File System: NTFS
User: Donnapc

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 281818
Time Elapsed: 11 min, 18 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 0
(No malicious items detected)

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)

(end)

 

C:\FRST\Quarantine\C\Users\Donnapc\Downloads\rcp_dcomnew_sec_728.exe.xBAD MSIL/AdvancedSystemProtector.D potentially unwanted application
C:\temp\InstallFilter64.msi a variant of Win32/AdWare.Adpeak.G application
 


  • 0

#20
LiquidTension

LiquidTension

    Expert

  • Expert
  • 1,151 posts

Hi cloroxmartini,
 
Using Windows Explorer, please navigate to the following file: C:\temp\InstallFilter64.msi
Right-click the file and click Delete.

 
STEP 1
CXrghb6.png Update Outdated Software

Outdated software contain security risks that must be patched. Please download and install the latest version of the programmes below.

  • u9DsAVv.png Follow these instructions to check for and download the latest Windows Updates.
     

STEP 2
zANS9oB.png Disable Java in Your Browser
Due to frequent exploits we recommend you disable Java in your browser. For information on Java vulnerabilities, please read the following article (point #7).

  • Press the Windows Key pdKOQKY.png on your keyboard at the same time. Type Java Control Panel (or javacpl) in the search bar. 
  • Click on the Java Control Panel. Once opened, click the Security tab.
  • Deselect the check box for Enable Java content in the browser. This will disable the Java plug-in in the browser. 
  • Click Apply. When the Windows User Account Control (UAC) AVOiBNU.jpg appears, allow permissions to make the changes. 
  • Click OK in the Java Plug-in confirmation window.
  • Restart your browser(s) for changes to take effect.
  • More information can be found here and here.
     

STEP 3
oxliOQk.png Security Check

  • Please download SecurityCheck and save the file to your desktop.
  • Double-click SecurityCheck.exe and follow the onscreen instructions inside the black box.
  • A log (checkup.txt) will automatically open on your desktop.
  • Copy the contents of the log and paste in your next reply.
     

======================================================
 
STEP 4
pfNZP4A.png Logs
In your next reply please include the following logs. Please be sure to copy and paste the requested logs, as well as provide information on any questions I may have asked.

  • Confirmation you had no issues with the instructions. 
  • checkup.txt
  • Comments on how your computer is performing. 

Note: There are important steps to follow. Please ensure you continue following this topic until I give you the "All Clean".


  • 0

#21
cloroxmartini

cloroxmartini

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

Instructions are fine.

 

 Results of screen317's Security Check version 0.99.85 
   x64 (UAC is enabled) 
 Internet Explorer 11 
``````````````Antivirus/Firewall Check:``````````````
 Windows Firewall Enabled! 
Windows Defender  
 WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
 Java 7 Update 60 
 Adobe Reader XI 
 Google Chrome 35.0.1916.114 
 Google Chrome 35.0.1916.153 
````````Process Check: objlist.exe by Laurent```````` 
 Windows Defender MSMpEng.exe
 Windows Defender MpCmdRun.exe  
`````````````````System Health check`````````````````
 Total Fragmentation on Drive C:  %
````````````````````End of Log``````````````````````

 

Machine runs pretty good now, thank you.

 

There were two malicious files found during the escan:

C:\FRST\Quarantine\C\Users\Donnapc\Downloads\rcp_dcomnew_sec_728.exe.xBAD MSIL/AdvancedSystemProtector.D potentially unwanted application
C:\temp\InstallFilter64.msi a variant of Win32/AdWare.Adpeak.G application

 

What do we do with those?
 


Edited by cloroxmartini, 02 July 2014 - 11:15 AM.

  • 0

#22
LiquidTension

LiquidTension

    Expert

  • Expert
  • 1,151 posts

Hi cloroxmartini,
 

Machine runs pretty good now, thank you.

I'm glad to hear. smile.png
 

C:\FRST\Quarantine\C\Users\Donnapc\Downloads\rcp_dcomnew_sec_728.exe.xBAD MSIL/AdvancedSystemProtector.D potentially unwanted application

This file has already been dealt with. The file location shows the file is in quarantine, and the extension shows the file is no longer active. The instructions below will show you how to remove the tools we've used. This process will subsequently remove the associated quarantine folders; permanently removing the quarantined files from your computer.

C:\temp\InstallFilter64.msi a variant of Win32/AdWare.Adpeak.G

This was the file I had you manually delete earlier. 

 

 
STEP 1
Z2qgMOy.png OTL

  • Please download OTL and save the file to your desktop.
  • Double-click OTL.exe to run the programme. Ensure all other windows are closed
  • Copy the entire contents of the codebox below and paste into the 1wDyQ2v.png textbox.
    :OTL
    
    :Commands
    [emptytemp]
    [emptyjava]
    [clearallrestorepoints]
  • Click the j7yFJut.png button.
  • Let the programme run and reboot your computer if prompted
     

STEP 2
AFZxnZc.jpg DelFix

  • Please download DelFix and save the file to your Desktop.
  • Double-click DelFix.exe to run the programme.
  • Place a checkmark next to the following items:
    • Activate UAC
    • Remove disinfection tools
    • Create registry backup
    • Reset System Settings
  • Click the Run button.

-- This will remove the specialised tools we used to disinfect your system. Any leftover logs, files, folders or tools remaining on your Desktop which were not removed can be deleted manually (right-click the file + delete).
 
--- Malwarebytes Anti-Malware will still be present on your computer. I recommend keeping this programme, updating and scanning with it once a week to maintain security on your computer. If you do not wish to keep this programme on your computer, you can uninstall it by pressing the Windows Key pdKOQKY.png + r on your keyboard at the same time, typing appwiz.cpl, clicking OK and searching for Malwarebytes.
 
======================================================
 
All Clean!
Congratulations, your computer appears clean!   thumbup.gif
I no longer see signs of malware on your computer, and feel satisfied that our work here is done. Below I have compiled a list of resources you may find useful. The articles document information on computer security/maintenance, common infection vectors and how you can stay safe on the Internet.

The following security/maintenance programmes come highly recommended in the security community.

  • JEP5iWI.png Web of Trust (WOT) is a browser add-on designed to alert the user before interacting with a potentially malicious website. 
  • 6YRrgUC.png Malwarebytes Anti-Malware Premium incorporates real-time protection and is designed to run alongside your anti-virus. 
  • j1OLIec.png SpywareBlaster is a form of passive protection, designed to block the actions of malicious websites and tracking cookies.
  • A5RLVbX.png CCleaner (portable) is a handy temp file cleaner. Avoid the built-in registry cleaner => see this article for information. 
  • DgW1XL2.png Secuina PSI will scan your computer for vulnerable software that is outdatedand automatically find the latest update for you.
  • hkxnADR.png StartupLite will scan your computer for unnecessary startup programmes. Disabling identified programmes may improve boot-time
  • jv4nhMJ.png NoScript is a Firefox add-on that blocks the actions of malicious scripts by using whitelisting and other technology. 
  • KsUqI5A.png AdBlock is a browser add-on that blocks annoying banners, pop-ups and video ads.
     

Wary of a particular file/website? Need a second opinion? Scan the file/URL using these free online scanner services:

-- Should you have any questions on the above tools, or computer security in general, please feel free to ask
 
======================================================
 
Please confirm you have no outstanding issues, and are happy with the state of your computer. Once I have confirmation things are in order, we can wrap things up and I will close this thread. 
 
Thank you for using Geeks to Go!.
 
Safe Surfing.   thumbup.gif
LiquidTension.


  • 0

#23
cloroxmartini

cloroxmartini

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 139 posts

That was great! Thank you! Everything is working top drawer.


  • 0

#24
LiquidTension

LiquidTension

    Expert

  • Expert
  • 1,151 posts
You are more than welcome. :)
  • 0

#25
CatByte

CatByte

    GeekU Teacher

  • GeekU Moderator
  • 2,705 posts
  • MVP
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0

Advertisements







Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP