Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Random Browser dropouts especially on startup & eventviewer proble


  • Please log in to reply

#76
phickspc

phickspc

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 478 posts

================== Search Registry: "C97FCC79-E628-407D-AE68-A06AD6D8B4D1" ===========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}]

====== End of Search ======


  • 0

Advertisements


#77
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP

Get Process Explorer

https://live.sysinte...com/procexp.exe

Save it to your desktop then run it (Vista or Win7+ - right click and Run As Administrator).  

View, Select Column, check Verified Signer, OK
Options, Verify Image Signatures


Click twice on the CPU column header  to sort things by CPU usage with the big hitters at the top.  

Wait a full minute then:

File, Save As, Save.  Note the file name.   Open the file  on your desktop and copy and paste the text to a reply.

 

 

Can you capture the delay with Process Monitor?  Start Process Monitor then bring up a browser or start your VPN connection.  Stop the monitoring as soon as delay is over.  File Save As (use the default) call it delay. Then send it as before.


  • 0

#78
phickspc

phickspc

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 478 posts

ProcExplorerLogV2

 

1.I just had firefox open, launched PML, disabled LAN adaptor then re-enabled it, then launched a bookmark. Towards the end, the tab loaded the page title, but didn't display the page for another 2-3mins. Once it did, I stopped PML:

PML-LANDisableRe-EnableV1 -

 

2.Launched PML. Launched VPN, clicked to connect to a server I haven't connected to today. Waited until it connected to server then stopped PML:

PML-VPNEnableV1


Edited by phickspc, 24 November 2019 - 05:27 PM.

  • 0

#79
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP

Can you uninstall Sandboxie


  • 0

#80
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP

The second PML is only 2 minutes long.  Thought it would take longer.


  • 0

#81
phickspc

phickspc

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 478 posts

Duration of Network delay varies.

Do you know how I can backup any master settings for Sandboxie?


  • 0

#82
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP
I think it's sandboxie.ini   Location

Sandboxie looks for the file Sandboxie.ini in the following folders, in this order:

  • In the Windows folder: C:\WINDOWS on most Windows installation; C:\WINNT on Windows 2000
  • In the Sandboxie installation folder: Typically C:\Program Files\Sandboxie

  • 0

#83
phickspc

phickspc

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 478 posts

Uninstalled Sandboxie. Rebooted. Network Delay still present. Re-installed Sandboxie.


  • 0

#84
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP

Would be better to uninstall sandboxie, make a new Process Monitor log then reinstall.  I am trying to compare to a standard Win 7 setup and sandboxie changes everything.


  • 0

#85
phickspc

phickspc

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 478 posts

Uninstalled Sandboxie. 

Set PML to do bootlog. Rebooted. Waited until webpage loaded and then stopped/collected PML boot log:

PMLBootNoSndbxV1pt.1.zip

PMLBootNoSndbxV1pt.2.zip

 

Captured PML whilst disabling then re-enabling LAN Adaptor then loaded webpage:

PMLLANDisableRe-EnableNoSndbxV1.zip

 

Captured PML whilst connecting to VPN server, and then lading a webpage:

PMLVPNConnect&PageloadV1.zip

 

Re-installed Sandboxie.


  • 0

Advertisements


#86
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP

Do you know what program is responsible for:

 

C:\PortPFs\INET\FFx\Stabl\Data\profile\extensions\{8fbc7259-8015-4172-9af1-20e1edfbbd3a}.xpi  ?

 

FF spends most of its time looking in things hiding in C:\PortPFs\INET\FFx\Stabl\Data

 

It also wastes a lot of time searching through fonts.  Do you have a nonstandard theme or font set?


  • 0

#87
phickspc

phickspc

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 478 posts

{8fbc7259-8015-4172-9af1-20e1edfbbd3a}.xpi is a 'Recommended' addon to change colours of page to make things comfortable to for my eyes at night:

https://addons.mozil...tum/?src=search

 

No special fonts configured.

This is my fav Dark Theme, it's tiny and uncomplicated: https://addons.mozil...-we/?src=search

 

Also, I tried an older Firefox (52) which was much slower with more addons, for years, but it still loaded pages. But remember ever since the network delay the pages don't load on any of firefoxes or Internet Explorer until the delay is finished.


  • 0

#88
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP

Can I see the file:  C:\Windows\inf\setupapi.app.log

 

Mine doesn't write to this file and I'm wondering why yours does.


  • 0

#89
phickspc

phickspc

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 478 posts

I see a few versions of the file. They started in 2016. But the most recent updated one started in 2018, but was only updated up to yesterday. But I'm logged into day, and the internet delay occurred today at bootup, so if this file was responsible for the delay it should have updated today right?

 

Regardless, I googled searched the first 2 lines of the log adding quotation marks to narrow the search for the keyword: "[Device Install Log] OS Version = 6.1.7601"

and this article came up:

https://lb.raspberry...ic.php?t=180222

Not sure what it means.


Edited by phickspc, 27 November 2019 - 08:41 AM.

  • 0

#90
RKinner

RKinner

    Malware Expert

  • Expert
  • 23,140 posts
  • MVP

Logs are sequentially written so the stuff at the top is very old.  We are interested in the latest stuff  which we be at the bottom.


  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP