Got rid of McAfee.... sort of

Flooring Forum

Help Support Flooring Forum:

This site may earn a commission from merchant affiliate links, including eBay, Amazon, and others.
Here's OTL
All processes killed
========== OTL ==========
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

User: Randy
->Temp folder emptied: 98854612 bytes
->Temporary Internet Files folder emptied: 101867 bytes
->FireFox cache emptied: 375307535 bytes
->Flash cache emptied: 1006 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 22413129 bytes
RecycleBin emptied: 1036382 bytes

Total Files Cleaned = 475.00 mb


[EMPTYFLASH]

User: All Users

User: Default

User: Default User

User: Public

User: Randy
->Flash cache emptied: 0 bytes

Total Flash Files Cleaned = 0.00 mb


[EMPTYJAVA]

User: All Users

User: Default

User: Default User

User: Public

User: Randy

Total Java Files Cleaned = 0.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 07282017_223725

Files\Folders moved on Reboot...
C:\Users\Randy\AppData\Local\Microsoft\Windows\INetCache\counters.dat moved successfully.
File move failed. C:\windows\temp\_avast_\AvLock.txt scheduled to be moved on reboot.
File\Folder C:\windows\temp\_avast_\nsfsp0000000C.tmp not found!
C:\windows\temp\LAPTOP-1ARSTH9B-20170728-0020.log moved successfully.
File\Folder C:\windows\temp\officeclicktorun.exe_streamserver(201707280020244A0).log not found!

PendingFileRenameOperations files...

Registry entries deleted on Reboot...
 
After reboot, I believe........ Two additional notepad items appeared:


[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21799

and:


[.ShellClassInfo]
LocalizedResourceName=@%SystemRoot%\system32\shell32.dll,-21769
IconResource=%SystemRoot%\system32\imageres.dll,-183
 
How is it running now ?

Try running JRT To remove those last two files if they are there . [ Junk File Remover].

https://www.google.com/url?q=http:/...ds-cse&usg=AFQjCNHRNd33dPrs-cHoNHpoRrPrc0h7gg

Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.
 
How is it running now ?

Try running JRT To remove those last two files if they are there . [ Junk File Remover].

https://www.google.com/url?q=http:/...ds-cse&usg=AFQjCNHRNd33dPrs-cHoNHpoRrPrc0h7gg

Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
Post the contents of JRT.txt into your next message.
I haven't really used the HP for anything yet. I'v just been getting it ready to use. I still use my PC 99.99% of the time. All I've done with this HP notebook is load Avast, REVO, IrfanView Malwarebytes, Hijack This and Superantispyware.
The problems appear from removing McAfee. I must have done something wrong deleting it's remnants.
Now the left click doesn't work on the start icon. Also, the connection icon moved into the hidden icon location on the task bar, but I drug it back down.
I think it would be simpler to restore the computer to its original condition and just start over.
I bough notebook this as a backup for my PC, not something to use on a regular basis unless the PC croaks.
 
I hadn't removed OTL yet, so I started it back up and removed it......... those two files I showed are gone now too.
Hi ho, hi ho.......... Customer is gone for the weekend, so I'm gonna go move appliances and put some floor down so I get em back in place by Monday morning when he gets home. I'm not doing anything more today on the notebook.
Maybe tonight when I get back.
 
Those two lines of code came from running it through the CMD Line ..

If you ever want to remove cleaning software ,

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download 51a5ce45263de-delfix.pngDelFix by Xplode to your desktop. http://redirect.viglink.com/?format...<strong class="bbc">DelFix by Xplode</strong>

Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:

Activate UAC (optional; some users prefer to keep it off)
Remove disinfection tools
Create registry backup
Purge System Restore
Reset system settings


Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.
 
Those two lines of code came from running it through the CMD Line ..

If you ever want to remove cleaning software ,

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download 51a5ce45263de-delfix.pngDelFix by Xplode to your desktop. http://redirect.viglink.com/?format...<strong class="bbc">DelFix by Xplode</strong>

Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:

Activate UAC (optional; some users prefer to keep it off)
Remove disinfection tools
Create registry backup
Purge System Restore
Reset system settings


Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.
I realized shortly after buying the notebook that the operating system and installed HP crap takes up 80% of the tiny HD. OK, really 21.7 used and 6.12 free. If you set a restore point you lose a lot of space. I do have one set now by OTL.
I'm guessing that's why this notebook came with the restore point turned off. :rolleyes:
 
Last edited:
Maybe this will help. Event viewer.These are just the past 48 hours.
What's going berzerk?

70517.jpg
 
Event ID 5973 :
Open Run (Windows Key + R) and type it Regedit
Navigate to HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData
Right click, select Permissions and then add "ALL APPLICATION PACKAGES" to the "Group or user names" box and give full control to the registry key above.

Event 10010:

1. Open Regedit
2. Go to HKEY_Classes_Root\CLSID\{C2F03A33-21F5-47FA-B4BB-156362A2F239}
3. Right click on it then select permissions
4. Click Advance and change the owner to Administrators group. Also click the box that will appear below the owner line. ("Replace owner ...")
5. Apply full control

6. Go to HKEY_LocalMachine\Software\Classes\AppID\{316CDED5-E4AE-4B15-9113-7055D84DCC97}
7. Right click on it then select permission
8. Click Advance and change the owner to Administrators group
9. Click the box that will appear below the owner line
10. Click Apply and grant full control to the Administrators group

11. Go to Administrative tools
12. Open component services
13. Click Computer, click my computer, then click DCOM
14. Look for the corresponding service that appears on the error viewer [Immersive Shell]
15. Right click on it then click properties
16. Click security tab then click Add User. Add Local Service then apply
17. Tick the Activate local box
 
Event ID 5973 :
Open Run (Windows Key + R) and type it Regedit
Navigate to HKEY_CURRENT_USER\Software\Classes\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData
Right click, select Permissions and then add "ALL APPLICATION PACKAGES" to the "Group or user names" box and give full control to the registry key above.

Event 10010:

1. Open Regedit
2. Go to HKEY_Classes_Root\CLSID\{C2F03A33-21F5-47FA-B4BB-156362A2F239}
3. Right click on it then select permissions
4. Click Advance and change the owner to Administrators group. Also click the box that will appear below the owner line. ("Replace owner ...")
5. Apply full control

6. Go to HKEY_LocalMachine\Software\Classes\AppID\{316CDED5-E4AE-4B15-9113-7055D84DCC97}
7. Right click on it then select permission
8. Click Advance and change the owner to Administrators group
9. Click the box that will appear below the owner line
10. Click Apply and grant full control to the Administrators group

11. Go to Administrative tools
12. Open component services
13. Click Computer, click my computer, then click DCOM
14. Look for the corresponding service that appears on the error viewer [Immersive Shell]
15. Right click on it then click properties
16. Click security tab then click Add User. Add Local Service then apply
17. Tick the Activate local box

I'm working today, so not going to go there yet.
How do I delete event viewer errors list so I can start from scratch? It's added up over 17,000 errors since i turned the confuzer on 15 minutes ago.
....... all of them are those same event ID numbers, so I'm now past 103,000 errors in the past week, 87,000+ in the past 24 hours. :rolleyes:
 
I been investigatin'
Here's when the errors all started..... During an Upgrade. I tried to shut down the confuzer and it didn't want to........ then the screen came up with "installing upgrade, do not turn computer off........... so I waited and waited. It finally completed but stopped completing at some point so I restarted it and it finished.
........I recall it was around 12AM when I went to bed, and that's the time of the "Upgrade" (looks like downgrade to me)
Check the times and how they coincide with the start of the errors.
Here are the starting time of the errors.
The time and dates of the upgrade files.
Then, what's inside the Upgrade Folder.
Hope this helps.
Maybe I can undo the upgrade?
I gotta go.

The start of event viewer errors mwsnap.jpg


W10 upgrade date and time.jpg


W10 upgrade files and dlls.jpg
 

Latest posts

Back
Top