Inactive "Updater has stopped working" ... Continuous Popup

Windows Repair finally finished at 3 am ... 7 hours. I had to stay up because of numerous restarts requiring my passwords.

I'm not even trying anything, just happy to have my computer back.

At first glance though, it seems to be a little slow, but that could just be me being a little quick because of all the coffee I drank.

I'll report back Sunday when I get up.

Dennis
 
Hi Broni,

I've had a few hours to play around. Man ... that process took forever!

Here's a few observations, then a couple of questions:

For some reason, the slowness/sluggishness I reported in my last has disappeared and the computer is performing nicely.

The permission problems for that ABC folder and XYZ file are STILL present. I think I have to read up on permissions and just learn how to deal with problems as they surface. The problem doesn't come up that often ... it's just frustrating when it occurs.

Shortcuts icons (on desktop and in folders) have lost the customized icons
- just a blank white document & arrow now (annoying, but I'll customize later)
- some desktop shortcuts have lost their target locations (again, annoying, but I'll get the targets back)

Desktop lost the background picture but I re-established it.

================

QUESTIONS

Can Windows Defender, MSE, and Windows Firewall all be running at the same time?
I don't understand why some security programs conflict with others.


I know we did a lot of stuff, especially with all the logs we produced in the first days. Can you summarize why we had to do that and the info you got from them?

Dennis
 
Shortcuts icons (on desktop and in folders) have lost the customized icons
- just a blank white document & arrow now (annoying, but I'll customize later)
- some desktop shortcuts have lost their target locations (again, annoying, but I'll get the targets back)

Desktop lost the background picture but I re-established it.
Repair installation will do that.

Can Windows Defender, MSE, and Windows Firewall all be running at the same time?
Yes. The only exception is Windows 8 where Windows Defender is just renamed MSE.
Before Windows 8 Windows Defender is more of an antimalware program not an AV program.
Be aware that it's more or less useless and it can be safely disabled.
MBAM is the tool you want to use.

I know we did a lot of stuff, especially with all the logs we produced in the first days. Can you summarize why we had to do that and the info you got from them?
We ran different tools since they're looking for different things.

For now...

Your computer is clean

1. This step will remove all cleaning tools we used, it'll reset restore points (so you won't get reinfected by accidentally using some older restore point) and it'll make some other minor adjustments...
This is a very crucial step so make sure you don't skip it.
Download
51a5ce45263de-delfix.png
DelFix by Xplode to your desktop. Delfix will delete all the used tools and logfiles.

Double-click Delfix.exe to start the tool.
Make sure the following items are checked:
  • Activate UAC (optional; some users prefer to keep it off)
  • Remove disinfection tools
  • Create registry backup
  • Purge System Restore
  • Reset system settings
Now click "Run" and wait patiently.
Once finished a logfile will be created. You don't have to attach it to your next reply.

2. Make sure Windows Updates are current.

3. If any trojans, rootkits or bootkits were listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

4. Check if your browser plugins are up to date.
Firefox - https://www.mozilla.org/en-US/plugincheck/
other browsers: https://browsercheck.qualys.com/ (click on "Launch a quick scan now" link)

5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

7. Run Temporary File Cleaner (TFC), AdwCleaner and Junkware Removal Tool (JRT) weekly (you need to redownload these tools since they were removed by DelFix).

8. Download and install Secunia Personal Software Inspector (PSI): https://www.techspot.com/downloads/4898-secunia-personal-software-inspector-psi.html. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

10. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

11. Read:
How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html
Simple and easy ways to keep your computer safe and secure on the Internet: http://www.bleepingcomputer.com/tutorials/keep-your-computer-safe-online/
About those Toolbars and Add-ons - Potentially Unwanted Programs (PUPs) which change your browser settings: http://www.bleepingcomputer.com/for...curity-questions-best-practices/#entry3187642

12. Please, let me know, how your computer is doing.

When done....

I still want to investigate permission issue.
Create new administrator account and see if it has same issue.
Profiles do get corrupted.
 
Okay, thanks for your reply.

I have to go out for an hour or two so I'll get on these new instructions as soon as I get back. We did these steps before (for example, Secunia is still resident on my computer). Do we have to do them again?

You're my hero !!!!!!!
 
Tuesday, Aug 12 -- 7:30 pm ish

Hi Broni,

Well, things are not doing well with this machine. I've listed some issues below. This was a Notepad file I kept adding to so please don't think badly of me for it being so long. I'm sure you will just skim over stuff that you find unimportant.

-------------------------------
I've been getting this error message about once a week since forever:

Error message:

Web Browser

Stop running this script?

A script on this page is causing your web browser to run slowly.
If it continues to run, your computer might become unresponsive.

Yes No

I clicked 'Yes'


What the heck is this? It keeps coming up every week or so.

-------------------------------

I had a Windows Update notification


105 important updates
and
About 45 optional updates


IMPORTANT

About 20 of these:
Security Update for MS.NET Framework 3.5.1 on W7 and Windows Server 2008 R2 for x64 based Systems (KB2832414)

About 85 of these:
Security Update for Windows 7 for x64-based Systems (KB2479943)

1 of this:
Windows Malicious Software Removal Tool x64 - July 2014 (KB890830)

-----------------

OPTIONAL UPDATES

1 of this:
Platform Update for Windows 7 x64-Edition (KB2670838)

1 of this:
Update for Kernel-Mode Driver Framework version 1.11 for Windows 7 for x64-based Systems (KB2685811)

1 of this:
Update for User-Mode Driver Framework version 1.11 for Windows 7 for x64-based Systems (KB2685813)

About 40 of these
Update for Windows 7 for x64-based Systems (KB2928562)


I installed the important ones and accidently installed the optional ones.

Why were there so many?

-------------------------------

I have uninstalled Malwarebytes, then downloaded it again ... for 2 reasons:

1. To make sure I had the latest version.
2. Because a lot of the pretty icons disappeared and I wanted a new Malware icon in the folder where I keep those kinds of programs

As soon as I tried to move the proper MalwareBYtes icon from desktop into my Security folder, the icon changed from the proper Malware icon to that blank document folder thing.

I tried to move it back to the desktop and I got the permission error message again, and couldn't move it. That permission problem is happening in lots of places on my computer now.


I can't activate any shortcut in my security folder that has this blank notepad type icon. Double clicking does absolutely nothing. Right clicking gives the drop down menu, but the "Take Ownership" option we put into that menu a few days ago is NOT present.

-------------------------------

I ran Qualys Browser scanner Tuesday morning ...

First, you have to know that for most of these maintenance type programs you suggested I run once a week, I copied the URL and made a shortcut in the [Security and Firewalls] folder I have on my desktop.

The shortcut is there, but with planet Earth as the icon. When I double click on the icon, I get the following error message:

------------------------
Problem with Shortcut

The target "" of this Internet Shortcut is not valid. Go to the Internet Shortcut property sheet and make sure the target is correct.

OK button
------------------------

Once on the properties sheet, I see the following list in the "Group or user names:" window:

SYSTEM
Administrators (Dennis-PC\Administrators) ----- note the extra "s" at the end of "Administrators".
Account Unknown(S-1-5-5-0-278455)

The SYSTEM one is highlighted in grey.


In the "Permissions for SYSTEM window, all checkboxes are checked under 'Allow'. except 'Special permissions'.

---------------------------------------

Basic Qualys Scan Result:

message:
Congratulations! You passed Qualys BrowserCheck.
We recommend you scan your browser regularly to stay up to date with the latest versions and plugins.


All these were up to date:

Google Chrome
Adobe Flash Player
Adobe Reader
Apple Quicktime
Java Runtime
Silverlight
VLC Media Player


Windows Media Player
- disabled (why ???)


-------------

Intermediate Qualys Scan Result:


detected browsers:
Google Chrome (green checkmark)
Internet Explorer (red X)


The intermediate scan wanted me to download this and run it (I did):


Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB2962872)


I re-scanned

message:
Although there were no critical issues detected, we recommend you install the latest updates. See the results below for details.

detected browsers:
Google Chrome (green checkmark)
Internet Explorer (green checkmark)


Silverlight
Apple Quicktime
Abode Reader
Java Runtime
Windows Media Player
VLC Media Player
Abode Flash Player
Google Chrome


All above listed as Up to Date

***
I stopped using Internet Explorer a long time ago and didn't really want to install it, but I figured why not have it. There have have been times in the past when I couldn't do something without it, so I just did without. Now that I installed it, I thought, "Why not just get the latest version, so I installed Internet Explorer 11 with all the required updates. I think that was a mistake after reading up on it.

-------------

Advanced Qualys Scan Result:


message:
Scan start time: Tue Aug 12 2014, 12:31 PM
Scan duration: 02:46 (mm:ss)
8 Security Issues Detected
Follow the recommended actions in the results below to get software updates and resolve security issues.

There was a new tab (in red): MS Updates



detected browsers:
Google Chrome (green checkmark)
Internet Explorer (green checkmark)


Silverlight
Apple Quicktime
Abode Reader
Java Runtime
Windows Media Player
VLC Media Player
Abode Flash Player
Google Chrome


All above listed as Up to Date


I downloaded the updates.


-------------------------------

By now, I've learned the 5-7 steps I need to take to change the permissions to: Dennis DENNIS-PC
That process allows me to use the shortcur or file normally.

That process also brings back the icon picture as it should be.


Here are the steps I take to change permission:

Double click shortcut icon


[error message]

Target is not valid. --> OK (error msg box disappears)
or

Right click shortcut icon --> delete



[error message]

File Access Denied

You need permission to perform this action.

You require permission from Dennis-PC\Dennis to make changes to this file

Try Again Cancel




Right click --> properties --> 'security' tab --> 'edit' button
--> 'add' button --> 'advanced' button --> 'find now' button
--> select 'Dennis DENNIS-PC' from the list at the bottom
--> OK --> OK (click the Full Control checkbox)
--> OK --> OK

After I complete these steps, PROPERTIES BOX DISAPPEARS and shortcut becomes active and target is valid



-------------------------------

There is a long list of names in the [Select Users or Groups] box ...


Right click on a shortcut --> properties --> Security tab
--> Continue button --> Add button --> Advanced button
--> Find Now button --> this gives 'Search Results window where these names are:



Name (RDN) In Folder


Administrator DENNIS-PC
Administrators DENNIS-PC
ANONYMOUS LOGON
Authenticated Users
BATCH
CONSOLE LOGON
CREATOR GROUP
CREATOR OWNER
Dennis DENNIS-PC
DIALUP
Distributed COM Users DENNIS-PC
Event Log Readers DENNIS-PC
Everyone
Guest DENNIS-PC
Guests DENNIS-PC
Home Users DENNIS-PC
IIS_IUSRS DENNIS-PC
INTERACTIVE
IUSR
July14-2014 DENNIS-PC
Local account
Local account and member of Administrators group
LOCAL SERVICE
NETWORK
NETWORK SERVICE
OWNER RIGHTS
Performance Log Users DENNIS-PC
Performance Monitor Users DENNIS-PC
REMOTE INTERACTIVE LOGON
SERVICE
SYSTEM
TERMINAL SERVICE USER
This Organization Certificate
Users DENNIS-PC
 
What the heck is this? It keeps coming up every week or so.
That happens. It's an issue with a webpage not your computer.

Why were there so many?
It's normal after repair installation. Some updates have to be reinstalled.

Then you were supposed to create new admin account and see if those permission issues are there as well.
 
Okay, I must be really stupid!

I created the new user account -- DFA -- as administrator type account. I switched user to DFA.

There were only a few icons there (recycle bin, Google Earth, ...) and no clear way to connect to the internet ...

- no Google Chrome
- no hotmail
- no way!

I tried the Google Earth and I got there hoping to find a tab for a new Google window, but there was no tab.

Besides that, there didn't seem to be any way for me to create a website shortcut.

When I right clicked the desktop --> new --> shortcut

I typed Google.ca

an error message said computer could not find that.

I switched users back to my old admin acct to send this.

I'm going to plug in my USB stick and copy a problem file from my old admin acct to the new DFA user acct.
 
As soon as I tried to copy the problem file to my stick:

right click folder --> copy -->
right click empty space on stick -->
paste --> ERROR MESSAGE


Property Loss

Are you sure you want to copy this file without its properties?

The file E-S-I Dec11-12.txt has properties that can't be copied to the new location.

YES SKIP CANCEL


[checkbox] Do this for all current items (5 found)

I clicked YES


Another error msg:

FILE ACCESS DENIED
"You'll need to provide administrator permission to copy this file

There are 3 option buttons at the bottom of this error msg:
Continue Skip Cancel

[checkbox] Do this for all current items (1)


I clicked CONTINUE

The folder completes pasting.


On the stick, I tried opening the problem Notepad file and the copy I made of it ...

Both opened and displayed the expected content.



I closed the stick, removed it from my laptop ...

I went into task manager to switch user to the new DFA admin acct



Once there, I tried opening the problem Notepad file and the copy I made of it ...

Both opened and displayed the expected content
 
Creating that new admin user account (or installing IE 11) caused many minor problems. Here's a few:

- lost all my bookmark favourites in Google
- lost all my form auto-fill settings
- changed the avatar for Google searches
- lost many cookies
- error message that said the product key I entered for Windows 7 was incorrect


Many more I can't remember right now. It seems every time I do something new, another minor problem surfaces.


I got online with MS help and the tech took remote control of my computer and solved the product key issue last night. I think she activated the product key from her side of things.

This is getting very frustrating.


It might just be coincidence that all these things happened when they did, and I'm not sure whether creating new acct or installing IE 11 is responsible, but this is what I would like to do at this point:


Do a system restore.
Uninstall all IE.
Delete the new user acct.


Please advise.

Dennis
 
It looks like your Windows installation has some issues which are beyond repair.

You still can try to create new topic in Windows forum.
In this forum, we make sure, your computer is free of malware and your computer is clean :)
Because the access to malware forum is very limited, your best option is to create new topic about your current issue, at Windows section.
You'll get more attention.

Other than that clean reinstall would be the only other option.
 
Broni, I can't tell you how much I appreciate all the work and endless hours that went into your attempts to clean my machine and make it workable.

To me, the end result of a clean machine isn't even as important to me as the idea that a complete stranger would spend so much time helping people like me. Thank you. A lot!!

I've decided to reformat the computer -- I think it's the only way I can solve all the problems in one stroke -- and am beginning to transfer important files over to one of my external hard drives. This is going to be a tedious process, for sure.

I've looked for tips to make the process easier, and found the following site that advises to download certain programs to make the job easier (I would appreciate your evaluation of the site's instructions):

http://features.en.softonic.com/8-things-you-must-do-before-reformatting-your-pc

Maybe you have a great set of steps I can follow?

I wish I could send you some money (bet you do too) for all your efforts, but I'm a 61 year old man who lives on a meager disability income that doesn't even pay all the bills.

If there's any other way I could possibly help you, all you have to do is ask.

Again, thank you immensely for your time and dedication.

Dennis
 
Back