Kernel Power BSOD event 41 when my computer goes to sleep

Hewlett-packard Pavilion a6030n desktop
April 27, 2015 at 09:26:17
Specs: Windows 7, 6 GB
This happened once or twice about a month ago and now it consistenly happens: Everytime my computer goes to sleep it shuts down. When I turn it back on it says "Windows has recovered from an unexpected shutdown". When I look at the details it says the Problem Signature: Problem Event Name: Blue Screen.
When I look in the Event log it lists
EVENT ID: 41
SOURCE: Kernel-Power
LOG: system

Help please!!! Would love to fix this one my own if possible rather than take it into computer guy. Bear in mind I am not a computer expert... so please "dumb down" your answers :)
Thanks so much


See More: Kernel Power BSOD event 41 when my computer goes to sleep

Report •


#1
April 27, 2015 at 16:45:17

Report •

#2
April 27, 2015 at 16:58:49
But doesn't this just "mask" the problem? I've always had the same setting and it's been fine. Now all of a sudden it shuts down upon sleep. Seems like there's a problem that needs to be fixed?

Report •

#3
April 27, 2015 at 17:08:33
"But doesn't this just "mask" the problem?"
In a way, yes, but we need to isolate the problem.

This gives you an idea of how to find the needle in the haystack.

windows 7 event id 41 kernel-power
https://www.google.com.au/webhp?hl=...


Report •

Related Solutions

#4
April 27, 2015 at 17:59:44
Extract from Microsoft.
"An underpowered or failing power supply may cause this behavior. For example, if you added RAM or additional devices or hard disks when this problem began, the power supply may cause the problem"

Dust is a big enemy of comps.
Take a cover off & clean out the dust, put an external fan on & see if it behaves with the extra cooling. Make sure all the fans ( including the power supply ) are spinning fast, with the power off, give them a spin with a matchstick to make sure they are not stuck.

Information about cleaning computer components
http://www.computerhope.com/cleanin...
http://www.wiscocomputing.com/artic...
http://www.bleepingcomputer.com/tut...
http://pcgyaan.wordpress.com/2009/0...
Getting The Grunge Out Of Your PC, Fred Langa cleans the dirtiest PC he can find, and along the way shows you how you can easily tackle yours. There are 7 pages.
http://www.informationweek.com/news...
Quiet noisy computer fans with a drop of oil
http://www.techrepublic.com/article...
http://www.bleepingcomputer.com/for...


Report •

#5
April 28, 2015 at 08:30:24
I think I solved the problem. I went into my adapter settings in the Control Panel and unchecked the IPv6 box. When the computer went to sleep it did not shut down!
Seems weird though because I've had this box checked for years with no problems and now all of a sudden it crashes my computer?
Does that make sense to you?
also, is there any problem with me having the IPv6 box unchecked??? Wondering if it's one of those "masking the problem" fixes.

Report •

#6
April 28, 2015 at 12:52:05
"Does that make sense to you?"
If it works without issues, you are the only one that will know.

effects of disabling ipv6 windows 7
https://www.google.com.au/?gws_rd=s...

I can go through these logs for you & see if anything gives me a clue.

Please download Farbar Recovery Scan Tool and save it onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
http://www.bleepingcomputer.com/dow...
If we have to run Farbar more than once, refer this SS.
http://i.imgur.com/yUxNw0j.gif
Note: You need to run the version compatible with your system. If you are not sure which version applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.
Double-click to run it. When the tool opens click Yes to disclaimer.
Press Scan button.
It will make a log (FRST.txt) on the Desktop.
The first time the tool is run, it makes also another log (Addition.txt).
The logs are large, upload them using this, or upload to a site of your choosing. No account needed. Give us the links please.
http://www.zippyshare.com/
Instructions on how to use ZippyShare.
http://i.imgur.com/naG6t2T.gif
http://i.imgur.com/Vi9ZdIh.gif
http://i.imgur.com/1IZu5kP.gif


Report •

#7
April 28, 2015 at 12:53:56
Also,

Copy & Paste the dump (.dmp ) file onto your desktop & then upload it using ZippyShare.

Minidump file is located in C:\Windows\Minidump
How to see hidden files in Windows
http://www.bleepingcomputer.com/tut...


Report •

#8
April 28, 2015 at 13:17:39
well, I spoke too soon. it didn't solve the problem :(
thanks for your help Johnw... I will do the above and put it on here within the next couple days.

Report •

#9
April 28, 2015 at 17:27:04
"I will do the above and put it on here within the next couple days"
In the meantime, test the trouble free power settings.

Then if it still fails, we have eliminated one area of possibles.


Report •

#10
April 29, 2015 at 08:39:04
okay...here are the files... hopefully I did this right ;)
http://www65.zippyshare.com/v/vl4Vv...
http://www65.zippyshare.com/v/UWxdy...

I couldn't find the MiniDump file though--it said that folder is empty. I unchecked all the "hide the files", etc....


Report •

#11
April 29, 2015 at 13:34:25
"hopefully I did this right"
Perfect, going through them now.

"I couldn't find the MiniDump file though"
Right click on My Computer and select Properties.
Then select Advanced system settings Tab on the left menu.
Under the Startup and Recovery section, click on Settings.
Make sure "Write an event to the system log" is checked and "Automatically Restart" is unchecked. In the drop down menu under "Write Debugging Information," select Small memory dump (64KB or 128 KB) press OK and OK again.


Report •

#12
April 29, 2015 at 13:52:38
I shall start by dealing with this side of things.

Here are the first 2 steps, there will be more steps needed, after I see the results of these logs.

Run them in this order.

Step 1: Run AdwCleaner
http://www.softpedia.com/get/Antivi...
http://www.raymond.cc/blog/adwclean...
http://www.bleepingcomputer.com/dow...
Author's site
http://general-changelog-team.fr/en...
Tutorial
http://general-changelog-team.fr/en...
Close all open programs and internet browsers.
Double click on AdwCleaner.exe to run the tool.
Click on Clean.
Confirm each time with Ok.
Your computer will be rebooted automatically. A text file will open after the restart.
Please Copy & Paste the contents of that logfile with your next answer.
You can find the logfile at C:\AdwCleaner[S1].txt as well.

Step 2: Run Junkware Removal Tool
http://www.softpedia.com/get/Securi...
http://www.bleepingcomputer.com/dow...
http://thisisudax.org/
http://thisisudax.blogspot.com.au/2...
Download Junkware Removal Tool onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Warning! Once the scan is complete JRT will shut down your browser with NO warning.
Shut down your protection software now to avoid potential conflicts.
Temporarily disable your antivirus and any antispyware real time protection before performing a scan.
Click this link to see a list of security programs that should be disabled and how to disable them.
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Run the tool by double-clicking it. If you are using Windows Vista or Windows 7/8, right-click JRT and select Run as Administrator.
The tool will open and start scanning your system.
Please be patient as this can take a while to complete depending on your system's specifications.
On completion, a log (JRT.txt) is saved onto your Desktop and will automatically open.
Copy and Paste the contents of the JRT.txt log please.


Report •

#13
April 29, 2015 at 18:14:50
Again... hopefully I did this right... here are the files
http://www8.zippyshare.com/v/DoHPSl...
http://www8.zippyshare.com/v/aB8S56...


Mini Dump file: I have all those boxes checked. However, when I go into the directory it says it is the folder is empty


Report •

#14
April 29, 2015 at 18:35:01
"Again... hopefully I did this right... here are the files"
Perfect again.

"Mini Dump file: I have all those boxes checked. However, when I go into the directory it says it is the folder is empty"
No problem, we probably will not need it, I would say we are now on track to dismantle the nasties step by step.

Download ComboFix onto your Desktop & then run. If your default download location is not the Desktop, drag it out of it's location onto the Desktop. Copy & Paste the contents of the log in your next post please. ComboFix's log should be located at C:\COMBOFIX.TXT.
The logs are large, upload them using this, or upload to a site of your choosing. No account needed. Give us the links please.
http://www.zippyshare.com/
Instructions on how to use ZippyShare.
http://i.imgur.com/naG6t2T.gif
http://i.imgur.com/Vi9ZdIh.gif
http://i.imgur.com/1IZu5kP.gif
http://www.bleepingcomputer.com/dow...
http://download.bleepingcomputer.co...
http://www.forospyware.com/sUBs/Com...
A guide and tutorial on using ComboFix
http://www.bleepingcomputer.com/com...
http://www.winhelp.us/index.php/gen...
Manually restoring the Internet connection
http://www.bleepingcomputer.com/com...
There are circumstances ComboFix will hang, crash or stall at various stages due to malware interference, failure to disable other real-time protection tools or the presence of CD Emulators (Daemon Tools, Alchohol 120%, Astroburn, AnyDVD) so that it does not complete successfully. Also, depending on how badly a system is infected, ComboFix may take longer to complete its routine than it normally does or fail to run properly. While that is not normal behavior, it is not unusual"
If you think it's frozen, look at the computer clock.
If it's running, Combofix is still working.
NOTE: Do not mouseclick combofix's window while it is running. That may cause it to stall.
NOTE: ComboFix will check to see if the Microsoft Windows Recovery Console is installed.
***It's strongly recommended to have the Recovery Console installed before doing any malware removal.***
**Please Note: If the Microsoft Windows Recovery Console is already installed, ComboFix will automatically proceed with its scan.
The Recovery Console provides a recovery/repair mode should a problem occur during a Combofix run.
Allow ComboFix to download the Recovery Console.
Accept the End-User License Agreement.
The Recovery Console will be installed.
You will then get this next prompt that asks if you want to continue the malware scan, select yes.
If after running Combofix you discover none of your programs will open up, and you recieve the following error: "Illegal operation attempted on a registry key that has been marked for deletion". Then the answer is to REBOOT the machine, and all will be corrected.
Can't Install an Antivirus - Windows Security Center still detects previous AV
http://www.experts-exchange.com/Vir...
We are almost ready to start ComboFix, but before we do so, we need to take some preventative measures so that there are no conflicts with other programs when running ComboFix. At this point you should do the following:
* Close all open Windows including this one.
* Close or disable all running Antivirus, Antispyware, and Firewall programs as they may interfere with the proper running of ComboFix. Instructions on disabling these type of programs can be found in this topic.
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Once these two steps have been completed, double-click on the ComboFix icon found on your Desktop.
Please Note: Once you start ComboFix you should not click anywhere on the ComboFix window as it can cause the program to stall. In fact, when ComboFix is running, do not touch your computer at all. The scan could take a while, so please be patient.


Report •

#15
April 30, 2015 at 06:53:44
I'm not comfortable doing that ComboFix one. I read a bit about it online and it sounds like you could really mess up your computer if you do something wrong... and since I'm not a computer expert by any means.
My computer seems to be okay now... yesterday it went into sleep mode everytime without shutting down. I had cleaned out all the dust and updated drivers... not sure if that has anything to do with it??
I'm curious though... did you find anything "bad" in the files I sent you??

Report •

#16
April 30, 2015 at 15:16:09
"I'm curious though... did you find anything "bad" in the files I sent you??"
Everything those programs removed was bad.

Malware is like cancer, you have to remove it all.

You are not yet clean.

Run ESET Online Scanner, Copy and Paste the contents of the log in your reply please. This scan may take a very long while, so please be patient. Maybe start it before going to work or bed.
http://www.eset.com/us/online-scann...
http://www.eset.com/home/products/o...
If your comp is unbootable, or won't let you download, you will have to download ESET from a good computer, put it on a flash/thumb/pen/usb drive & run it from there.
Create a ESET SysRescue CD or USB drive
http://kb.eset.com/esetkb/index?pag...
How do I use my ESET SysRescue CD or USB flash drive to scan and clean my system?
http://kb.eset.com/esetkb/index?pag...
Configure ESET this way & disable your AV.
http://i.imgur.com/3U7YC.gif
How to Temporarily Disable your Anti-virus
http://www.bleepingcomputer.com/for...
http://www.techsupportforum.com/for...
Which web browsers are compatible with ESET Online Scanner?
http://www.nod32.fi/eset-online-sca...
http://kb.eset.com/esetkb/index?pag...
Online Scanner not working
http://kb.eset.com/esetkb/index?pag...
My ESET product detected a threat—what should I do?
http://kb.eset.com/esetkb/index?pag...
Why Would I Ever Need an Online Virus Scanner? I already have an antivirus program installed, isn't that enough?
http://www.squidoo.com/the-best-fre...
Once onto a machine, malware can disable antivirus programs, prevent antimalware programs from downloading updates, or prevent a user from running antivirus scans or installing new antivirus software or malware removal tools. At this point even though you are aware the computer is infected, removal is very difficult.
5: Why does the ESET Online Scanner run slowly on my computer?
If you have other antivirus, antispyware or anti-malware programs running on your computer, they may intercept the scan being performed by the ESET Online Scanner and hinder performance. You may wish to disable the real-time protection components of your other security software before running the ESET Online Scanner. Remember to turn them back on after you are finished.
17: How can I view the log file from ESET Online Scanner?
http://kb.eset.com/esetkb/index?pag...
http://www.eset.com/home/products/o...
The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is "C:\Program Files\EsetOnlineScanner\log.txt". You can view this file by navigating to the directory and double-clicking on it in Windows Explorer, or by copying and pasting the path specification above (including the quotation marks) into the Start ? Run dialog box from the Start Menu on the Desktop.
If no threats are found, you will simply see an information window that no threats were found.
http://www.trishtech.com/security/s...


Report •

#17
May 1, 2015 at 09:23:47
I ran the eset scanner but it didn't save anything to my computer. when it was done it said there were 7 infected and cleaned files. nothing saved though?

Report •

#18
May 1, 2015 at 14:12:53
"7 infected and cleaned files. nothing saved though?"

Are you really sure?
Double check for me please.

From my post #16.
"The ESET Online Scanner saves a log file after running, which can be examined or sent in to ESET for further analysis. The path to the log file is "C:\Program Files\EsetOnlineScanner\log.txt". You can view this file by navigating to the directory and double-clicking on it in Windows Explorer, or by copying and pasting the path specification above (including the quotation marks) into the Start ? Run dialog box from the Start Menu on the Desktop"


Report •

#19
May 1, 2015 at 15:44:16
I can't even find an EsetOnlineScanner directory. I've done a search for that file and directory and nothing comes up. yet when I go into my control panel, it is listed under all the programs but all the info is blank (i.e., date installed, size of program.)

Report •

#20
May 1, 2015 at 15:55:32
"I can't even find an EsetOnlineScanner directory"
Weird.
Keep ESET in your toolbox, if you need to run it again on any comp, it will update itself before scanning.

I see you have Malwarebytes installed, update & then run. Post the log please.


Report •

#21
May 1, 2015 at 16:53:44
Found the ESET File. It was in the Programs(86x) directory... this is all that was in the log.txt

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK

Malware log:
Malwarebytes Anti-Malware
www.malwarebytes.org

Scan Date: 5/1/2015
Scan Time: 4:13:23 PM
Logfile: mw.txt
Administrator: Yes

Version: 2.00.4.1028
Malware Database: v2015.05.01.07
Rootkit Database: v2015.04.21.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Self-protection: Disabled

OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Julie

Scan Type: Threat Scan
Result: Completed
Objects Scanned: 345497
Time Elapsed: 9 min, 33 sec

Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Disabled
Heuristics: Enabled
PUP: Warn
PUM: Enabled

Processes: 0
(No malicious items detected)

Modules: 0
(No malicious items detected)

Registry Keys: 2
PUP.Optional.Mindspark.A, HKLM\SOFTWARE\WOW6432NODE\InternetSpeedTracker_9t, Quarantined, [8dee4747ff8b76c08bfbe9600401ad53],
PUP.Optional.Mindspark.A, HKU\S-1-5-21-613391319-1381275329-1498010347-1000-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\APPDATALOW\SOFTWARE\InternetSpeedTracker_9t, Quarantined, [106b523ca4e6ca6c8e60a25eb0543bc5],

Registry Values: 0
(No malicious items detected)

Registry Data: 0
(No malicious items detected)

Folders: 0
(No malicious items detected)

Files: 0
(No malicious items detected)

Physical Sectors: 0
(No malicious items detected)


(end)


Report •

#22
May 1, 2015 at 16:57:26
Good one teacket, they are the ones I wanted to get rid of.

Download the latest version and save it onto your Desktop. If your default download location is not the Desktop, drag it out of it's location onto the Desktop.
Run Farbar again please, follow this SS & upload the 2 new logs.
http://i.imgur.com/i3fg3Pf.gif


Report •

#23
Report •

#24
May 2, 2015 at 14:32:02
I'm online teacket, give me about 15 mins.

Report •

#25
May 2, 2015 at 14:53:31
Copy & Paste the text below ( starting closeprocesses: ), save it into Notepad on your Desktop & name it fixlist.txt
NOTE: It is important that Notepad is used. The fix will not work if Word or some other program is used.
NOTE: It is important that both files, FRST/FRST64 and fixlist.txt are in the same location or the fix will not work.
NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system.

closeprocesses:
emptytemp:
Internet Speed Tracker Internet Explorer Toolbar (HKLM-x32\...\InternetSpeedTracker_9tbar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-613391319-1381275329-1498010347-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Julie\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-21-613391319-1381275329-1498010347-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
SearchScopes: HKLM -> {223AD165-F79C-4874-BBF4-B27176E02BE8} URL = http://www.amazon.com/s/ref=azs_osd...
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-3...
SearchScopes: HKLM-x32 -> {223AD165-F79C-4874-BBF4-B27176E02BE8} URL = http://www.amazon.com/s/ref=azs_osd...
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Specia...
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-3...
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-613391319-1381275329-1498010347-1000 -> {223AD165-F79C-4874-BBF4-B27176E02BE8} URL = http://www.amazon.com/s/ref=azs_osd...
SearchScopes: HKU\S-1-5-21-613391319-1381275329-1498010347-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-3...
BHO: BlspcHlpr Class -> {15C9938F-CB96-496D-800A-B827F2E34EA1} -> C:\Program Files\ATT Internet Tools\amd64\blspc_x64.dll No File
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: No Name -> {15C9938F-CB96-496D-800A-B827F2E34EA1} -> No File
BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
BHO-x32: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
Toolbar: HKU\S-1-5-21-613391319-1381275329-1498010347-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
CHR HomePage: Default -> hxxp://www.foxnews.com/
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\pdf.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
U0 SR; No ImagePath
U2 srservice; No ImagePath

Run FRST/FRST64 and press the Fix button just once and wait.
If for some reason the tool needs a restart, please make sure you let the system restart normally. After that, let the tool complete its run.
When finished FRST will generate a log on the Desktop (Fixlog.txt). Please Copy & Paste the contents into your reply.


Report •

#26
May 2, 2015 at 14:58:31
Two questions...
What is this going to do to my computer? Is this going to fix the shutting down at Sleep Mode???
Where does the copy & paste end ... the 0 right before SearchScopes???

Report •

#27
May 2, 2015 at 15:11:25
Start > closeprocesses:

Finish > U2 srservice; No ImagePath

"What is this going to do to my computer? Is this going to fix the shutting down at Sleep Mode???"
Time will tell, the bugs have to be removed as a first step.

message edited by Johnw


Report •

#28
May 2, 2015 at 15:43:48
Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 29-04-2015
Ran by Julie at 2015-05-02 15:38:15 Run:1
Running from C:\Users\Julie\Desktop
Loaded Profiles: Julie (Available profiles: Julie)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
closeprocesses:
emptytemp:
Internet Speed Tracker Internet Explorer Toolbar (HKLM-x32\...\InternetSpeedTracker_9tbar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION
CustomCLSID: HKU\S-1-5-21-613391319-1381275329-1498010347-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}\localserver32 -> C:\Users\Julie\AppData\Roaming\Dropbox\bin\Dropbox.exe /autoplay No File
HKU\.DEFAULT\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-19\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-20\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKU\S-1-5-21-613391319-1381275329-1498010347-1000\Software\Classes\exefile: "%1" %* <===== ATTENTION!
HKLM\...\Policies\Explorer: [NoFolderOptions] 0
SearchScopes: HKLM -> {223AD165-F79C-4874-BBF4-B27176E02BE8} URL = http://www.amazon.com/s/ref=azs_osd...
SearchScopes: HKLM -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-3...
SearchScopes: HKLM-x32 -> {223AD165-F79C-4874-BBF4-B27176E02BE8} URL = http://www.amazon.com/s/ref=azs_osd...
SearchScopes: HKLM-x32 -> {d43b3890-80c7-4010-a95d-1e77b5924dc3} URL = http://en.wikipedia.org/wiki/Specia...
SearchScopes: HKLM-x32 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-3...
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-613391319-1381275329-1498010347-1000 -> {223AD165-F79C-4874-BBF4-B27176E02BE8} URL = http://www.amazon.com/s/ref=azs_osd...
SearchScopes: HKU\S-1-5-21-613391319-1381275329-1498010347-1000 -> {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = http://rover.ebay.com/rover/1/711-3...
BHO: BlspcHlpr Class -> {15C9938F-CB96-496D-800A-B827F2E34EA1} -> C:\Program Files\ATT Internet Tools\amd64\blspc_x64.dll No File
BHO-x32: HP Print Enhancer -> {0347C33E-8762-4905-BF09-768834316C61} -> C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll [2009-05-21] (Hewlett-Packard Co.)
BHO-x32: No Name -> {15C9938F-CB96-496D-800A-B827F2E34EA1} -> No File
BHO-x32: No Name -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> No File
BHO-x32: Skype Browser Helper -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
BHO-x32: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> No File
Toolbar: HKU\S-1-5-21-613391319-1381275329-1498010347-1000 -> No Name - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll [2012-01-17] (Skype Technologies S.A.)
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
CHR HomePage: Default -> hxxp://www.foxnews.com/
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\pdf.dll No File
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U37) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll No File
U0 SR; No ImagePath
U2 srservice; No ImagePath
*****************

Processes closed successfully.
Internet Speed Tracker Internet Explorer Toolbar (HKLM-x32\...\InternetSpeedTracker_9tbar Uninstall Internet Explorer) (Version: - Mindspark Interactive Network) <==== ATTENTION => Error: No automatic fix found for this entry.
"HKU\S-1-5-21-613391319-1381275329-1498010347-1000_Classes\CLSID\{005A3A96-BAC4-4B0A-94EA-C0CE100EA736}" => Key deleted successfully.
"HKU\.DEFAULT\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-19\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-20\Software\Classes\exefile" => Key deleted successfully.
"HKU\S-1-5-21-613391319-1381275329-1498010347-1000\Software\Classes\exefile" => Key deleted successfully.
HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\\NoFolderOptions => value deleted successfully.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{223AD165-F79C-4874-BBF4-B27176E02BE8}" => Key deleted successfully.
HKCR\CLSID\{223AD165-F79C-4874-BBF4-B27176E02BE8} => Key not found.
"HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Key deleted successfully.
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{223AD165-F79C-4874-BBF4-B27176E02BE8}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{223AD165-F79C-4874-BBF4-B27176E02BE8} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Key not found.
HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope => value deleted successfully.
"HKU\S-1-5-21-613391319-1381275329-1498010347-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{223AD165-F79C-4874-BBF4-B27176E02BE8}" => Key deleted successfully.
HKCR\CLSID\{223AD165-F79C-4874-BBF4-B27176E02BE8} => Key not found.
"HKU\S-1-5-21-613391319-1381275329-1498010347-1000\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}" => Key deleted successfully.
HKCR\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC} => Key not found.
"HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15C9938F-CB96-496D-800A-B827F2E34EA1}" => Key deleted successfully.
"HKCR\CLSID\{15C9938F-CB96-496D-800A-B827F2E34EA1}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0347C33E-8762-4905-BF09-768834316C61}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{0347C33E-8762-4905-BF09-768834316C61}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{15C9938F-CB96-496D-800A-B827F2E34EA1}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{15C9938F-CB96-496D-800A-B827F2E34EA1} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{761497BB-D6F0-462C-B6EB-D4DAF1D92D43} => Key not found.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}" => Key deleted successfully.
HKCR\Wow6432Node\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9} => Key not found.
HKU\S-1-5-21-613391319-1381275329-1498010347-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => value deleted successfully.
HKCR\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} => Key not found.
"HKCR\Wow6432Node\PROTOCOLS\Handler\skype-ie-addon-data" => Key deleted successfully.
"HKCR\Wow6432Node\CLSID\{91774881-D725-4E58-B298-07617B9B86A8}" => Key deleted successfully.
"HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
"HKLM\Software\Wow6432Node\MozillaPlugins\@microsoft.com/GENUINE" => Key deleted successfully.
Chrome HomePage deleted successfully.
C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\ppGoogleNaClPluginChrome.dll not found.
C:\Program Files (x86)\Google\Chrome\Application\42.0.2311.90\pdf.dll not found.
C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll not found.
C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll not found.
c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll not found.
SR => Service deleted successfully.
srservice => Service deleted successfully.
EmptyTemp: => Removed 196.7 MB temporary data.


The system needed a reboot.

==== End of Fixlog 15:38:55 ====


Report •

#29
May 2, 2015 at 15:49:33
Very good, now it is testing time.

Report •

#30
May 2, 2015 at 16:23:31
If you want me to run some tests... you're gonna have to be more explicit... :)

Report •

#31
May 2, 2015 at 17:46:34
"If you want me to run some tests... you're gonna have to be more explicit... :)"

"Is this going to fix the shutting down at Sleep Mode???"


Report •

#32
May 2, 2015 at 19:36:34
The latest thing that has happened is when my computer goes into sleep mode it doesn't shut down. It kind of goes into a non-responsive state. Monitor goes black. But I cant see it is still on... but the light doesn't turn orange like when when it goes into sleep. And then when it I move the mouse, it doesn't wake up at all. So I have to shut down the computer and turn it back on.

Report •

#33
May 2, 2015 at 23:40:34
The comp appears to be clean of malware, it now could be anything.
Power supply, CPU, memory, motherboard etc, etc.

Report •

#34
May 3, 2015 at 08:26:22
okay... I guess i'll just put power settings on computer never going to sleep. other than that the computer works fine.
thanks so much John for all your help... I appreciate the time you put into getting my computer clean of malware & helping me narrow down reasons for my computer problems!

Report •


Ask Question