Author Topic: Issue in DL: Base Filtering Engine not running. Wha?!  (Read 42599 times)

0 Members and 1 Guest are viewing this topic.

REDACTED

  • Guest
Re: Issue in DL: Base Filtering Engine not running. Wha?!
« Reply #15 on: December 05, 2014, 07:07:17 PM »
==================== Event log errors: =========================

Application errors:
==================
Error: (12/05/2014 00:38:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/02/2014 00:02:13 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/01/2014 08:28:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program main.exe version 4.2.45.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: db4

Start Time: 01d00dbfeb68bd55

Termination Time: 25

Application Path: C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

Report Id:

Error: (12/01/2014 08:26:53 PM) (Source: VSS) (EventID: 12293) (User: )
Description: Volume Shadow Copy Service error: Error calling a routine on a Shadow Copy Provider {b5946137-7b9f-4925-af80-51abd60b20d5}. Routine details GetSnapshotProperties({169502e5-074e-4083-ab4b-6127a0efbef3}) [hr = 0x800706b5, The interface is unknown.
].


Operation:
   Executing Asynchronous Operation

Context:
   Current State: DoSnapshotSet

Error: (12/01/2014 06:39:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/24/2014 03:02:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/15/2014 03:27:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program main.exe version 4.2.45.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: f04

Start Time: 01d000ad20245440

Termination Time: 29

Application Path: C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

Report Id:

Error: (11/15/2014 03:22:27 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/13/2014 09:13:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program main.exe version 4.2.45.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 58ac

Start Time: 01cfff245f56f18c

Termination Time: 84

Application Path: C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

Report Id:

Error: (11/13/2014 04:29:41 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program main.exe version 4.2.45.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 5e54

Start Time: 01cfff1540101db8

Termination Time: 13

Application Path: C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

Report Id:


System errors:
=============
Error: (12/05/2014 00:50:10 PM) (Source: volsnap) (EventID: 14) (User: )
Description: The shadow copies of volume C: were aborted because of an IO failure on volume C:.

Error: (12/02/2014 11:45:14 AM) (Source: Service Control Manager) (EventID: 7031) (User: )
Description: The Razer Game Scanner service terminated unexpectedly.  It has done this 1 time(s).  The following corrective action will be taken in 5000 milliseconds: Restart the service.

Error: (12/02/2014 00:03:35 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The McAfee Personal Firewall Service service depends the following service: MpsSvc. This service might not be installed.

Error: (12/02/2014 00:03:35 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The McAfee Personal Firewall Service service depends the following service: MpsSvc. This service might not be installed.

Error: (12/02/2014 00:02:06 AM) (Source: Service Control Manager) (EventID: 7001) (User: )
Description: The HomeGroup Provider service depends on the Function Discovery Resource Publication service which failed to start because of the following error:
%%-2147024891

Error: (12/02/2014 00:02:06 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891

Error: (12/02/2014 00:00:53 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The IPsec Policy Agent service depends the following service: BFE. This service might not be installed.

Error: (12/02/2014 00:00:52 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The McAfee Personal Firewall Service service depends the following service: MpsSvc. This service might not be installed.

Error: (12/02/2014 00:00:51 AM) (Source: Service Control Manager) (EventID: 7003) (User: )
Description: The IKE and AuthIP IPsec Keying Modules service depends the following service: BFE. This service might not be installed.

Error: (12/02/2014 00:00:45 AM) (Source: Service Control Manager) (EventID: 7023) (User: )
Description: The Function Discovery Resource Publication service terminated with the following error:
%%-2147024891


Microsoft Office Sessions:
=========================
Error: (12/05/2014 00:38:39 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/02/2014 00:02:13 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (12/01/2014 08:28:37 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: main.exe4.2.45.0db401d00dbfeb68bd5525C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

Error: (12/01/2014 08:26:53 PM) (Source: VSS) (EventID: 12293) (User: )
Description: {b5946137-7b9f-4925-af80-51abd60b20d5}GetSnapshotProperties({169502e5-074e-4083-ab4b-6127a0efbef3})0x800706b5, The interface is unknown.


Operation:
   Executing Asynchronous Operation

Context:
   Current State: DoSnapshotSet

Error: (12/01/2014 06:39:38 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/24/2014 03:02:07 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/15/2014 03:27:52 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: main.exe4.2.45.0f0401d000ad2024544029C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

Error: (11/15/2014 03:22:27 AM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (11/13/2014 09:13:32 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: main.exe4.2.45.058ac01cfff245f56f18c84C:\Program Files (x86)\Razer\Razer Game Booster\main.exe

Error: (11/13/2014 04:29:41 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: main.exe4.2.45.05e5401cfff1540101db813C:\Program Files (x86)\Razer\Razer Game Booster\main.exe


CodeIntegrity Errors:
===================================
  Date: 2014-08-18 08:06:47.379
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-08-18 08:06:47.377
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-08-18 08:06:47.375
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-08-18 08:06:47.322
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-22 12:27:32.384
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-22 12:27:32.382
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-22 12:27:32.380
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-09 12:22:40.439
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-09 12:22:40.436
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.

  Date: 2014-06-09 12:22:40.433
  Description: Code Integrity is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files\Common Files\McAfee\VSCore\mfeelamk.sys because the set of per-page image hashes could not be found on the system.


==================== Memory info ===========================

Processor: Intel(R) Core(TM) i7-2600 CPU @ 3.40GHz
Percentage of memory in use: 38%
Total physical RAM: 8174.45 MB
Available physical RAM: 5046.62 MB
Total Pagefile: 16347.08 MB
Available Pagefile: 12333.14 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:1383.98 GB) (Free:965.1 GB) NTFS
Drive d: (SIMCITY) (CDROM) (Total:1.85 GB) (Free:0 GB) UDF

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 1397.3 GB) (Disk ID: 93D8918E)
Partition 1: (Not Active) - (Size=39 MB) - (Type=DE)
Partition 2: (Active) - (Size=13.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=1384 GB) - (Type=07 NTFS)

==================== End Of Log ============================



So thats all the info I could gather atm, Ive saved all the tools if theyll come in handy to figure this out.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Issue in DL: Base Filtering Engine not running. Wha?!
« Reply #16 on: December 05, 2014, 07:14:41 PM »
You could have attached the logs it would have been easier for you :)

You had zero access hence all the damage

CAUTION :  This fix is only valid for this specific machine, using it on another may break your computer

Open notepad and copy/paste the text in the quotebox below into it:
 
Quote
Winsock: Catalog5 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
Winsock: Catalog5-x64 01 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\system32\NLAapi.dll"
Winsock: Catalog5-x64 05 mswsock.dll File Not found () ATTENTION: The LibraryPath should be "%SystemRoot%\System32\mswsock.dll"
C:\Windows\Installer\{6a83217e-12a7-61e3-e560-8cc0f95811e4}
C:\Users\Di-Doh\AppData\Local\{6a83217e-12a7-61e3-e560-8cc0f95811e4}
EmptyTemp:
CMD: bitsadmin /reset /allusers

 
Save this as fixlist.txt, in the same location as FRST.exe

Run FRST and press Fix
On completion a log will be generated please post that

THEN

Could you install Avast and run a scan please