Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Win 7 HP Laptop Shuts down when running virus scan AND intermittently


  • Please log in to reply
2 replies to this topic

#1 truckin2001

truckin2001

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:55 AM

Posted 04 September 2014 - 02:01 PM

I'll try to make this as breif as possible... The machine in question 
is an HP g7, 2.53 Ghz dual core intel processor with 4 GB ram running Windows 7 Home premium and 
Office 2010 with Avast A/V. 
 After cleaning up my double anti-virus issue  as suggested in another post with a
 similar problem (machine will shut down at any given time for no apparent reason) - and other 
general house cleaning of unused programs (still approx. 200 GB on 500 GB drive), I was running
 "Housecall" overnight (scanning all files), and woke up to a shut down machine, which won't
 start now. This has been an ongoing issue for months. It may start later today, or tomorrow... it 
seems to be taking longer before it will restart.  I've caught it twice shutting down during 
virus scans when over 90% complete - scanning All Files. Same thing running MalwareBytes and a 
command line scan in safe mode with windows defender and AVAST a/v.  I have gotten Cureit 
to complete (no help), and  FRST (got a log file).
I suspect there is something in the Windows folder / sub folders, but 
I'm at wits end. The processor was overheating before my housecleaning (according to system log files),
 but seemed to be running much cooler last night.
Flash Player starts throwing errors soon after boot - "unknown s/w 
exception (0xc0000710) occured in application at location 0x7728a389"  Idk if its the same 
error/location all the time, but I wrote that one down! I have the latest version and it pops up errors
 VERY frequently. One scanner I ran (I forget which one) said it could` not scan Hkey_Local_Machine\
Software\ims\winnt\currentver\perflib\009 "you may not have administrator privliges" (if  i can read my writing -
 "software\ims" could be schimas - if it exists!)
Other weird issues that started within in the last month or so... task
 manager wont show processes from "all users" and processes are in a unchangable plain window. Also 
IE 11 quit working about a week or 2 ago. I have all the latest updates from Microsoft. My CD/ dvd 
burner wouldn't work at all until I ran DEFOGGER and re-enabled CD. It still wont burn though 
(invalid or no media present).
I'm sending this from my old Toshiba laptop with Win XP - which has a 
similar/ same issue (it has all the latest updates as well :). 
Also note - when these problems began, someone was breaking into my 
house regularly while I was at work (after my Identity info I discovered), and I was using both 
computers to run cameras (to no avail).
I'd better post this... this Toshiba died last time I tried to log in!
 I was A+ certified in 2000, so I'm not computer illiterate but my knowledge is very outdated.
Please HELP! I've had enough for the year. lol 
Thanks!


BC AdBot (Login to Remove)

 


#2 truckin2001

truckin2001
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:55 AM

Posted 06 September 2014 - 07:39 AM

My machine continues the intermittent shutdowns, and the processor is running much cooler after my house cleaning. I ran GMER and it found kgtiapow.sys listed under Rootkit/malware This was just during a quickscan. Result: GMER 2.1.19357 -
Rootkit scan 2014-09-06 08:54:16
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.02.0 465.76GB
Running: 2ub23s4q.exe; Driver: C:\Users\Owner\AppData\Local\Temp\kgtiapow.sys
---- Threads - GMER 2.1 ----
Thread  C:\Windows\System32\svchost.exe [2220:3444]  000007fef8729688
---- EOF - GMER 2.1 ----
 

I found kgtiapow.sys in the registry (I've been playing around in my registrys since the Win 95 days ;] ) It has its own key located at Hkey_Local_Machine/System/ControlSet001/services/kgtiapow  ------------------------( also under current control settings. I have a control set 002 where its not listed as well)

(DEFAULT) (type) REG_SZ (Data) (value not set)

Error Control (type) Reg_DWORD is set at 1

Group (type) REG_EXPAND_SZ (data) Base

Image path (type) REG_EXPAND_SZ  (data) \??\C:\Users\Owner\AppData\Local\Temp\kgtiapow.sys

Start (type) Reg_DWORD is set at 3

Type (type) Reg_DWORD is set at 1

SUBKEY:

ENUM

(DEFAULT) (type) REG_SZ (Data) (value not set)

0 (type) REG_SZ (Data) Root\LEGACY_KGTIAPOW\0000

Count (type) Reg_DWORD is set at 1

Nextinstance (type) Reg_DWORD is set at 1

 

Normally I would delete the file and registry key(s), but I've been fighting this so long, I'm afraid I have other issues... and I, like most others - DEPEND on my machine for too much (lol), and want to be sure It has a clean bill of health when I'm done with this issue.

I'll have GMER do a in depth scan while I'm out today... I would have done it already but wanted to post this first, as I'm afraid my machine will shut down doing an in depth scan, as it does with virus/malware scans mentioned in my orig. post.

It shut down again recording video (no processor overheating  in system log). Idk if thats a coincidence or not.

 

I know all you knowledgeable folks are real busy here... I hope someone can help me out here soon. I have countless hours wasted with this issue and still have it!

Thanks!


Edited by truckin2001, 06 September 2014 - 07:57 AM.


#3 truckin2001

truckin2001
  • Topic Starter

  • Members
  • 16 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:55 AM

Posted 08 September 2014 - 10:15 AM

Sorry I cant seem to edit or delete my previous post... I realize kgtiapow.sys is a part of GMER. My machine shut down yesterday when I tried to post. mbam and mbar now will complete (but find nothing) without the machine shutting down. I ran the following scans, all of which found nothing. TDSSkiller, Security Check, and Farbar.
GMER found MANY issues... after I made the MBR drive B: GMER also found  Kernel code. The Log is too big to post, so I only posted the first section of user code. most of the other exe files in the user code section have the exact same 45 ntdll.dll commands. I can't seem to Attach the entire log. The Minitoolbox log is scary as well!
 
GMER 2.1.19357 - http://www.gmer.net
Rootkit scan 2014-09-08 10:34:45
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.02.0 465.76GB
Running: 2ub23s4q.exe; Driver: C:\Users\Owner\AppData\Local\Temp\kgtiapow.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                    
                                          fffff800031b0000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 575                                    
 
                                          fffff800031b002f 16 bytes [00, 00, 00, 00, 00, 00, 00, ...]
---- User code sections - GMER 2.1 ----
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort               
                                          0000000076d31360 5 bytes JMP 0000000149a60460
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtQueryObject                        
 
                                          0000000076d313b0 5 bytes JMP 0000000149a60450
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenProcess                        
                                          0000000076d31510 5 bytes JMP 0000000149a60370
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePortEx             
 
                                          0000000076d31560 5 bytes JMP 0000000149a60470
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateProcess                   
                                          0000000076d31570 5 bytes JMP 0000000149a603e0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSection                        
 
                                          0000000076d31620 5 bytes JMP 0000000149a60320
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                 
                                          0000000076d31650 5 bytes JMP 0000000149a603b0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtDuplicateObject                    
 
                                          0000000076d31670 5 bytes JMP 0000000149a60390
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEvent                          
                                          0000000076d316b0 5 bytes JMP 0000000149a602e0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEvent                        
 
                                          0000000076d31730 5 bytes JMP 0000000149a602d0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSection                      
                                          0000000076d31750 5 bytes JMP 0000000149a60310
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThread                       
 
                                          0000000076d31790 5 bytes JMP 0000000149a603c0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtTerminateThread                    
                                          0000000076d317e0 5 bytes JMP 0000000149a603f0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtAddBootEntry                       
 
                                          0000000076d31940 5 bytes JMP 0000000149a60230
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtAlpcSendWaitReceivePort            
                                          0000000076d31b00 5 bytes JMP 0000000149a60480
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtAssignProcessToJobObject           
 
                                          0000000076d31b30 5 bytes JMP 0000000149a603a0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateEventPair                    
                                          0000000076d31c10 5 bytes JMP 0000000149a602f0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateIoCompletion                 
 
                                          0000000076d31c20 5 bytes JMP 0000000149a60350
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateMutant                       
                                          0000000076d31c80 5 bytes JMP 0000000149a60290
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateSemaphore                    
 
                                          0000000076d31d10 5 bytes JMP 0000000149a602b0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                     
                                          0000000076d31d30 5 bytes JMP 0000000149a603d0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtCreateTimer                        
 
                                          0000000076d31d40 5 bytes JMP 0000000149a60330
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtDebugActiveProcess                 
                                          0000000076d31db0 5 bytes JMP 0000000149a60410
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtDeleteBootEntry                    
 
                                          0000000076d31de0 5 bytes JMP 0000000149a60240
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtLoadDriver                         
                                          0000000076d320a0 5 bytes JMP 0000000149a601e0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtModifyBootEntry                    
 
                                          0000000076d32160 5 bytes JMP 0000000149a60250
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeKey                    
                                          0000000076d32190 5 bytes JMP 0000000149a60490
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtNotifyChangeMultipleKeys           
 
                                          0000000076d321a0 5 bytes JMP 0000000149a604a0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenEventPair                      
                                          0000000076d321d0 5 bytes JMP 0000000149a60300
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenIoCompletion                   
 
                                          0000000076d321e0 5 bytes JMP 0000000149a60360
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenMutant                         
                                          0000000076d32240 5 bytes JMP 0000000149a602a0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenSemaphore                      
 
                                          0000000076d32290 5 bytes JMP 0000000149a602c0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenThread                         
                                          0000000076d322c0 5 bytes JMP 0000000149a60380
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtOpenTimer                          
 
                                          0000000076d322d0 5 bytes JMP 0000000149a60340
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThreadEx                   
                                          0000000076d325c0 5 bytes JMP 0000000149a60440
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootEntryOrder                  
 
                                          0000000076d327c0 5 bytes JMP 0000000149a60260
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSetBootOptions                     
                                          0000000076d327d0 5 bytes JMP 0000000149a60270
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                   
 
                                          0000000076d327e0 5 bytes JMP 0000000149a60400
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemInformation               
                                          0000000076d329a0 5 bytes JMP 0000000149a601f0
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSetSystemPowerState                
 
                                          0000000076d329b0 5 bytes JMP 0000000149a60210
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtShutdownSystem                     
                                          0000000076d32a20 5 bytes JMP 0000000149a60200
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendProcess                     
 
                                          0000000076d32a80 5 bytes JMP 0000000149a60420
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSuspendThread                      
                                          0000000076d32a90 5 bytes JMP 0000000149a60430
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtSystemDebugControl                 
 
                                          0000000076d32aa0 5 bytes JMP 0000000149a60220
.text     C:\Windows\system32\csrss.exe[484] C:\Windows\SYSTEM32\ntdll.dll!NtVdmControl                         
                                          0000000076d32b80 5 bytes JMP 0000000149a60280
.text     C:\Windows\system32\wininit.exe[648] C:\Windows\SYSTEM32\ntdll.dll!NtReplyWaitReceivePort             
 
                                          0000000076d31360 5 bytes JMP 0000000076e90460
 
---- Threads - GMER 2.1 ----
Thread    C:\Windows\System32\svchost.exe [2180:2900]                                                           
                                          000007fef6b09688
---- Registry - GMER 2.1 ----
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\cc52af69bebf                           
                                         
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\cc52af69bebf@1c69a59a5c69              
 
                                          0x2E 0xA5 0xA5 0x70 ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\cc52af69bebf@c4438f91eb2e              
                                          0x00 0xD5 0x6E 0x63 ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\cc52af69bebf@0015833d0a57              
 
                                          0x07 0x6C 0x17 0xB4 ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\cc52af69bebf@ecf35b299f7f              
                                          0x18 0x67 0x06 0x1E ...
Reg       HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E1E3A70D-C166-48AD-B14F-
 
E2F87F2E568E}@LeaseObtainedTime                      1410186031
Reg       HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E1E3A70D-C166-48AD-B14F-
E2F87F2E568E}@T1                                     1410186046
Reg       HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E1E3A70D-C166-48AD-B14F-
 
E2F87F2E568E}@T2                                     1410186057
Reg       HKLM\SYSTEM\CurrentControlSet\services\Tcpip\Parameters\Interfaces\{E1E3A70D-C166-48AD-B14F-
E2F87F2E568E}@LeaseTerminatesTime                    1410186061
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\cc52af69bebf (not active ControlSet)       
 
                                         
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\cc52af69bebf@1c69a59a5c69                  
                                          0x2E 0xA5 0xA5 0x70 ...
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\cc52af69bebf@c4438f91eb2e                  
 
                                          0x00 0xD5 0x6E 0x63 ...
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\cc52af69bebf@0015833d0a57                  
                                          0x07 0x6C 0x17 0xB4 ...
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\cc52af69bebf@ecf35b299f7f                  
 
                                          0x18 0x67 0x06 0x1E ...
---- EOF - GMER 2.1 ----

MiniToolBox by Farbar  Version: 21-07-2014
Ran by Owner (administrator) on 08-09-2014 at 11:01:40
Running from "C:\Users\Owner\Desktop"
Microsoft Windows 7 Home Premium  Service Pack 1 (X64)
Boot Mode: Normal
***************************************************************************

========================= Flush DNS: ===================================

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

========================= IE Proxy Settings: ==============================

Proxy is not enabled.
No Proxy Server is set.

"Reset IE Proxy Settings": IE Proxy Settings were reset.

========================= FF Proxy Settings: ==============================


"Reset FF Proxy Settings": Firefox Proxy settings were reset.

========================= Hosts content: =================================

127.0.0.1       localhost

========================= IP Configuration: ================================

Broadcom 4313 802.11b/g/n = Wireless Network Connection (Connected)
VirtualBox Host-Only Ethernet Adapter = VirtualBox Host-Only Network (Connected)
Realtek PCIe FE Family Controller = Local Area Connection (Media disconnected)


# ----------------------------------
# IPv4 Configuration
# ----------------------------------
pushd interface ipv4

reset
set global icmpredirects=enabled
set subinterface interface=?) subinterface=ethernet_6 mtu=1477
add address name="VirtualBox Host-Only Network" address=192.168.56.1 mask=255.255.255.0


popd
# End of IPv4 configuration



Windows IP Configuration

   Host Name . . . . . . . . . . . . : Owner-HP
   Primary Dns Suffix  . . . . . . . :
   Node Type . . . . . . . . . . . . : Hybrid
   IP Routing Enabled. . . . . . . . : No
   WINS Proxy Enabled. . . . . . . . : No
   DNS Suffix Search List. . . . . . : att.net

Wireless LAN adapter Wireless Network Connection:

   Connection-specific DNS Suffix  . : att.net
   Description . . . . . . . . . . . : Broadcom 4313 802.11b/g/n
   Physical Address. . . . . . . . . : CC-52-AF-5C-3B-86
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes
   IPv6 Address. . . . . . . . . . . : 2602:306:bcfc:f230:e5cf:cfb8:4028:5226(Preferred)
   Temporary IPv6 Address. . . . . . : 2602:306:bcfc:f230:4587:bde0:bd49:b90d(Preferred)
   Link-local IPv6 Address . . . . . : fe80::e5cf:cfb8:4028:5226%14(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.1.104(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Lease Obtained. . . . . . . . . . : Monday, September 08, 2014 9:15:15 AM
   Lease Expires . . . . . . . . . . : Monday, September 08, 2014 11:02:17 AM
   Default Gateway . . . . . . . . . : fe80::b277:acff:fe34:20f0%14
                                       192.168.1.155
   DHCP Server . . . . . . . . . . . : 192.168.1.155
   DHCPv6 IAID . . . . . . . . . . . : 382489263
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-22-06-30-98-4B-E1-C6-FB-BB
   DNS Servers . . . . . . . . . . . : 192.168.1.155
   NetBIOS over Tcpip. . . . . . . . : Enabled

Ethernet adapter Local Area Connection:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Realtek PCIe FE Family Controller
   Physical Address. . . . . . . . . : 98-4B-E1-C6-FB-BB
   DHCP Enabled. . . . . . . . . . . : Yes
   Autoconfiguration Enabled . . . . : Yes

Ethernet adapter VirtualBox Host-Only Network:

   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : VirtualBox Host-Only Ethernet Adapter
   Physical Address. . . . . . . . . : 08-00-27-00-A8-FB
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
   Link-local IPv6 Address . . . . . : fe80::29f8:6a6c:32f1:f24%18(Preferred)
   IPv4 Address. . . . . . . . . . . : 192.168.56.1(Preferred)
   Subnet Mask . . . . . . . . . . . : 255.255.255.0
   Default Gateway . . . . . . . . . :
   DHCPv6 IAID . . . . . . . . . . . : 671612967
   DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-15-22-06-30-98-4B-E1-C6-FB-BB
   DNS Servers . . . . . . . . . . . : fec0:0:0:ffff::1%1
                                       fec0:0:0:ffff::2%1
                                       fec0:0:0:ffff::3%1
   NetBIOS over Tcpip. . . . . . . . : Enabled

Tunnel adapter isatap.{261BC2BD-47CE-4809-A440-9215ECAF2369}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Local Area Connection* 12:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft 6to4 Adapter
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.att.net:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . : att.net
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #3
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter Teredo Tunneling Pseudo-Interface:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Teredo Tunneling Pseudo-Interface
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes

Tunnel adapter isatap.{10E414F3-29CE-4C7D-A9F1-3AF4AF8184A3}:

   Media State . . . . . . . . . . . : Media disconnected
   Connection-specific DNS Suffix  . :
   Description . . . . . . . . . . . : Microsoft ISATAP Adapter #4
   Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
   DHCP Enabled. . . . . . . . . . . : No
   Autoconfiguration Enabled . . . . : Yes
Server:  dsldevice.att.net
Address:  192.168.1.155

Name:    google.com
Addresses:  2607:f8b0:4000:806::1005
      74.125.227.167
      74.125.227.162
      74.125.227.164
      74.125.227.168
      74.125.227.165
      74.125.227.169
      74.125.227.163
      74.125.227.160
      74.125.227.166
      74.125.227.161
      74.125.227.174


Pinging google.com [2607:f8b0:4000:806::1005] with 32 bytes of data:
Reply from 2607:f8b0:4000:806::1005: time=59ms
Reply from 2607:f8b0:4000:806::1005: time=57ms

Ping statistics for 2607:f8b0:4000:806::1005:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 57ms, Maximum = 59ms, Average = 58ms
Server:  dsldevice.att.net
Address:  192.168.1.155

Name:    yahoo.com
Addresses:  206.190.36.45
      98.138.253.109
      98.139.183.24


Pinging yahoo.com [98.139.183.24] with 32 bytes of data:
Reply from 98.139.183.24: bytes=32 time=47ms TTL=48
Reply from 98.139.183.24: bytes=32 time=52ms TTL=48

Ping statistics for 98.139.183.24:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 47ms, Maximum = 52ms, Average = 49ms

Pinging 127.0.0.1 with 32 bytes of data:
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128
Reply from 127.0.0.1: bytes=32 time<1ms TTL=128

Ping statistics for 127.0.0.1:
    Packets: Sent = 2, Received = 2, Lost = 0 (0% loss),
Approximate round trip times in milli-seconds:
    Minimum = 0ms, Maximum = 0ms, Average = 0ms
===========================================================================
Interface List
 14...cc 52 af 5c 3b 86 ......Broadcom 4313 802.11b/g/n
 12...98 4b e1 c6 fb bb ......Realtek PCIe FE Family Controller
 18...08 00 27 00 a8 fb ......VirtualBox Host-Only Ethernet Adapter
  1...........................Software Loopback Interface 1
 25...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #2
 13...00 00 00 00 00 00 00 e0 Microsoft 6to4 Adapter
 24...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #3
 15...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface
 22...00 00 00 00 00 00 00 e0 Microsoft ISATAP Adapter #4
===========================================================================

IPv4 Route Table
===========================================================================
Active Routes:
Network Destination        Netmask          Gateway       Interface  Metric
          0.0.0.0          0.0.0.0    192.168.1.155    192.168.1.104     25
        127.0.0.0        255.0.0.0         On-link         127.0.0.1    306
        127.0.0.1  255.255.255.255         On-link         127.0.0.1    306
  127.255.255.255  255.255.255.255         On-link         127.0.0.1    306
      192.168.1.0    255.255.255.0         On-link     192.168.1.104    281
    192.168.1.104  255.255.255.255         On-link     192.168.1.104    281
    192.168.1.255  255.255.255.255         On-link     192.168.1.104    281
     192.168.56.0    255.255.255.0         On-link      192.168.56.1    276
     192.168.56.1  255.255.255.255         On-link      192.168.56.1    276
   192.168.56.255  255.255.255.255         On-link      192.168.56.1    276
        224.0.0.0        240.0.0.0         On-link         127.0.0.1    306
        224.0.0.0        240.0.0.0         On-link      192.168.56.1    276
        224.0.0.0        240.0.0.0         On-link     192.168.1.104    281
  255.255.255.255  255.255.255.255         On-link         127.0.0.1    306
  255.255.255.255  255.255.255.255         On-link      192.168.56.1    276
  255.255.255.255  255.255.255.255         On-link     192.168.1.104    281
===========================================================================
Persistent Routes:
  None

IPv6 Route Table
===========================================================================
Active Routes:
 If Metric Network Destination      Gateway
 14    281 ::/0                     fe80::b277:acff:fe34:20f0
  1    306 ::1/128                  On-link
 14     33 2602:306:bcfc:f230::/64  On-link
 14    281 2602:306:bcfc:f230:4587:bde0:bd49:b90d/128
                                    On-link
 14    281 2602:306:bcfc:f230:e5cf:cfb8:4028:5226/128
                                    On-link
 18    276 fe80::/64                On-link
 14    281 fe80::/64                On-link
 18    276 fe80::29f8:6a6c:32f1:f24/128
                                    On-link
 14    281 fe80::e5cf:cfb8:4028:5226/128
                                    On-link
  1    306 ff00::/8                 On-link
 18    276 ff00::/8                 On-link
 14    281 ff00::/8                 On-link
===========================================================================
Persistent Routes:
  None
========================= Winsock entries =====================================

Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation)
Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation)
Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation)
Catalog5 05 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 06 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [145280] (Microsoft Corp.)
Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation)
Catalog5 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog5 09 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation)
Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation)
x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation)
x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation)
x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation)
x64-Catalog5 05 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 06 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [170880] (Microsoft Corp.)
x64-Catalog5 07 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation)
x64-Catalog5 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog5 09 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation)
x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)
x64-Catalog9 11 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation)

========================= Event log errors: ===============================

Application errors:
==================
Error: (09/07/2014 11:30:30 PM) (Source: Desktop Window Manager) (User: )
Description: The Desktop Window Manager has encountered a fatal error (0x0)

Error: (09/07/2014 01:52:12 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5540.  Message ID: [0x2509].

Error: (09/07/2014 01:42:11 AM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5904.  Message ID: [0x2509].

Error: (09/06/2014 04:37:51 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4656.  Message ID: [0x2509].

Error: (09/06/2014 04:35:39 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4044.  Message ID: [0x2509].

Error: (09/06/2014 04:34:08 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5768.  Message ID: [0x2509].

Error: (09/06/2014 03:55:26 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5932.  Message ID: [0x2509].

Error: (09/06/2014 03:55:18 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5912.  Message ID: [0x2509].

Error: (09/06/2014 01:35:09 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3668.  Message ID: [0x2509].

Error: (09/06/2014 01:32:46 PM) (Source: .NET Runtime) (User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3572.  Message ID: [0x2509].


System errors:
=============
Error: (09/08/2014 08:47:03 AM) (Source: Service Control Manager) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
%%2

Error: (09/08/2014 00:41:34 AM) (Source: Service Control Manager) (User: )
Description: The IPsec Policy Agent service terminated with the following error:
%%1747

Error: (09/08/2014 00:41:27 AM) (Source: Service Control Manager) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
%%2

Error: (09/08/2014 00:34:01 AM) (Source: DCOM) (User: )
Description: {AD3EDBCA-0901-415B-82E9-C16D3B65E38C}

Error: (09/07/2014 11:37:55 PM) (Source: Service Control Manager) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
%%2

Error: (09/07/2014 11:29:50 PM) (Source: Service Control Manager) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
%%2

Error: (09/07/2014 11:19:12 PM) (Source: Service Control Manager) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
%%2

Error: (09/07/2014 02:22:14 PM) (Source: Service Control Manager) (User: )
Description: The IPsec Policy Agent service terminated with the following error:
%%1747

Error: (09/07/2014 02:21:54 PM) (Source: Service Control Manager) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
%%2

Error: (09/07/2014 01:17:56 PM) (Source: Service Control Manager) (User: )
Description: The ZoneAlarm Privacy Service service failed to start due to the following error:
%%2


Microsoft Office Sessions:
=========================
Error: (09/07/2014 11:30:30 PM) (Source: Desktop Window Manager)(User: )
Description: 0x0

Error: (09/07/2014 01:52:12 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5540.  Message ID: [0x2509].

Error: (09/07/2014 01:42:11 AM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5904.  Message ID: [0x2509].

Error: (09/06/2014 04:37:51 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4656.  Message ID: [0x2509].

Error: (09/06/2014 04:35:39 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 4044.  Message ID: [0x2509].

Error: (09/06/2014 04:34:08 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5768.  Message ID: [0x2509].

Error: (09/06/2014 03:55:26 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5932.  Message ID: [0x2509].

Error: (09/06/2014 03:55:18 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 5912.  Message ID: [0x2509].

Error: (09/06/2014 01:35:09 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3668.  Message ID: [0x2509].

Error: (09/06/2014 01:32:46 PM) (Source: .NET Runtime)(User: )
Description: .NET Runtime version 4.0.30319.18444 - There was a failure initializing profiling API attach infrastructure.  This process will not allow a profiler to attach.  HRESULT: 0x80004005.  Process ID (decimal): 3572.  Message ID: [0x2509].


CodeIntegrity Errors:
===================================
  Date: 2014-09-03 13:46:12.982
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\F4B4.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-03 13:46:12.904
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\F4B4.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 22:20:09.314
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 22:20:09.252
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 22:20:09.096
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 22:20:09.018
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 22:20:06.912
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 22:20:06.818
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 20:27:06.206
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-09-02 20:27:06.130
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume2\Windows\System32\A03F.tmp because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


========================= Devices: ================================

Name: Broadcom 2070 Bluetooth
Description: Broadcom 2070 Bluetooth
Class Guid: {e0cbf06c-cd8b-4647-bb8a-263b43f0f974}
Manufacturer: Broadcom
Service: BTHUSB
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: CyberLink WebCam Virtual Driver
Description: CyberLink WebCam Virtual Driver
Class Guid: {4d36e96c-e325-11ce-bfc1-08002be10318}
Manufacturer: CyberLink
Service: clwvd
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: HP Webcam-101
Description: USB Video Device
Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f}
Manufacturer: Microsoft
Service: usbvideo
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: KINGSTON4GB
Description: DataTraveler 2.0
Class Guid: {eec5ad98-8080-425f-922a-dabf3de3f69a}
Manufacturer: Kingston
Service: WUDFRd
Problem: : Windows has stopped this device because it has reported problems. (Code 43)
Resolution: One of the drivers controlling the device notified the operating system that the device failed in some manner. For more information about how to diagnose the problem, see the hardware documentation.


========================= Memory info: ===================================

Percentage of memory in use: 62%
Total physical RAM: 3893.86 MB
Available physical RAM: 1466.39 MB
Total Pagefile: 7785.9 MB
Available Pagefile: 5079.92 MB
Total Virtual: 4095.88 MB
Available Virtual: 3976.5 MB

========================= Partitions: =====================================

1 Drive b: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS
2 Drive c: () (Fixed) (Total:450.9 GB) (Free:304.92 GB) NTFS
3 Drive d: (RECOVERY) (Fixed) (Total:14.56 GB) (Free:1.81 GB) NTFS
5 Drive h: (KINGSTON4GB) (Removable) (Total:3.8 GB) (Free:3.76 GB) FAT32

========================= Users: ========================================

User accounts for \\OWNER-HP

Administrator            Guest                    Owner                   

========================= Minidump Files ==================================

No minidump file found

========================= Restore Points ==================================

06-09-2014 04:35:40 Scheduled Checkpoint
06-09-2014 22:28:49 Windows Update

**** End of log ****


Edited by truckin2001, 08 September 2014 - 10:32 AM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users