Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Not sure if malware has been removed [Solved]


  • This topic is locked This topic is locked

#31
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts

Just checking the thread at work.  I will update the programs identified in post #17 when I get home.

 

ok.
 

No, I don't want to upgrade to Windows 10.  (Is there any benefit?  I already don't like the user interface with 8.1, that's why I installed Classic Shell so that it looks like XP.)

 

I will not discuss that :)

 

The Windows 10 offer can interfere with the install of Windows Updates and also start downloading in the background using bandwidth and hard disk space...

 

 

Lets stop the Windows 10 Offer

 

Please download GWX Control Panel and run the tool
0JeJmUzoR8I9rKfqBv6u91ZK8EdFzu.png
You can use the options:

  • Disable 'Get Windows 10' App (remove icon)
  • Delete Windows 10 Download Folders...
  • Prevent Automatic Windows 10 Upgrades

After this restart the PC.


  • 0

Advertisements


#32
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

Something strange is going on.  Started the computer, desktop and icons loaded normally. I clicked on Outlook and it took fully 2 minutes to load.  Clicked on Start, and long delay before anything showed up on the screen.  Tried to go into Task Manager and it wouldn't load for almost 2 minutes as well. 

 

Ran the tool from previous post. 

 

Awaiting further instructions.


  • 0

#33
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts

Any recent changes besides what we did?

 

Download MiniToolBox and save the file to the Desktop.
Close the browser and run the tool, check the following options:

  • List last 10 Event Viewer Errors

Click on Go.

Post the resulting log in your next reply.
 

 


  • 0

#34
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

No other changes than per this thread.  (I haven't made the updates yet from post #17.)

 

MiniToolBox by Farbar  Version: 07-02-2016 01
Ran by Robert (administrator) on 04-04-2016 at 17:15:31
Running from "C:\Users\Robert\Desktop"
Microsoft Windows 8.1  (X64)
Model: HP Pavilion 17 Notebook PC Manufacturer: Hewlett-Packard
Boot Mode: Normal
***************************************************************************

========================= Event log errors: ===============================

Application errors:
==================
Error: (04/03/2016 08:37:53 PM) (Source: Application Error) (User: )
Description: Faulting application name: egui.exe, version: 8.0.319.0, time stamp: 0x559d2313
Faulting module name: ToastNotify.dll, version: 8.0.319.0, time stamp: 0x559d2398
Exception code: 0xc0000005
Fault offset: 0x0000000000002f3e
Faulting process id: 0x1224
Faulting application start time: 0xegui.exe0
Faulting application path: egui.exe1
Faulting module path: egui.exe2
Report Id: egui.exe3
Faulting package full name: egui.exe4
Faulting package-relative application ID: egui.exe5

Error: (04/03/2016 08:37:00 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) - Update 'Microsoft Access Database Engine 2010 Service Pack 1 (SP1)' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI380a8.LOG.

Error: (04/03/2016 08:37:00 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) -- Error 1706. Setup cannot find the required files.  Check your connection to the network, or CD-ROM drive.    For other potential solutions to this problem, see SETUP.CHM.


System errors:
=============
Error: (04/04/2016 04:36:43 PM) (Source: Service Control Manager) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
%%577

Error: (04/04/2016 04:35:38 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}

Error: (04/04/2016 04:29:00 PM) (Source: Service Control Manager) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
%%577

Error: (04/04/2016 04:27:40 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}

Error: (04/03/2016 09:54:00 PM) (Source: Service Control Manager) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
%%577

Error: (04/03/2016 09:53:01 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}

Error: (04/03/2016 08:42:00 PM) (Source: Service Control Manager) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
%%577

Error: (04/03/2016 08:41:17 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}

Error: (04/03/2016 08:37:05 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024002d: Service Pack 1 for Microsoft Access Database Engine 2010 (KB2460011) 64-bit Edition.


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2016-04-04 16:36:43.197
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-04 16:29:00.110
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-03 21:54:00.721
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-03 20:42:00.803
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-03 18:52:54.478
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-10-28 23:06:29.137
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-10-28 22:50:17.447
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-10-28 22:42:44.415
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2015-10-28 22:27:02.996
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


**** End of log ****
 


  • 0

#35
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts
Check Windows System files integrity
  • open the Command Prompt as Administrator (Tutorial)
  • type the following command and press Enter:
    sfc /scannow
    Note: This may take some time to finish.

    let me know if it doesn't say "No integrity violations found"

  • 0

#36
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

Scan finished. "Windows Resource Protection found corrupt files but was unable to fix some of them."


  • 0

#37
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts
  • Download SFCFix.exe (by Niemiro) and save it to the Desktop
  • Run SFCFix (accept the security warning and follow the instructions on the screen)
  • Upon completion, a log file SFCFix.txt should be created on your Desktop
  • Open the SFCFix.txt log and copy & paste the contents to your post

  • 0

#38
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

Please see log below.

 

SFCFix version 3.0.0.0 by niemiro.
Start time: 2016-04-05 15:51:26.505
Microsoft Windows 8.1 Update 3 - amd64
Not using a script file.




AutoAnalysis::
FIXED: Performed DISM repair on file Amd64\CNBJ2530.DPB of version 6.3.9600.17415.




SUMMARY: No corruptions were detected.
AutoAnalysis:: directive completed successfully.




Successfully processed all directives.
SFCFix version 3.0.0.0 by niemiro has completed.
Currently storing 0 datablocks.
Finish time: 2016-04-05 16:54:17.054
----------------------EOF-----------------------

 

After the scan I restarted the computer.  Like before, the desktop and icons loaded right away, but it still takes longer than usual (but faster than before) to open things like Outlook and my browser.  Maybe another sfc /scannow is required?  What about the malware?  Has that been cleaned up?

 

Also, I have a notice to download some Windows updates.  Should I go ahead and do that?

 

Thank you for your assistance in all this by the way.  It's greatly appreciated.  (I will be out this evening, so I won't be able to do anything more from about an hour from now until around 10pm, EST.)


Edited by Jackpine, 05 April 2016 - 03:13 PM.

  • 0

#39
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts

Hi,

 

Run sfc /scannow again to confirm that it passes. If it does let install the Windows Updates.

 

I don't see evidences of malware in the logs.


  • 0

#40
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

Second sfc /scannow completed.  Windows did not find any integrity violations.

 

I will try Windows update now and report.

 

There were 3 updates available.  Two of them installed.  The third wouldn't.  Error Code 8024002D.

 

Programs slow to load: about 2 minutes for Outlook.  Even clicking on Start button takes a while before anything appears on the screen.


Edited by Jackpine, 06 April 2016 - 03:41 PM.

  • 0

Advertisements


#41
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts

Post the name of the Update please (KBxxxxx) and a new Minitoolbox log with List last 10 Event Viewer Errors


  • 0

#42
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

The update is KB2460011.  Except for this particular update, Windows update works well.  If this can't be fixed, I can probably live without it.  I'm more concerned about the long startup time for all programs.  On the other hand, maybe the two are linked?

 

Minitoolbox log is below.

 

MiniToolBox by Farbar  Version: 07-02-2016 01
Ran by Robert (administrator) on 07-04-2016 at 07:21:53
Running from "C:\Users\Robert\Desktop"
Microsoft Windows 8.1  (X64)
Model: HP Pavilion 17 Notebook PC Manufacturer: Hewlett-Packard
Boot Mode: Normal
***************************************************************************

========================= Event log errors: ===============================

Application errors:
==================
Error: (04/06/2016 06:14:40 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) - Update 'Microsoft Access Database Engine 2010 Service Pack 1 (SP1)' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI44ead.LOG.

Error: (04/06/2016 06:14:40 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) -- Error 1706. Setup cannot find the required files.  Check your connection to the network, or CD-ROM drive.    For other potential solutions to this problem, see SETUP.CHM.

Error: (04/06/2016 06:10:04 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) - Update 'Microsoft Access Database Engine 2010 Service Pack 1 (SP1)' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI12e0.LOG.

Error: (04/06/2016 06:10:04 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) -- Error 1706. Setup cannot find the required files.  Check your connection to the network, or CD-ROM drive.    For other potential solutions to this problem, see SETUP.CHM.

Error: (04/06/2016 05:33:01 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) - Update 'Microsoft Access Database Engine 2010 Service Pack 1 (SP1)' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSIde0b0.LOG.

Error: (04/06/2016 05:33:01 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) -- Error 1706. Setup cannot find the required files.  Check your connection to the network, or CD-ROM drive.    For other potential solutions to this problem, see SETUP.CHM.

Error: (04/05/2016 11:41:08 PM) (Source: Application Error) (User: )
Description: Faulting application name: egui.exe, version: 8.0.319.0, time stamp: 0x559d2313
Faulting module name: ToastNotify.dll, version: 8.0.319.0, time stamp: 0x559d2398
Exception code: 0xc0000005
Fault offset: 0x0000000000002f3e
Faulting process id: 0x113c
Faulting application start time: 0xegui.exe0
Faulting application path: egui.exe1
Faulting module path: egui.exe2
Report Id: egui.exe3
Faulting package full name: egui.exe4
Faulting package-relative application ID: egui.exe5

Error: (04/04/2016 05:38:37 PM) (Source: Perflib) (User: )
Description: BITSC:\Windows\System32\bitsperf.dll8

Error: (04/03/2016 08:37:53 PM) (Source: Application Error) (User: )
Description: Faulting application name: egui.exe, version: 8.0.319.0, time stamp: 0x559d2313
Faulting module name: ToastNotify.dll, version: 8.0.319.0, time stamp: 0x559d2398
Exception code: 0xc0000005
Fault offset: 0x0000000000002f3e
Faulting process id: 0x1224
Faulting application start time: 0xegui.exe0
Faulting application path: egui.exe1
Faulting module path: egui.exe2
Report Id: egui.exe3
Faulting package full name: egui.exe4
Faulting package-relative application ID: egui.exe5

Error: (04/03/2016 08:37:00 PM) (Source: MsiInstaller) (User: NT AUTHORITY)
Description: Product: Microsoft Access database engine 2010 (English) - Update 'Microsoft Access Database Engine 2010 Service Pack 1 (SP1)' could not be installed. Error code 1603. Additional information is available in the log file C:\Windows\TEMP\MSI380a8.LOG.


System errors:
=============
Error: (04/07/2016 07:18:22 AM) (Source: Service Control Manager) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
%%577

Error: (04/06/2016 09:16:31 PM) (Source: DCOM) (User: Shadowfax)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}ShadowfaxRobertS-1-5-21-3511957844-2261570385-1743981658-1005LocalHost (Using LRPC)UnavailableUnavailable

Error: (04/06/2016 09:16:31 PM) (Source: DCOM) (User: Shadowfax)
Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}ShadowfaxRobertS-1-5-21-3511957844-2261570385-1743981658-1005LocalHost (Using LRPC)UnavailableUnavailable

Error: (04/06/2016 09:16:11 PM) (Source: Service Control Manager) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
%%577

Error: (04/06/2016 06:14:42 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024002d: Service Pack 1 for Microsoft Access Database Engine 2010 (KB2460011) 64-bit Edition.

Error: (04/06/2016 06:10:06 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024002d: Service Pack 1 for Microsoft Access Database Engine 2010 (KB2460011) 64-bit Edition.

Error: (04/06/2016 05:52:21 PM) (Source: DCOM) (User: Shadowfax)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}

Error: (04/06/2016 05:38:05 PM) (Source: Service Control Manager) (User: )
Description: The Windows Defender Service service failed to start due to the following error:
%%577

Error: (04/06/2016 05:37:34 PM) (Source: DCOM) (User: NT AUTHORITY)
Description: {DDCFD26B-FEED-44CD-B71D-79487D2E5E5A}

Error: (04/06/2016 05:33:06 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x8024002d: Service Pack 1 for Microsoft Access Database Engine 2010 (KB2460011) 64-bit Edition.


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2016-04-07 07:18:22.962
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-06 21:16:11.470
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-06 17:38:05.676
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-06 16:46:43.931
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-05 22:59:18.702
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-05 22:51:02.611
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-05 17:05:34.050
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-05 15:40:28.250
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-04 16:36:43.197
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2016-04-04 16:29:00.110
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume4\Program Files\Windows Defender\MsMpEng.exe because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


**** End of log ****
 


  • 0

#43
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts

Hi,

 

The update is failing because it doesn't find the files for Microsoft Access database engine 2010! I'm not sure about the source of this program if you have the program in a CD you need to put the disc on the drive before installing the update of reinstall the program.

 

Disable the Windows Defender to see if that resolves the speed problem.


  • 0

#44
Jackpine

Jackpine

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 347 posts

Microsoft Windows Defender is already disabled.  (I checked.)  I have a CD for Microsoft Office 2007 32 bit, which is what was installed.  I used this on my desktop computer. But of course since the desktop has Windows XP, I don't get any updates.  (Desktop is not used for any financial transactions, or other personal items.)


  • 0

#45
SleepyDude

SleepyDude

    Trusted Helper

  • Malware Removal
  • 4,406 posts

Microsoft Windows Defender is already disabled.  (I checked.)

Its generating some errors...

 

Open the Command Prompt as Administrator and Copy & Paste the following command:

sc config WinDefend start= demand

Respect the spaces exactly as I typed or it will fail. The result must be [SC] ChangeServiceConfig SUCCESS

 

 

I have a CD for Microsoft Office 2007 32 bit, which is what was installed.  I used this on my desktop computer. But of course since the desktop has Windows XP, I don't get any updates.  (Desktop is not used for any financial transactions, or other personal items.)

 

Some program installed Microsoft Access database engine 2010 see if you can repair the install using the Control Panel -> Programs and Features.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP