Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

xp will only boot in safe mode without networking


  • This topic is locked This topic is locked
4 replies to this topic

#1 lroyce

lroyce

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:28 PM

Posted 27 March 2014 - 07:58 AM

hello,

I am having problems with xp . After a failed linux mint install my current xp install went down under. I get to the loading screen and after some time it freezes. I tried safe mode and it works. I tried safe mode with networking and it freezes after showing that mup.sys is loading . I tried in safe mode to set up a diagnostic startup . One restart later it still freezes, which is odd since I thought that diagnostic startup is basically safe mode. I have two hdd so I took out the hdd with the xp install and I intalled xp sp3 on the hdd with the failed mint install on it. Everything ran fine (and slow) and after a restart I got the same problem on this new xp installation. It only works in safe mode without networking. The lan card can't be the problem since the internet works if I boot from a puppy linux or even mint linux cd. But just to be safe I tried booting xp without the lan card. Same problem, xp freezes at loading screen.

Maybe the attached report about what is scheduled to be loade/run may be useful. To view it you need http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

Is there any way to trace the boot process so i may see where exactly xp freezes? boot logging I understand will not work . There are some entries in the log file but I think only the sessions where I booted into safe mode are in that log. I will attach that file too (it's too long to post) .

 

Thanks

Attached Files



BC AdBot (Login to Remove)

 


#2 dls62

dls62

  • Members
  • 623 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Berkshire, UK
  • Local time:11:28 AM

Posted 27 March 2014 - 09:28 AM

I notice in the Autoruns file that there is a startup rohklm.cmd.  Is that related to XP SP3 Black Edition?



#3 lroyce

lroyce
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:28 PM

Posted 27 March 2014 - 10:15 AM

I notice in the Autoruns file that there is a startup rohklm.cmd.  Is that related to XP SP3 Black Edition?

First i just want to say i tried an xp home sp2 iso from one of those "shady" sites and it works. Now i will check what the rohklm file is about. I think it was created during slipstreaming.  I hope this xp-dead-freeze at loading  isn't something sp3 related


Edited by lroyce, 27 March 2014 - 10:28 AM.


#4 lroyce

lroyce
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:12:28 PM

Posted 27 March 2014 - 10:27 AM


 

I notice in the Autoruns file that there is a startup rohklm.cmd.  Is that related to XP SP3 Black Edition

 

rohklm.cmd. Since i never got to start xp in normal mode after setup i guess this cmd file never managed to run and get deleted

@ECHO OFF
TITLE RunOnce // HKLM


ECHO Starting HKLM RunOnce
ECHO ===============================================================================
ping -n 3 localhost 1>NUL


:: Loads the Default User "NTUSER.DAT" file.
REG LOAD "HKU\TempHive" "%SystemDrive%\Documents and Settings\Default User\NTUSER.DAT" 1>NUL

:: If a Windows XP component was removed then this needs be set to "ffffff9d" (Off) or to "00000004" (Disable Prompts).
ECHO.
ECHO Disabling the System File Protection...
REG ADD "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "SfcDisable" /t REG_DWORD /d "ffffff9d" /f 1>NUL

ECHO.
ECHO Disabling the Windows XP Start Menu advertising...
REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "StartButtonBalloonTip" /t REG_DWORD /d "00000002" /f 1>NUL
REG ADD "HKU\TempHive\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "StartButtonBalloonTip" /t REG_DWORD /d "00000002" /f 1>NUL
REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "StartMenuInit" /t REG_DWORD /d "00000002" /f 1>NUL
REG ADD "HKU\TempHive\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced" /v "StartMenuInit" /t REG_DWORD /d "00000002" /f 1>NUL

ECHO.
ECHO Enabling the Windows XP Quick Launch...
REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop" /v "TaskbarWinXP" /t REG_BINARY /d "0c000000080000000300000000000000b0e22bd86457d011a96e00c04fd705a222001c000a1100001a000000010000000000000000000000000000004c0000000114020000000000c0000000000000468100000011000000b6f3c3b323f7cd012eeb4acb23f7cd01888549bf23f7cd01000000000000000001000000000000000000000000000000ff0114001f50e04fd020ea3a6910a2d808002b30309d19002f433a5c000000000000000000000000000000000000005c0031000000000034425d7c1000444f43554d457e310000440003000400efbe34426d1334425d7c1400000044006f00630075006d0065006e0074007300200061006e0064002000530065007400740069006e00670073000000180034003100000000003442617c10006c6f6c330000200003000400efbe34425d7c3442617c140000006c006f006c0033000000140064003100000000003442ae1313004150504c49437e3100004c0003000400efbe34425d7c3442607c140036004100700070006c00690063006100740069006f006e00200044006100740061000000407368656c6c33322e646c6c2c2d323137363500180042003100000000003442617c14004d4943524f537e3100002a0003000400efbe34425d7c3442647c140000004d006900630072006f0073006f00660074000000180052003100000000003442657c1000494e5445524e7e3100003a0003000400efbe34425d7c3442697c1400000049006e007400650072006e006500740020004500780070006c006f007200650072000000180048003100000000003442697c1100515549434b4c7e310000300003000400efbe34425d7c3442697c1400000051007500690063006b0020004c00610075006e006300680000001800000060000000030000a05800000000000000636f6d70757465722d38373730000000d47d27172263fa40955d9c421902fca89ed0420b1763e211a805080027169eb7d47d27172263fa40955d9c421902fca89ed0420b1763e211a805080027169eb710000000050000a01a000000210100000000000008000000020000000c01000001000000020000008a000000010000007c0032002f0300003442647c20004c41554e43487e312e4c4e4b0000600003000400efbe3442647c3442647c140000004c00610075006e0063006800200049006e007400650072006e006500740020004500780070006c006f007200650072002000420072006f0077007300650072002e006c006e006b0000001c000000000000007600000000000000680032004f0000003442697c200053484f5744457e312e53434600004c0003000400efbe3442697c3442697c14003600530068006f00770020004400650073006b0074006f0070002e0073006300660000004078707370327265732e646c6c2c2d36313030001c000000000000000000000060070000000000001e00000000000000000000001e000000000000000100000001000000aa4f2868486ad0118c7800c04fd918b47f010000600d0000000000001e00000000000000000000001e0000000000000001000000020000008b8a0d543f1c324e8132530f6a5020901d00000060050000000000001c00000000000000000000001c0000000000000001000000" /f 1>NUL
REG ADD "HKU\TempHive\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop" /v "TaskbarWinXP" /t REG_BINARY /d "0c000000080000000300000000000000b0e22bd86457d011a96e00c04fd705a222001c000a1100001a000000010000000000000000000000000000004c0000000114020000000000c0000000000000468100000011000000b6f3c3b323f7cd012eeb4acb23f7cd01888549bf23f7cd01000000000000000001000000000000000000000000000000ff0114001f50e04fd020ea3a6910a2d808002b30309d19002f433a5c000000000000000000000000000000000000005c0031000000000034425d7c1000444f43554d457e310000440003000400efbe34426d1334425d7c1400000044006f00630075006d0065006e0074007300200061006e0064002000530065007400740069006e00670073000000180034003100000000003442617c10006c6f6c330000200003000400efbe34425d7c3442617c140000006c006f006c0033000000140064003100000000003442ae1313004150504c49437e3100004c0003000400efbe34425d7c3442607c140036004100700070006c00690063006100740069006f006e00200044006100740061000000407368656c6c33322e646c6c2c2d323137363500180042003100000000003442617c14004d4943524f537e3100002a0003000400efbe34425d7c3442647c140000004d006900630072006f0073006f00660074000000180052003100000000003442657c1000494e5445524e7e3100003a0003000400efbe34425d7c3442697c1400000049006e007400650072006e006500740020004500780070006c006f007200650072000000180048003100000000003442697c1100515549434b4c7e310000300003000400efbe34425d7c3442697c1400000051007500690063006b0020004c00610075006e006300680000001800000060000000030000a05800000000000000636f6d70757465722d38373730000000d47d27172263fa40955d9c421902fca89ed0420b1763e211a805080027169eb7d47d27172263fa40955d9c421902fca89ed0420b1763e211a805080027169eb710000000050000a01a000000210100000000000008000000020000000c01000001000000020000008a000000010000007c0032002f0300003442647c20004c41554e43487e312e4c4e4b0000600003000400efbe3442647c3442647c140000004c00610075006e0063006800200049006e007400650072006e006500740020004500780070006c006f007200650072002000420072006f0077007300650072002e006c006e006b0000001c000000000000007600000000000000680032004f0000003442697c200053484f5744457e312e53434600004c0003000400efbe3442697c3442697c14003600530068006f00770020004400650073006b0074006f0070002e0073006300660000004078707370327265732e646c6c2c2d36313030001c000000000000000000000060070000000000001e00000000000000000000001e000000000000000100000001000000aa4f2868486ad0118c7800c04fd918b47f010000600d0000000000001e00000000000000000000001e0000000000000001000000020000008b8a0d543f1c324e8132530f6a5020901d00000060050000000000001c00000000000000000000001c0000000000000001000000" /f 1>NUL

ECHO.
ECHO Adding a Registry Key to execute the file "ROHKCU.CMD" at
ECHO the first desktop start...
REG ADD "HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce" /v "ROHKCU" /t REG_EXPAND_SZ /d "\"%%SystemRoot%%\ROHKCU.CMD\"" /f 1>NUL

:: Unloads the Default User "NTUSER.DAT" file.
REG UNLOAD "HKU\TempHive" 1>NUL


ECHO.
ECHO ----------------------------------[Finished]-----------------------------------
ping -n 3 localhost 1>NUL
:REPEAT
DEL "%SystemRoot%\ROHKLM.CMD" >NUL 2>&1
ping -n 1 localhost 1>NUL
IF EXIST "%SystemRoot%\ROHKLM.CMD" GOTO REPEAT
ExIT

What good tools    that may help trace the boot process of win xp are there?to bad i can't try debugging mode since i don't have a spare pc around with a serial port.


Edited by lroyce, 27 March 2014 - 10:44 AM.


#5 hamluis

hamluis

    Moderator


  • Moderator
  • 56,272 posts
  • ONLINE
  •  
  • Gender:Male
  • Location:Killeen, TX
  • Local time:05:28 AM

Posted 27 March 2014 - 11:28 AM

The file rohklm.cmd appears to relate XP Black Edition, which is an illegal download/install violating the Windows EULA/licensing terms.

 

Excerpt from the forum rules (link in my signature):

 

"No subject matter will be allowed whose purpose is to defeat existing copyright or security measures. If a user persists and/or the activity is obviously illegal the staff reserves the right to remove such content and/or ban the user. This would also mean encouraging the use or continued use of pirated software is not permitted, and subject to the same consequences."

Your use of an illegal version of Windows prevents us from offering any further assistance to you.

 

This topic is now closed.  If you wish to contact me about my actions, please do so via PM and I will attempt to respond responsibly.

 

Louis






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users