mij Posted December 27, 2016 Posted December 27, 2016 Quite a few days ago you tube suddenly took more than a few seconds to open a video. That is very unusual here as it has always been very quick and responsive. I also noticed that at the same time it was taking longer to open other pages, some it would not load at all leaving the page blank. My camera refuses to download pictures to the computer even with a new lead (I have mislaid the old one - card reader on way). I have gone onto the update site and the computer was sitting on the there for quite a while and it said 0% was downloaded - yet I have just run a scan with ME and it said it was up to date. Jim PS I forgot details W7, 64bit. Quote
seedy21 Posted December 29, 2016 Posted December 29, 2016 Hi Mij, Did you managed to get your machine to update in the end? Lets see if we can get some more information about your machine with this tool. https://sites.google.com/site/cannedfixes/minitoolbox/51e15692b05a4-MiniToolbox.PNG Scan with MiniToolBox Please download MiniToolBox by Farbar and save it to your desktop. Right-click on https://sites.google.com/site/cannedfixes/minitoolbox/51e15692b05a4-MiniToolbox.PNG icon and select https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg Run as Administrator to start the tool. In the main window please checkmark the following checkboxes: Flush DNS; Report IE Proxy Settings; Report FF Proxy Settings; List content of Hosts; List IP configuration; List Winsock Entries; List last 10 Event Viewer log; List Installed Programs; List Devices (Only problems); List Users, Partitions and Memory size; List Minidump Files. [*]Click Go and wait paiently. [*]Upon completion (a reboot may be needed) a file called Result.txt will be saved on your desktop. Please include the content of that file in your next reply. Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted December 29, 2016 Author Posted December 29, 2016 Thanks Seedy for answering the call. I have hopefully done what you have said and pasted the results below. Jim. MiniToolBox by Farbar Version: 17-06-2016 Ran by jims-pc (administrator) on 29-12-2016 at 21:04:25 Running from "C:\Users\jims-pc\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Model: GA-78LMT-USB3 Manufacturer: Gigabyte Technology Co., Ltd. Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= FF Proxy Settings: ============================== ========================= IP Configuration: ================================ HP 802.11b/g Wireless Network Adapter = Wireless Network Connection (Connected) Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected) # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : jims-pc-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : lan Wireless LAN adapter Wireless Network Connection 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter Physical Address. . . . . . . . . : 06-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Wireless LAN adapter Wireless Network Connection: Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : HP 802.11b/g Wireless Network Adapter Physical Address. . . . . . . . . : 00-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::f9c1:e645:c39a:5830%11(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.1.90(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : 29 December 2016 08:18:01 Lease Expires . . . . . . . . . . : 30 December 2016 09:58:05 Default Gateway . . . . . . . . . : 192.168.1.254 DHCP Server . . . . . . . . . . . : 192.168.1.254 DHCPv6 IAID . . . . . . . . . . . : 184598696 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1E-75-AE-E3-00-C0-A8-C3-BB-F7 DNS Servers . . . . . . . . . . . : 192.168.1.254 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.lan: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: dsldevice.lan Address: 192.168.1.254 Name: google.com Addresses: 2a00:1450:4009:809::200e 216.58.198.174 Pinging google.com [216.58.201.14] with 32 bytes of data: Request timed out. Reply from 216.58.201.14: bytes=32 time=12ms TTL=53 Ping statistics for 216.58.201.14: Packets: Sent = 2, Received = 1, Lost = 1 (50% loss), Approximate round trip times in milli-seconds: Minimum = 12ms, Maximum = 12ms, Average = 12ms Server: dsldevice.lan Address: 192.168.1.254 Name: yahoo.com Addresses: 2001:4998:c:a06::2:4008 2001:4998:58:c02::a9 2001:4998:44:204::a7 98.139.183.24 206.190.36.45 98.138.253.109 Pinging yahoo.com [98.139.183.24] with 32 bytes of data: Reply from 98.139.183.24: bytes=32 time=182ms TTL=49 Reply from 98.139.183.24: bytes=32 time=185ms TTL=49 Ping statistics for 98.139.183.24: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 182ms, Maximum = 185ms, Average = 183ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 12...06 c0 a8 c3 bb f7 ......Microsoft Virtual WiFi Miniport Adapter 11...00 c0 a8 c3 bb f7 ......HP 802.11b/g Wireless Network Adapter 1...........................Software Loopback Interface 1 14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.90 25 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.1.0 255.255.255.0 On-link 192.168.1.90 281 192.168.1.90 255.255.255.255 On-link 192.168.1.90 281 192.168.1.255 255.255.255.255 On-link 192.168.1.90 281 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.1.90 281 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.1.90 281 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 306 ::1/128 On-link 11 281 fe80::/64 On-link 11 281 fe80::f9c1:e645:c39a:5830/128 On-link 1 306 ff00::/8 On-link 11 281 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128] (Apple Inc.) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [133392] (Apple Inc.) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 03:49:24 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 10:04:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2016 08:56:00 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 04:50:52 PM) (Source: Application Error) (User: ) Description: Faulting application name: splwow64.exe, version: 6.1.7601.17514, time stamp: 0x4ce7b4c8 Faulting module name: E_IERSLEE.DLL, version: 1.2.2.7, time stamp: 0x4ff3f697 Exception code: 0xc0000005 Fault offset: 0x00000000000b8abc Faulting process id: 0xadc Faulting application start time: 0xsplwow64.exe0 Faulting application path: splwow64.exe1 Faulting module path: splwow64.exe2 Report Id: splwow64.exe3 Error: (12/25/2016 01:40:26 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 01:34:46 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 01:29:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/29/2016 08:46:37 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Error: (12/29/2016 08:46:36 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Error: (12/29/2016 08:46:36 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Error: (12/29/2016 08:19:01 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/28/2016 05:58:53 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/28/2016 02:15:53 AM) (Source: Service Control Manager) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (12/27/2016 09:06:21 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/27/2016 03:48:51 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/27/2016 03:46:48 PM) (Source: Service Control Manager) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (12/27/2016 10:04:08 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Microsoft Office Sessions: ========================= Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 03:49:24 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 10:04:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2016 08:56:00 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 04:50:52 PM) (Source: Application Error)(User: ) Description: splwow64.exe6.1.7601.175144ce7b4c8E_IERSLEE.DLL1.2.2.74ff3f697c000000500000000000b8abcadc01d25eb43f3be7fdC:\Windows\splwow64.exeC:\Windows\system32\spool\DRIVERS\x64\3\E_IERSLEE.DLL4b53d93f-cac2-11e6-af2d-fe4901257aa0 Error: (12/25/2016 01:40:26 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 01:34:46 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 01:29:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 =========================== Installed Programs ============================ Ad Muncher v4.94.34121 (Free) (HKLM-x32\...\Ad Muncher) (Version: - ) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Christmas Symphony Screensaver 1.0 (HKLM-x32\...\Christmas Symphony Screensaver_is1) (Version: - FullScreensavers.com) ClocX (1.6.0) (HKLM-x32\...\ClocX) (Version: - ) Epson Event Manager (HKLM-x32\...\{17FA0444-A025-43B9-862C-81AE6307C2F2}) (Version: 3.10.0050 - Seiko Epson Corporation) EPSON Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-412 413 415 Series Printer Uninstall (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Free Desktop Timer 1.21 (HKLM-x32\...\Free Desktop Timer_is1) (Version: - Drive Software Company) Games Manager (HKCU\...\GamesManager) (Version: 2.12.1.698 - iWin Inc.) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.32.7 - Google Inc.) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Morning Snowfall Wallpaper 2.0 (HKLM-x32\...\Morning Snowfall Wallpaper_is1) (Version: - FullScreensavers.com) Mozilla Firefox 50.1.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-GB)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) MyEpson Portal (HKLM-x32\...\{3361D415-BA35-4143-B301-661991BA6219}) (Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) OpenOffice 4.1.2 (HKLM-x32\...\{4E96CB8B-444E-4EA3-8EF4-26060B0B411F}) (Version: 4.12.9782 - Apache Software Foundation) RailMaster 1.64 (HKLM-x32\...\{100BA60D-8CFF-4E64-92A0-2029ABAEB3A0}_is1) (Version: - Hornby International Ltd) Reimage Protector (HKLM\...\Reimage Protector) (Version: - Reimage) SCARM 0.9.34 beta (HKLM-x32\...\{9BF3D390-A0AD-4733-AFC8-18E306B8E219}_is1) (Version: 0.9.34 - Milen Peev) Scrabble (HKLM-x32\...\Scrabble) (Version: - iWin.com) Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) SRWare Iron version 53.0.2800.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: 53.0.2800.0 - SRWare) Stellarium 0.15.0 (HKLM\...\Stellarium_is1) (Version: 0.15.0 - Stellarium team) TomTom HOME (HKLM-x32\...\{3C595537-D968-48D5-AAB1-CCB2E90FA59A}) (Version: 2.9.94 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) ========================= Devices: ================================ Name: Ethernet Controller Description: Ethernet Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&1F909778&0&0030 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Universal Serial Bus (USB) Controller Description: Universal Serial Bus (USB) Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_1106&DEV_3483&SUBSYS_50071458&REV_01\4&324195DD&0&0020 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ========================= Memory info: =================================== Percentage of memory in use: 30% Total physical RAM: 7661.55 MB Available physical RAM: 5352.73 MB Total Virtual: 15321.29 MB Available Virtual: 12678.03 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:930.97 GB) (Free:844.91 GB) NTFS 3 Drive e: (USB DISK) (Removable) (Total:59.51 GB) (Free:10.39 GB) FAT32 ========================= Users: ======================================== User accounts for \\JIMS-PC-PC Administrator Guest jims-pc ========================= Minidump Files ================================== No minidump file found **** End of log **** Quote
seedy21 Posted December 29, 2016 Posted December 29, 2016 Hi Mij. It looks like you are losing some packets from the Internet. I would like you to try this. We need to run a Command with Command Prompt Click on Start, type in "cmd.exe" and Right Click on Command Prompted and select Run as Administrator Type in the following line followed by clicking Enter netsh winsock reset Type in the following line followed by clicking Enter netsh int ip reset Once this has finished you can close Command Prompted and then restart your machine to make the changes. Once this has finished please re-run Minitoolbox as described in my above post and post the log file created in your next reply. Thanks Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted December 29, 2016 Author Posted December 29, 2016 Thanks for that quick reply Seedy. I have done that, it took me a couple of goes though :). The result is below. Jim MiniToolBox by Farbar Version: 17-06-2016 Ran by jims-pc (administrator) on 29-12-2016 at 23:27:48 Running from "C:\Users\jims-pc\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Model: GA-78LMT-USB3 Manufacturer: Gigabyte Technology Co., Ltd. Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= FF Proxy Settings: ============================== ========================= Hosts content: ================================= ========================= IP Configuration: ================================ HP 802.11b/g Wireless Network Adapter = Wireless Network Connection (Connected) Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected) # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : jims-pc-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : lan Wireless LAN adapter Wireless Network Connection 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter Physical Address. . . . . . . . . : 06-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Wireless LAN adapter Wireless Network Connection: Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : HP 802.11b/g Wireless Network Adapter Physical Address. . . . . . . . . : 00-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::f9c1:e645:c39a:5830%11(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.1.90(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : 29 December 2016 23:23:59 Lease Expires . . . . . . . . . . : 30 December 2016 23:23:58 Default Gateway . . . . . . . . . : 192.168.1.254 DHCP Server . . . . . . . . . . . : 192.168.1.254 DHCPv6 IAID . . . . . . . . . . . : 184598696 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1E-75-AE-E3-00-C0-A8-C3-BB-F7 DNS Servers . . . . . . . . . . . : 192.168.1.254 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.lan: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: dsldevice.lan Address: 192.168.1.254 Name: google.com Addresses: 2a00:1450:4009:80f::200e 216.58.198.174 Pinging google.com [216.58.213.110] with 32 bytes of data: Reply from 216.58.213.110: bytes=32 time=11ms TTL=53 Reply from 216.58.213.110: bytes=32 time=11ms TTL=53 Ping statistics for 216.58.213.110: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 11ms, Maximum = 11ms, Average = 11ms Server: dsldevice.lan Address: 192.168.1.254 Name: yahoo.com Addresses: 2001:4998:44:204::a7 2001:4998:58:c02::a9 2001:4998:c:a06::2:4008 206.190.36.45 98.138.253.109 98.139.183.24 Pinging yahoo.com [98.139.183.24] with 32 bytes of data: Reply from 98.139.183.24: bytes=32 time=89ms TTL=49 Reply from 98.139.183.24: bytes=32 time=89ms TTL=49 Ping statistics for 98.139.183.24: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 89ms, Maximum = 89ms, Average = 89ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 12...06 c0 a8 c3 bb f7 ......Microsoft Virtual WiFi Miniport Adapter 11...00 c0 a8 c3 bb f7 ......HP 802.11b/g Wireless Network Adapter 1...........................Software Loopback Interface 1 14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.90 26 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.1.0 255.255.255.0 On-link 192.168.1.90 281 192.168.1.90 255.255.255.255 On-link 192.168.1.90 281 192.168.1.255 255.255.255.255 On-link 192.168.1.90 281 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.1.90 281 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.1.90 281 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 306 ::1/128 On-link 11 281 fe80::/64 On-link 11 281 fe80::f9c1:e645:c39a:5830/128 On-link 1 306 ff00::/8 On-link 11 281 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128] (Apple Inc.) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [133392] (Apple Inc.) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (12/29/2016 11:25:35 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 03:49:24 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 10:04:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2016 08:56:00 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 04:50:52 PM) (Source: Application Error) (User: ) Description: Faulting application name: splwow64.exe, version: 6.1.7601.17514, time stamp: 0x4ce7b4c8 Faulting module name: E_IERSLEE.DLL, version: 1.2.2.7, time stamp: 0x4ff3f697 Exception code: 0xc0000005 Fault offset: 0x00000000000b8abc Faulting process id: 0xadc Faulting application start time: 0xsplwow64.exe0 Faulting application path: splwow64.exe1 Faulting module path: splwow64.exe2 Report Id: splwow64.exe3 Error: (12/25/2016 01:40:26 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 01:34:46 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/29/2016 11:24:56 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/29/2016 11:22:51 PM) (Source: Service Control Manager) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (12/29/2016 08:46:37 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Error: (12/29/2016 08:46:36 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Error: (12/29/2016 08:46:36 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Error: (12/29/2016 08:19:01 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/28/2016 05:58:53 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/28/2016 02:15:53 AM) (Source: Service Control Manager) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (12/27/2016 09:06:21 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/27/2016 03:48:51 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Microsoft Office Sessions: ========================= Error: (12/29/2016 11:25:35 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 03:49:24 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 10:04:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2016 08:56:00 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 04:50:52 PM) (Source: Application Error)(User: ) Description: splwow64.exe6.1.7601.175144ce7b4c8E_IERSLEE.DLL1.2.2.74ff3f697c000000500000000000b8abcadc01d25eb43f3be7fdC:\Windows\splwow64.exeC:\Windows\system32\spool\DRIVERS\x64\3\E_IERSLEE.DLL4b53d93f-cac2-11e6-af2d-fe4901257aa0 Error: (12/25/2016 01:40:26 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/25/2016 01:34:46 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 =========================== Installed Programs ============================ Ad Muncher v4.94.34121 (Free) (HKLM-x32\...\Ad Muncher) (Version: - ) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Christmas Symphony Screensaver 1.0 (HKLM-x32\...\Christmas Symphony Screensaver_is1) (Version: - FullScreensavers.com) ClocX (1.6.0) (HKLM-x32\...\ClocX) (Version: - ) Epson Event Manager (HKLM-x32\...\{17FA0444-A025-43B9-862C-81AE6307C2F2}) (Version: 3.10.0050 - Seiko Epson Corporation) EPSON Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-412 413 415 Series Printer Uninstall (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Free Desktop Timer 1.21 (HKLM-x32\...\Free Desktop Timer_is1) (Version: - Drive Software Company) Games Manager (HKCU\...\GamesManager) (Version: 2.12.1.698 - iWin Inc.) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.32.7 - Google Inc.) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Morning Snowfall Wallpaper 2.0 (HKLM-x32\...\Morning Snowfall Wallpaper_is1) (Version: - FullScreensavers.com) Mozilla Firefox 50.1.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-GB)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) MyEpson Portal (HKLM-x32\...\{3361D415-BA35-4143-B301-661991BA6219}) (Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) OpenOffice 4.1.2 (HKLM-x32\...\{4E96CB8B-444E-4EA3-8EF4-26060B0B411F}) (Version: 4.12.9782 - Apache Software Foundation) RailMaster 1.64 (HKLM-x32\...\{100BA60D-8CFF-4E64-92A0-2029ABAEB3A0}_is1) (Version: - Hornby International Ltd) Reimage Protector (HKLM\...\Reimage Protector) (Version: - Reimage) SCARM 0.9.34 beta (HKLM-x32\...\{9BF3D390-A0AD-4733-AFC8-18E306B8E219}_is1) (Version: 0.9.34 - Milen Peev) Scrabble (HKLM-x32\...\Scrabble) (Version: - iWin.com) Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) SRWare Iron version 53.0.2800.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: 53.0.2800.0 - SRWare) Stellarium 0.15.0 (HKLM\...\Stellarium_is1) (Version: 0.15.0 - Stellarium team) TomTom HOME (HKLM-x32\...\{3C595537-D968-48D5-AAB1-CCB2E90FA59A}) (Version: 2.9.94 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) ========================= Devices: ================================ Name: Ethernet Controller Description: Ethernet Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&1F909778&0&0030 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Universal Serial Bus (USB) Controller Description: Universal Serial Bus (USB) Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_1106&DEV_3483&SUBSYS_50071458&REV_01\4&324195DD&0&0020 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ========================= Memory info: =================================== Percentage of memory in use: 20% Total physical RAM: 7661.55 MB Available physical RAM: 6096.39 MB Total Virtual: 15321.29 MB Available Virtual: 13806.26 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:930.97 GB) (Free:844.64 GB) NTFS ========================= Users: ======================================== User accounts for \\JIMS-PC-PC Administrator Guest jims-pc ========================= Minidump Files ================================== No minidump file found **** End of log **** Quote
seedy21 Posted December 30, 2016 Posted December 30, 2016 Hi Mij Looks like we are still having the same issue. I would like to Disable IPv6 From the Start menu, select Control Panel. Make sure you are in the Large or Small icons view Open Network and Sharing Center. On the left, select Change adapter settings (Windows 7) or Manage network connections (Vista). Right-click on Wireless Network Connection and select Properties. Uncheck Internet Protocol Version 6 (TCP/IPv6) and click OK. Please Reboot your machine and re-run MiniToolBox like before. Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted December 30, 2016 Author Posted December 30, 2016 Hello Seedy again and thanks for your patience. I have followed your instructions and pasted the results below. I hope they reward our efforts. Jim. MiniToolBox by Farbar Version: 17-06-2016 Ran by jims-pc (administrator) on 30-12-2016 at 22:07:46 Running from "C:\Users\jims-pc\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Model: GA-78LMT-USB3 Manufacturer: Gigabyte Technology Co., Ltd. Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= FF Proxy Settings: ============================== ========================= Hosts content: ================================= ========================= IP Configuration: ================================ HP 802.11b/g Wireless Network Adapter = Wireless Network Connection (Connected) Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected) # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : jims-pc-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : lan Wireless LAN adapter Wireless Network Connection 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter Physical Address. . . . . . . . . : 06-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Wireless LAN adapter Wireless Network Connection: Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : HP 802.11b/g Wireless Network Adapter Physical Address. . . . . . . . . : 00-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes IPv4 Address. . . . . . . . . . . : 192.168.1.90(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : 30 December 2016 22:05:40 Lease Expires . . . . . . . . . . : 31 December 2016 22:05:44 Default Gateway . . . . . . . . . : 192.168.1.254 DHCP Server . . . . . . . . . . . : 192.168.1.254 DNS Servers . . . . . . . . . . . : 192.168.1.254 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.lan: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: dsldevice.lan Address: 192.168.1.254 Name: google.com Addresses: 2a00:1450:400c:c0c::8b 216.58.198.174 Pinging google.com [216.58.212.110] with 32 bytes of data: Reply from 216.58.212.110: bytes=32 time=11ms TTL=53 Reply from 216.58.212.110: bytes=32 time=11ms TTL=53 Ping statistics for 216.58.212.110: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 11ms, Maximum = 11ms, Average = 11ms Server: dsldevice.lan Address: 192.168.1.254 Name: yahoo.com Addresses: 2001:4998:c:a06::2:4008 2001:4998:58:c02::a9 2001:4998:44:204::a7 98.139.183.24 98.138.253.109 206.190.36.45 Pinging yahoo.com [98.139.183.24] with 32 bytes of data: Reply from 98.139.183.24: bytes=32 time=122ms TTL=49 Reply from 98.139.183.24: bytes=32 time=128ms TTL=49 Ping statistics for 98.139.183.24: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 122ms, Maximum = 128ms, Average = 125ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 12...06 c0 a8 c3 bb f7 ......Microsoft Virtual WiFi Miniport Adapter 11...00 c0 a8 c3 bb f7 ......HP 802.11b/g Wireless Network Adapter 1...........................Software Loopback Interface 1 14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.90 25 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.1.0 255.255.255.0 On-link 192.168.1.90 281 192.168.1.90 255.255.255.255 On-link 192.168.1.90 281 192.168.1.255 255.255.255.255 On-link 192.168.1.90 281 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.1.90 281 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.1.90 281 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 306 ::1/128 On-link 1 306 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128] (Apple Inc.) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [133392] (Apple Inc.) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (12/30/2016 10:07:16 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 09:53:32 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 07:41:42 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 11:25:35 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 03:49:24 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 10:04:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2016 08:56:00 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (12/30/2016 10:06:34 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/30/2016 10:04:45 PM) (Source: Microsoft Antimalware) (User: ) Description: %NT AUTHORITY60 has encountered an error trying to update signatures. New Signature Version: Previous Signature Version: 1.233.3363.0 Update Source: %NT AUTHORITY59 Update Stage: 4.9.0218.00 Source Path: 4.9.0218.01 Signature Type: %NT AUTHORITY602 Update Type: %NT AUTHORITY604 User: NT AUTHORITY\SYSTEM Current Engine Version: %NT AUTHORITY605 Previous Engine Version: %NT AUTHORITY606 Error code: %NT AUTHORITY607 Error description: %NT AUTHORITY608 Error: (12/30/2016 09:52:57 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/30/2016 09:50:45 PM) (Source: Service Control Manager) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (12/30/2016 07:41:07 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/30/2016 01:49:55 AM) (Source: Service Control Manager) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (12/29/2016 11:24:56 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/29/2016 11:22:51 PM) (Source: Service Control Manager) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (12/29/2016 08:46:37 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Error: (12/29/2016 08:46:36 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR3. Microsoft Office Sessions: ========================= Error: (12/30/2016 10:07:16 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 09:53:32 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 07:41:42 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 11:25:35 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 03:49:24 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 10:04:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/26/2016 08:56:00 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 =========================== Installed Programs ============================ Ad Muncher v4.94.34121 (Free) (HKLM-x32\...\Ad Muncher) (Version: - ) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Christmas Symphony Screensaver 1.0 (HKLM-x32\...\Christmas Symphony Screensaver_is1) (Version: - FullScreensavers.com) ClocX (1.6.0) (HKLM-x32\...\ClocX) (Version: - ) Epson Event Manager (HKLM-x32\...\{17FA0444-A025-43B9-862C-81AE6307C2F2}) (Version: 3.10.0050 - Seiko Epson Corporation) EPSON Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-412 413 415 Series Printer Uninstall (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Free Desktop Timer 1.21 (HKLM-x32\...\Free Desktop Timer_is1) (Version: - Drive Software Company) Games Manager (HKCU\...\GamesManager) (Version: 2.12.1.698 - iWin Inc.) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.32.7 - Google Inc.) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Morning Snowfall Wallpaper 2.0 (HKLM-x32\...\Morning Snowfall Wallpaper_is1) (Version: - FullScreensavers.com) Mozilla Firefox 50.1.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-GB)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) MyEpson Portal (HKLM-x32\...\{3361D415-BA35-4143-B301-661991BA6219}) (Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) OpenOffice 4.1.2 (HKLM-x32\...\{4E96CB8B-444E-4EA3-8EF4-26060B0B411F}) (Version: 4.12.9782 - Apache Software Foundation) RailMaster 1.64 (HKLM-x32\...\{100BA60D-8CFF-4E64-92A0-2029ABAEB3A0}_is1) (Version: - Hornby International Ltd) Reimage Protector (HKLM\...\Reimage Protector) (Version: - Reimage) SCARM 0.9.34 beta (HKLM-x32\...\{9BF3D390-A0AD-4733-AFC8-18E306B8E219}_is1) (Version: 0.9.34 - Milen Peev) Scrabble (HKLM-x32\...\Scrabble) (Version: - iWin.com) Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) SRWare Iron version 53.0.2800.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: 53.0.2800.0 - SRWare) Stellarium 0.15.0 (HKLM\...\Stellarium_is1) (Version: 0.15.0 - Stellarium team) TomTom HOME (HKLM-x32\...\{3C595537-D968-48D5-AAB1-CCB2E90FA59A}) (Version: 2.9.94 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) ========================= Devices: ================================ Name: Ethernet Controller Description: Ethernet Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&1F909778&0&0030 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Universal Serial Bus (USB) Controller Description: Universal Serial Bus (USB) Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_1106&DEV_3483&SUBSYS_50071458&REV_01\4&324195DD&0&0020 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ========================= Memory info: =================================== Percentage of memory in use: 17% Total physical RAM: 7661.55 MB Available physical RAM: 6353.2 MB Total Virtual: 15321.29 MB Available Virtual: 13965.52 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:930.97 GB) (Free:844.78 GB) NTFS ========================= Users: ======================================== User accounts for \\JIMS-PC-PC Administrator Guest jims-pc ========================= Minidump Files ================================== No minidump file found **** End of log **** Quote
seedy21 Posted January 1, 2017 Posted January 1, 2017 Hi Mij It looks like we are still losting packets. Can you tell me if you have any other internet devices like Tablet or another computer. If so are you having the same issue with them? Please can you power off your Router (Box that gives you internet) for 10 seconds and start it back up again. After doing that can you please rerun MiniToolBox Thanks Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted January 4, 2017 Author Posted January 4, 2017 (edited) I am unsure whether the router was the problem or not but when I switched it off to carry out the the process outlined by you it would not work when I switched it back on and had to await the delivery and set up of a new one. That took until now! We are lost without the interenet :(. Ok new router installed and I hope the file that the test software produced (with router switched off) is still valid. Jim. PS SWMBO says that her desktop is not what it should be. A fr'instance is the DVD drive does not work. It is a Dell Studio One and I am too unsure to be trying my luck at diagnosing the fault on that. Any DVD or CD that is tried in it is immediately ejected. I have taken it apart before but I know nothing to enable a sensible diagnosis to be made. Luckily previously it was repaired under warrantee. MiniToolBox by Farbar Version: 17-06-2016 Ran by jims-pc (administrator) on 01-01-2017 at 19:33:08 Running from "C:\Users\jims-pc\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Model: GA-78LMT-USB3 Manufacturer: Gigabyte Technology Co., Ltd. Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= FF Proxy Settings: ============================== ========================= Hosts content: ================================= ========================= IP Configuration: ================================ HP 802.11b/g Wireless Network Adapter = Wireless Network Connection (Media disconnected) Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected) # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : jims-pc-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No Wireless LAN adapter Wireless Network Connection 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter Physical Address. . . . . . . . . : 06-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Wireless LAN adapter Wireless Network Connection: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : HP 802.11b/g Wireless Network Adapter Physical Address. . . . . . . . . : 00-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Tunnel adapter isatap.{09918D2E-CDC7-4119-808D-775181E51018}: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter isatap.lan: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2 Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: UnKnown Address: 127.0.0.1 Ping request could not find host google.com. Please check the name and try again. Server: UnKnown Address: 127.0.0.1 Ping request could not find host yahoo.com. Please check the name and try again. Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 12...06 c0 a8 c3 bb f7 ......Microsoft Virtual WiFi Miniport Adapter 11...00 c0 a8 c3 bb f7 ......HP 802.11b/g Wireless Network Adapter 1...........................Software Loopback Interface 1 14...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface 25...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2 =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 306 ::1/128 On-link 1 306 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128] (Apple Inc.) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [133392] (Apple Inc.) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (01/01/2017 07:32:24 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 09:07:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2016 07:44:13 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 10:07:16 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 09:53:32 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 07:41:42 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 11:25:35 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/01/2017 07:31:44 PM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (01/01/2017 09:07:04 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/31/2016 07:43:37 AM) (Source: DCOM) (User: NT AUTHORITY) Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC) Error: (12/30/2016 11:17:29 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (12/30/2016 11:17:29 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (12/30/2016 11:17:28 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (12/30/2016 11:17:28 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (12/30/2016 11:17:27 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (12/30/2016 11:17:27 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Error: (12/30/2016 11:17:26 PM) (Source: Disk) (User: ) Description: The driver detected a controller error on \Device\Harddisk1\DR1. Microsoft Office Sessions: ========================= Error: (01/01/2017 07:32:24 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 09:07:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2016 07:44:13 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 10:07:16 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 09:53:32 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 07:41:42 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 11:25:35 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/29/2016 08:19:25 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/28/2016 05:59:28 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/27/2016 09:06:51 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 =========================== Installed Programs ============================ Ad Muncher v4.94.34121 (Free) (HKLM-x32\...\Ad Muncher) (Version: - ) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Christmas Symphony Screensaver 1.0 (HKLM-x32\...\Christmas Symphony Screensaver_is1) (Version: - FullScreensavers.com) ClocX (1.6.0) (HKLM-x32\...\ClocX) (Version: - ) Epson Event Manager (HKLM-x32\...\{17FA0444-A025-43B9-862C-81AE6307C2F2}) (Version: 3.10.0050 - Seiko Epson Corporation) EPSON Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-412 413 415 Series Printer Uninstall (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Free Desktop Timer 1.21 (HKLM-x32\...\Free Desktop Timer_is1) (Version: - Drive Software Company) Games Manager (HKCU\...\GamesManager) (Version: 2.12.1.698 - iWin Inc.) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.32.7 - Google Inc.) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Morning Snowfall Wallpaper 2.0 (HKLM-x32\...\Morning Snowfall Wallpaper_is1) (Version: - FullScreensavers.com) Mozilla Firefox 50.1.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-GB)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) MyEpson Portal (HKLM-x32\...\{3361D415-BA35-4143-B301-661991BA6219}) (Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) OpenOffice 4.1.2 (HKLM-x32\...\{4E96CB8B-444E-4EA3-8EF4-26060B0B411F}) (Version: 4.12.9782 - Apache Software Foundation) RailMaster 1.64 (HKLM-x32\...\{100BA60D-8CFF-4E64-92A0-2029ABAEB3A0}_is1) (Version: - Hornby International Ltd) Reimage Protector (HKLM\...\Reimage Protector) (Version: - Reimage) SCARM 0.9.34 beta (HKLM-x32\...\{9BF3D390-A0AD-4733-AFC8-18E306B8E219}_is1) (Version: 0.9.34 - Milen Peev) Scrabble (HKLM-x32\...\Scrabble) (Version: - iWin.com) Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) SRWare Iron version 53.0.2800.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: 53.0.2800.0 - SRWare) Stellarium 0.15.0 (HKLM\...\Stellarium_is1) (Version: 0.15.0 - Stellarium team) TomTom HOME (HKLM-x32\...\{3C595537-D968-48D5-AAB1-CCB2E90FA59A}) (Version: 2.9.94 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) ========================= Devices: ================================ Name: Ethernet Controller Description: Ethernet Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&1F909778&0&0030 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Universal Serial Bus (USB) Controller Description: Universal Serial Bus (USB) Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_1106&DEV_3483&SUBSYS_50071458&REV_01\4&324195DD&0&0020 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ========================= Memory info: =================================== Percentage of memory in use: 16% Total physical RAM: 7661.55 MB Available physical RAM: 6393.77 MB Total Virtual: 15321.29 MB Available Virtual: 14010.75 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:930.97 GB) (Free:844.77 GB) NTFS ========================= Users: ======================================== User accounts for \\JIMS-PC-PC Administrator Guest jims-pc ========================= Minidump Files ================================== No minidump file found **** End of log **** Edited January 4, 2017 by mij Quote
seedy21 Posted January 4, 2017 Posted January 4, 2017 Hi Jim, Are you still having the issues with the new router? if so can I have a new log with MiniToolBox? Thanks Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted January 4, 2017 Author Posted January 4, 2017 Coo that was a quick answer Seedy, nearly caught me out with that one :). I will go and try my usual addys and get back to you :). Jim Quote
mij Posted January 4, 2017 Author Posted January 4, 2017 Thank you for that very quick response Seedy, that really was quick. I was initially thinkingeverything was fine but there is still some that take an inordinate time to start which did not happen before. I have put the new file below. Jim. MiniToolBox by Farbar Version: 17-06-2016 Ran by jims-pc (administrator) on 04-01-2017 at 21:23:08 Running from "C:\Users\jims-pc\Desktop" Microsoft Windows 7 Home Premium Service Pack 1 (X64) Model: GA-78LMT-USB3 Manufacturer: Gigabyte Technology Co., Ltd. Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows IP Configuration Successfully flushed the DNS Resolver Cache. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. ========================= FF Proxy Settings: ============================== ========================= Hosts content: ================================= ========================= IP Configuration: ================================ HP 802.11b/g Wireless Network Adapter = Wireless Network Connection (Connected) Microsoft Virtual WiFi Miniport Adapter = Wireless Network Connection 2 (Media disconnected) # ---------------------------------- # IPv4 Configuration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled popd # End of IPv4 configuration Windows IP Configuration Host Name . . . . . . . . . . . . : jims-pc-PC Primary Dns Suffix . . . . . . . : Node Type . . . . . . . . . . . . : Hybrid IP Routing Enabled. . . . . . . . : No WINS Proxy Enabled. . . . . . . . : No DNS Suffix Search List. . . . . . : lan Wireless LAN adapter Wireless Network Connection 2: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter Physical Address. . . . . . . . . : 06-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Wireless LAN adapter Wireless Network Connection: Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : HP 802.11b/g Wireless Network Adapter Physical Address. . . . . . . . . : 00-C0-A8-C3-BB-F7 DHCP Enabled. . . . . . . . . . . : Yes Autoconfiguration Enabled . . . . : Yes Link-local IPv6 Address . . . . . : fe80::f9c1:e645:c39a:5830%11(Preferred) IPv4 Address. . . . . . . . . . . : 192.168.1.1(Preferred) Subnet Mask . . . . . . . . . . . : 255.255.255.0 Lease Obtained. . . . . . . . . . : 04 January 2017 12:00:13 Lease Expires . . . . . . . . . . : 05 January 2017 12:00:13 Default Gateway . . . . . . . . . : 192.168.1.254 DHCP Server . . . . . . . . . . . : 192.168.1.254 DHCPv6 IAID . . . . . . . . . . . : 184598696 DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1E-75-AE-E3-00-C0-A8-C3-BB-F7 DNS Servers . . . . . . . . . . . : 192.168.1.254 NetBIOS over Tcpip. . . . . . . . : Enabled Tunnel adapter isatap.lan: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : lan Description . . . . . . . . . . . : Microsoft ISATAP Adapter Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Tunnel adapter Teredo Tunneling Pseudo-Interface: Media State . . . . . . . . . . . : Media disconnected Connection-specific DNS Suffix . : Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0 DHCP Enabled. . . . . . . . . . . : No Autoconfiguration Enabled . . . . : Yes Server: dsldevice.lan Address: 192.168.1.254 Name: google.com Addresses: 2a00:1450:4009:809::200e 216.58.198.174 Pinging google.com [216.58.198.174] with 32 bytes of data: Reply from 216.58.198.174: bytes=32 time=11ms TTL=53 Reply from 216.58.198.174: bytes=32 time=27ms TTL=53 Ping statistics for 216.58.198.174: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 11ms, Maximum = 27ms, Average = 19ms Server: dsldevice.lan Address: 192.168.1.254 Name: yahoo.com Addresses: 2001:4998:c:a06::2:4008 2001:4998:58:c02::a9 2001:4998:44:204::a7 98.138.253.109 206.190.36.45 98.139.183.24 Pinging yahoo.com [98.138.253.109] with 32 bytes of data: Reply from 98.138.253.109: bytes=32 time=120ms TTL=48 Reply from 98.138.253.109: bytes=32 time=120ms TTL=48 Ping statistics for 98.138.253.109: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 120ms, Maximum = 120ms, Average = 120ms Pinging 127.0.0.1 with 32 bytes of data: Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Reply from 127.0.0.1: bytes=32 time<1ms TTL=128 Ping statistics for 127.0.0.1: Packets: Sent = 2, Received = 2, Lost = 0 (0% loss), Approximate round trip times in milli-seconds: Minimum = 0ms, Maximum = 0ms, Average = 0ms =========================================================================== Interface List 12...06 c0 a8 c3 bb f7 ......Microsoft Virtual WiFi Miniport Adapter 11...00 c0 a8 c3 bb f7 ......HP 802.11b/g Wireless Network Adapter 1...........................Software Loopback Interface 1 15...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter 13...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4 Route Table =========================================================================== Active Routes: Network Destination Netmask Gateway Interface Metric 0.0.0.0 0.0.0.0 192.168.1.254 192.168.1.1 25 127.0.0.0 255.0.0.0 On-link 127.0.0.1 306 127.0.0.1 255.255.255.255 On-link 127.0.0.1 306 127.255.255.255 255.255.255.255 On-link 127.0.0.1 306 192.168.1.0 255.255.255.0 On-link 192.168.1.1 281 192.168.1.1 255.255.255.255 On-link 192.168.1.1 281 192.168.1.255 255.255.255.255 On-link 192.168.1.1 281 224.0.0.0 240.0.0.0 On-link 127.0.0.1 306 224.0.0.0 240.0.0.0 On-link 192.168.1.1 281 255.255.255.255 255.255.255.255 On-link 127.0.0.1 306 255.255.255.255 255.255.255.255 On-link 192.168.1.1 281 =========================================================================== Persistent Routes: None IPv6 Route Table =========================================================================== Active Routes: If Metric Network Destination Gateway 1 306 ::1/128 On-link 11 281 fe80::/64 On-link 11 281 fe80::f9c1:e645:c39a:5830/128 On-link 1 306 ff00::/8 On-link 11 281 ff00::/8 On-link =========================================================================== Persistent Routes: None ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [122128] (Apple Inc.) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [133392] (Apple Inc.) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (01/04/2017 08:50:46 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/03/2017 08:55:44 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/02/2017 09:37:39 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 08:04:37 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 07:53:52 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 07:46:01 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 07:32:24 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 09:07:41 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2016 07:44:13 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 10:07:16 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/04/2017 10:33:09 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:55 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:43 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:33 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:23 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:03 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:31:54 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:31:44 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:31:25 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:31:16 AM) (Source: cdrom) (User: ) Description: The device, \Device\CdRom0, has a bad block. Microsoft Office Sessions: ========================= Error: (01/04/2017 08:50:46 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/03/2017 08:55:44 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/02/2017 09:37:39 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 08:04:37 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 07:53:52 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 07:46:01 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 07:32:24 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/01/2017 09:07:41 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/31/2016 07:44:13 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (12/30/2016 10:07:16 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 =========================== Installed Programs ============================ Ad Muncher v4.94.34121 (Free) (HKLM-x32\...\Ad Muncher) (Version: - ) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Christmas Symphony Screensaver 1.0 (HKLM-x32\...\Christmas Symphony Screensaver_is1) (Version: - FullScreensavers.com) ClocX (1.6.0) (HKLM-x32\...\ClocX) (Version: - ) Epson Event Manager (HKLM-x32\...\{17FA0444-A025-43B9-862C-81AE6307C2F2}) (Version: 3.10.0050 - Seiko Epson Corporation) EPSON Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-412 413 415 Series Printer Uninstall (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Free Desktop Timer 1.21 (HKLM-x32\...\Free Desktop Timer_is1) (Version: - Drive Software Company) Games Manager (HKCU\...\GamesManager) (Version: 2.12.1.698 - iWin Inc.) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (HKLM-x32\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.32.7 - Google Inc.) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Malwarebytes Anti-Malware version 2.2.1.1043 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.1.1043 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Morning Snowfall Wallpaper 2.0 (HKLM-x32\...\Morning Snowfall Wallpaper_is1) (Version: - FullScreensavers.com) Mozilla Firefox 50.1.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-GB)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) MyEpson Portal (HKLM-x32\...\{3361D415-BA35-4143-B301-661991BA6219}) (Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) OpenOffice 4.1.2 (HKLM-x32\...\{4E96CB8B-444E-4EA3-8EF4-26060B0B411F}) (Version: 4.12.9782 - Apache Software Foundation) RailMaster 1.64 (HKLM-x32\...\{100BA60D-8CFF-4E64-92A0-2029ABAEB3A0}_is1) (Version: - Hornby International Ltd) Reimage Protector (HKLM\...\Reimage Protector) (Version: - Reimage) SCARM 0.9.34 beta (HKLM-x32\...\{9BF3D390-A0AD-4733-AFC8-18E306B8E219}_is1) (Version: 0.9.34 - Milen Peev) Scrabble (HKLM-x32\...\Scrabble) (Version: - iWin.com) Software Updater (HKLM-x32\...\{8DBC5A0A-31C4-46C7-B252-6B593EA11A87}) (Version: 4.3.7 - SEIKO EPSON CORPORATION) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) SRWare Iron version 53.0.2800.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: 53.0.2800.0 - SRWare) Stellarium 0.15.0 (HKLM\...\Stellarium_is1) (Version: 0.15.0 - Stellarium team) TomTom HOME (HKLM-x32\...\{3C595537-D968-48D5-AAB1-CCB2E90FA59A}) (Version: 2.9.94 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) ========================= Devices: ================================ Name: Ethernet Controller Description: Ethernet Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_10EC&DEV_8168&SUBSYS_E0001458&REV_06\4&1F909778&0&0030 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Universal Serial Bus (USB) Controller Description: Universal Serial Bus (USB) Controller Class Guid: Manufacturer: Service: Device ID: PCI\VEN_1106&DEV_3483&SUBSYS_50071458&REV_01\4&324195DD&0&0020 Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ========================= Memory info: =================================== Percentage of memory in use: 25% Total physical RAM: 7661.55 MB Available physical RAM: 5708.46 MB Total Virtual: 15321.29 MB Available Virtual: 13309.88 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:930.97 GB) (Free:843.83 GB) NTFS 2 Drive d: (WATERCOLOUR_FAST_AND_LOOSE) (CDROM) (Total:3.18 GB) (Free:0 GB) UDF ========================= Users: ======================================== User accounts for \\JIMS-PC-PC Administrator Guest jims-pc ========================= Minidump Files ================================== No minidump file found **** End of log **** Quote
seedy21 Posted January 6, 2017 Posted January 6, 2017 Hi Jim, Lets make sure it isn't anything malicious. Step 1 Scan your computer with Malwarebytes Anti Malware If you still have version 2 installed ..... Then just update the definitions and scan with that. If you don't have MalwareBytes installed........ On installation the 14 day trial version will begin. At the end of the 14 day trial, the program will switch to the free version. (and you will lose some of the functions) Malwarebytes 3.0 Free will have the same capabilities as Malwarebytes Anti-Malware Free, but with a 3x to 4x scan speed improvement. Download Malwarebytes 3 and save it to your desktop Double click the desktop icon, click Run, then OK Click Next Select I accept the agreement then continue to click Next then finally click Install Click Finish . MalwareBytes will now open to the Dashboard. http://img.photobucket.com/albums/v708/starbuck50/NMBv3/nmb12_zpslgp53gyt.png All protection should now enable and the update process should begin. Once the update process has completed, Click Scan Now to start your Threat scan. To find the reports From the main Dashboard click Reports (left hand side) Double click on the scan log which shows the Date and time of the scan that showed the infections. Click Export >> Copy to Clipboard Paste the contents of the clipboard into your reply. . http://img.photobucket.com/albums/v708/starbuck50/NMBv3/nmb14_zpsdq4dkyqo.png Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted January 6, 2017 Author Posted January 6, 2017 Hi Seedy and thanks again for helping. This stuff is not easy for me and I invariably click the wrong thing :). I think I may have got this though so I hope all is well with this stage. I did stop the firewall working as I did think that it might intefere with things, I also did a restore before asking here. jim. Malwarebytes http://www.malwarebytes.com -Log Details- Scan Date: 1/6/17 Scan Time: 6:10 PM Logfile: Administrator: Yes -Software Information- Version: 3.0.5.1299 Components Version: 1.0.43 Update Package Version: 1.0.944 License: Trial -System Information- OS: Windows 7 Service Pack 1 CPU: x64 File System: NTFS User: jims-pc-PC\jims-pc -Scan Summary- Scan Type: Threat Scan Result: Completed Objects Scanned: 326072 Time Elapsed: 2 min, 28 sec -Scan Options- Memory: Enabled Startup: Enabled Filesystem: Enabled Archives: Enabled Rootkits: Disabled Heuristics: Enabled PUP: Enabled PUM: Enabled -Scan Details- Process: 2 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE\REIMAGE PROTECTOR\REISYSTEM.EXE, No Action By User, [1317], [327181],1.0.944 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE\REIMAGE PROTECTOR\REIGUARD.EXE, No Action By User, [1317], [327181],1.0.944 Module: 2 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE\REIMAGE PROTECTOR\REISYSTEM.EXE, No Action By User, [1317], [327181],1.0.944 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE\REIMAGE PROTECTOR\REIGUARD.EXE, No Action By User, [1317], [327181],1.0.944 Registry Key: 29 PUP.Optional.Reimage, HKLM\SYSTEM\CURRENTCONTROLSET\SERVICES\ReimageRealTimeProtector, No Action By User, [1317], [327181],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\INTERFACE\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{9BB31AD8-5DB2-459E-A901-DEA536F23BA4}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\INTERFACE\{BD51A48E-EB5F-4454-8774-EF962DF64546}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\INTERFACE\{BD51A48E-EB5F-4454-8774-EF962DF64546}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\INTERFACE\{BD51A48E-EB5F-4454-8774-EF962DF64546}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\TYPELIB\{FA6468D2-FAA4-4951-A53B-2A5CF9CC0A36}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\CLSID\{801B440B-1EE3-49B0-B05D-2AB076D4E8CB}, No Action By User, [1317], [327206],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, No Action By User, [1317], [332494],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, No Action By User, [1317], [332494],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\{28FF42B8-A0DA-4BE5-9B81-E26DD59B350A}, No Action By User, [1317], [332494],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\REI_AxControl.ReiEngine, No Action By User, [1317], [327205],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\REI_AxControl.ReiEngine.1, No Action By User, [1317], [327205],1.0.944 PUP.Optional.Reimage, HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\EXT\SETTINGS\{10ECCE17-29B5-4880-A8F5-EAD298611484}, No Action By User, [1317], [327205],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\CLSID\{10ECCE17-29B5-4880-A8F5-EAD298611484}, No Action By User, [1317], [327205],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\APPID\REI_AxControl.DLL, No Action By User, [1317], [327193],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TREE\ReimageUpdater, No Action By User, [1317], [332364],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\REIMAGE\Reimage Repair, No Action By User, [1317], [336077],1.0.944 PUP.Optional.Reimage, HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\SOFTWARE\LOCAL APPWIZARD-GENERATED APPLICATIONS\Reimage - Windows Problem Relief., No Action By User, [1317], [327203],1.0.944 PUP.Optional.Reimage, HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\SOFTWARE\REIMAGE\PC REPAIR, No Action By User, [1317], [327204],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\UNINSTALL\Reimage Protector, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\WOW6432NODE\CLASSES\APPID\REI_AxControl.DLL, No Action By User, [1317], [327193],1.0.944 PUP.Optional.Reimage, HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\SOFTWARE\Reimage, No Action By User, [1317], [357494],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\REIMAGE\REIMAGE PROTECTOR, No Action By User, [1317], [332504],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\CLASSES\WOW6432NODE\APPID\REI_AxControl.DLL, No Action By User, [1317], [327193],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9C9A49DD-9EDF-446F-BA31-CEFC5816EFC8}, No Action By User, [1317], [332365],1.0.944 Registry Value: 3 PUP.Optional.Reimage, HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\SOFTWARE\REIMAGE\PC REPAIR|QUITMESSAGE, No Action By User, [1317], [327204],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\REIMAGE\REIMAGE PROTECTOR|CFLPATH, No Action By User, [1317], [332504],1.0.944 PUP.Optional.Reimage, HKLM\SOFTWARE\MICROSOFT\WINDOWS NT\CURRENTVERSION\SCHEDULE\TASKCACHE\TASKS\{9C9A49DD-9EDF-446F-BA31-CEFC5816EFC8}|PATH, No Action By User, [1317], [332365],1.0.944 Data Stream: 0 (No malicious items detected) Folder: 8 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\Microsoft.VC90.CRT, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\Results, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\tmp, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\PROGRAMDATA\REIMAGE PROTECTOR, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\Microsoft.VC90.CRT, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE, No Action By User, [1317], [332482],1.0.944 File: 68 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE\REIMAGE PROTECTOR\REISYSTEM.EXE, No Action By User, [1317], [327181],1.0.944 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE\REIMAGE PROTECTOR\REIGUARD.EXE, No Action By User, [1317], [327181],1.0.944 PUP.Optional.Reimage, C:\PROGRAMDATA\REIMAGE PROTECTOR\CFL.REI, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\Microsoft.VC90.CRT\msvcr90.dll, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\aevdf.dat, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\aelidb.dat, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\aemvdb.dat, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\aeset.dat, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase000.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase001.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase002.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase003.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase004.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase005.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase006.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase007.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase008.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase009.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase010.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase011.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase012.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase013.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase014.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase015.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase016.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase017.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase018.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase019.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase020.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase021.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase022.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase023.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase024.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase025.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase026.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase027.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase028.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase029.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase030.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\vbase031.vdf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\avupdate.conf, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\avupdate.exe, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\avupdate.log, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\avupdate_msg.avr, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\HBEDV.KEY, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\master.idx, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\savapi3_restart.exe, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\savapi3_start.exe, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\AV\savapi3_stop.exe, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\Results\ProtectorPackage.log, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\Results\ProtectorUpdater.log, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\Results\ScanAgent.log, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\Results\ScanAgentDebugRepair.log, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\Results\scan_agent_result_log.txt, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\ProgramData\Reimage Protector\Results\url_setting_definitions.txt, No Action By User, [1317], [327186],1.0.944 PUP.Optional.Reimage, C:\USERS\JIMS-PC\APPDATA\LOCAL\TEMP\REIMAGE.LOG, No Action By User, [1317], [334717],1.0.944 PUP.Optional.Reimage, C:\USERS\JIMS-PC\APPDATA\LOCAL\TEMP\REIMAGEPACKAGE.EXE, No Action By User, [1317], [331559],1.0.944 PUP.Optional.SpeedItUp, C:\WINDOWS\REIMAGE.INI, No Action By User, [1421], [329423],1.0.944 PUP.Optional.Reimage, C:\PROGRAM FILES\REIMAGE\REIMAGE PROTECTOR\savapi3.dll, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\Microsoft.VC90.CRT\Microsoft.VC90.CRT.manifest, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\Microsoft.VC90.CRT\msvcr90.dll, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\ProtectorUpdater.exe, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\ReiProtectorM.exe, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\ReiScanner.exe, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\REI_AVIRA.exe, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\Program Files\Reimage\Reimage Protector\uninst.exe, No Action By User, [1317], [332482],1.0.944 PUP.Optional.Reimage, C:\WINDOWS\SYSTEM32\TASKS\REIMAGEUPDATER, No Action By User, [1317], [327190],1.0.944 Physical Sector: 0 (No malicious items detected) (end) Quote
seedy21 Posted January 6, 2017 Posted January 6, 2017 Hi Mij, I have moved you topic to the Malware Removal part. Lets run part 2 Note: There are both 32-bit and 64-bit versions of Farbar Recovery Scan Tool available. Please pick the version that matches your operating system's bit type. If you are unsure what you're system bit type is..... click Here for help. For x32 bit systems download Farbar Recovery Scan Tool and save it to your Desktop. For x64 bit systems download Farbar Recovery Scan Tool x64 and save it to your Desktop. Double-click the downloaded icon to run the tool. Vista/Windows 7/8/10 users right-click and select Run As Administrator http://img.photobucket.com/albums/v708/starbuck50/frsticon_zpsdc3cbdc3.png When the tool opens click Yes to disclaimer. http://img.photobucket.com/albums/v708/starbuck50/frstdis_zps7f598f12.png Press Scan button. http://img.photobucket.com/albums/v708/starbuck50/newfrst_zpsa63ffa3d.png It will make a log (FRST.txt) in the same directory the tool is run. Please copy and paste this to your reply. The first time the tool is run, it also makes another log (Addition.txt). Please copy and paste this to your reply also. When FRST is run it will make a backup of your registry before compiling the report. Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted January 6, 2017 Author Posted January 6, 2017 Hi Seedy and thanks for persuing this problem. I hope I have done this stage ok and might have to put these logs in two posts. I am not sure of their length. Jim Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-01-2017 Ran by jims-pc (06-01-2017 20:47:52) Running from C:\Users\jims-pc\Desktop Windows 7 Home Premium Service Pack 1 (X64) (2016-03-12 11:01:19) Boot Mode: Normal ========================================================== ==================== Accounts: ============================= Administrator (S-1-5-21-3499627929-3589410846-2533986498-500 - Administrator - Disabled) Guest (S-1-5-21-3499627929-3589410846-2533986498-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3499627929-3589410846-2533986498-1002 - Limited - Enabled) jims-pc (S-1-5-21-3499627929-3589410846-2533986498-1001 - Administrator - Enabled) => C:\Users\jims-pc ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Microsoft Security Essentials (Enabled - Up to date) {768124D7-F5F7-6D2F-DDC2-94DFA4017C95} AS: Microsoft Security Essentials (Enabled - Up to date) {CDE0C533-D3CD-62A1-E772-AFADDF863628} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Ad Muncher v4.94.34121 (Free) (HKLM-x32\...\Ad Muncher) (Version: - ) Adobe Acrobat Reader DC (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AC0F074E4100}) (Version: 15.020.20042 - Adobe Systems Incorporated) Adobe Flash Player 24 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Adobe Flash Player 24 PPAPI (HKLM-x32\...\Adobe Flash Player PPAPI) (Version: 24.0.0.186 - Adobe Systems Incorporated) Apple Application Support (32-bit) (HKLM-x32\...\{D4B07658-F443-4445-A261-E643996E139D}) (Version: 4.3.2 - Apple Inc.) Apple Application Support (64-bit) (HKLM\...\{A6B0442B-E159-444B-B49D-6B9AC531EAE3}) (Version: 4.3.2 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{2E4AF2A6-50EA-4260-9BA4-5E582D11879A}) (Version: 9.3.0.15 - Apple Inc.) Apple Software Update (HKLM-x32\...\{56EC47AA-5813-4FF6-8E75-544026FBEA83}) (Version: 2.2.0.150 - Apple Inc.) BBC iPlayer Downloads (HKLM-x32\...\{148784F3-3B6E-4DFA-B7A1-3400B277DAF3}) (Version: 1.14.2 - BBC) Belarc Advisor 8.5c (HKLM-x32\...\Belarc Advisor) (Version: 8.5.3.0 - Belarc Inc.) Bonjour (HKLM\...\{56DDDFB8-7F79-4480-89D5-25E1F52AB28F}) (Version: 3.1.0.1 - Apple Inc.) Christmas Symphony Screensaver 1.0 (HKLM-x32\...\Christmas Symphony Screensaver_is1) (Version: - FullScreensavers.com) ClocX (1.6.0) (HKLM-x32\...\ClocX) (Version: - ) Epson Event Manager (HKLM-x32\...\{17FA0444-A025-43B9-862C-81AE6307C2F2}) (Version: 3.10.0050 - Seiko Epson Corporation) EPSON Manuals (HKLM-x32\...\{84CECC1B-21EF-41B1-9A91-3E724E5D99D3}) (Version: 1.50.0.0 - SEIKO EPSON CORPORATION) EPSON Scan (HKLM-x32\...\EPSON Scanner) (Version: - Seiko Epson Corporation) Epson Software Updater (HKLM-x32\...\{7BAC3F7A-B963-468E-982E-B5608A87408D}) (Version: 4.4.4 - SEIKO EPSON CORPORATION) EPSON XP-412 413 415 Series Printer Uninstall (HKLM\...\EPSON XP-412 413 415 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM-x32\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.6.0 - SEIKO EPSON CORPORATION) Free Desktop Timer 1.21 (HKLM-x32\...\Free Desktop Timer_is1) (Version: - Drive Software Company) Games Manager (HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\...\GamesManager) (Version: 2.12.1.698 - iWin Inc.) GIMP 2.8.16 (HKLM\...\GIMP-2_is1) (Version: 2.8.16 - The GIMP Team) Google Earth (HKLM-x32\...\{A0C18B96-AB79-46BD-8321-6FA83E6D25B9}) (Version: 7.1.7.2606 - Google) Google Update Helper (x32 Version: 1.3.32.7 - Google Inc.) Hidden IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.37 - Irfan Skiljan) Malwarebytes version 3.0.5.1299 (HKLM\...\{35065F43-4BB2-439A-BFF7-0F1014F2E0CD}_is1) (Version: 3.0.5.1299 - Malwarebytes) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Security Essentials (HKLM\...\Microsoft Security Client) (Version: 4.9.218.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x64) - 12.0.30501 (HKLM-x32\...\{050d4fc8-5d48-4b8f-8972-47c82c46020f}) (Version: 12.0.30501.0 - Microsoft Corporation) Morning Snowfall Wallpaper 2.0 (HKLM-x32\...\Morning Snowfall Wallpaper_is1) (Version: - FullScreensavers.com) Mozilla Firefox 50.1.0 (x86 en-GB) (HKLM-x32\...\Mozilla Firefox 50.1.0 (x86 en-GB)) (Version: 50.1.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 50.1.0.6186 - Mozilla) MyEpson Portal (HKLM-x32\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) MyEpson Portal (x32 Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden OpenOffice 4.1.2 (HKLM-x32\...\{4E96CB8B-444E-4EA3-8EF4-26060B0B411F}) (Version: 4.12.9782 - Apache Software Foundation) RailMaster 1.64 (HKLM-x32\...\{100BA60D-8CFF-4E64-92A0-2029ABAEB3A0}_is1) (Version: - Hornby International Ltd) Reimage Protector (HKLM\...\Reimage Protector) (Version: - Reimage) <==== ATTENTION SCARM 0.9.34 beta (HKLM-x32\...\{9BF3D390-A0AD-4733-AFC8-18E306B8E219}_is1) (Version: 0.9.34 - Milen Peev) Scrabble (HKLM-x32\...\Scrabble) (Version: - iWin.com) Speccy (HKLM\...\Speccy) (Version: 1.29 - Piriform) SRWare Iron version 53.0.2800.0 (HKLM-x32\...\{C59CF2CE-B302-4833-AA35-E0E07D8EBC52}_is1) (Version: 53.0.2800.0 - SRWare) Stellarium 0.15.0 (HKLM\...\Stellarium_is1) (Version: 0.15.0 - Stellarium team) TomTom HOME (HKLM-x32\...\{3C595537-D968-48D5-AAB1-CCB2E90FA59A}) (Version: 2.9.94 - TomTom) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.4 - VideoLAN) ==================== Custom CLSID (Whitelisted): ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== Scheduled Tasks (Whitelisted) ============= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) Task: {2B0C05EF-7A53-4DA1-9572-3E95C7E4024E} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2016-10-21] (Adobe Systems Incorporated) Task: {6CBAC875-B8F0-4093-A63A-E2B9B03E4733} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-07] (Google Inc.) Task: {8553BFB1-1EC4-4AAF-B937-5C7625631047} - System32\Tasks\Adobe Flash Player PPAPI Notifier => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_186_pepper.exe [2016-12-13] (Adobe Systems Incorporated) Task: {96D7FC4B-87F1-4009-8DB0-519617B2506F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2016-12-13] (Adobe Systems Incorporated) Task: {9C9A49DD-9EDF-446F-BA31-CEFC5816EFC8} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION Task: {B68D8A0B-91CB-40EE-A589-3A337E4D9EF5} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2016-04-07] (Google Inc.) Task: {F3367D19-9F69-441E-BE45-601AB2F6DC45} - System32\Tasks\{2D164C03-554B-4C7A-9D19-487DEC6AD0F6} => pcalua.exe -a C:\Users\jims-pc\Downloads\irfanview_plugins_442_setup.exe -d C:\Users\jims-pc\Downloads (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job => C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_24_0_0_186_pepper.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Shortcuts ============================= (The entries could be listed to be restored or removed.) ShortcutWithArgument: C:\Users\jims-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iWin Games\Play iWin Games.lnk -> C:\Users\jims-pc\AppData\Local\GamesManager\GamesManager.exe (iWin Inc) -> -config.channel=00000000 -config.uri=hxxp://gm/iwin/index.html ShortcutWithArgument: C:\Users\jims-pc\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\iWin Games\Games\Launch - Scrabble.lnk -> C:\Users\jims-pc\AppData\Local\GamesManager\GamesManager.exe (iWin Inc) -> -config.channel=00000000 -config.sku=6900320298672579551 -config.uri=hxxp://gm/iwin/index.html ==================== Loaded Modules (Whitelisted) ============== 2016-07-05 14:23 - 2016-07-05 14:23 - 00092472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2016-07-05 14:23 - 2016-07-05 14:23 - 01354040 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2017-01-06 18:08 - 2016-12-14 12:55 - 02259232 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\PoliciesControllerImpl.dll 2017-01-06 18:08 - 2016-12-14 12:55 - 02813904 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\arwlib.dll 2017-01-06 18:08 - 2016-12-14 12:55 - 02247632 _____ () C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\MwacLib.dll 2016-03-24 09:06 - 2015-07-25 01:39 - 00634880 _____ () C:\Program Files (x86)\Free Desktop Timer\DesktopTimer.exe ==================== Alternate Data Streams (Whitelisted) ========= (If an entry is included in the fixlist, only the ADS will be removed.) ==================== Safe Mode (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MBAMService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MBAMService => ""="Service" ==================== Association (Whitelisted) =============== (If an entry is included in the fixlist, the registry item will be restored to default or removed.) ==================== Internet Explorer trusted/restricted =============== (If an entry is included in the fixlist, it will be removed from the registry.) ==================== Hosts content: =============================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 02:34 - 2016-06-23 12:13 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\jims-pc\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.254 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 2) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1) Windows Firewall is enabled. ==================== MSCONFIG/TASK MANAGER disabled items == ==================== FirewallRules (Whitelisted) =============== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) FirewallRules: [{15AD97B3-D141-42B1-A8D2-2A10589B9BD8}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{2934BA0A-7102-4169-B295-C30C852E3EFD}] => C:\Program Files (x86)\Mozilla Firefox\firefox.exe FirewallRules: [{CB6F7A3C-3321-4A43-AF1B-9580A536EEE8}] => C:\Users\jims-pc\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{02D1260A-1244-4262-8C53-28873C0D2C18}] => C:\Users\jims-pc\AppData\Local\Temp\EpInsNav\DL\3013\Network\EpsonNetSetup\EpsonNetSetup3_6_1_2200\ENEasyApp.exe FirewallRules: [{8ED41B99-2A72-404A-8CE4-975D7131539A}] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [{D53B0062-2047-4859-9FE0-2946D5330C9C}] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe FirewallRules: [TCP Query User{8E241318-959F-4246-A7EF-5D19E5518F57}C:\program files (x86)\srware iron\chrome.exe] => C:\program files (x86)\srware iron\chrome.exe FirewallRules: [uDP Query User{99DD8A61-48C1-4E64-BD6F-DFD7D477E4B6}C:\program files (x86)\srware iron\chrome.exe] => C:\program files (x86)\srware iron\chrome.exe FirewallRules: [{517918D8-9555-4F80-B4B3-E20C2D939D60}] => C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{8E035147-1552-4FE3-86B6-1613924F398C}] => C:\Program Files\Bonjour\mDNSResponder.exe FirewallRules: [{92666E44-2897-4E57-AB38-8C6DC494FD02}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [{EED0320A-C15D-4AB4-8982-EFB351D2D800}] => C:\Program Files (x86)\Bonjour\mDNSResponder.exe FirewallRules: [TCP Query User{96FF6C4B-369B-4966-A203-516F84E9B65A}C:\program files (x86)\railmaster\railmaster.exe] => C:\program files (x86)\railmaster\railmaster.exe FirewallRules: [uDP Query User{6A815060-5893-46F0-A0AC-B0B0BFC01B9B}C:\program files (x86)\railmaster\railmaster.exe] => C:\program files (x86)\railmaster\railmaster.exe ==================== Restore Points ========================= 07-12-2016 08:38:48 Windows Update 11-12-2016 09:01:29 Windows Update 18-12-2016 05:12:39 Installed TomTom HOME. 20-12-2016 08:33:59 Windows Update 27-12-2016 10:06:04 Windows Update 01-01-2017 19:59:50 Restore Operation 05-01-2017 08:43:29 Windows Update 06-01-2017 20:40:47 Installed Software Updater ==================== Faulty Device Manager Devices ============= Name: Ethernet Controller Description: Ethernet Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Universal Serial Bus (USB) Controller Description: Universal Serial Bus (USB) Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/06/2017 08:41:13 PM) (Source: MsiInstaller) (EventID: 1013) (User: jims-pc-PC) Description: Product: Software Updater -- Newer version of this software is already installed. Error: (01/06/2017 07:32:17 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/06/2017 05:58:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/06/2017 06:49:26 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/05/2017 08:43:41 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/04/2017 08:50:46 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/03/2017 08:55:44 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/02/2017 09:37:39 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/01/2017 08:04:37 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. Error: (01/01/2017 07:53:52 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected. System errors: ============= Error: (01/06/2017 07:30:42 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: The Reimage Real Time Protector service failed to start due to the following error: The system cannot find the file specified. Error: (01/06/2017 07:29:44 PM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (01/06/2017 05:58:06 PM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (01/06/2017 06:48:47 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (01/06/2017 01:42:07 AM) (Source: Service Control Manager) (EventID: 7043) (User: ) Description: The Windows Update service did not shut down properly after receiving a preshutdown control. Error: (01/05/2017 08:43:05 AM) (Source: DCOM) (EventID: 10016) (User: NT AUTHORITY) Description: The application-specific permission settings do not grant Local Launch permission for the COM Server application with CLSID {C97FCC79-E628-407D-AE68-A06AD6D8B4D1} and APPID {344ED43D-D086-4961-86A6-1106F4ACAD9B} to the user NT AUTHORITY\SYSTEM SID (S-1-5-18) from address LocalHost (Using LRPC). This security permission can be modified using the Component Services administrative tool. Error: (01/04/2017 10:33:09 AM) (Source: cdrom) (EventID: 7) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:55 AM) (Source: cdrom) (EventID: 7) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:43 AM) (Source: cdrom) (EventID: 7) (User: ) Description: The device, \Device\CdRom0, has a bad block. Error: (01/04/2017 10:32:33 AM) (Source: cdrom) (EventID: 7) (User: ) Description: The device, \Device\CdRom0, has a bad block. ==================== Memory info =========================== Processor: AMD FX-4130 Quad-Core Processor Percentage of memory in use: 28% Total physical RAM: 7661.55 MB Available physical RAM: 5496.84 MB Total Virtual: 15321.29 MB Available Virtual: 12985.78 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:930.97 GB) (Free:844.49 GB) NTFS Drive d: (WATERCOLOUR_FAST_AND_LOOSE) (CDROM) (Total:3.18 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 8FC79151) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=450 MB) - (Type=27) ==================== End of Addition.txt ============================ Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 01-01-2017 Ran by jims-pc (administrator) on JIMS-PC-PC (06-01-2017 20:46:57) Running from C:\Users\jims-pc\Desktop Loaded Profiles: jims-pc (Available Profiles: jims-pc) Platform: Windows 7 Home Premium Service Pack 1 (X64) Language: English (United States) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MsMpEng.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\NisSrv.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\msseces.exe (Malwarebytes) C:\Program Files\Malwarebytes\Anti-Malware\mbamtray.exe () C:\Program Files (x86)\Free Desktop Timer\DesktopTimer.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (Murray Hurps Software Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch.exe (Murray Hurps Software Pty Ltd) C:\Program Files (x86)\Ad Muncher\AdMunch64.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.32.7\GoogleCrashHandler64.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Microsoft Corporation) C:\Program Files\Microsoft Security Client\MpCmdRun.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mep.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\epson\MyEpson Portal\mepService.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe ==================== Registry (Whitelisted) ==================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [MSC] => c:\Program Files\Microsoft Security Client\msseces.exe [1340192 2016-01-29] (Microsoft Corporation) HKLM\...\Run: [Malwarebytes TrayApp] => C:\PROGRAM FILES\MALWAREBYTES\ANTI-MALWARE\mbamtray.exe [2776528 2016-12-14] (Malwarebytes) HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1065968 2015-07-23] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [Ad Muncher] => C:\Program Files (x86)\Ad Muncher\AdMunch.exe [560760 2016-03-14] (Murray Hurps Software Pty Ltd) HKU\S-1-5-21-3499627929-3589410846-2533986498-1001\...\Run: [FreeDesktopTimer] => C:\Program Files (x86)\Free Desktop Timer\DesktopTimer.exe [634880 2015-07-25] () ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.254 Tcpip\..\Interfaces\{15E0ED78-7809-4C2E-9AF0-AA320606C071}: [DhcpNameServer] 192.168.1.254 Internet Explorer: ================== DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxps://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: belarc - {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\BelarcAdvisor\System\BAVoilaX.dll [2016-01-04] (Belarc, Inc.) FireFox: ======== FF DefaultProfile: kgpc9i97.default FF ProfilePath: C:\Users\jims-pc\AppData\Roaming\TomTom\HOME\Profiles\rr2k8saq.default [2016-12-18] FF Extension: (Map status indicator) - C:\Program Files (x86)\TomTom HOME 2\xul\extensions\MapShare-status@tomtom.com [2016-12-18] [not signed] FF ProfilePath: C:\Users\jims-pc\AppData\Roaming\Mozilla\Firefox\Profiles\kgpc9i97.default [2017-01-06] FF Homepage: Mozilla\Firefox\Profiles\kgpc9i97.default -> hxxp://www.google.co.uk/ FF Extension: (YouTube Center) - C:\Users\jims-pc\AppData\Roaming\Mozilla\Firefox\Profiles\kgpc9i97.default\Extensions\jid1-cwbvBTE216jjpg@jetpack.xpi [2016-09-09] FF Extension: (New Tab Tools) - C:\Users\jims-pc\AppData\Roaming\Mozilla\Firefox\Profiles\kgpc9i97.default\Extensions\newtabtools@darktrojan.net.xpi [2016-11-08] FF Extension: (Open about:permissons) - C:\Users\jims-pc\AppData\Roaming\Mozilla\Firefox\Profiles\kgpc9i97.default\Extensions\open.about.permissions@jasnapaka.com.xpi [2016-08-18] FF Extension: (Skeptical Science) - C:\Users\jims-pc\AppData\Roaming\Mozilla\Firefox\Profiles\kgpc9i97.default\Extensions\{1bedbcc0-a50c-11df-981c-0800200c9a66}.xpi [2016-05-05] FF Extension: (Adblock Plus) - C:\Users\jims-pc\AppData\Roaming\Mozilla\Firefox\Profiles\kgpc9i97.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2016-11-23] FF Extension: (Navigational Sounds) - C:\Users\jims-pc\AppData\Roaming\Mozilla\Firefox\Profiles\kgpc9i97.default\Extensions\{d84a846d-f7cb-4187-a408-b171020e8940}.xpi [2016-08-18] FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_24_0_0_186.dll [2016-12-13] () FF Plugin: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_24_0_0_186.dll [2016-12-13] () FF Plugin-x32: @Google.com/GoogleEarthPlugin -> C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll [2016-10-06] (Google) FF Plugin-x32: @microsoft.com/GENUINE -> disabled [No File] FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.32.7\npGoogleUpdate3.dll [2016-12-17] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.2 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.2.4 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2016-06-01] (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Acrobat Reader DC\Reader\AIR\nppdf32.dll [2016-10-27] (Adobe Systems Inc.) ==================== Services (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 Apple Mobile Device Service; C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [83768 2016-03-02] (Apple Inc.) R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [144560 2012-05-17] (Seiko Epson Corporation) R2 MBAMService; C:\Program Files\Malwarebytes\Anti-Malware\mbamservice.exe [4317648 2016-12-14] (Malwarebytes) R2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [23808 2016-01-29] (Microsoft Corporation) R2 MyEpson Portal Service; C:\Program Files (x86)\EPSON\MyEpson Portal\mepService.exe [703696 2016-08-08] (SEIKO EPSON CORPORATION) R3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [374344 2016-01-29] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X] ===================== Drivers (Whitelisted) ====================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R1 ESProtectionDriver; C:\Windows\system32\drivers\mbae64.sys [77416 2016-12-14] () R2 MBAMChameleon; C:\Windows\system32\drivers\MBAMChameleon.sys [176064 2017-01-06] (Malwarebytes) R3 MBAMFarflt; C:\Windows\system32\drivers\farflt.sys [102856 2017-01-06] (Malwarebytes) R3 MBAMProtection; C:\Windows\system32\drivers\mbam.sys [43968 2017-01-06] (Malwarebytes) R0 MBAMSwissArmy; C:\Windows\System32\drivers\MBAMSwissArmy.sys [250816 2017-01-06] (Malwarebytes) R3 MBAMWebProtection; C:\Windows\system32\drivers\mwac.sys [81696 2017-01-06] (Malwarebytes) R0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [289120 2015-11-13] (Microsoft Corporation) R3 NisDrv; C:\Windows\System32\DRIVERS\NisDrvWFP.sys [133816 2015-11-13] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-01-06 20:46 - 2017-01-06 20:47 - 00008798 _____ C:\Users\jims-pc\Desktop\FRST.txt 2017-01-06 20:46 - 2017-01-06 20:46 - 02418176 _____ (Farbar) C:\Users\jims-pc\Desktop\FRST64.exe 2017-01-06 18:09 - 2017-01-06 20:32 - 00081696 _____ (Malwarebytes) C:\Windows\system32\Drivers\mwac.sys 2017-01-06 18:09 - 2017-01-06 19:31 - 00250816 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2017-01-06 18:09 - 2017-01-06 19:31 - 00102856 _____ (Malwarebytes) C:\Windows\system32\Drivers\farflt.sys 2017-01-06 18:09 - 2017-01-06 19:31 - 00043968 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2017-01-06 18:09 - 2017-01-06 18:09 - 00176064 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMChameleon.sys 2017-01-06 18:08 - 2017-01-06 18:08 - 00001867 _____ C:\Users\Public\Desktop\Malwarebytes.lnk 2017-01-06 18:08 - 2017-01-06 18:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes 2017-01-06 18:08 - 2017-01-06 18:08 - 00000000 ____D C:\Program Files\Malwarebytes 2017-01-06 18:08 - 2016-12-14 12:55 - 00077416 _____ C:\Windows\system32\Drivers\mbae64.sys 2017-01-04 21:23 - 2017-01-04 21:23 - 00022949 _____ C:\Users\jims-pc\Desktop\MTB.txt 2017-01-04 21:21 - 2017-01-04 21:21 - 00892416 _____ (Farbar) C:\Users\jims-pc\Desktop\MiniToolBox.exe 2017-01-03 09:39 - 2017-01-03 09:39 - 00012485 _____ C:\Users\jims-pc\Documents\2017 January goals.odt 2017-01-01 23:07 - 2017-01-01 23:07 - 00010347 _____ C:\Users\jims-pc\Documents\Re-setting the PLUSNET router.odt 2017-01-01 20:04 - 2017-01-01 20:04 - 00000000 ____D C:\Users\jims-pc\Documents\New folder 2016-12-29 12:02 - 2016-12-29 12:02 - 00133909 _____ C:\Users\jims-pc\Documents\aa organiser 2016.ods 2016-12-28 08:19 - 2016-12-28 08:19 - 00077010 _____ C:\Users\jims-pc\Desktop\glimate change 1.jpg 2016-12-28 06:29 - 2016-12-28 06:34 - 00161364 _____ C:\Users\jims-pc\Desktop\Timeline.jpg 2016-12-25 13:46 - 2016-12-25 13:46 - 00000000 _____ C:\History 2016-12-25 13:45 - 2016-12-25 13:54 - 00000000 ____D C:\ProgramData\Reimage Protector 2016-12-25 13:45 - 2016-12-25 13:45 - 00004282 _____ C:\Windows\System32\Tasks\ReimageUpdater 2016-12-25 13:44 - 2016-12-25 13:54 - 00000000 ____D C:\Program Files\Reimage 2016-12-25 13:44 - 2016-12-25 13:45 - 00000150 _____ C:\Windows\Reimage.ini 2016-12-19 08:42 - 2016-12-19 08:42 - 00035443 _____ C:\Users\jims-pc\Desktop\unnamed.jpg 2016-12-18 09:04 - 2017-01-05 03:25 - 00000617 _____ C:\Users\jims-pc\Desktop\clock.cgl_config 2016-12-18 05:13 - 2016-12-18 05:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TomTom 2016-12-15 13:49 - 2016-12-16 08:25 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2016-12-13 20:16 - 2016-12-13 20:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FullScreensavers.com 2016-12-13 20:15 - 2016-12-13 20:39 - 00000000 ____D C:\Program Files (x86)\FullScreensavers.com 2016-12-13 15:16 - 2016-12-13 15:16 - 00216057 _____ C:\Users\jims-pc\Documents\christmas card 2016 helens.odt 2016-12-11 12:19 - 2016-12-11 12:19 - 00001720 _____ C:\Users\Public\Desktop\Stellarium.lnk 2016-12-11 12:19 - 2016-12-11 12:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stellarium 2016-12-08 17:05 - 2016-12-08 17:05 - 00000967 _____ C:\Users\jims-pc\Desktop\SCARM.lnk ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2017-01-06 20:46 - 2016-11-16 15:43 - 00000000 ____D C:\Users\jims-pc\AppData\LocalLow\Mozilla 2017-01-06 20:46 - 2014-12-15 21:24 - 00000000 ____D C:\FRST 2017-01-06 20:10 - 2016-11-06 07:21 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2017-01-06 19:52 - 2016-03-13 00:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\EPSON Software 2017-01-06 19:52 - 2016-03-13 00:56 - 00000000 ____D C:\Program Files (x86)\EPSON Software 2017-01-06 19:51 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\inf 2017-01-06 19:38 - 2009-07-14 04:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2017-01-06 19:38 - 2009-07-14 04:45 - 00028944 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2017-01-06 19:34 - 2009-07-14 05:13 - 00781298 _____ C:\Windows\system32\PerfStringBackup.INI 2017-01-06 19:30 - 2009-07-14 05:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2017-01-06 18:08 - 2016-06-08 07:14 - 00000000 ____D C:\ProgramData\Malwarebytes 2017-01-06 16:32 - 2016-04-23 11:02 - 00000000 ____D C:\Users\jims-pc\Desktop\Dailies 2017-01-05 22:38 - 2016-03-12 11:16 - 00003942 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{859DB235-8B79-4F6A-A4FE-687A84F293B0} 2017-01-04 21:16 - 2016-03-12 11:20 - 00000000 ___RD C:\Users\jims-pc\Desktop\Daily Programs 2017-01-03 21:00 - 2016-03-12 15:26 - 00000000 ____D C:\Users\jims-pc\AppData\Roaming\vlc 2017-01-03 20:14 - 2016-03-13 23:16 - 00000000 ____D C:\Users\jims-pc\AppData\Local\Microsoft Games 2017-01-03 20:12 - 2016-06-18 07:54 - 00000000 ____D C:\Users\jims-pc\AppData\Local\GamesManager 2017-01-02 19:01 - 2016-10-16 21:46 - 00000000 ____D C:\Users\jims-pc\AppData\Roaming\Stellarium 2017-01-01 20:23 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\system32\NDF 2017-01-01 20:03 - 2016-03-12 11:01 - 00000000 ____D C:\Users\jims-pc 2017-01-01 20:02 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\registration 2017-01-01 20:01 - 2016-03-12 11:21 - 00000000 ___RD C:\Users\jims-pc\Desktop\jims folder 2016-12-29 01:14 - 2016-10-11 23:28 - 00000000 ____D C:\ProgramData\SCARM 2016-12-27 13:28 - 2016-06-08 08:13 - 00000194 _____ C:\Users\jims-pc\Desktop\Extreme Tech Support - Free PC Help.url 2016-12-26 13:47 - 2009-07-14 03:18 - 00000000 __SHD C:\$Recycle.Bin 2016-12-26 08:58 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\winsxs 2016-12-26 08:54 - 2010-11-21 03:47 - 00017266 _____ C:\Windows\PFRO.log 2016-12-25 00:46 - 2016-07-01 21:23 - 00000892 _____ C:\Windows\Tasks\Adobe Flash Player PPAPI Notifier.job 2016-12-18 05:13 - 2016-03-12 17:57 - 00000000 ____D C:\Program Files (x86)\TomTom HOME 2 2016-12-18 05:11 - 2016-03-12 13:35 - 00000000 ____D C:\Users\jims-pc\AppData\Local\Downloaded Installations 2016-12-17 01:01 - 2016-04-07 00:43 - 00003330 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2016-12-17 01:01 - 2016-04-07 00:43 - 00003202 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2016-12-16 08:25 - 2016-03-12 15:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2016-12-13 18:10 - 2016-11-06 07:21 - 00003768 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2016-12-13 18:10 - 2016-07-01 21:23 - 00003894 _____ C:\Windows\System32\Tasks\Adobe Flash Player PPAPI Notifier 2016-12-13 18:10 - 2016-03-12 15:04 - 00802904 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2016-12-13 18:10 - 2016-03-12 15:04 - 00144472 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2016-12-13 18:10 - 2016-03-12 15:04 - 00000000 ____D C:\Windows\SysWOW64\Macromed 2016-12-13 18:10 - 2016-03-12 15:04 - 00000000 ____D C:\Windows\system32\Macromed 2016-12-13 18:10 - 2009-07-14 03:20 - 00000000 ____D C:\Windows\SysWOW64 2016-12-12 13:22 - 2016-03-13 01:38 - 00000000 ____D C:\Users\jims-pc\AppData\Local\ElevatedDiagnostics 2016-12-11 12:20 - 2016-10-16 21:46 - 00000000 ____D C:\Users\jims-pc\AppData\Local\stellarium 2016-12-11 12:19 - 2016-10-16 21:45 - 00000000 ____D C:\Program Files\Stellarium 2016-12-10 21:18 - 2016-11-30 01:43 - 00016775 _____ C:\Users\jims-pc\Documents\December 2016 goals.odt 2016-12-08 17:05 - 2016-11-30 00:28 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SCARM 2016-12-08 17:05 - 2016-11-30 00:28 - 00000000 ____D C:\Program Files (x86)\SCARM 2016-12-08 12:34 - 2016-03-15 11:31 - 00000000 ____D C:\Users\jims-pc\.gimp-2.8 ==================== Files in the root of some directories ======= 2016-06-30 14:55 - 2016-06-30 14:55 - 0002107 _____ () C:\Users\jims-pc\AppData\Local\recently-used.xbel Some files in TEMP: ==================== C:\Users\jims-pc\AppData\Local\Temp\ReimagePackage.exe ==================== Bamital & volsnap ====================== (There is no automatic fix for files that do not pass verification.) C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2017-01-03 11:57 ==================== End of FRST.txt ============================ Quote
seedy21 Posted January 8, 2017 Posted January 8, 2017 Hi Jim, Step 1 We need to remove programs using "Add/Remove Programs" Click "Start" on the taskbar and then click on the "Control Panel" icon. Please double-click the "Add or Remove Programs" icon. A list of programs installed will be "populated" (this may take a bit of time). If they exist, uninstall the following by clicking on the below entries and selecting "Remove": Reimage Protector Additional instructions can be found here if needed. Step 2 Fix with Farbar Recovery Scan Tool This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable. Press the + R on your keyboard at the same time. Type Notepad and click OK. Copy the entire content of the codebox below and paste into the Notepad document: start CloseProcesses: Task: {9C9A49DD-9EDF-446F-BA31-CEFC5816EFC8} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X] C:\Program Files\Reimage C:\ProgramData\Reimage Protector C:\Windows\System32\Tasks\ReimageUpdater C:\Windows\Reimage.ini C:\Users\jims-pc\AppData\Local\Temp\ReimagePackage.exe EmptyTemp: end Click File, Save As and type fixlist.txt as the File Name. Both files, FRST and fixlist.txt have to be in the same location or the fix will not work! Right-click on icon and select Run as Administrator to start the tool. (XP users click run after receipt of Windows Security Warning - Open File). Press the Fix button just once and wait. If for some reason the tool needs a restart, please make sure you let the system restart normally. After that let the tool complete its run. When finished FRST will generate a log on the Desktop, called Fixlog.txt. Please post it to your reply. Step 3 Please re-run MalwareBytes and allow it to quarantine anything it finds this time. Step 4 https://sites.google.com/site/cannedfixes/roguekiller/RogueKiller.png Scan with RogueKiller Please download RogueKiller and save the file to your desktop. Temporary disable your AntiVirus and AntiSpyware protection - instructions here. Right-click on https://sites.google.com/site/cannedfixes/roguekiller/RogueKiller.png icon and select https://sites.google.com/site/cannedfixes/home/hosted-images-tools/RunAsAdmin.jpg Run as Administrator to start the tool. Wait patiently until the pre-scan will be done. It shouldn't take more than 2-3 minutes. Accept the Terms of use. When the Scan button becomes available, please click it. RogueKiller will start a full scan. Let this process run uninterrupted!. When finished, a Report button will become available. Click it. You will be presented with a logfile. Please include the content of this logfile in your next reply. Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted January 8, 2017 Author Posted January 8, 2017 Hi Jim, Step 1 We need to remove programs using "Add/Remove Programs" Click "Start" on the taskbar and then click on the "Control Panel" icon. Please double-click the "Add or Remove Programs" icon. A list of programs installed will be "populated" (this may take a bit of time). If they exist, uninstall the following by clicking on the below entries and selecting "Remove": Reimage Protector OK, done that bit Step 2 Fix with Farbar Recovery Scan Tool This fix was created for this user for use on that particular machine. Running it on another one may cause damage and render the system unstable. Press the + R on your keyboard at the same time. Type Notepad and click OK. I was Llost here. I did manage to open a notepad document and pasted in a copy of the listed instructions but unable to understand the rest of 'need to be in the same place' Copy the entire content of the codebox below and paste into the Notepad document: start CloseProcesses: Task: {9C9A49DD-9EDF-446F-BA31-CEFC5816EFC8} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X] C:\Program Files\Reimage C:\ProgramData\Reimage Protector C:\Windows\System32\Tasks\ReimageUpdater C:\Windows\Reimage.ini C:\Users\jims-pc\AppData\Local\Temp\ReimagePackage.exe EmptyTemp: end Click File, Save As and type fixlist.txt as the File Name. I was able to do this bit. Both files, FRST and fixlist.txt have to be in the same location or the fix will not work! Did not understand what the above meant jim Quote
mij Posted January 9, 2017 Author Posted January 9, 2017 I am a bit fresher this morning and think I sussed that the prog.s needed to be in the same location i.e. the desktop. The fixlog turned up ok but not any others. Two others files did show immediatly after FRST was run but not on the desktop where they were before. These programs (rogue and FRST) were run in the wrong order, I hope that is ok. I used the "delete" button at the end of rogue to get rid of the 'pups' and reimage even though it earliershowed as deleted. Jim Quote
mij Posted January 9, 2017 Author Posted January 9, 2017 I am a bit fresher this morning and think I sussed that the prog.s needed to be in the same location i.e. the desktop. The fixlog turned up ok but not any others. Two others files did show immediatly after FRST was run but not on the desktop where they were before. These programs (rogue and FRST) were run in the wrong order, I hope that is ok. I used the "delete" button at the end of rogue to get rid of the 'pups' and reimage even though it earliershowed as deleted. Jim There was a party here yesterday so am a bit at sixes and sevens. I think I have got the location of the two programs (FRST and Rogue) correct but I think I ran them in the wrong order. I hope that has not had too much effect. I forgot to put the file on my answer. Here it is. Jim Fix result of Farbar Recovery Scan Tool (x64) Version: 08-01-2017 Ran by jims-pc (09-01-2017 09:08:43) Run:2 Running from C:\Users\jims-pc\Desktop Loaded Profiles: jims-pc (Available Profiles: jims-pc) Boot Mode: Normal ============================================== fixlist content: ***************** start CloseProcesses: Task: {9C9A49DD-9EDF-446F-BA31-CEFC5816EFC8} - System32\Tasks\ReimageUpdater => C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe <==== ATTENTION S2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [X] C:\Program Files\Reimage C:\ProgramData\Reimage Protector C:\Windows\System32\Tasks\ReimageUpdater C:\Windows\Reimage.ini C:\Users\jims-pc\AppData\Local\Temp\ReimagePackage.exe EmptyTemp: end ***************** Processes closed successfully. HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9C9A49DD-9EDF-446F-BA31-CEFC5816EFC8} => key not found. ReimageRealTimeProtector => service not found. "C:\Program Files\Reimage" => not found. "C:\ProgramData\Reimage Protector" => not found. "C:\Windows\System32\Tasks\ReimageUpdater" => not found. "C:\Windows\Reimage.ini" => not found. C:\Users\jims-pc\AppData\Local\Temp\ReimagePackage.exe => moved successfully =========== EmptyTemp: ========== BITS transfer queue => 8388608 B DOMStore, IE Recovery, AppCache, Feeds Cache, Thumbcache, IconCache => 186778401 B Java, Flash, Steam htmlcache => 16469 B Windows/system/drivers => 187996055 B Edge => 0 B Chrome => 0 B Firefox => 400370582 B Opera => 0 B Temp, IE cache, history, cookies, recent: Users => 0 B Default => 0 B Public => 0 B ProgramData => 0 B systemprofile => 66356 B systemprofile32 => 66356 B LocalService => 66228 B NetworkService => 8657558 B jims-pc => 227293278 B RecycleBin => 119278079 B EmptyTemp: => 1.1 GB temporary data Removed. ================================ The system needed a reboot. ==== End of Fixlog 09:09:00 ==== Quote
seedy21 Posted January 9, 2017 Posted January 9, 2017 Hi Jim, Thanks it looks like you managed to run FRST correctly. Can you please re-run Rougekiller and post me the report it creates. Thanks Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted January 10, 2017 Author Posted January 10, 2017 Hi Seedy, sorry about the delay in answering but wasn't seeing the second page. Ok I have rerun roguekiller and exported a text report to the desktop where I will attach it to this post. There is nothing found as I deleted all the 'pups' and as I said the re-image which I thought was deleted using W7 control panel. jim RogueKiller V12.9.1.0 (x64) [Jan 2 2017] (Premium) by Adlice Software mail : http://www.adlice.com/contact/ Feedback : http://forum.adlice.com Website : http://www.adlice.com/download/roguekiller/ Blog : http://www.adlice.com Operating System : Windows 7 (6.1.7601 Service Pack 1) 64 bits version Started in : Normal mode User : jims-pc [Administrator] Started from : C:\Users\jims-pc\Desktop\RogueKillerX64.exe Mode : Scan -- Date : 01/09/2017 23:40:04 (Duration : 00:15:05) ¤¤¤ Processes : 0 ¤¤¤ ¤¤¤ Registry : 0 ¤¤¤ ¤¤¤ Tasks : 0 ¤¤¤ ¤¤¤ Files : 0 ¤¤¤ ¤¤¤ WMI : 0 ¤¤¤ ¤¤¤ Hosts File : 0 ¤¤¤ ¤¤¤ Antirootkit : 0 (Driver: Loaded) ¤¤¤ ¤¤¤ Web browsers : 0 ¤¤¤ ¤¤¤ MBR Check : ¤¤¤ +++++ PhysicalDrive0: ST1000DM003-1CH162 ATA Device +++++ --- User --- [MBR] 4749e1a2c376a0a559c52c112e97fa4b [bSP] 021c241e7dbd8cfb264d9cd470c1e03a : Windows Vista/7/8|VT.Unknown MBR Code Partition table: 0 - [ACTIVE] NTFS (0x7) [VISIBLE] Offset (sectors): 2048 | Size: 100 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 1 - [XXXXXX] NTFS (0x7) [VISIBLE] Offset (sectors): 206848 | Size: 953317 MB [Windows Vista/7/8 Bootstrap | Windows Vista/7/8 Bootloader] 2 - [XXXXXX] ACER (0x27) [VISIBLE] Offset (sectors): 1952600064 | Size: 450 MB User = LL1 ... OK User = LL2 ... OK Quote
seedy21 Posted January 11, 2017 Posted January 11, 2017 Hi Jim, Great job. How is the performance of the machine now? Are you still having internet issues? Thanks Quote “It's only after we've lost everything that we're free to do anything.”― Chuck Palahniuk, Fight Club http://www.geekstogo.com/downloads/unite_blue.png Need help with your computer problems? Then why not join Free PC Help. Register here If Free PC Help has helped you then please consider a donation. Click here We are all members helping other members.Please return here where you may be able to help someone else. After all, no one knows everything and you may have the answer that someone needs.
mij Posted January 11, 2017 Author Posted January 11, 2017 Hi Jim, Great job. How is the performance of the machine now? Are you still having internet issues? Thanks Hi Seedy, thanks for coming back to me on this. Yes, still getting the delay before seeing a youtube video. I have also lost the use of the printer. It just says something about the network not there. I have tried the printer set up but it says something about needing a W7 MS update, and of course it will not update. It just does not download anything. I have tried entering the guff on the new router but it's not accepting anything. jim. Quote
mij Posted January 12, 2017 Author Posted January 12, 2017 I have just changed search engine and browser to a Russian one, Yandex. It gives a dire warning that this site has malware on it. I wonder if that is correct or if something else is causing that. jim. Quote
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.