Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

NT Kernel & System

NT Kernel

  • Please log in to reply

#46
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

Did you make the ownership/permission changes on both Keys? - Yes - then restarted, Remote Access and Internet Access work

 

HKEY_CLASSES_ROOT\CLSID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5}

 

and

 

 HKEY_CLASSES_ROOT\AppID\{AB8902B4-09CA-4bb6-B78D-A8F59079A8D5} ?

 

Apparently you have two computers with the same name on your network.  Do you know which computer is 192.168.1.3?  Sometimes if you have two interfaces active on one computer you will get this error.

 

Interesting discovery.  I bought two of these computers on Ebay refurbished in 2016 and 2018  - looks like these two have that same name(Also have a computer I bought in 2013 When I checked Speccy they both have the same name - the NETBIOS and DNS name - MININT-OEST1FQ

 

Found this at services.msc - Windows Driver Foundation User Mode, right click on it and select Properties then change the startup to 2 - but could not see where to change startup - Picture attached

 

Looks like Adobe is running ok now.

 

System runs faster with each change - very quick to boot and quick to access the internet.  Thanks!

 

Attached Thumbnails

  • Windows Driver Foundation User mode Driver Framework.PNG

  • 0

Advertisements


#47
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Typo:  Should have been Startup Type: and you change it to Automatic but yours is already set to Automatic so that's not the problem.

 

See if you still have the problem:

 

First clear the alarms:

 

Right click on (My) Computer and select Manage (Continue) Then click on the arrow in front of Event Viewer. Next Click on the arrow in front of Windows Logs Right click on System and Clear Log, Clear. Repeat for Application.

Then Reboot.

 

Wait a few minutes and run VEW as before and let's see if we have any errors.


  • 0

#48
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

I wanted to see how well the computer was performing and I ran the Performance Troubleshooter.  It said that "Superfetch" was off and it turned it on.  Wanted to know if you thought it should be off?

 

Also do you recommend I change the name of this computer so it does not conflict?  It has two names - the one in System that is attached and another name "E6540" that I see when I push the Start button.

 

Files attached as requested from VEW

 

Thanks for your help

 

Vino's Event Viewer v01c run on Windows 2008 in English
Report run at 01/12/2020 7:25:37 PM

Note: All dates below are in the format dd/mm/yyyy

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Critical Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Error Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 02/12/2020 12:18:45 AM
Type: Error Category: 0
Event: 10010 Source: Microsoft-Windows-DistributedCOM
The server {E10F6C3A-F1AE-4ADC-AA9D-2FE65525666E} did not register with DCOM within the required timeout.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
'System' Log - Warning Type
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Log: 'System' Date/Time: 02/12/2020 12:19:22 AM
Type: Warning Category: 0
Event: 27 Source: e1dexpress
Intel® Ethernet Connection I217-LM  Network link is disconnected.

Log: 'System' Date/Time: 02/12/2020 12:19:20 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WUDFRd failed to load for the device USB\VID_0A5C&PID_5802&MI_03\7&95fd152&0&0003.

Log: 'System' Date/Time: 02/12/2020 12:19:20 AM
Type: Warning Category: 212
Event: 219 Source: Microsoft-Windows-Kernel-PnP
The driver \Driver\WUDFRd failed to load for the device USB\VID_0A5C&PID_5802&MI_01\7&95fd152&0&0001.

Log: 'System' Date/Time: 02/12/2020 12:18:49 AM
Type: Warning Category: 0
Event: 4001 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN AutoConfig service has successfully stopped.

Log: 'System' Date/Time: 02/12/2020 12:18:49 AM
Type: Warning Category: 0
Event: 10002 Source: Microsoft-Windows-WLAN-AutoConfig
WLAN Extensibility Module has stopped.  Module Path: C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\ihvs\AthIHVManager.dll


 

Attached Thumbnails

  • Superfetch1201201917.PNG
  • System Info 1201201934.PNG

  • 0

#49
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

I also wanted to mentioned I have a "Dell Unified Wireless Suite" that starts up when I reboot.  I always turn it off.  Thought it was related to internet access but seems like it is unrelated.

Attached Thumbnails

  • Dell Unified Wireless Suite.PNG

Edited by joseph456, 01 December 2020 - 06:39 PM.

  • 0

#50
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Superfetch is supposed to speed up the PC.  My experience is that it does not and often slows the PC down by using too much CPU.  I leave sysmain set to Manual or Disabled on my PCs.

 

Might be better to change the name of the other PC if this one has to connect to work.   Or you can just live with it especially if you turn off NetBT.

 

The "Dell Unified Wireless Suite" is supposed to automatically turn off wireless if you connect via a cable.  Rumor has it that it doesn't work that well so if you aren't using it then uninstall it.


 


  • 0

#51
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

Set SysMain to Manual.

 

Have I turned of NetBT or if not how do I turn it off?

 

Can I just turn off Dell Unified Wireless Suite in case I need it in the future?  How do I do that?

 

Does changing the name of the other computer have any impact on anything it is doing?  Do I just change it using "Change Settings?"

 

Thanks.


  • 0

#52
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Doesn't look like NetBT is on since it is not complaining about another computer with the same name unless you have turned the other computer off. 

 

Shouldn't make any difference what the thing is called.  I just don't like to change things with work computers.

 

As for the dell thing;

 

It appears to be these two services:

 

R3 AthNetAgent; C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\Agent\AthNetAgent.exe [168760 2015-02-27] (Qualcomm Atheros -> Quacomm Atheros, Inc.) [File not signed]
R3 DCDhcpService; C:\Program Files (x86)\Dell\Dell Unified Wireless Suite\DirectConnect\DCDhcpService.exe [197944 2015-02-27] (Qualcomm Atheros -> Qualcomm Atheros Inc.) [File not signed]

 

So you can probably Search for:

services.msc

hit Enter

 

I assume they are labeled Dell Unified Wireless something rather than Athnet... & DHDhcp... but I don't know for sure.  If you can find them you can probably change the Startup Type: to Disabled which should keep them from starting.  I think they are currently set to Manual.

 

Another way to stop them would be to search for

msconfig

hit Enter then under the Service tab see if you can find the two entries.  Uncheck the box and OK.  They should not bother you on the reboot. 

 

Otherwise they are in the registry under:

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\AthNetAgent

and

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\DCDhcpService

 

You would need to change the Start for each of them from 3 to 4.


  • 0

#53
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

I just use this personal computer to remote access my work computer.

 

Think I found the startup programs in CC Cleaner.  Should I just turn them off there?

 

Also attaching the registry cleaner scan from CC Cleaner.  Looks like the files it is looking to clean are related to previous programs that were deleted.  Think it would be ok to delete these?

 

Curious question - noticed that System Restore only has one entry from 12:15 today.  Any idea how I could be deleting the previous ones?.  Usually see 6 or 7 entries on there.

Attached Thumbnails

  • CC Cleaner Startup Windows.PNG

Attached Files


  • 0

#54
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Looks like there are actually three entries for the Suite.  I suppose CCleaner will work.  I assume it just turns them off rather than removing them altogether.

 

I'm not real fond of registry cleaners.  Seen too many systems messed up by them but that being said it does appear that these are all related to programs you have removed.  I assume it backs up what it removes so if things go South you can revert back?


  • 0

#55
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

Disabled the three entries.

 

Restarted - Unified Wireless did not start up

 

Backed up the registry entries and deleted them.

 

Restarted in 25 seconds!


Edited by joseph456, 01 December 2020 - 09:28 PM.

  • 0

Advertisements


#56
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

I think that's about as good as it is going to get.  Time to clean up:

 

Time to clean up:
If we used FRST to clean your PC:

right click on FRST.exe or FRST64.exe (whichever you used) and rename it to uninstall.exe.  Then right click on uninstall.exe and Run as Admin.

 
If we installed Speccy it needs to be uninstalled.  Ditto for Latency Monitor.  Process Explorer, VEW,  and their logs and Speccy's log can just be deleted.

Also make sure you have the latest versions of any adobe.com products you use like Shockwave, Flash or Acrobat.  Flash is now the most malware targeted program so it must be kept up to date. Flash is officially obsolete and should be uninstalled.   Be careful with Adobe.  They are fond of offering optional downloads like yahoo or Ask toolbars or that worthless McAfee Security Scan.  Go slow and uncheck the optional stuff.

Whether you use adobe reader, acrobat or fox-it to read pdf files you need to disable Javascript in the program.  There is an exploit out there now that can use it to get on your PC.  For Adobe Reader:  Start, All Programs, Adobe Reader, Edit, Preferences, Click on Javascript in the left column and uncheck Enable Acrobat Javascript.  OK Close program.  It's the same for Foxit reader except you uncheck Enable Javascript Actions.


If you use Chrome/Firefox/Edge then get the Ublock Origin extension.  For IE go to adblockplus.org  and get the program.
If Chrome/Firefox is slow loading make sure it only has the current Java add-on.  Then download and run Speedy Fox.
http://www.crystalidea.com/speedyfox. Close Chrome/Firefox/Skpe. Hit Optimize.   You can run it any time that Chrome/Firefox seems slow starting..
(If it complains about Chrome still running you can stop it with Task Manager or go into Chrome then go to:

chrome://settings/

Hit Advanced at the bottom of the page then scroll down to near the bottom where it says System.

Change
Continue running background apps when Google Chrome is closed
to Off (slide the blue thing to the left and it turns brown)
Close Chrome.


If the browser is still slow then go in and disable all of your extensions, close the browser and Optimize with SpeedyFox then restart the browser.  If that helps then one or more of your extensions is at fault.  Go back in and turn them on one at a time and see if you can figure out which ones slow things down the most.

If you are a Facebook user get the FB Purity extension for your browser:
http://www.fbpurity.com/
This will stop all of the suggested pages and ads so that Facebook loads much quicker.


Be warned:  If you use Limewire, utorrent or any of the other P2P programs you will probably be coming back to the Malware Removal forum.  If you must use P2P then submit any files you get to http://virustotal.combeforeyou open them.

Due to a recent rise in the number of Crytolocker infections I am now recommending you install:

https://www.bleeping...somware/dl/306/
It's currently a free version.

If you have a router, log on to it today and change the default password!  If using a Wireless router you really should be using encryption on the link.  Use the strongest (newest) encryption method that your router and PC wireless adapter support especially if you own a business.
If you don't know how, visit the router maker's website.  They all have detailed step by step instructions or a wizard you can download.

Special note on Java.  Old Java versions should be removed after first clearing the Java Cache by following the instructions in:
http://www.java.com/...lugin_cache.xml
Then remove the old versions by going to Control Panel, Programs and Features and Uninstall all Java programs which are not the latest.  If in doubt uninstall all.  These may call themselves: Java Runtime, Runtime Environment, Runtime, JRE, Java Virtual Machine, Virtual Machine, Java VM, JVM, VM, J2RE, J2SE.  Get the latest version from Java.com.  They will usually attempt to foist some garbage like the Ask toolbar, Yahoo toolbar or McAfee Security Scan on you as part of the download.  Just uncheck the garbage before the download (or install) starts.  If you use a 64-bit browser and want the 64-bit version of Java you need to use it to visit java.com.
Due to multiple security problems with Java we are now recommending that it not be installed unless you absolutely know you need it.  IF that is the case then go to Control Panel, Java, Security and slide it up to the highest level.  OK.

If you are running Win 10 you probably want Classic Shell:  http://www.classicshell.net/ This program will make Win 10 act like Win 7 with the same controls you are used to.



Recommended software: (I'm not saying you should download these just that if you have a need for a new program these are safe and work)  
Compression:  7-zip.  Avoid WinRar and WinZip as the free versions have adware.
Video Player:  VLC  Unlike Windows Media Player it never seems to need extra files to work.
Office like free program:  Open Office: https://www.openoffice.org/download/
or
LibreOffice: https://www.libreoffice.org/
Free Anti-Virus:  Avast
Free Malware prevention:  MBAM: Free version at https://www.malwareb...m/mwb-download/
Can run with your anti-virus.
Paid Anti-Virus:  Kaspersky or BitDefender
Utilities:
Root Kit Detector:  MBAR: https://www.malwareb...om/antirootkit/
Process Explorer:  Show you what is running on the PC.  Like Task manager but better:  http://live.sysinter...com/procexp.exe
WhoCrashed: Why did your system crash?
http://www.resplendence.com/downloads
Then click on Download free home edition
where it says:
WhoCrashed 5.51
Comprehensible crash dump analysis tool
for Windows 10/8.1/8/7/Vista/XP/2012/2008/2003 (x86 and x64)
System Health:
Speccy:  
http://www.filehippo.com/download_speccy (Look in the upper right for the Download
Latest Version button  - Do NOT press the large Start Download button on the upper left!)  Decline CCleaner if offered.  Pay attention to SMART info on your hard drives and to temps.  If in doubt about temps try:
SpeedFan:  Try speedfan
http://www.filehippo...nload_speedfan/
Download, save and Install it (Win 7 or Vista right click and Run As Admin.) then run it.
Video Downloader Professional  To save online video.   This extension (available for Chrome or Firefox)  allows you to start a recording and then switch to a different window and record another video.

With Win 10 only there is a new Game recorder program.  It's supposed to only work for games but it works nicely to record any video you watch.  Hit the Win key + Alt + r to start the recorder.  The first time it asks you if it is looking at a game.  Just tell it yes.  After that it starts recording whenever you bring it up.  Videos are saved to the Captures folder under Videos.  You can only record what you watch so limited to only one video at a time.  Best to go to full screen before starting the recorder.

Avoid:  
Advanced System Care
SuperAntiSpyware
HitmanPro
Spybot S&D
Any P2P software especially if it comes from Conduit.
Registry Cleaners
Driver updating software.
PC fixing or Speed up software.
Running more than one anti-virus.
Seagate hard drives.  If you have one it's going to fail on you so backup your data now!

 


  • 0

#57
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

Thanks for your help and patience..  Saw significant performance improvements.  As a computer user, it is difficult to know what to uninstall or change..  I appreciate the guidance.  Tips are helpful also..


  • 0

#58
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

Hi RKinner,

 

 

System is running well.

 

The MBAR shortcut and folder are on my desktop. I did not see an option to remove the program.  Should I leave it there, move it to another folder, or delete it?  If so, how do I delete it?

 

Also - should I remove the Bing Rewards program.  Not sure how it got there.

 

When I run the Revo Junk Files Scan I get a number of files labeled as junk (these are not being removed by CCleaner).  Should I remove them?  Or is there a better way to delete these type files?

 

Thanks.

Attached Thumbnails

  • Mbar & folder.PNG
  • Bing Rewards.PNG
  • Revo Junk Files Scan.PNG
  • Revo Junk Files Scan page 2.PNG

  • 0

#59
RKinner

RKinner

    Malware Expert

  • Expert
  • 24,625 posts
  • MVP

Just delete the MBAR folder and the shortcut.

 

Definitely uninstall Bing Rewards

 

I'm not sure about the files.  I don't see why you would want to delete the thumbs.db files.  These are the thumbnails that you see when you look at a folder in file explorer.  If you delete them they will just come back again the next time you open the folder but it will take a bit more time.

 

.old files can certainly go.  Probably the .tmp too.  I don't like to mess with .dat files.  I assume but don't know for certain the ~ in front of them means they were copies used when the file was opened.  They should normally be removed when the file is closed.


  • 0

#60
joseph456

joseph456

    Member

  • Topic Starter
  • Member
  • PipPipPip
  • 455 posts

Thanks.

 

Microsoft Update keeps wanting to me to install Microsoft Silverlight and I keep hiding the programs.  Is there something else I can do to stop it?

Attached Thumbnails

  • Hidden Windows Updates.PNG

  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP