"Windows mail could not be started. error 80041161

Page 7 of 8 FirstFirst ... 5678 LastLast

  1. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #61

    Yeah, there seem to be a lot of toolbars - usually packed with an installer of other pgms. This is a fairly common "problem", but not necessarily harmful.

    The only one you might want to keep is Winamp - but a toolbar can always be replaced, so I suggest letting AdwCleaner clean up everything in the next step (clean)

    AdwCleaner is a two step process. Scan then Clean

    AdwCleaner Step 2: Scan and Clean
    • Right-click AdwCleaner.exe on your Desktop and select Run As Administrator.

    • Click on the Scan button.
      >> AdwCleaner begins scanning your system. It might take some time to complete.
    • After the scan has finished... click on the Clean button.
      • Answer OK to the "close all programs" prompt, then follow the onscreen prompts.
      • Answer OK to the "restart the computer" prompt to complete the removal process.
        >> The AdwCleaner[S#].txt log is opened in your default Text editor when the machine has restarted.
        [R#] gets incremented every time you run AdwCleaner - the highest number is the most recent.
    • Paste the entire AdwCleaner log in your next post.
      AdwCleaner logs are located in the C:\AdwCleaner folder if you need to reference them again.

      My Computer


  2. Posts : 59
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #62

    Thanks Slartybart

    This is the log which emerged from doing the Clean in AdwCleaner.

    I recognise some entries - in the few minutes since the Clean run I only notice FireFox may have been set back to an earlier state - no big deal.

    You mentioned WinAmp - I noted that after the Scan run and did a Control Panel Uninstall on it as I have never used it sufficiently to keep it.

    The Log:

    # AdwCleaner v3.018 - Report created 09/02/2014 at 20:31:35
    # Updated 28/01/2014 by Xplode
    # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits)
    # Username : pfo - FURIOUSFRED
    # Running from : C:\Users\pfo\Downloads\AdwCleaner.exe
    # Option : Clean

    ***** [ Services ] *****


    ***** [ Files / Folders ] *****

    Folder Deleted : C:\ProgramData\boost_interprocess
    Folder Deleted : C:\ProgramData\Partner
    [x] Not Deleted : C:\Program Files (x86)\jZip
    Folder Deleted : C:\Program Files (x86)\Nosibay
    Folder Deleted : C:\Program Files (x86)\Common Files\Software Update Utility
    [x] Not Deleted : C:\Users\pfo\AppData\Local\jZip
    Folder Deleted : C:\Users\pfo\AppData\Local\OpenCandy
    Folder Deleted : C:\Users\pfo\AppData\Local\Temp\jZip
    Folder Deleted : C:\Users\pfo\AppData\LocalLow\jziptoolbar
    Folder Deleted : C:\Users\pfo\AppData\Roaming\Nosibay
    File Deleted : C:\Users\pfo\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\jZip.lnk
    File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
    File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.xpt
    File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
    File Deleted : C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.xpt

    ***** [ Shortcuts ] *****


    ***** [ Registry ] *****

    Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\dnu.EXE
    Key Deleted : HKLM\SOFTWARE\Classes\dnUpdate
    Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser
    Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUIBrowser.1
    Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController
    Key Deleted : HKLM\SOFTWARE\Classes\dnUpdater.DownloadUpdController.1
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASAPI32
    Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\datamngrUI_RASMANCS
    Key Deleted : HKLM\SOFTWARE\Classes\AppID\{6C259840-5BA8-46E6-8ED1-EF3BA47D8BA1}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{35B8892D-C3FB-4D88-990D-31DB2EBD72BD}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E1164984-B567-47BD-A7FF-240C2594404A}
    Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E15A9BFD-D16D-496D-8222-44CADF316E70}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
    Key Deleted : HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{92380354-381A-471F-BE2E-DD9ACD9777EA}
    Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{93E3D79C-0786-48FF-9329-93BC9F6DC2B3}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41C4AA37-1DDD-4345-B8DC-734E4B38414D}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{25CEE8EC-5730-41BC-8B58-22DDC8AB8C20}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{41C4AA37-1DDD-4345-B8DC-734E4B38414D}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EBF2BA02-9094-4C5A-858B-BB198F3D8DE2}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7B089B94-D1DC-4C6B-87E1-8156E22C1D96}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{898EA8C8-E7FF-479B-8935-AEC46303B9E5}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1E48C56F-08CD-43AA-A6EF-C1EC891551AB}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3614D305-2DBB-4991-9297-750DD60FFC73}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
    Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
    Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
    Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{AE07101B-46D4-4A98-AF68-0333EA26E113}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{3F607E46-0D3C-4442-B1DE-DE7FA4768F5C}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{660E6F4F-840D-436D-B668-433D9591BAC5}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{E7435878-65B9-44D1-A443-81754E5DFC90}
    Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{FE0273D1-99DF-4AC0-87D5-1371C6271785}
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41C4AA37-1DDD-4345-B8DC-734E4B38414D}
    Value Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{AE07101B-46D4-4A98-AF68-0333EA26E113}]
    Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2102}
    Key Deleted : HKCU\Software\APN PIP
    Key Deleted : HKCU\Software\jZip
    Key Deleted : HKCU\Software\Nosibay
    Key Deleted : HKCU\Software\smartbar
    Key Deleted : HKCU\Software\YahooPartnerToolbar
    Key Deleted : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
    Key Deleted : HKLM\Software\jZip
    Key Deleted : HKLM\Software\PIP
    Key Deleted : HKLM\Software\PrimoPDF\OpenCandy
    Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\jZip
    Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SoftwareUpdUtility

    ***** [ Browsers ] *****

    -\\ Internet Explorer v11.0.9600.16428


    -\\ Mozilla Firefox v22.0 (en-US)

    [ File : C:\Users\pfo\AppData\Roaming\Mozilla\Firefox\Profiles\v679wako.default-1391462979186\prefs.js ]


    *************************

    AdwCleaner[R0].txt - [12051 octets] - [05/02/2014 21:25:52]
    AdwCleaner[R1].txt - [9021 octets] - [09/02/2014 19:07:19]
    AdwCleaner[S0].txt - [7418 octets] - [09/02/2014 20:31:35]

    ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7478 octets] ##########
      My Computer


  3. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #63

    ok thanks,

    These were not cleaned for some reason:
    [x] Not Deleted : C:\Program Files (x86)\jZip
    [x] Not Deleted : C:\Users\pfo\AppData\Local\jZip

    Please restart you machine and then follow this guide fro jZip virus removal:
    Remove Search.Jzip.com (Virus Removal Guide)

    Run the scans in the order specified and paste all logs here for review. You can run all of the scans and then post all of the logs on one post.

    There will be more scanners to run until your machine is clean. I'll look at the logs when they are posted.

    Thanks,

    Bill
    .
      My Computer


  4. Posts : 59
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #64

    Thank you.


    OK here we go:
    STEP 1: Remove Search.Jzip.com browser hijacker with AdwCleaner

    logs for scan and clean attached


    STEP 2: Remove Search.Jzip.com from Internet Explore, Firefox and Google Chrome with Junkware Removal Tool



    jrt.txt log attached

    STEP 3: Remove Search.Jzip.com malicious files from your computer with Malwarebytes Anti-Malware Free


    STEP 4: Double check for the Search.Jzip.com infection with HitmanPro

    Hope this is useful.
    "Windows mail could not be started.  error 80041161 Attached Files
      My Computer


  5. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #65

    Ok, good. it will take me a while to read through the logs.

    There were other malware threats that I saw before this run of scanners, but I think the scans you ran should have addressed some of them. There might be one or two still hanging on, so I'll post what I see and suggest teh next course of action.

    Bill
    .
      My Computer


  6. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #66

    JRT cleaned up a bunch of 'stuff' interestingly there were a lot of WLM empty folders (a bug fixed in WEM 2012). I wonder if they got in the way of the original issue posted.

    Since WLM did not do proper garbage collection, I want you to run Old Timer- Temp File Cleaner

    Restart your machine in case there are any system operations pending

    Click here to download Old Timer-TFC.
    >> save the application to your Desktop.
    Old Timer-TFC is a standalone application, there is no install.

    Save your work and close all open windows.
    TFC will close ALL open programs including your browser!

    Right click, run as administratorTFC

    Click the Start button to begin cleaning up temporary files and folders.

    Do not work on other things while TFC is running - most applications use some sort of temporary files. Just let TFC run by itself on the machine until it completes.

    If TFC prompts you to reboot, do so immediately.
    If TFC does NOT prompt you, then reboot your machine immediately after TFC has completed.

    After restarting the machine - yet another set of scans (you don't have to download the same scanners again)

    Mobogenie is classified as a Potential Unwanted Program (PUP).
    See: Remove Mobogenie virus (Removal Guide) - it's pretty much the same set of scans, but you uninstall Mobogenie 1st, then let the scanners clean up.

    When that's all done, there's one more I'd like to use, just to cover the bases.

    You're doing great, soon you can try to install WLM again!... but not yet

    Bill
    .
      My Computer


  7. Posts : 59
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #67

    Thanks Slartybart - unfortunately the TFC scan has been running over 12 hours. If it is still working that's fine. There is no indication of anything happening. There seems no hint of any log file when looking in from the other laptop.

    The first two 'user' temp folders flew in as there were no files requiring deletion. My user account has been worked on for over 12 hours. Last time TFC was run it was all done in, I believe, less than 3 hours.

    I will run it again just now to see what happens, but will stop it after a few hours done or not.
      My Computer


  8. Posts : 59
    Microsoft Windows 7 Home Premium 64-bit 7601 Multiprocessor Free Service Pack 1
    Thread Starter
       #68

    And. to answer my own question: shut down, boot Safe Mode, shut down, boot normal, run TFC. All as expected.

    Log attached.
    "Windows mail could not be started.  error 80041161 Attached Files
      My Computer


  9. Posts : 6,458
    x64 (6.3.9600) Win8.1 Pro & soon dual boot x64 (6.1.7601) Win7_SP1 HomePrem
       #69

    muymalestado said:
    And. to answer my own question: shut down, boot Safe Mode, shut down, boot normal, run TFC. All as expected.

    Log attached.
    I like it when members answer their own questions :)

    I guess what ever is on your system was fighting OTL. There really wasn't much (3.5MB GB) cleaned up once you got into safe mode.

    I would run the machine in safe mode until things improve. No sense having malware retrench your system.

    Ok, I have to backtrack a bit. I've been working on some other threads and I need to figure out what you need to do next so I don't suggest something you've already done (unless it needs to be repeated)

    Give me a bit of time to regroup.

    thanks

    Bill
    .
    Last edited by Slartybart; 12 Feb 2014 at 16:31. Reason: ooops GB, not MB
      My Computer


  10. Posts : 33
    Windows 7 Home Premium 64 bit
       #70

    [QUOTE=Slartybart;2688372
    There really wasn't much (3.5 MB) cleaned up once you got into safe mode.[/QUOTE]

    Wasn't it 3.5GB?
      My Computer


 
Page 7 of 8 FirstFirst ... 5678 LastLast

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 18:31.
Find Us