Startup anomaly

epson9 -  
Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   -
Hello
Each time I start up, I have the following incident in the reliability history regarding File Picker UI host:

functioning stopped
Description
Path of the failing application: C:\Windows\System32\PickerHost.Exe

Problem signature
Problem event name: APPCRASH
Application name: PickerHost.Exe
Application version: 10.0.17134.1

I have done a restoration but no changes, thank you in advance for your help

Configuration: Windows / Firefox 63.0

11 answers

  1. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    Hello,

    To check the computer, I invite you to run this FRST analysis and provide the reports in return:

    Follow the FRST tutorial. ( take the time to read carefully - everything is well explained ).

    Download and run the FRST scan,
    Wait for the scan to finish, a message will indicate that the analysis is complete.

    Three FRST reports will be generated:
    • FRST.txt
    • Shortcut.txt
    • Additionnal.txt


    Send these 3 reports to the site https://pjjoint.malekal.com/ to share them.
    In return, provide the 3 pjjoint links leading to the reports here in a new response so that we can review them.

    --
    Please press a key to continue the disinfection...
    0
  2. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    Uninstall Driver Booster
    You also installed Advanced System Care while you already have CCleaner.
    It's best to avoid driver update and cleaning software, it messes up Windows.

    Here is the fix to perform with FRST. You can refer to this explanatory note with screenshots.
    Launch FRST and then press CTRL + Y on your keyboard.
    The Notepad will open, copy/paste this.

    CreateRestorePoint:
    CloseProcesses:
    2018-11-02 15:38 - 2018-11-02 15:38 - 003174784 _____ C:\Users\Regis Blicq.hp\Downloads\ZHPDiag3(1).exe
    2018-11-02 15:17 - 2018-11-02 15:17 - 003285376 _____ C:\Users\Regis Blicq.hp\Downloads\ZHPCleaner(1).exe
    2018-11-01 13:53 - 2018-11-01 13:53 - 017435592 _____ (Glarysoft Ltd) C:\Users\Regis Blicq.hp\Downloads\Glary_Utilities_v5.108.0.133.exe
    IFEO\Dashlane_Launcher.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\DSPut.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\Feedback.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\IObitDownloader.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\IUDM.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\IUService.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\iush.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\MicrosoftEdge.exe: [Debugger] /
    IFEO\NoteIcon.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\ScreenShot.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\SendBugReportNew.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\SpecUTool.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    EmptyTemp:
    RemoveProxy:
    Reboot:


    Save the content through the file menu then save.

    Close Notepad, go back to FRST and click on the "Fix" button
    A restart may be necessary and automatic.
    A text file will appear, copy/paste the content here in a new message.

    Restart the computer

    ~~

    2) You can run a SFC scan and repair

    In the Windows search bar, type command prompt
    On the result, right-click then run as administrator.
    In the black window of the command prompt, type sfc /scannow in the window.
    See this image: https://www.malekal.com/wp-content/uploads/ouvrir-invite-commandes-administrateur-Windows10.gif

    It should inform you that the protection has detected damaged items, which need a restart to correct. At that point, restart.

    Then, run a DISM repair
    Still in the command prompt window, execute these two commands sequentially.

    DISM /Online /Cleanup-image /Scanhealth
    DISM /Online /Cleanup-image /Restorehealth


    (note, there is a space before each command starting with / /Online /Cleanup-image etc)
    Make sure the scan and repair reach completion and no errors are displayed.

    Restart the computer.
    Try the updates again, if it still crashes, move to the next step.

    3) If nothing works, you will need to repair Windows 10: how to repair Windows 10 without data loss.

    --
    Please press a key to continue the disinfection...
    0
  3. Epson99 Posted messages 11 Registration date   Status Member Last intervention  
     
    Results of Farbar Recovery Scan Tool (x64) Version: 24.10.2018
    Executed by Regis Blicq (03-11-2018 15:26:03) Run:1
    Executed from C:\Users\Regis Blicq.hp\Downloads
    Loaded Profiles: Regis Blicq (Available Profiles: Regis Blicq)
    Boot Mode: Normal
    ==============================================

    fixlist content:
    CreateRestorePoint:
    CloseProcesses:
    2018-11-02 15:38 - 2018-11-02 15:38 - 003174784 _____ C:\Users\Regis Blicq.hp\Downloads\ZHPDiag3(1).exe
    2018-11-02 15:17 - 2018-11-02 15:17 - 003285376 _____ C:\Users\Regis Blicq.hp\Downloads\ZHPCleaner(1).exe
    2018-11-01 13:53 - 2018-11-01 13:53 - 017435592 _____ (Glarysoft Ltd) C:\Users\Regis Blicq.hp\Downloads\Glary_Utilities_v5.108.0.133.exe
    IFEO\Dashlane_Launcher.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\DSPut.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\Feedback.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\IObitDownloader.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\IUDM.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\IUService.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\iush.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\MicrosoftEdge.exe: [Debugger] /
    IFEO\NoteIcon.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\ScreenShot.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\SendBugReportNew.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    IFEO\SpecUTool.exe: [Debugger] C:\Program Files (x86)\IObit\Advanced SystemCare\AutoReactivator.exe
    EmptyTemp:
    RemoveProxy:
    Reboot:

    The restore point was created successfully.
    Processes closed successfully.
    C:\Users\Regis Blicq.hp\Downloads\ZHPDiag3(1).exe => moved successfully
    C:\Users\Regis Blicq.hp\Downloads\ZHPCleaner(1).exe => moved successfully
    C:\Users\Regis Blicq.hp\Downloads\Glary_Utilities_v5.108.0.133.exe => moved successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Dashlane_Launcher.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\DSPut.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\Feedback.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\IObitDownloader.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\IUDM.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\IUService.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\iush.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\MicrosoftEdge.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\NoteIcon.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\ScreenShot.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SendBugReportNew.exe => removed successfully
    HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\SpecUTool.exe => removed successfully

    ========= RemoveProxy: =========

    HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully
    "HKU\S-1-5-21-3018160818-984268725-927044822-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\DefaultConnectionSettings" => removed successfully
    "HKU\S-1-5-21-3018160818-984268725-927044822-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Connections\\SavedLegacySettings" => removed successfully

    ========= End of RemoveProxy: =========

    =========== EmptyTemp: ==========

    BITS transfer queue => 9199616 B
    DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 97576862 B
    Java, Flash, Steam htmlcache => 1258 B
    Windows/system/drivers => 853514 B
    Edge => 21042 B
    Chrome => 0 B
    Firefox => 250509223 B
    Opera => 1004004 B

    Temp, IE cache, history, cookies, recent:
    Default => 7680 B
    Users => 0 B
    ProgramData => 0 B
    Public => 0 B
    systemprofile => 0 B
    systemprofile32 => 0 B
    LocalService => 7680 B
    LocalService => 0 B
    NetworkService => 19248 B
    NetworkService => 0 B
    Regis Blicq.hp => 118431770 B

    RecycleBin => 3324389 B
    EmptyTemp: => 458.7 MB temporary data deleted.

    ================================

    The system had to reboot.

    End of Fixlog 15:27:22

    0
  4. Epson99 Posted messages 11 Registration date   Status Member Last intervention  
     
    run sfc /scannow
    no integrity violation
    0
  5. Epson99 Posted messages 11 Registration date   Status Member Last intervention  
     
    I just restarted and I'm still getting the same message for file picker UI host
    Path of the faulty application: C:\Windows\System32\PickerHost.Exe

    Problem Signature
    Problem event name: APPCRASH
    Application name: PickerHost.Exe
    Application version: 10.0.17134.1
    Application timestamp: 2fa59209
    Fault module name: StackHash_cf1b
    Fault module version: 10.0.17134.376
    Fault module timestamp: 60d78cf9
    Exception code: c0000374
    Exception offset: PCH_3C_FROM_ntdll+0x000000000009AA54
    OS version: 10.0.17134.2.0.0.768.101
    Locale ID: 1036
    Additional information 1: cf1b
    Additional information 2: cf1bb9b0dd5583d1f8d1bbd639941a16
    Additional information 3: 4adc
    Additional information 4: 4adc057da6aa530f61c0c0e56cca7c2e

    Additional problem information
    Bucket ID: e8c0153f53e642be48b6cd7954db55ba (1780836623670007226)
    0
  6. Epson99 Posted messages 11 Registration date   Status Member Last intervention  
     
    I have followed the procedure and just received the following message

    0x80070570 0x2000c
    the installation failed in the SAFE-OS phase with an error during the APPLY-IMAGE operation

    best regards
    0
  7. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    The solution to reset Windows 10 is: https://www.malekal.com/reinitialiser-windows-10/
    And if that doesn't work, you'll need to reset Windows 10.

    --
    Please press a key to continue the disinfection...
    0
    1. Epson99 Posted messages 11 Registration date   Status Member Last intervention  
       
      The second reset attempt was successful, but unfortunately I still have the same issue with the file
      attached error message when I connected tonight
      Description
      Path of the failing application: C:\Windows\System32\PickerHost.Exe

      Problem signature
      Problem event name: APPCRASH
      Application name: PickerHost.Exe
      Application version: 10.0.17134.1
      Application timestamp: 2fa59209
      Default module name: StackHash_cf1b
      0
    2. Epson99 Posted messages 11 Registration date   Status Member Last intervention  
       
      Hello
      I followed this procedure and so far it seems to be working.
      Should I delete the old local administrator account?
      Best regards
      Thank you for your help
      0
    3. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712 > Epson99 Posted messages 11 Registration date   Status Member Last intervention  
       
      yes, it looks damaged.
      Don't forget to retrieve the data from C:\users\XXXX
      0
    4. Epson99 Posted messages 11 Registration date   Status Member Last intervention  
       
      Everything is fine except that I have this when I want to go to the control panel: mouse
      The rundll32.exe program version 10.0.17134.1 has stopped interacting with Windows and has been closed. To determine if additional information is available, check the problem history in the Security and Maintenance control panel.
      Process ID: e00
      Start time: 01d4751589651d7f
      End time: 4294967295
      Application path: C:\Windows\System32\rundll32.exe
      Report ID: acb32827-92bf-49f5-aef1-d353c193b3dd
      Full name of the failing package:
      Application ID related to the failing package:

      Sincerely
      0
  8. Malekal_morte- Posted messages 178136 Registration date   Status Moderator, Security Contributor Last intervention   24 712
     
    I'm having a hard time determining whether it's your Windows that's dead or if it's a hardware issue.
    The reset didn't help...

    From the Windows 10 search box.
    Type "cmd", right-click on cmd.exe and select "Run as Administrator"
    In the command prompt window that opens, type chkdsk C: /F /R

    Try to repair Windows 10 from there: https://www.malekal.com/reparer-windows10-sans-perte-donnees/

    --
    Please press any key to continue with the disinfection...
    0