Can you explain what you mean by "that's when all my trouble began", what trouble?
It's been a couple of weeks, and my memory is not the best any longer, but I'll try. (A year ago, I fell and had a bad concussion, and I still have not been able to get my memory back to where it was.)
- The machine was running slowly, and so I plugged into hard wire to see if that would help.
- The first thing that happened was that I received two separate notifications from McAfee telling me that I had been infected by a Trojan, and instructing me to shut down the machine so it could complete the cleaning. On both occasions, I did as instructed.
- Sometime after that, maybe a couple of days, I started experiencing difficulty while using IE Explorer. The first thing being that I would receive a message any time I tried to download a file saying that my security would not allow me to download a file. Around the same time, I started losing my home page assignment. I tried to download Malwarebytes, but received the message saying my security would not allow it.
- In addition, McAfee started running a "scan" that literally never ended. I had it set to automatically run a scan every Thursday at 3:00 a.m., but this was not part of the regularly scheduled scan. I could not shut it down, and the process was using 100% of my CPU.
- I also noticed several duplicate processes running … don't remember exactly which ones, but the "typical" processes that happen when you're infected by a Trojan.
- I did not remember how to reset my security to allow downloads, nor did I remember that I was a member here. I tried to find a way to get help online, but was unable to download files.
- Finally, in exasperation, I took the machine to someone local to fix. I left it there in his shop for 2 days, brought it home and plugged it in again the next day. I started experiencing the same behavior … changed print settings, and changed home page. I called the guy who I had paid and left a message.
- He called me back two days later saying he would have time to help …only he didn't.
- I remembered that this was the board I had used successfully before, and here I am.
=========================================
MiniToolBox by Farbar Version: 21-07-2014
Ran by [removed] (administrator) on 15-11-2014 at 14:36:58
Running from "C:\Users\RevSusan\Desktop"
Microsoft Windows 7 Home Premium Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************
========================= Flush DNS: ===================================
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
"Reset IE Proxy Settings": IE Proxy Settings were reset.
========================= IP Configuration: ================================
Intel(R) WiFi Link 5100 AGN = Wireless Network Connection (Connected)
Marvell Yukon 88E8040 PCI-E Fast Ethernet Controller = Local Area Connection (Media disconnected)
# ———————————-
# IPv4 Configuration
# ———————————-
pushd interface ipv4
reset
popd
# End of IPv4 configuration
Windows IP Configuration
Host Name . . . . . . . . . . . . : Susan-Laptop
Primary Dns Suffix . . . . . . . :
Node Type . . . . . . . . . . . . : Hybrid
IP Routing Enabled. . . . . . . . : No
WINS Proxy Enabled. . . . . . . . : No
DNS Suffix Search List. . . . . . : hsd1.ca.comcast.net.
Wireless LAN adapter Wireless Network Connection:
Connection-specific DNS Suffix . : hsd1.ca.comcast.net.
Description . . . . . . . . . . . : Intel(R) WiFi Link 5100 AGN
Physical Address. . . . . . . . . : 00-24-D6-42-A3-EA
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2601:9:3980:34f:1928:79dc:3c42:5d90(Preferred)
Temporary IPv6 Address. . . . . . : 2601:9:3980:34f:289d:d013:8f0:45a0(Preferred)
Link-local IPv6 Address . . . . . : fe80::1928:79dc:3c42:5d90%11(Preferred)
IPv4 Address. . . . . . . . . . . : 10.0.0.8(Preferred)
Subnet Mask . . . . . . . . . . . : 255.255.255.0
Lease Obtained. . . . . . . . . . : Thursday, November 13, 2014 1:21:54 PM
Lease Expires . . . . . . . . . . : Saturday, November 22, 2014 2:08:31 PM
Default Gateway . . . . . . . . . : fe80::ea89:2cff:fe29:ac41%11
10.0.0.1
DHCP Server . . . . . . . . . . . : 10.0.0.1
DHCPv6 IAID . . . . . . . . . . . : 218113238
DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-12-B1-FA-62-00-25-64-79-07-12
DNS Servers . . . . . . . . . . . : 2001:558:feed::1
2001:558:feed::2
75.75.75.75
75.75.76.76
NetBIOS over Tcpip. . . . . . . . : Enabled
Ethernet adapter Local Area Connection:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : hsd1.ca.comcast.net.
Description . . . . . . . . . . . : Marvell Yukon 88E8040 PCI-E Fast Ethernet Controller
Physical Address. . . . . . . . . : 00-25-64-79-07-12
DHCP Enabled. . . . . . . . . . . : Yes
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 12:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Microsoft 6to4 Adapter
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Tunnel adapter Local Area Connection* 14:
Connection-specific DNS Suffix . :
Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
IPv6 Address. . . . . . . . . . . : 2001:0:9d38:90d7:384f:1531:b3ea:9bac(Preferred)
Link-local IPv6 Address . . . . . : fe80::384f:1531:b3ea:9bac%18(Preferred)
Default Gateway . . . . . . . . . :
NetBIOS over Tcpip. . . . . . . . : Disabled
Tunnel adapter isatap.hsd1.ca.comcast.net.:
Media State . . . . . . . . . . . : Media disconnected
Connection-specific DNS Suffix . : hsd1.ca.comcast.net.
Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
DHCP Enabled. . . . . . . . . . . : No
Autoconfiguration Enabled . . . . : Yes
Server: cdns01.comcast.net
Address: 2001:558:feed::1
Name: google.com
Addresses: 2607:f8b0:4005:802::1008
[removed]
[removed]
[removed]
[removed]
[removed]
74.125.239.142
74.125.239.134
74.125.239.130
74.125.239.135
74.125.239.128
74.125.239.129
Pinging google.com [2607:f8b0:4010:801::1000] with 32 bytes of data:
Request timed out.
Request timed out.
Ping statistics for 2607:f8b0:4010:801::1000:
Packets: Sent = 2, Received = 0, Lost = 2 (100% loss),
DNS request timed out.
timeout was 2 seconds.
Server: UnKnown
Address: 2001:558:feed::1
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
DNS request timed out.
timeout was 2 seconds.
Ping request could not find host yahoo.com. Please check the name and try again.
Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Ping statistics for 127.0.0.1:
Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
11…00 24 d6 42 a3 ea ……Intel(R) WiFi Link 5100 AGN
10…00 25 64 79 07 12 ……Marvell Yukon 88E8040 PCI-E Fast Ethernet Controller
1………………………Software Loopback Interface 1
12…00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
18…00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
19…00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
===========================================================================
IPv4 Route Table
===========================================================================
Active Routes:
Network Destination Netmask Gateway Interface Metric
0.0.0.0 0.0.0.0 10.0.0.1 10.0.0.8 25
10.0.0.0 255.255.255.0 On-link 10.0.0.8 281
10.0.0.8 255.255.255.255 On-link 10.0.0.8 281
10.0.0.255 255.255.255.255 On-link 10.0.0.8 281
127.0.0.0 255.0.0.0 On-link 127.0.0.1 306
127.0.0.1 255.255.255.255 On-link 127.0.0.1 306
127.255.255.255 255.255.255.255 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 127.0.0.1 306
224.0.0.0 240.0.0.0 On-link 10.0.0.8 281
255.255.255.255 255.255.255.255 On-link 127.0.0.1 306
255.255.255.255 255.255.255.255 On-link 10.0.0.8 281
===========================================================================
Persistent Routes:
None
IPv6 Route Table
===========================================================================
Active Routes:
If Metric Network Destination Gateway
11 281 ::/0 fe80::ea89:2cff:fe29:ac41
1 306 ::1/128 On-link
18 58 2001::/32 On-link
18 306 2001:0:9d38:90d7:384f:1531:b3ea:9bac/128
On-link
11 33 2601:9:3980:34f::/64 On-link
11 281 2601:9:3980:34f:1928:79dc:3c42:5d90/128
On-link
11 281 2601:9:3980:34f:289d:d013:8f0:45a0/128
On-link
11 281 fe80::/64 On-link
18 306 fe80::/64 On-link
11 281 fe80::1928:79dc:3c42:5d90/128
On-link
18 306 fe80::384f:1531:b3ea:9bac/128
On-link
1 306 ff00::/8 On-link
18 306 ff00::/8 On-link
11 281 ff00::/8 On-link
===========================================================================
Persistent Routes:
None
========================= Winsock entries =====================================
Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 08 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog5 09 C:\Program Files (x86)\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 08 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [132968] (Apple Inc.)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
========================= Event log errors: ===============================
Application errors:
==================
System errors:
=============
Error: (11/13/2014 00:39:05 PM) (Source: Service Control Manager) (User: )
Description: The HP Network Devices Support service terminated with the following error:
%%126
Error: (11/13/2014 01:11:05 AM) (Source: Service Control Manager) (User: )
Description: The HP Network Devices Support service terminated with the following error:
%%126
Error: (11/13/2014 01:07:29 AM) (Source: Service Control Manager) (User: )
Description: The Windows Update service did not shut down properly after receiving a preshutdown control.
Error: (11/12/2014 01:16:44 AM) (Source: DCOM) (User: )
Description: {209500FC-6B45-4693-8871-6296C4843751}
Error: (11/12/2014 01:16:21 AM) (Source: Service Control Manager) (User: )
Description: The HP Network Devices Support service terminated with the following error:
%%126
Error: (11/11/2014 03:48:40 PM) (Source: Service Control Manager) (User: )
Description: The HP Network Devices Support service terminated with the following error:
%%126
Error: (11/10/2014 04:16:28 PM) (Source: Service Control Manager) (User: )
Description: The HP Network Devices Support service terminated with the following error:
%%126
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2011-01-14 14:00:31.263
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2011-01-14 14:00:31.247
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2011-01-14 13:00:38.374
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2011-01-14 13:00:38.343
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2011-01-14 12:34:19.983
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2011-01-14 12:34:19.967
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2011-01-14 12:00:49.795
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
Date: 2011-01-14 12:00:49.763
Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Program Files (x86)\FastLynx\FastLynx.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.
========================= Memory info: ===================================
Percentage of memory in use: 41%
Total physical RAM: 4092.36 MB
Available physical RAM: 2392.88 MB
Total Pagefile: 8182.89 MB
Available Pagefile: 6255.61 MB
Total Virtual: 4095.88 MB
Available Virtual: 3976.66 MB
========================= Partitions: =====================================
1 Drive c: (OS) (Fixed) (Total:283.4 GB) (Free:205.1 GB) NTFS
========================= Users: ========================================
User accounts for
\\SUSAN-LAPTOPAdministrator Guest RevSusan
========================= Minidump Files ==================================
No minidump file found
**** End of log ****
Click Start, type command prompt in the Search Programs and files box, right-click Command Prompt, and then click Run as administrator.
At the command prompt, type the following commands. Press Enter after each command. (be sure to include the space between ipconfig /)
I saved the output from this on Notepad. Did you want to see it?
I've tested a bit today. It's a weekend, and some sites are worse than others. I just assume that this is to be expected. Nothing is lightening fast. This site is fairly slow to respond, but once I'm on this page, it's fine.
Thank you.
Susan