Page 1 of 3 123 LastLast
Results 1 to 10 of 27
  1. #1
    Member
    Join Date
    Dec 2015
    Posts
    22
    Points
    0

    Default How do I block Windows 10?

    Hi.....just a simple question really. having reverted back to good old, trusted Windows 8.1 (works for me), I keep getting these wretched reminders to upgrade to Windows 10. I don't want the reminders to keep popping up, I definitely DO NOT want windows 10, best thing for windows 10 is to launch it into orbit with no return!!! Please.......how do I (or can I even?) stop the reminders for Windows 10? How do I turn off, or block windows 10 reminders?

  2. #2
    Member Spyware Fighter DonnaB's Avatar
    Join Date
    Apr 2009
    Location
    Illiana, Ill. USA
    Posts
    3,521
    Points
    563

    Default

    Hi ChrisCCB,

    Go to Windows Updates and look for Show all available updates. Click on that and in the list of updates waiting to be installed, look for Upgrade to Windows 10 home, version (numbers). Uncheck the box to the left of that update/upgrade then right click and choose hide.

    That will hide the update. Now we need to disable it in the registry. Changing things in the registry can be dangerous since it is the "brains" of the operating system. If you do not feel comfortable following the instructions below, let me know and we can resort to another trick I have up my sleeve that consists of installing a program and having it do the work for you.

    Please read the instructions carefully and follow them to a "T"...

    • In your Search field, type in Regedit and click Ok
    • If User Account Control UAC pops up, click Yes and proceed.
    • Click Computer to highlight.
    • Click File > Export... from the Registry Editor menu.
    • In the Export Registry File window you see next, choose a location on your computer to save the file to.
      • Note: I recommend choosing your desktop so you can easily find in the future if you need to restore this backup.

    • Find the File name: field and type a name for the registry backup file.
      • Note: Try to name this something that makes sense, especially if you have other registry backups stored in the same place. A good name might be Vista Registry Backup, along with the current date.

    • Click Save.
      • Note: A file with the REG file extension will be created at the location with whatever name you chose. As an example, Vista Registry Backup regfix.reg if that's what you decided on.


    Now we can safely make the following changes to the registry, knowing that you have a complete backup of the entire registry.

    • Open notepad and copy then paste the following script below into the notepad.
      Windows Registry Editor Version 5.00

      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\GWX]
      "DisableGWX"=dword:00000001

      [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\OSUpgrade]
      "AllowOSUpgrade"=dword:00000000
      "ReservationsAllowed"=dword:00000000

      [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU]
      "DisableOSUpgrade"=dword:00000001
    • Click on File in the menu bar.
    • In the left column click on Desktop
    • Look for the File name: field and type in GWX.reg
    • Just below that, look for Save as type: and click on the drop down arrow to the right and choose All Files (*.*)
    • Next, click on the Save button at the bottom.


    Now, go to the desktop and double click on the GWX.reg file.
    If User Account Control UAC pops up, click Yes and proceed.
    A Registry Editor box will pop up with a warning and ask, Are you sure you want to continue?
    Click Yes.

    Once complete, go ahead and delete the .reg files on your desktop. You should now no longer be bothered by the Windows 10 upgrade.

    Let me know when you are finished and how it goes for you.

    Donna
    Last edited by DonnaB; 12-09-2015 at 11:19 PM.
    If you think you might be infected with malware or have recently cleansed your computer of malware without the help of an expert, please read and follow the instructions in How to Start Removing Viruses and Spyware from your Computer. This can alleviate time consumed in trouble shooting your current computer problems.

    If your problem is solved, here's how to say thanks!

    Very proud parent of a U.S. Navy "CB"



    "People may forget what you say,
    People may forget what you did,
    but People will never forget how you made them feel!"

  3. The Following User Says Thank You to DonnaB For This Useful Post:


  4. #3
    Member
    Join Date
    Dec 2015
    Posts
    22
    Points
    0

    Default

    Hi DonnaB - thank you for the direction. I tried (really tried).......I know I'm really 'trying'..... you have a lot of patience & your computer knowledge puts me to shame. However, I've tried to follow your steps to a 'T' as requested, I think (?), nothing has changed. My PC knowledge is good (of sorts), but I'm most certainly no wizard as some people think I am......poor souls!!!! You said you might have something else up your sleeve (other than your arm)........sorry...my jokes are less than funny, please could you advise me on the program that can solve the problem for me? Not the least because I'm a coward & my fear of doing something wrong is as vast as the Titanic.......and look what happened to that!!!!! Please, if you could advise? Thank you for your patience & time.

  5. #4
    Member Spyware Fighter DonnaB's Avatar
    Join Date
    Apr 2009
    Location
    Illiana, Ill. USA
    Posts
    3,521
    Points
    563

    Default

    Hi Chris,

    No problem at all! Would it comfort you to know that not long ago (6 1/2 years ago) I didn't even know how to copy and paste? I don't mean to scare you off by sharing that bit of truth, but to encourage you that if I can learn, so can you with my guidance. If it wasn't for the members here at H2G, I wouldn't know what I do know.

    Yes. There is another way, but first I will need for you to download the following program that when executed will generate a log report. The log report will tell me where the Windows 10 files are located so can I create a script that will remove those files associated with Windows 10.

    Please read the instructions below line by line and you will be just fine.

    I do have to run off to work before I make myself late for work. If you could please follow the instructions below and provide the logs that I need to see, as soon as I get home around 4pm my time (it is now 6:11 am) I will have a look and provide that script for you to follow.

    Please download the Farbar Recovery Scan program from >> HERE<< and save it to your desktop. <<< Very Important!

    It will take a few minutes for the tool to audit your system and create the log report, so please be patient.

    Note: You will need to run the version compatible with your system. If you are not sure which version (32 or 64-bit) applies to your system download both of them and try to run them. Only one of them will run on your system, that will be the right version.

    • Make sure that FRST is on the desktop of the infected system
    • Right click and choose Run as administrator. When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will produce a log called FRST.txt in the same directory the tool is run from.
    • Please copy and paste log back here.
    • The first time the tool is run it generates a second log (Addition.txt - also located in the same directory as FRST.exe/FRST64.exe). Please also paste that along with the FRST.txt into your reply.
    If you think you might be infected with malware or have recently cleansed your computer of malware without the help of an expert, please read and follow the instructions in How to Start Removing Viruses and Spyware from your Computer. This can alleviate time consumed in trouble shooting your current computer problems.

    If your problem is solved, here's how to say thanks!

    Very proud parent of a U.S. Navy "CB"



    "People may forget what you say,
    People may forget what you did,
    but People will never forget how you made them feel!"

  6. #5
    Member
    Join Date
    Dec 2015
    Posts
    22
    Points
    0

    Default

    Hi DonnaB - thank you for the encouragement & for making me feel better. However, I think you might end up pulling your hair out & screaming at 'ChrisCCB' & thinking, "why did I ever get involved.......where do these geeks come from"!!! Anyway....I've attempted to (again) follow your instructions, and surprise, surprise my system has blocked the download of the FRST file on account it labels it as a suspect file which could harm my system. I trust you implicitly, I really do, even though I don't know you, and if there is a safe way of allowing the file to do the job, hey...you have my vote. All this is because I just wanted to 'serve notice' on Windows 10 & its promptings to download it, sorry for the headache. I'm not a complete idiot....honest!!

  7. #6
    Member
    Join Date
    Dec 2015
    Posts
    22
    Points
    0

    Default

    Hi DonnaB.....now, I'm totally confused.......my system had (displayed by a message on screen) blocked the file download, but.....here it is.....and I'm not even going to try & work it out??!!!! The logs as requested...........

    Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:12-12-2015
    Ran by Chris (administrator) on OFFICEPC (12-12-2015 12:56:15)
    Running from C:\Users\Chris\Desktop
    Loaded Profiles: Chris (Available Profiles: Chris)
    Platform: Windows 8.1 (X64) Language: English (United Kingdom)
    Internet Explorer Version 11 (Default browser: IE)
    Boot Mode: Normal
    Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Malware Removal Guides and Tutorials

    ==================== Processes (Whitelisted) =================

    (If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

    (AMD) C:\Windows\System32\atiesrxx.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
    (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
    (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
    (Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
    (AMD) C:\Windows\System32\atieclxx.exe
    (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe
    (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe
    (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
    (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
    (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Google Inc.) C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
    (Piriform Ltd) C:\Program Files\CCleaner\CCleaner64.exe
    (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
    (Microsoft Corporation) C:\Windows\splwow64.exe
    (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
    (Adobe Systems Incorporated) C:\Windows\System32\Macromed\Flash\FlashUtil_ActiveX.exe


    ==================== Registry (Whitelisted) ===========================

    (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

    HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe [766688 2014-07-04] (Advanced Micro Devices, Inc.)
    HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [7021880 2015-12-11] (AVAST Software)
    HKU\S-1-5-21-2499712881-288055672-3602056328-1001\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
    HKU\S-1-5-21-2499712881-288055672-3602056328-1001\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [50755200 2015-12-08] (Skype Technologies S.A.)
    HKU\S-1-5-21-2499712881-288055672-3602056328-1001\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [8591272 2015-11-16] (Piriform Ltd)
    ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll [2015-12-11] (AVAST Software)

    ==================== Internet (Whitelisted) ====================

    (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

    Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{35D7A473-AA3B-403A-9F5F-017C8B80DCEA}: [DhcpNameServer] 192.168.0.1
    Tcpip\..\Interfaces\{E26390F9-5D5D-441E-8DEE-0812182BE595}: [DhcpNameServer] 192.168.0.1

    Internet Explorer:
    ==================
    HKU\S-1-5-21-2499712881-288055672-3602056328-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://msn.com/
    BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll [2015-12-11] (AVAST Software)
    BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-11] (Google Inc.)
    BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
    BHO: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
    BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2015-12-11] (AVAST Software)
    BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-11] (Google Inc.)
    BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)
    BHO-x32: Office Document Cache Handler -> {B4F3A835-0E21-4959-BA22-42B3008E02FF} -> C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL [2010-02-28] (Microsoft Corporation)
    Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-11] (Google Inc.)
    Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-12-11] (Google Inc.)
    Toolbar: HKU\S-1-5-21-2499712881-288055672-3602056328-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-12-11] (Google Inc.)
    Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll [2015-10-12] (Microsoft Corporation)
    Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll [2015-10-12] (Microsoft Corporation)

    FireFox:
    ========
    FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL [2010-01-09] (Microsoft Corporation)
    FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL [2010-03-24] (Microsoft Corporation)
    FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-11] (Google Inc.)
    FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-11] (Google Inc.)
    FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
    FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2015-12-11]

    Chrome:
    =======
    CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-12-11]

    ==================== Services (Whitelisted) ========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed]
    R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [226440 2015-12-11] (AVAST Software)
    R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1433216 2015-10-12] (Microsoft Corporation)
    R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1773696 2015-10-12] (Microsoft Corporation)
    S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [347880 2014-11-22] (Microsoft Corporation)
    S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23824 2014-11-22] (Microsoft Corporation)

    ===================== Drivers (Whitelisted) ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    R2 AODDriver4.2.0; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59648 2013-09-20] (Advanced Micro Devices)
    R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [28656 2015-12-11] (AVAST Software)
    R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [97648 2015-12-11] (AVAST Software)
    R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93528 2015-12-11] (AVAST Software)
    R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65224 2015-12-11] (AVAST Software)
    R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1055560 2015-12-11] (AVAST Software)
    R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [450504 2015-12-11] (AVAST Software)
    R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [155304 2015-12-11] (AVAST Software)
    R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [273784 2015-12-11] (AVAST Software)
    S0 ebdrv; C:\Windows\System32\drivers\evbda.sys [3357024 2013-08-22] (Broadcom Corporation)
    S3 WdBoot; C:\Windows\system32\drivers\WdBoot.sys [35856 2014-11-22] (Microsoft Corporation)
    S3 WdFilter; C:\Windows\system32\drivers\WdFilter.sys [257880 2014-11-22] (Microsoft Corporation)
    S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [123224 2014-11-22] (Microsoft Corporation)

    ==================== NetSvcs (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== One Month Created files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-12 12:56 - 2015-12-12 12:56 - 00009888 _____ C:\Users\Chris\Desktop\FRST.txt
    2015-12-12 12:56 - 2015-12-12 12:56 - 00000000 ____D C:\FRST
    2015-12-12 12:42 - 2015-12-12 12:42 - 02369536 _____ (Farbar) C:\Users\Chris\Desktop\FRST64.exe
    2015-12-12 11:28 - 2015-12-12 11:28 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_LocationProvider_01_11_00.Wdf
    2015-12-11 16:59 - 2015-12-11 16:59 - 00000000 ____D C:\Users\Chris\Tracing
    2015-12-11 12:13 - 2015-12-12 12:43 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Skype
    2015-12-11 12:13 - 2015-12-11 12:13 - 00002713 _____ C:\Users\Public\Desktop\Skype.lnk
    2015-12-11 12:13 - 2015-12-11 12:13 - 00000000 ___RD C:\Program Files (x86)\Skype
    2015-12-11 12:13 - 2015-12-11 12:13 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
    2015-12-11 12:12 - 2015-12-11 12:13 - 00000000 ____D C:\ProgramData\Skype
    2015-12-11 11:42 - 2015-12-11 11:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
    2015-12-11 11:41 - 2015-12-11 11:41 - 00000000 ____D C:\Windows\System32\Tasks\OfficeSoftwareProtectionPlatform
    2015-12-11 11:41 - 2015-12-11 11:41 - 00000000 ____D C:\Windows\PCHEALTH
    2015-12-11 11:38 - 2015-12-11 11:41 - 00000000 ____D C:\Program Files (x86)\Microsoft Office
    2015-12-11 11:38 - 2015-12-11 11:38 - 00000000 ____D C:\Users\Chris\AppData\Local\Microsoft Help
    2015-12-11 11:38 - 2015-12-11 11:38 - 00000000 ____D C:\Program Files\Microsoft Office
    2015-12-11 11:38 - 2015-12-11 11:38 - 00000000 ____D C:\Program Files (x86)\Microsoft Analysis Services
    2015-12-11 11:37 - 2015-12-11 11:37 - 00000000 __RHD C:\MSOCache
    2015-12-11 11:26 - 2015-12-11 11:26 - 00002790 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC
    2015-12-11 11:26 - 2015-12-11 11:26 - 00000834 _____ C:\Users\Public\Desktop\CCleaner.lnk
    2015-12-11 11:26 - 2015-12-11 11:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
    2015-12-11 11:25 - 2015-12-11 11:26 - 00000000 ____D C:\Program Files\CCleaner
    2015-12-11 11:21 - 2015-12-11 11:21 - 00000000 ____D C:\Users\Chris\AppData\Local\AMD
    2015-12-11 11:20 - 2015-12-11 11:20 - 00000000 ____D C:\Users\Chris\AppData\Roaming\ATI
    2015-12-11 11:20 - 2015-12-11 11:20 - 00000000 ____D C:\Users\Chris\AppData\Local\ATI
    2015-12-11 11:20 - 2015-12-11 11:20 - 00000000 ____D C:\ProgramData\ATI
    2015-12-11 11:14 - 2015-12-11 11:24 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Google
    2015-12-11 11:05 - 2015-12-12 12:15 - 00000924 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
    2015-12-11 11:05 - 2015-12-12 10:17 - 00000920 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
    2015-12-11 11:05 - 2015-12-11 11:14 - 00000000 ____D C:\Users\Chris\AppData\Local\Google
    2015-12-11 11:05 - 2015-12-11 11:10 - 00003896 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
    2015-12-11 11:05 - 2015-12-11 11:10 - 00003660 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
    2015-12-11 11:05 - 2015-12-11 11:05 - 00000000 ____D C:\ProgramData\Google
    2015-12-11 11:05 - 2015-12-11 11:05 - 00000000 ____D C:\Program Files\Google
    2015-12-11 11:05 - 2015-12-11 11:05 - 00000000 ____D C:\Program Files (x86)\Google
    2015-12-11 11:04 - 2015-12-11 11:03 - 00386096 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
    2015-12-11 11:03 - 2015-12-12 10:17 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update
    2015-12-11 11:03 - 2015-12-11 11:03 - 01055560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00450504 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00273784 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00155304 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00097648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00093528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00065224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00043112 _____ (AVAST Software) C:\Windows\avastSS.scr
    2015-12-11 11:03 - 2015-12-11 11:03 - 00028656 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
    2015-12-11 11:03 - 2015-12-11 11:03 - 00001938 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
    2015-12-11 11:03 - 2015-12-11 11:03 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_11_00.Wdf
    2015-12-11 11:03 - 2015-12-11 11:03 - 00000000 ____D C:\Windows\System32\Tasks\AVAST Software
    2015-12-11 11:03 - 2015-12-11 11:03 - 00000000 ____D C:\Users\Chris\AppData\Roaming\AVAST Software
    2015-12-11 11:03 - 2015-12-11 11:03 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
    2015-12-11 11:03 - 2015-12-11 11:03 - 00000000 ____D C:\Program Files\Common Files\AV
    2015-12-11 11:02 - 2015-12-11 11:02 - 00000000 ____D C:\Program Files\AVAST Software
    2015-12-11 11:01 - 2015-12-11 11:01 - 00000000 ____D C:\ProgramData\AVAST Software
    2015-12-11 10:53 - 2015-12-11 10:53 - 00000329 _____ C:\Users\Chris\Desktop\Gmail.url
    2015-12-11 10:52 - 2015-12-12 10:20 - 00003926 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{AC71DBD5-EAB8-406D-A390-E853216F4A47}
    2015-12-11 10:52 - 2015-12-11 10:52 - 00000000 __SHD C:\Users\Chris\AppData\LocalLow\EmieUserList
    2015-12-11 10:52 - 2015-12-11 10:52 - 00000000 __SHD C:\Users\Chris\AppData\LocalLow\EmieSiteList
    2015-12-11 10:52 - 2015-12-11 10:52 - 00000000 __SHD C:\Users\Chris\AppData\LocalLow\EmieBrowserModeList
    2015-12-11 10:52 - 2015-12-11 10:52 - 00000000 __SHD C:\Users\Chris\AppData\Local\EmieUserList
    2015-12-11 10:52 - 2015-12-11 10:52 - 00000000 __SHD C:\Users\Chris\AppData\Local\EmieSiteList
    2015-12-11 10:52 - 2015-12-11 10:52 - 00000000 __SHD C:\Users\Chris\AppData\Local\EmieBrowserModeList
    2015-12-11 10:52 - 2015-12-11 10:52 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Macromedia
    2015-12-11 10:51 - 2015-12-11 10:52 - 00000000 ____D C:\Windows\LastGood.Tmp
    2015-12-11 10:50 - 2015-12-11 10:50 - 00000000 ____D C:\ProgramData\Package Cache
    2015-12-11 10:50 - 2015-12-11 10:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AMD Catalyst Control Center
    2015-12-11 10:50 - 2015-12-11 10:50 - 00000000 ____D C:\ProgramData\AMD
    2015-12-11 10:50 - 2015-12-11 10:50 - 00000000 ____D C:\Program Files\ATI Technologies
    2015-12-11 10:50 - 2015-12-11 10:50 - 00000000 ____D C:\Program Files (x86)\ATI Technologies
    2015-12-11 10:50 - 2015-12-11 10:50 - 00000000 ____D C:\AMD
    2015-12-11 10:50 - 2015-12-11 10:50 - 00000000 _____ C:\Windows\ativpsrm.bin
    2015-12-11 10:49 - 2015-12-11 10:49 - 00000000 ____D C:\Program Files\Common Files\ATI Technologies
    2015-12-11 10:49 - 2015-12-11 10:49 - 00000000 ____D C:\Program Files\AMD
    2015-12-11 10:46 - 2015-12-12 11:24 - 00003596 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2499712881-288055672-3602056328-1001
    2015-12-11 10:46 - 2015-12-11 10:46 - 00000000 ____D C:\Users\Chris\AppData\Local\GWX
    2015-12-11 10:41 - 2015-12-11 16:59 - 00000000 ____D C:\Users\Chris
    2015-12-11 10:41 - 2015-12-11 10:42 - 00000000 ____D C:\Users\Chris\AppData\Local\Packages
    2015-12-11 10:41 - 2015-12-11 10:41 - 00001442 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
    2015-12-11 10:41 - 2015-12-11 10:41 - 00000020 ___SH C:\Users\Chris\ntuser.ini
    2015-12-11 10:41 - 2015-12-11 10:41 - 00000000 ____D C:\Windows\System32\Tasks\WPD
    2015-12-11 10:41 - 2015-12-11 10:41 - 00000000 ____D C:\Users\Chris\AppData\Roaming\Adobe
    2015-12-11 10:41 - 2015-12-11 10:41 - 00000000 ____D C:\Users\Chris\AppData\Local\VirtualStore
    2015-12-11 10:41 - 2014-11-22 01:02 - 00000369 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Pictures.lnk
    2015-12-11 10:41 - 2014-11-22 01:02 - 00000369 _____ C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Documents.lnk
    2015-12-11 10:39 - 2015-12-11 10:42 - 00000000 ___SD C:\Windows\system32\GWX
    2015-12-11 10:39 - 2015-12-11 10:39 - 00000000 ___SD C:\Windows\SysWOW64\GWX
    2015-12-11 10:37 - 2015-11-14 14:50 - 00133248 _____ (Microsoft Corporation) C:\Windows\system32\RestoreOptIn.exe
    2015-12-11 10:37 - 2015-11-14 14:50 - 00114160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RestoreOptIn.exe
    2015-12-11 10:37 - 2015-10-20 21:54 - 00136904 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
    2015-12-11 10:37 - 2015-10-20 14:53 - 03705856 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
    2015-12-11 10:37 - 2015-10-20 14:36 - 02243072 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
    2015-12-11 10:37 - 2015-10-20 14:35 - 00891904 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll
    2015-12-11 10:37 - 2015-10-20 14:34 - 00409088 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll
    2015-12-11 10:37 - 2015-10-20 14:34 - 00140288 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
    2015-12-11 10:37 - 2015-10-20 14:34 - 00035840 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
    2015-12-11 10:37 - 2015-10-20 14:33 - 00095744 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll
    2015-12-11 10:37 - 2015-10-20 14:14 - 00721920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
    2015-12-11 10:37 - 2015-10-20 14:13 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
    2015-12-11 10:37 - 2015-10-20 14:13 - 00081920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
    2015-12-11 10:37 - 2015-10-20 14:13 - 00029696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
    2015-12-11 10:37 - 2015-08-11 02:47 - 02757072 _____ (Microsoft Corporation) C:\Windows\explorer.exe
    2015-12-11 10:37 - 2015-08-11 02:47 - 02414096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe
    2015-12-11 10:37 - 2015-07-09 18:40 - 00359936 _____ (Microsoft Corporation) C:\Windows\system32\WinSetupUI.dll
    2015-12-11 10:37 - 2015-06-27 03:08 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\wups.dll
    2015-12-11 10:37 - 2015-06-27 03:08 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
    2015-12-11 10:37 - 2015-06-27 02:14 - 00027136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
    2015-12-11 10:37 - 2015-03-14 01:51 - 00015360 _____ (Microsoft Corporation) C:\Windows\system32\wu.upgrade.ps.dll
    2015-12-11 10:37 - 2014-10-18 06:50 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\wuaext.dll
    2015-12-11 10:30 - 2015-12-11 11:27 - 00000000 ____D C:\Windows\Panther

    ==================== One Month Modified files and folders ========

    (If an entry is included in the fixlist, the file/folder will be moved.)

    2015-12-12 12:56 - 2013-08-22 13:36 - 00000000 ____D C:\Windows
    2015-12-12 11:28 - 2013-08-22 13:36 - 00000000 ____D C:\Windows\Inf
    2015-12-11 17:57 - 2013-08-22 15:36 - 00000000 ___HD C:\Program Files\WindowsApps
    2015-12-11 11:50 - 2014-11-22 01:01 - 00818732 _____ C:\Windows\system32\PerfStringBackup.INI
    2015-12-11 11:45 - 2013-08-22 14:45 - 00000006 ____H C:\Windows\Tasks\SA.DAT
    2015-12-11 11:45 - 2013-08-22 14:44 - 00410392 _____ C:\Windows\system32\FNTCACHE.DAT
    2015-12-11 11:44 - 2013-08-22 13:25 - 00262144 ___SH C:\Windows\system32\config\BBI
    2015-12-11 11:41 - 2013-08-22 15:36 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
    2015-12-11 11:38 - 2014-11-22 00:45 - 00000000 ____D C:\Windows\ShellNew
    2015-12-11 10:55 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\AppReadiness
    2015-12-11 10:39 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\SysWOW64\en-GB
    2015-12-11 10:39 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\system32\en-GB
    2015-12-11 10:38 - 2013-08-22 15:20 - 00000000 ____D C:\Windows\CbsTemp
    2015-12-11 10:38 - 2013-08-22 13:36 - 00000000 ____D C:\Windows\system32\AdvancedInstallers
    2015-12-11 10:37 - 2013-08-22 15:36 - 00000000 ____D C:\Windows\rescache
    2015-12-11 10:30 - 2013-08-22 15:36 - 00262144 _____ C:\Windows\system32\config\BCD-Template

    Some files in TEMP:
    ====================
    C:\Users\Chris\AppData\Local\Temp\ose00000.exe


    ==================== Bamital & volsnap =================

    (There is no automatic fix for files that do not pass verification.)

    C:\Windows\system32\winlogon.exe => File is digitally signed
    C:\Windows\system32\wininit.exe => File is digitally signed
    C:\Windows\explorer.exe => File is digitally signed
    C:\Windows\SysWOW64\explorer.exe => File is digitally signed
    C:\Windows\system32\svchost.exe => File is digitally signed
    C:\Windows\SysWOW64\svchost.exe => File is digitally signed
    C:\Windows\system32\services.exe => File is digitally signed
    C:\Windows\system32\User32.dll => File is digitally signed
    C:\Windows\SysWOW64\User32.dll => File is digitally signed
    C:\Windows\system32\userinit.exe => File is digitally signed
    C:\Windows\SysWOW64\userinit.exe => File is digitally signed
    C:\Windows\system32\rpcss.dll => File is digitally signed
    C:\Windows\system32\dnsapi.dll => File is digitally signed
    C:\Windows\SysWOW64\dnsapi.dll => File is digitally signed
    C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed


    LastRegBack: 2015-12-11 10:31

    ==================== End of FRST.txt ============================


    dditional scan result of Farbar Recovery Scan Tool (x64) Version:12-12-2015
    Ran by Chris (2015-12-12 12:56:51)
    Running from C:\Users\Chris\Desktop
    Windows 8.1 (X64) (2015-12-11 10:41:00)
    Boot Mode: Normal
    ==========================================================


    ==================== Accounts: =============================

    Administrator (S-1-5-21-2499712881-288055672-3602056328-500 - Administrator - Disabled)
    Chris (S-1-5-21-2499712881-288055672-3602056328-1001 - Administrator - Enabled) => C:\Users\Chris
    Guest (S-1-5-21-2499712881-288055672-3602056328-501 - Limited - Disabled)
    HomeGroupUser$ (S-1-5-21-2499712881-288055672-3602056328-1003 - Limited - Enabled)

    ==================== Security Center ========================

    (If an entry is included in the fixlist, it will be removed.)

    AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
    AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
    AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

    ==================== Installed Programs ======================

    (Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

    Avast Free Antivirus (HKLM-x32\...\Avast) (Version: 11.1.2245 - AVAST Software)
    Catalyst Control Center (HKLM-x32\...\WUCCCApp) (Version: 1.00.0000 - AMD)
    CCleaner (HKLM\...\CCleaner) (Version: 5.12 - Piriform)
    Google Toolbar for Internet Explorer (HKLM-x32\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.6904.2028 - Google Inc.)
    Google Toolbar for Internet Explorer (x32 Version: 1.0.0 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden
    Google Update Helper (x32 Version: 1.3.29.1 - Google Inc.) Hidden
    Microsoft Office Home and Student 2010 (HKLM-x32\...\Office14.SingleImage) (Version: 14.0.4763.1000 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
    Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.5.0.9082 - Microsoft Corporation)
    Skype™ 7.16 (HKLM-x32\...\{FC965A47-4839-40CA-B618-18F486F042C6}) (Version: 7.16.102 - Skype Technologies S.A.)

    ==================== Custom CLSID (Whitelisted): ==========================

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)


    ==================== Restore Points =========================

    11-12-2015 10:37:53 Windows Modules Installer
    11-12-2015 10:38:17 Windows Modules Installer

    ==================== Hosts content: ===============================

    (If needed Hosts: directive could be included in the fixlist to reset Hosts.)

    2013-08-22 13:25 - 2013-08-22 13:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts


    ==================== Scheduled Tasks (Whitelisted) =============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    Task: {06946545-8722-49A0-AE2C-54EBF551782E} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-11] (Google Inc.)
    Task: {1185D3AE-1E6E-454C-949E-1E657337D5D5} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-12-11] (AVAST Software)
    Task: {25D5AF7F-A747-4212-9927-B65803B47EFB} - System32\Tasks\AVAST Software\Avast settings backup => C:\Program Files\Common Files\AV\avast! Antivirus\backup.exe [2015-12-11] (AVAST Software)
    Task: {78077EC9-2FC5-4AB9-90FF-23D60F326AAB} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-12-11] (Google Inc.)
    Task: {E8BA03C4-75E6-4DA3-A6F2-BAA062B6963E} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2015-11-16] (Piriform Ltd)

    (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)

    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
    Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

    ==================== Shortcuts =============================

    (The entries could be listed to be restored or removed.)

    ==================== Loaded Modules (Whitelisted) ==============

    2014-07-04 21:33 - 2014-07-04 21:33 - 00127488 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
    2014-07-04 21:33 - 2014-07-04 21:33 - 00102400 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
    2015-12-11 11:03 - 2015-12-11 11:03 - 00103888 _____ () C:\Program Files\AVAST Software\Avast\log.dll
    2015-12-11 11:03 - 2015-12-11 11:03 - 00125512 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
    2015-12-11 11:04 - 2015-12-11 11:04 - 02803200 _____ () C:\Program Files\AVAST Software\Avast\defs\15121000\algo.dll
    2015-12-11 11:03 - 2015-12-11 11:03 - 00469008 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
    2015-12-11 11:46 - 2015-12-11 11:46 - 02803200 _____ () C:\Program Files\AVAST Software\Avast\defs\15121100\algo.dll
    2015-12-12 11:21 - 2015-12-12 11:21 - 02803200 _____ () C:\Program Files\AVAST Software\Avast\defs\15121200\algo.dll
    2015-11-25 20:18 - 2015-11-25 20:18 - 00147136 ____R () C:\Program Files (x86)\Skype\Phone\ssScreenVVS2.dll
    2015-12-11 11:03 - 2015-12-11 11:03 - 40539648 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
    2010-01-30 02:41 - 2010-01-30 02:41 - 04254560 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\office14\Cultures\office.odf

    ==================== Alternate Data Streams (Whitelisted) =========

    (If an entry is included in the fixlist, only the ADS will be removed.)


    ==================== Safe Mode (Whitelisted) ===================

    (If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)


    ==================== EXE Association (Whitelisted) ===============

    (If an entry is included in the fixlist, the registry item will be restored to default or removed.)


    ==================== Internet Explorer trusted/restricted ===============

    (If an entry is included in the fixlist, it will be removed from the registry.)


    ==================== Other Areas ============================

    (Currently there is no automatic fix for this section.)

    HKU\S-1-5-21-2499712881-288055672-3602056328-1001\Control Panel\Desktop\\Wallpaper -> C:\Users\Chris\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper
    DNS Servers: 192.168.0.1
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
    Windows Firewall is enabled.

    ==================== MSCONFIG/TASK MANAGER disabled items ==

    (Currently there is no automatic fix for this section.)


    ==================== FirewallRules (Whitelisted) ===============

    (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)

    FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
    FirewallRules: [TCP Query User{A2B47ED7-72EE-49AA-B7F7-73A23B43FF01}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [UDP Query User{104ABD8E-DD90-444D-9666-6A9E311AC2EA}C:\program files (x86)\skype\phone\skype.exe] => (Allow) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [TCP Query User{69AFF802-EEF4-4404-8256-DF0D1F99B453}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe
    FirewallRules: [UDP Query User{517A71CD-AF86-4657-BB2F-9F2A1B17314E}C:\program files (x86)\skype\phone\skype.exe] => (Block) C:\program files (x86)\skype\phone\skype.exe

    ==================== Faulty Device Manager Devices =============


    ==================== Event log errors: =========================

    Application errors:
    ==================
    Error: (12/11/2015 10:42:12 AM) (Source: Software Protection Platform Service) (EventID: 8198) (User: )
    Description: License Activation (slui.exe) failed with the following error code:
    hr=0xC004E028
    Command-line arguments:
    RuleId=31e71c49-8da7-4a2f-ad92-45d98a1c79ba;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=9e4b231b-3e45-41f4-967f-c914f178b6ac;NotificationInterval=1440;Trigger=UserLogon;SessionId=1


    System errors:
    =============
    Error: (12/12/2015 11:27:14 AM) (Source: Schannel) (EventID: 4120) (User: NT AUTHORITY)
    Description: A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 10. The Windows SChannel error state is 10.

    Error: (12/11/2015 09:23:10 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the AudioEndpointBuilder service.

    Error: (12/11/2015 09:22:40 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
    Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the WlanSvc service.

    Error: (12/11/2015 11:45:45 AM) (Source: DCOM) (EventID: 10016) (User: OfficePC)
    Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}OfficePCChrisS-1-5-21-2499712881-288055672-3602056328-1001LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/11/2015 11:45:45 AM) (Source: DCOM) (EventID: 10016) (User: OfficePC)
    Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}OfficePCChrisS-1-5-21-2499712881-288055672-3602056328-1001LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/11/2015 11:45:45 AM) (Source: DCOM) (EventID: 10016) (User: OfficePC)
    Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}OfficePCChrisS-1-5-21-2499712881-288055672-3602056328-1001LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/11/2015 11:45:45 AM) (Source: DCOM) (EventID: 10016) (User: OfficePC)
    Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}OfficePCChrisS-1-5-21-2499712881-288055672-3602056328-1001LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/11/2015 11:45:45 AM) (Source: DCOM) (EventID: 10016) (User: OfficePC)
    Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}OfficePCChrisS-1-5-21-2499712881-288055672-3602056328-1001LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/11/2015 11:45:44 AM) (Source: DCOM) (EventID: 10016) (User: OfficePC)
    Description: application-specificLocalLaunch{7022A3B3-D004-4F52-AF11-E9E987FEE25F}{ADA41B3C-C6FD-4A08-8CC1-D6EFDE67BE7D}OfficePCChrisS-1-5-21-2499712881-288055672-3602056328-1001LocalHost (Using LRPC)UnavailableUnavailable

    Error: (12/11/2015 11:24:55 AM) (Source: Schannel) (EventID: 4119) (User: NT AUTHORITY)
    Description: A fatal alert was received from the remote endpoint. The TLS protocol defined fatal alert code is 20.


    ==================== Memory info ===========================

    Processor: AMD A8-6500 APU with Radeon(tm) HD Graphics
    Percentage of memory in use: 48%
    Total physical RAM: 5317.45 MB
    Available physical RAM: 2738.67 MB
    Total Virtual: 6917.45 MB
    Available Virtual: 3828.04 MB

    ==================== Drives ================================

    Drive c: () (Fixed) (Total:464.81 GB) (Free:444.07 GB) NTFS
    Drive e: () (Removable) (Total:62.5 GB) (Free:60.92 GB) exFAT

    ==================== MBR & Partition Table ==================

    ========================================================
    Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: 00000000)

    Partition: GPT.

    ========================================================
    Disk: 1 (Size: 62.5 GB) (Disk ID: BCB7C70A)
    Partition 1: (Not Active) - (Size=62.5 GB) - (Type=07 NTFS)

    ==================== End of Addition.txt ============================

  8. #7
    Member Spyware Fighter DonnaB's Avatar
    Join Date
    Apr 2009
    Location
    Illiana, Ill. USA
    Posts
    3,521
    Points
    563

    Default

    Hi Chris,

    I am back. I see you have Avast installed. I have Avast installed as well and that happens to me all the time. In order to download a file that I know is safe I sometimes have to right click on the orange Avast orb in my task bar and go into the Avast shields control to disable the program for at least 10 minutes, or so, then I have no problems what so ever. It can be a pain but I don't complain since that is why I have Avast installed. It really is a good AntiVirus...sometimes too good!

    However, I think you might end up pulling your hair out & screaming at 'ChrisCCB' & thinking, "why did I ever get involved.......where do these geeks come from"!!!
    Never! With my help we are going to get this task accomplished successfully and that Windows 10 update/upgrade will never bother you again. All I need for you to do is take your time and read the instructions thoroughly.

    The following script will generate a log that will show me what the values for the Windows 10 registry keys are set for.

    Please do as follows:

    • Open notepad.
    • Please copy the entire contents of the code box below.
      (To do this highlight the contents of the box, right click on it and select copy. Right-click in the open notepad and select Paste).
    • Save it to the desktop.

      Code:
      Reg: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\GWX"
      Reg: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\OSUpgrade"
      Reg: reg query "HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU"
      NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
    • Right click on frst64.exe and choose Run as administrator. (please wait a moment to allow it to update if needed)
    • Click the Fix button just once and wait.
    • The fixlist.txt will disappear from the desktop and a Fixlog.txt will appear in it's place. Please post it to your next reply.
    If you think you might be infected with malware or have recently cleansed your computer of malware without the help of an expert, please read and follow the instructions in How to Start Removing Viruses and Spyware from your Computer. This can alleviate time consumed in trouble shooting your current computer problems.

    If your problem is solved, here's how to say thanks!

    Very proud parent of a U.S. Navy "CB"



    "People may forget what you say,
    People may forget what you did,
    but People will never forget how you made them feel!"

  9. The Following User Says Thank You to DonnaB For This Useful Post:


  10. #8
    Member
    Join Date
    Dec 2015
    Posts
    22
    Points
    0

    Default

    Hi DonnaB - are you confused yet or fed up with me? I've followed your instructions, and having pasted 'the code' on to 'notepad', it won't let me save it on to the desktop. In fact, it won't let me save it, period!!! The strange thing is though...there was a window icon in the bottom right hand corner of my screen, if I clicked on this icon it brought up a box with the option to upgrade to Windows 10. The point is...this window at the bottom right hand corner has gone, it is no more!!! I don't know if this is a fluke, if the computer is playing games with me, or if, having followed your initial instructions it has solved the problem? I have no idea. Do we (you) keep trying to address this issue, or do we now leave it & see what happens? If I wasn't confused before, I sure am now!!

  11. #9
    Member Spyware Fighter DonnaB's Avatar
    Join Date
    Apr 2009
    Location
    Illiana, Ill. USA
    Posts
    3,521
    Points
    563

    Default

    Hi Chris,

    I am kind of confused but fed up? Nope! Just wondering if maybe that first .reg fix I gave you to try in post #2 may have worked and you just didn't realize it. If it did work that little white windows icon in the bottom right hand corner of your screen should have disappeared. Let's make sure it isn't hidden.

    Do you see a little arrow that is pointing up in the lower right hand corner? It will look like this >

    Click on that and a little box should open up that has the work Customize.. in it. It will look "similar" to the one below



    Click on the word Customize.. and a bigger window should open that has a scroll bar on the right hand side. Place your cursor on that scroll bar and move it up and down. Do you see that little white windows icon in there anywhere?
    If you think you might be infected with malware or have recently cleansed your computer of malware without the help of an expert, please read and follow the instructions in How to Start Removing Viruses and Spyware from your Computer. This can alleviate time consumed in trouble shooting your current computer problems.

    If your problem is solved, here's how to say thanks!

    Very proud parent of a U.S. Navy "CB"



    "People may forget what you say,
    People may forget what you did,
    but People will never forget how you made them feel!"

  12. #10
    Member
    Join Date
    Dec 2015
    Posts
    22
    Points
    0

    Default

    Hi DonnaB.........bummer...and double bummer!!!!! ......sorry for the language, especially in front of a lady, I apologise. I followed your instructions further, and would you believe it, the window thingy is there, where you said it would be!!! Now what?????

Page 1 of 3 123 LastLast