Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

windows pc popups to backup, advertisement windows popus while surfing


  • Please log in to reply

#31
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

Even If I find the file, I have to replace it with your copy?

 

When I search for dxg in the drivers folder, I do find the file dxgkrnl.sys.

 

If I click properties, details:

 

fileversion: 6.3.9600.17415

productversion: 6.3.9600.17415

 

changed on date: 29-10-2014 04:57

 

ADDEd: it has the same filesize and properties as your copy. Do I still have to try to copy it?


Edited by HaraMo, 26 July 2015 - 12:28 PM.

  • 0

Advertisements


#32
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,024 posts
  • MVP

No.  If it appears to be the same file then there is either a permission issue or a mistake in the registry so that it is not looking in the correct location for the file.  right click on it and check the properties then the security tab.  Verify that System, Administrators and  User can read and execute.  Trusted Installer should have full control.  IF that seems normal then open an elevated command prompt (search for cmd then right click and Run As Admin).  Copy the following 2 lines and paste them into your elevated command window:

 

reg query "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DXGKrnl" > \junk.txt
notepad \junk.txt

 

Hit enter if notepad does not open.  Copy and paste the text from notepad into a reply.  It should look something like this:

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DXGKrnl
    DisplayName    REG_SZ    LDDM Graphics Subsystem
    Group    REG_SZ    Video Init
    ImagePath    REG_EXPAND_SZ    \SystemRoot\System32\drivers\dxgkrnl.sys
    Description    REG_SZ    Controls the underlying video driver stacks to provide fully-featured display capabilities.
    ErrorControl    REG_DWORD    0x0
    Start    REG_DWORD    0x3
    Tag    REG_DWORD    0x1
    Type    REG_DWORD    0x1

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DXGKrnl\Enum

 

Does your Image Path say the same as mine?

 

 

 


  • 0

#33
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

Only difference is dates if I match it to your copy. Strange that my changed date is previous then my made date?

 

made:  Wednesday 15-07-2015, 10:06:20

changed: 29-10-2014 04:57:39

latest opened: 15-07-2015 10:06:20

 

Your file has another date made: Tuesday 28-10-2014 22:57:40

changed: 26-07-2015

latest opened: 28-10-204 22:57:40

 

security tab is normal.

 

I will proceed with the  step


Edited by HaraMo, 26 July 2015 - 01:14 PM.

  • 0

#34
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

Image path is same yes:

 

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\DXGKrnl
    DisplayName    REG_SZ    LDDM Graphics Subsystem
    ErrorControl    REG_DWORD    0x0
    Group    REG_SZ    Video Init
    ImagePath    REG_EXPAND_SZ    \SystemRoot\System32\drivers\dxgkrnl.sys
    Start    REG_DWORD    0x3
    Tag    REG_DWORD    0x1
    Type    REG_DWORD    0x1
    Description    REG_SZ    Controls the underlying video driver stacks to provide fully-featured display capabilities.


  • 0

#35
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,024 posts
  • MVP

In the properties there is a Digital Certificate tab.  If I look at mine it expires 10/1/2015.  I wonder if yours could have expired?

 

My version number on the file is 6.3.9600.17415.  May not be the latest.  I only use the Win 8 as a DVR.


  • 0

#36
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,024 posts
  • MVP

Search for cmd and it should find cmd.exe right click and Open As Administrator then type (with an enter after the line):

sc  query  dxgkrnl

If it is not running then try:

sc  start  dxgkrnl

If it is running then maybe something we have done has fixed the error.


  • 0

#37
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

first oktober 2015 expire date

 

Same fileversion as mentioned before


Edited by HaraMo, 26 July 2015 - 01:48 PM.

  • 0

#38
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

It's running:

 

Microsoft Windows [Version 6.3.9600]
© 2013 Microsoft Corporation. Alle rechten voorbehouden.

C:\WINDOWS\system32>sc query dxgkrnl

SERVICE_NAME: dxgkrnl
        TYPE               : 1  KERNEL_DRIVER
        STATE              : 4  RUNNING
                                (STOPPABLE, NOT_PAUSABLE, IGNORES_SHUTDOWN)
        WIN32_EXIT_CODE    : 0  (0x0)
        SERVICE_EXIT_CODE  : 0  (0x0)
        CHECKPOINT         : 0x0
        WAIT_HINT          : 0x0

C:\WINDOWS\system32>


  • 0

#39
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,024 posts
  • MVP

OK.  I wonder if the boot log would show it starting now?  Does it still take too long to boot?


  • 0

#40
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

only strange happening:

 

like now: I installed teamviewer, suddenly, while installing, system does not react, even the mouse icon (blue circle) does not move or turn.

 

a minute later, windows IE pops up( as I have try to start it to see if something else is working). and teamviewer window appear that instalation is finished.

 

After this I go to control panel, click on security then windows update, then circle icon of mouse keeps turning, but windows update does not open. I then tried open IE, it opens immediatelly.

 

Now i want to add a language to OS, everything goes great, until I double click the englisch (Engeland) language to add, then circle keeps moving.

 

If I go back to windows update, it still does not start, the mouse icon keeps circling

 

No the language window and  control panel (security) are frozen...

 

ADDED: still mouse icon is circling, but only on the language window. the configuration panel (security) doe not react at all, I don't even see the mouse icon if I pass this window.

 

ADDEd: now i can move the mouse on the window (Arrow icon) , and want to close it, (red topcorner lights up) but windows stay open... and mouse still circling at the language window.

 

 

ADDED:strange, I took my iPhone usb cable (was charging my iPhone) , then went to see if window is free again, now the language windows has added the english lanuage , I close it by clicking ok.

 

but control panel (security) still stays open, does not react on mouse clicking

 

ADDED: I don't long how long it took but max 20 min, but windows update windows has appear.

 

After language was added I also heard processor slowing down... .

 

Do I have to worry? it's not an old laptop..  :-(

 

ADDED: then I click on 'change settings (to see the windows update settings), then it takes again a while... pfff

 

I rebooted the system, see if this helps and also to answer your question :

 

I had rebooted several times, and this time was the slowest time. strange no? 3 minutes to restart.

 

Maybe ok?


Edited by HaraMo, 26 July 2015 - 02:35 PM.

  • 0

Advertisements


#41
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,024 posts
  • MVP

Reboot once more but first erase the old ntbtlog.txt file and let's see if it makes a new log.  We may need to turn off the logging.  Not sure how it works on Win 8.

 

It sounds like some process is taking all of the CPU time so that nothing else can work. 

 

Get Process Explorer

http://live.sysinter...com/procexp.exe
Save it to your desktop then run it (Vista or Win7 - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Open the file Procexp.txt on your desktop and copy and paste the text to a reply.
 


  • 0

#42
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

pff , after reboot, i don't see McAfee icon anymore in the bottom, checking msconfig, all services are stopped, I think some services of McAfee were already stopped but this time all of them?


  • 0

#43
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

deleted the file ntbtlog.txt  rebooted: closing went faster, opening also little bit faster.

 

McAfee still not starting.

 

the file ntbtlog.txt is not anymore to find in windows folder.

 

I do have to add that since the prevoious slow boot, after laptop starts and loads windows, black screen appears, but this time the black screen did not stay that long as in the previous reboot.


Edited by HaraMo, 26 July 2015 - 02:51 PM.

  • 0

#44
RKinner

RKinner

    Malware Expert

  • Expert
  • 20,024 posts
  • MVP

The black screen is usually the loading of the video card so perhaps a newer video driver would help.  

 

IF McAfee is broken then you need to reinstall it (if you must have it.  It's not the best anti-virus.  Even the free Avast is better.)

 

Apparently you have to go back into the boot menu and turn on the boot log in order to get the ntbtlog.txt file to show up.  On Win 7 once you turn it on it keeps on logging each boot.


  • 0

#45
HaraMo

HaraMo

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 329 posts

Process CPU Private Bytes Working Set PID Description Company Name Verified Signer
System Idle Process 97.44 0 K 4 K 0   
procexp64.exe 1.46 27 344 K 51 980 K 4792 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
Interrupts 0.33 0 K 0 K n/a Hardware Interrupts and DPCs  
dwm.exe 0.26 14 360 K 25 476 K 992 Beheer van bureaubladvensters Microsoft Corporation (Verified) Microsoft Windows
csrss.exe 0.16 2 280 K 33 956 K 672 Runtimeproces voor client-server Microsoft Corporation (Verified) Microsoft Windows Publisher
mbam.exe 0.12 27 184 K 47 484 K 2892 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
McAPExe.exe 0.08 2 032 K 6 116 K 3792 McAfee Access Protection McAfee, Inc. (Verified) McAfee
System 0.07 148 K 19 804 K 4   
LMS.exe 0.01 1 104 K 4 380 K 6428 Local Manageability Service Intel Corporation (Verified) Intel Corporation
svchost.exe 0.01 5 016 K 11 592 K 848 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
TeamViewer_Service.exe 0.01 6 192 K 15 856 K 780 TeamViewer 10 TeamViewer GmbH (Verified) TeamViewer
Toshiba.Tempro.UI.CommonNotifier.exe 0.01 28 528 K 8 360 K 5816 Toshiba TEMPRO Toshiba Europe GmbH (Verified) Toshiba Europe GmbH
explorer.exe 0.01 51 780 K 102 472 K 2160 Windows Verkenner Microsoft Corporation (Verified) Microsoft Windows
iPodService.exe < 0.01 1 928 K 6 176 K 7028 iPodService Module (64-bit) Apple Inc. (Verified) Apple Inc.
TPCHWMsg.exe < 0.01 1 912 K 7 208 K 5820 TOSHIBA PC Health Monitor TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
AppleMobileDeviceService.exe < 0.01 3 040 K 9 872 K 1796 MobileDeviceService Apple Inc. (Verified) Apple Inc.
dts_apo_service.exe < 0.01 17 320 K 20 340 K 1916 dts_apo_service  (Verified) DTS
daemonu.exe < 0.01 5 976 K 9 080 K 6808 NVIDIA Settings Update Manager NVIDIA Corporation (Verified) NVIDIA Corporation
GFNEXSrv.exe < 0.01 1 692 K 5 752 K 1448 GFNEXSrv  (Verified) TOSHIBA CORPORATION
mstsc.exe < 0.01 34 560 K 49 684 K 5844 Verbinding met extern bureaublad Microsoft Corporation (Verified) Microsoft Windows
tv_w32.exe < 0.01 1 128 K 5 036 K 6220 TeamViewer 10 TeamViewer GmbH (Verified) TeamViewer
tv_x64.exe < 0.01 1 140 K 4 820 K 6704 TeamViewer 10 TeamViewer GmbH (Verified) TeamViewer
officeclicktorun.exe < 0.01 30 616 K 37 828 K 1872 Microsoft Office Click-to-Run Microsoft Corporation (Verified) Microsoft Corporation
svchost.exe < 0.01 63 968 K 76 712 K 420 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
SynTPEnh.exe < 0.01 3 692 K 14 588 K 5132 Synaptics TouchPad 64-bit Enhancements Synaptics Incorporated (Verified) Synaptics Incorporated
lsass.exe < 0.01 4 948 K 12 060 K 776 Local Security Authority Process Microsoft Corporation (Verified) Microsoft Windows Publisher
TeamViewer.exe < 0.01 12 188 K 33 888 K 5836 TeamViewer 10 TeamViewer GmbH (Verified) TeamViewer
iTunesHelper.exe < 0.01 3 944 K 12 660 K 5676 iTunesHelper Apple Inc. (Verified) Apple Inc.
nvvsvc.exe < 0.01 4 792 K 13 440 K 228 NVIDIA Driver Helper Service, Version 327.65 NVIDIA Corporation (Verified) NVIDIA Corporation
csrss.exe < 0.01 2 000 K 6 556 K 580 Runtimeproces voor client-server Microsoft Corporation (Verified) Microsoft Windows Publisher
TODDSrv.exe < 0.01 1 048 K 4 344 K 3716 TDCSrv Application TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
svchost.exe < 0.01 19 452 K 36 732 K 516 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
stacsv64.exe < 0.01 4 536 K 7 364 K 1036 IDT PC Audio IDT, Inc. (Geen handtekening aanwezig in het onderwerp) IDT, Inc.
wmpnetwk.exe  5 744 K 17 780 K 2308 Windows Media Player Network Sharing-service Microsoft Corporation (Verified) Microsoft Windows
WmiPrvSE.exe  2 516 K 6 836 K 4708 WMI Provider Host Microsoft Corporation (Verified) Microsoft Windows
winlogon.exe  1 416 K 8 348 K 724 Toepassing Windows-aanmelden Microsoft Corporation (Verified) Microsoft Windows
wininit.exe  888 K 4 008 K 680 Windows Toepassing Opstarten Microsoft Corporation (Verified) Microsoft Windows
unsecapp.exe  1 044 K 4 536 K 5172 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation (Verified) Microsoft Windows
UNS.exe  3 216 K 10 820 K 4832 User Notification Service Intel Corporation (Verified) Intel Corporation
TPCHSrv.exe  2 312 K 6 960 K 2984 TOSHIBA PC Health Monitor TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
TecoService.exe  2 312 K 7 992 K 3984 TOSHIBA eco Utility Service TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
TecoResident.exe  1 592 K 5 916 K 5884 Resident module of eco Utility TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
TCrdMain_Win8.exe  3 284 K 11 972 K 6116 TOSHIBA Function Key Main Module TOSHIBA Corporation (Verified) TOSHIBA CORPORATION
taskhostex.exe  11 228 K 17 660 K 1396 Hostproces voor Windows-taken Microsoft Corporation (Verified) Microsoft Windows
SynTPHelper.exe  712 K 3 244 K 7064 Synaptics Pointing Device Helper Synaptics Incorporated (Verified) Synaptics Incorporated
svchost.exe  15 484 K 20 096 K 1696 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe  7 720 K 12 084 K 592 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe  4 000 K 8 088 K 876 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe  6 524 K 13 676 K 1244 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe  3 524 K 10 564 K 1680 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe  16 404 K 22 680 K 404 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe  628 K 2 812 K 916 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
svchost.exe  1 708 K 4 816 K 7036 Hostproces voor Windows-services Microsoft Corporation (Verified) Microsoft Windows Publisher
SpotifyWebHelper.exe  1 444 K 5 424 K 7016 SpotifyWebHelper Spotify Ltd (Verified) Spotify AB
spoolsv.exe  3 280 K 9 432 K 1620 App voor Spooler-subsysteem Microsoft Corporation (Verified) Microsoft Windows
smss.exe  280 K 1 044 K 352 Windows-sessiebeheer Microsoft Corporation (Verified) Microsoft Windows Publisher
services.exe  3 832 K 7 472 K 768 Services en controller-app Microsoft Corporation (Verified) Microsoft Windows Publisher
SearchProtocolHost.exe  2 116 K 7 976 K 1820 Microsoft Windows Search Protocol Host Microsoft Corporation (Verified) Microsoft Windows
SearchIndexer.exe  25 104 K 22 212 K 3308 Indexeerfunctie van Microsoft Windows Search Microsoft Corporation (Verified) Microsoft Windows
SearchFilterHost.exe  1 680 K 5 368 K 6380 Microsoft Windows Search Filter Host Microsoft Corporation (Verified) Microsoft Windows
readLM.exe  1 500 K 6 256 K 6672 readLM TOSHIBA (Verified) TOSHIBA CORPORATION
procexp.exe  2 280 K 7 616 K 6168 Sysinternals Process Explorer Sysinternals - www.sysinternals.com (Verified) Microsoft Corporation
nvxdsync.exe  6 220 K 17 216 K 268 NVIDIA User Experience Driver Component NVIDIA Corporation (Verified) NVIDIA Corporation
nvvsvc.exe  2 076 K 7 204 K 1008 NVIDIA Driver Helper Service, Version 327.65 NVIDIA Corporation (Verified) NVIDIA Corporation
nvtray.exe  2 084 K 7 368 K 3060 NVIDIA Settings NVIDIA Corporation (Verified) NVIDIA Corporation
mfevtps.exe  2 468 K 6 484 K 2712 McAfee Process Validation Service McAfee, Inc. (Verified) McAfee
mfevtps.exe  856 K 3 272 K 2668 McAfee Process Validation Service McAfee, Inc. (Verified) McAfee
mfemms.exe  1 192 K 4 148 K 2560 McAfee Management Service McAfee, Inc. (Verified) McAfee
mfefire.exe  1 772 K 6 100 K 2820 McAfee Core Firewall Service McAfee, Inc. (Verified) McAfee
mfefire.exe  712 K 3 120 K 3844 McAfee Core Firewall Service McAfee, Inc. (Verified) McAfee
mDNSResponder.exe  1 404 K 4 892 K 1828 Bonjour Service Apple Inc. (Verified) Apple Inc.
McUICnt.exe  8 524 K 21 612 K 6472 McAfee McAfee, Inc. (Verified) McAfee
McSvHost.exe  35 320 K 4 996 K 3392 McAfee Service Host McAfee, Inc. (Verified) McAfee
mcshield.exe  136 164 K 137 708 K 2768 McAfee Scanner service McAfee, Inc. (Verified) McAfee
McCSPServiceHost.exe  3 384 K 10 908 K 6056 McAfee CSP Service Host McAfee, Inc. (Verified) McAfee
mbamservice.exe  253 968 K 9 956 K 2520 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
mbamscheduler.exe  4 324 K 10 052 K 2196 Malwarebytes Anti-Malware Malwarebytes Corporation (Verified) Malwarebytes Corporation
Jhi_service.exe  1 056 K 4 584 K 1372 Intel® Dynamic Application Loader Host Interface Intel Corporation (Verified) Intel Corporation
IntelMeFWService.exe  832 K 3 788 K 2496 Intel® ME Service Intel Corporation (Verified) Intel Corporation
igfxtray.exe  1 492 K 6 144 K 5528 igfxTray Module Intel Corporation (Verified) Intel Corporation - pGFX
igfxsrvc.exe  2 204 K 6 536 K 5892 igfxsrvc Module Intel Corporation (Verified) Intel Corporation - pGFX
igfxpers.exe  1 680 K 6 948 K 5736 persistence Module Intel Corporation (Verified) Intel Corporation - pGFX
ICCProxy.exe  1 240 K 5 240 K 6400 Intel® Integrated Clock Controller Service - Intel® ICCS Intel Corporation (Verified) Intel Corporation
hkcmd.exe  1 488 K 6 132 K 5668 hkcmd Module Intel Corporation (Verified) Intel Corporation - pGFX
HeciServer.exe  1 196 K 5 256 K 1264 Intel® Capability Licensing Service Interface Intel® Corporation (Verified) Intel® Upgrade Service
dd.exe  3 684 K 10 088 K 5244   (Verified) HEMA BV
dasHost.exe  840 K 3 852 K 1924 Device Association Framework Provider Host Microsoft Corporation (Verified) Microsoft Windows
audiodg.exe  6 936 K 10 288 K 6532 Grafiekisolatie voor Windows-audioapparaten Microsoft Corporation (Verified) Microsoft Windows
AmIcoSinglun64.exe  1 316 K 5 540 K 6796 Single LUN Icon Utility for VID 058F PID 6366 Alcor Micro Corp. (Geen handtekening aanwezig in het onderwerp) Alcor Micro Corp.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP