Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Windows fails to start. Safe mode doesn't work


  • This topic is locked This topic is locked
21 replies to this topic

#1 wukassa

wukassa

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 10 February 2015 - 04:20 AM

Hi there!

A friend gave me his Acer notebook  running on Windows 7 because it stopped working hoping that I can fix it.

It fails to start, safe mode doesn't work, last known configuration doesn't work, system repair doesn't work, system restore doesn't work.

 

The computer is extremely slow.

 

The Windows Repair Problem Signature
Problem Event Name: StartupRepairOffline
Problem Signature 1: 6.1.7600.16385
Problem Signature 2: 6.1.7600.16385
Problem Signature 3: Unknown
Problem Signature 4: 21200033
Problem Signature 5: AutoFailover
Problem Signature 6: 4
Problem Signature 7: NoRootCause
OS Version: 6.1.7600.2.0.0.256.1
Locale ID: 1040

 

I'm pretty much in this situation

http://www.bleepingcomputer.com/forums/t/448339/

 

So, in the meantime I've used Farbar Recovery Scan Tool, so I'm attaching the log file hoping that it can help.

 

Thank you for now.

Cheers!

 

Attached Files

  • Attached File  FRST.txt   14.17KB   1 downloads

Edited by wukassa, 10 February 2015 - 12:43 PM.
Moved from Win 7 to Malware Removal Logs - Hamluis.


BC AdBot (Login to Remove)

 


#2 wukassa

wukassa
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 11 February 2015 - 12:03 PM

Hi,

After some a few clean up tries, no changes all remain the same...here's the latest log.

 

Cheers!

 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-02-2015
Ran by SYSTEM on MININT-J1LFDSN on 11-02-2015 16:22:53
Running from H:\
Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Italiano (Italia)
Internet Explorer Version 11
Boot Mode: Recovery
 
The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.
 
 
==================== Registry (Whitelisted) ==================
 
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
 
HKLM\...\Run: [Power Management] => C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [1831016 2011-08-02] (Acer Incorporated)
HKLM-x32\...\Run: [BackupManagerTray] => C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe [297280 2011-04-23] (NTI Corporation)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-02-08] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-16] (Renesas Electronics Corporation)
HKLM-x32\...\Run: [ArcadeMovieService] => C:\Program Files (x86)\Acer\clear.fi\Movie\clear.fiMovieService.exe [177448 2011-05-09] (CyberLink Corp.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [979328 2010-10-12] (SEIKO EPSON CORPORATION)
HKLM-x32\...\Run: [MobileBroadband] => C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe [408576 2011-04-19] (Vodafone)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-04-23] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [ApnTBMon] => C:\Program Files (x86)\AskPartnerNetwork\Toolbar\Updater\TBNotifier.exe [2039192 2014-11-24] (APN)
HKLM-x32\...\Run: [NBAgent] => C:\Program Files (x86)\Nero\Nero BackItUp & Burn\Nero BackItUp\NBAgent.exe [1086760 2010-03-14] (Nero AG)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-05-15] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [98304 2014-09-01] (Apple Computer, Inc.)
HKU\Andalu\...\Run: [EPLTarget\P0000000000000000] => C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIHLE.EXE [283232 2012-02-28] (SEIKO EPSON CORPORATION)
HKU\Default\...\RunOnce: [ScrSav] => C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
HKU\Default User\...\RunOnce: [ScrSav] => C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-07-29] ()
 
==================== Services (Whitelisted) =================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY)
S2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-10-30] (APN LLC.)
S3 GamesAppIntegrationService; C:\Program Files (x86)\WildTangent Games\App\GamesAppIntegrationService.exe [227904 2014-01-13] (WildTangent)
S2 NTI IScheduleSvc; C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [256832 2011-04-23] (NTI Corporation)
S2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2183992 2014-03-22] (AVG)
S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-26] (Microsoft Corporation)
 
==================== Drivers (Whitelisted) ====================
 
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
 
S3 ewusbnet; C:\Windows\System32\DRIVERS\ewusbnet.sys [413696 2011-04-18] (Huawei Technologies Co., Ltd.)
S3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-02-10] (TuneUp Software)
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S3 L1C; system32\DRIVERS\L1C62x64.sys [X]
S3 RSUSBSTOR; \SystemRoot\System32\Drivers\RtsUStor.sys [X]
 
==================== NetSvcs (Whitelisted) ===================
 
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
 
 
==================== Memory info =========================== 
 
Percentage of memory in use: 17%
Total physical RAM: 4077.86 MB
Available physical RAM: 3352.86 MB
Total Pagefile: 4076.06 MB
Available Pagefile: 3352.23 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB
 
==================== Drives ================================
 
Drive c: (Acer) (Fixed) (Total:682.54 GB) (Free:590.19 GB) NTFS
Drive e: (PQSERVICE) (Fixed) (Total:16 GB) (Free:2.36 GB) NTFS
Drive h: () (Removable) (Total:3.73 GB) (Free:3.71 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
==================== MBR & Partition Table ==================
 
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 698.6 GB) (Disk ID: B1445F45)
Partition 1: (Not Active) - (Size=16 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=682.5 GB) - (Type=07 NTFS)
 
========================================================
Disk: 2 (MBR Code: Windows 7 or 8) (Size: 3.7 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=3.7 GB) - (Type=0B)
 
 
LastRegBack: 2015-01-24 02:53
 
==================== End Of Log ============================


#3 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,374 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:57 PM

Posted 14 February 2015 - 10:29 PM

Greetings wukassa and :welcome: to BleepingComputer's Virus/Trojan/Spyware/Malware Removal forum.

My name is Oh My! and I am here to help you! Now that we are "friends" please call me Gary.

If you would allow me to call you by your first name I would prefer to do that.

===================================================

Ground Rules:
  • First, I would like to inform you that most of us here at Bleeping Computer offer our expert assistance out of the goodness of our hearts. Please try to match our commitment to you with your patience toward us. If this was easy we would never have met. :)
  • Please do not run any tools or take any steps other than those I will provide for you while we work on your computer together. I need to be certain about the state of your computer in order to provide appropriate and effective steps for you to take. Most often "well intentioned" (and usually panic driven!) independent efforts can make things much worse for both of us. If at any point you would prefer to take your own steps please let me know, I will not be offended. I would be happy to focus on the many others who are waiting in line for assistance.
  • Please perform all steps in the order they are listed in each set of instructions. Some steps may be a bit complicated. If things are not clear, be sure to stop and let me know. We need to work on this together with confidence.
  • Please copy and paste all logs into your post unless directed otherwise. Please do not re-run any programs I suggest. If you encounter problems simply stop and tell me.
  • When you post your reply, use the Replytopic.jpg button instead.
  • In the upper right hand corner of the topic you will see the Followtopic.jpg button. Click on this then choose Immediate E-Mail notification and then Proceed and you will be sent an email once I have posted a response.
  • If you do not reply to your topic after 5 days we assume it has been abandoned and I will close it.
  • When your computer is clean I will alert you of such. I will also provide for you detailed information about how you can combat future infections.
  • I would like to remind you to make no further changes to your computer unless I direct you to do so.
  • Now let's get started :thumbup2:
===================================================

Now that I am assisting you, you can expect that I will be very responsive to your situation. If you are able, I would request you check this thread at least once per day so that we can try to resolve your issues effectively and efficiently. If you are going to be delayed please be considerate and post that information so that I know you are still with me. Unfortunately, there are many people waiting to be assisted and not enough of us at BleepingComputer to go around. I appreciate your understanding and diligence.

Thank you for your patience thus far. Please run the following for me.

===================================================

Farbar's Recovery Scan Tool - Run Fix

--------------------
  • From a clean computer press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it on the flashdrive as fixlist.txt
LastRegBack: 2015-01-24 02:53
  • Insert the USB device into your infected computer
  • Enter the System Recovery Options (press F8 during boot up), select Repair Your Computer, then select Command Prompt.
  • Run FRST as you did the first time and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the flashdrive (Fixlog.txt). Copy and paste that information in your reply.
  • Please attempt to boot your computer into Normal Mode or, if not, Safe Mode
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Does your computer boot?

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#4 wukassa

wukassa
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 16 February 2015 - 05:04 AM

Hi Oh My!

As I said before computer is extremely slow even loading the recovery options or Farbar.

I've tried to boot but the computer is stuck on the Starting Windows screen.

It looks like is running (the logo is "live") but after a long time that's all I get.

 

Here's the log!

 

Thanks!

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-02-2015
Ran by SYSTEM at 2015-02-16 10:36:09 Run:3
Running from H:\
Boot Mode: Recovery
==============================================
 
Content of fixlist:
*****************
LastRegBack: 2015-01-24 02:53
*****************
 
DEFAULT hive was successfully copied to System32\config\HiveBackup
DEFAULT hive was successfully restored from registry back up.
SAM hive was successfully copied to System32\config\HiveBackup
SAM hive was successfully restored from registry back up.
SECURITY hive was successfully copied to System32\config\HiveBackup
SECURITY hive was successfully restored from registry back up.
SOFTWARE hive was successfully copied to System32\config\HiveBackup
SOFTWARE hive was successfully restored from registry back up.
SYSTEM hive was successfully copied to System32\config\HiveBackup
SYSTEM hive was successfully restored from registry back up.
 
==== End of Fixlog 10:45:35 ====


#5 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,374 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:57 PM

Posted 16 February 2015 - 09:43 AM

Thank you.

I will be away from my computer for the next several hours but will reply immediately upon my return.

Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix

--------------------
  • From a clean computer press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it on the flashdrive as fixlist.txt
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S3 L1C; system32\DRIVERS\L1C62x64.sys [X]
S3 RSUSBSTOR; \SystemRoot\System32\Drivers\RtsUStor.sys [X]
  • Insert the USB device into your infected computer
  • Enter the System Recovery Options (press F8 during boot up), select Repair Your Computer, then select Command Prompt.
  • Run FRST as you did the first time and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the flashdrive (Fixlog.txt). Copy and paste that information in your reply.
  • Type the following in the Search Field
explorer.exe;winint.exe;userinit.exe;winlogon.exe;svchost.exe
  • Click Search File(s) button
  • A Search.txt document will be saved to your USB device
  • Copy and paste the contents of that document your reply
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog
  • Search.txt

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#6 wukassa

wukassa
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 16 February 2015 - 05:29 PM

Hi Oh My!

here's the fixlog.

The search log is taking forever to be generated. I even rebooted (unsuccesfully) because I thought it was stuck.

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-02-2015
Ran by SYSTEM at 2015-02-16 16:29:28 Run:4
Running from H:\
Boot Mode: Recovery
==============================================
 
Content of fixlist:
*****************
S3 IntcAzAudAddService; system32\drivers\RTKVHD64.sys [X]
S3 L1C; system32\DRIVERS\L1C62x64.sys [X]
S3 RSUSBSTOR; \SystemRoot\System32\Drivers\RtsUStor.sys [X]
*****************
 
IntcAzAudAddService => Service deleted successfully.
L1C => Service deleted successfully.
RSUSBSTOR => Service deleted successfully.
 
==== End of Fixlog 16:29:28 ====


#7 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,374 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:57 PM

Posted 16 February 2015 - 05:46 PM

OK you can stop the search and we will do it another way. Please do this.

===================================================

Farbar's Recovery Scan Tool - Run Fix

--------------------
  • From a clean computer press the windows key Windows_Logo_key.gif + r on your keyboard at the same time. Type in notepad and press Enter
  • Please copy and paste the contents of the below code box into the open notepad and save it on the flashdrive as fixlist.txt
File: C:\Windows\System32\winlogon.exe
File: C:\Windows\System32\wininit.exe
File: C:\Windows\SysWOW64\wininit.exe
File: C:\Windows\explorer.exe
File: C:\Windows\SysWOW64\explorer.exe
File: C:\Windows\System32\userinit.exe
File: C:\Windows\SysWOW64\userinit.exe
  • Insert the USB device into your infected computer
  • Enter the System Recovery Options (press F8 during boot up), select Repair Your Computer, then select Command Prompt.
  • Run FRST as you did the first time and press the Fix button just once and wait, the program will automatically launch fixlist.txt.
  • The tool will create a log on the flashdrive (Fixlog.txt). Copy and paste that information in your reply.
  • Please attempt to boot your computer into Normal Mode or, if not, Safe Mode
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • Fixlog

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#8 wukassa

wukassa
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 17 February 2015 - 04:50 AM

Sorry but it takes ages to do anyything.

If it can help understading the problem, everytime I start Farbar I see a removable drive (which is not actually there) in the Computer folder.

 

Here's the log!

 

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-02-2015
Ran by SYSTEM at 2015-02-17 10:42:07 Run:5
Running from H:\
Boot Mode: Recovery
==============================================
 
Content of fixlist:
*****************
File: C:\Windows\System32\winlogon.exe
File: C:\Windows\System32\wininit.exe
File: C:\Windows\SysWOW64\wininit.exe
File: C:\Windows\explorer.exe
File: C:\Windows\SysWOW64\explorer.exe
File: C:\Windows\System32\userinit.exe
File: C:\Windows\SysWOW64\userinit.exe
*****************
 
 
========================= File: C:\Windows\System32\winlogon.exe ========================
 
MD5: 8CEBD9D0A0A879CDE9F36F4383B7CAEA
Creation and modification date: 2014-10-15 07:22 - 2014-07-16 18:07
Size: 0455168
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: winlogon
Original Name: WINLOGON.EXE.MUI
Product Name: Sistema operativo Microsoft® Windows®
Description: Applicazione Accesso a Windows
File Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850)
Product Version: 6.1.7601.17514
Copyright: © Microsoft Corporation. Tutti i diritti riservati.
 
====== End Of File: ======
 
 
========================= File: C:\Windows\System32\wininit.exe ========================
 
MD5: 94355C28C1970635A31B3FE52EB7CEBA
Creation and modification date: 2009-07-13 15:52 - 2009-07-13 17:39
Size: 0129024
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: WinInit
Original Name: WinInit.exe.mui
Product Name: Sistema operativo Microsoft® Windows®
Description: Applicazione di avvio di Windows
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Version: 6.1.7600.16385
Copyright: © Microsoft Corporation. Tutti i diritti riservati.
 
====== End Of File: ======
 
 
========================= File: C:\Windows\SysWOW64\wininit.exe ========================
 
MD5: B5C5DCAD3899512020D135600129D665
Creation and modification date: 2009-07-13 15:36 - 2009-07-13 17:14
Size: 0096256
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: WinInit
Original Name: WinInit.exe.mui
Product Name: Sistema operativo Microsoft® Windows®
Description: Applicazione di avvio di Windows
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Version: 6.1.7600.16385
Copyright: © Microsoft Corporation. Tutti i diritti riservati.
 
====== End Of File: ======
 
 
========================= File: C:\Windows\explorer.exe ========================
 
MD5: 332FEAB1435662FC6C672E25BEB37BE3
Creation and modification date: 2011-07-13 21:30 - 2011-07-13 21:30
Size: 2871808
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: explorer
Original Name: EXPLORER.EXE.MUI
Product Name: Sistema operativo Microsoft® Windows®
Description: Esplora risorse
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Version: 6.1.7600.16385
Copyright: © Microsoft Corporation. Tutti i diritti riservati.
 
====== End Of File: ======
 
 
========================= File: C:\Windows\SysWOW64\explorer.exe ========================
 
MD5: 8B88EBBB05A0E56B7DCC708498C02B3E
Creation and modification date: 2011-07-13 21:30 - 2011-07-13 21:30
Size: 2616320
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: explorer
Original Name: EXPLORER.EXE.MUI
Product Name: Sistema operativo Microsoft® Windows®
Description: Esplora risorse
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Version: 6.1.7600.16385
Copyright: © Microsoft Corporation. Tutti i diritti riservati.
 
====== End Of File: ======
 
 
========================= File: C:\Windows\System32\userinit.exe ========================
 
MD5: BAFE84E637BF7388C96EF48D4D3FDD53
Creation and modification date: 2010-11-20 19:24 - 2010-11-20 19:24
Size: 0030720
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: userinit
Original Name: USERINIT.EXE.MUI
Product Name: Sistema operativo Microsoft® Windows®
Description: Applicazione accesso Userinit
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Version: 6.1.7600.16385
Copyright: © Microsoft Corporation. Tutti i diritti riservati.
 
====== End Of File: ======
 
 
========================= File: C:\Windows\SysWOW64\userinit.exe ========================
 
MD5: 61AC3EFDFACFDD3F0F11DD4FD4044223
Creation and modification date: 2010-11-20 19:23 - 2010-11-20 19:23
Size: 0026624
Attributes: ----A
Company Name: Microsoft Corporation
Internal Name: userinit
Original Name: USERINIT.EXE.MUI
Product Name: Sistema operativo Microsoft® Windows®
Description: Applicazione accesso Userinit
File Version: 6.1.7600.16385 (win7_rtm.090713-1255)
Product Version: 6.1.7600.16385
Copyright: © Microsoft Corporation. Tutti i diritti riservati.
 
====== End Of File: ======
 
 
==== End of Fixlog 10:43:58 ====


#9 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,374 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:57 PM

Posted 17 February 2015 - 09:36 AM

Thank you for the additional information.

Those files are all fine.

Can you provide more identifying information about the non-existent removable drive. Name, size, etc.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#10 wukassa

wukassa
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 17 February 2015 - 09:51 AM

Drive letter G:

0 bytes

unknown filesystem

unable to eject

unable to format

 

If i click the drive I get:

Please insert a disk into removable disk G:

 

----------

update

----------

 

sorry....it's probably just the card reader


Edited by wukassa, 17 February 2015 - 09:55 AM.


#11 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,374 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:57 PM

Posted 17 February 2015 - 10:02 AM

Thank you for the detailed informtion. I don't believe that is part of our problem.

It is possible we are facing a hardware issue. I want us to check your memory and the drive itself. Please do these things.

===================================================

Testing Computer Memory Using MemTest86+

--------------------
  • Download the latest version of MemTest86+ Windows Images: Image for creating boot-able CD , and and save it to your desktop
  • Right click on the folder and select Extract All...
  • Select Next, Next, then Finish
  • Burn the image file to a CD, as an image file. If you're unsure how to do this, see the How to Burn an ISO File tutorial.[/url. Be sure to uncheck any additional software that is offered.]
  • Put your CD in the drive and configure your machine to boot to the CD. This is different on all machines, but it's usually by pressing F12 or F10 as your system boots, and selecting either "CDROM" or your cdrom drive.
  • If you've done it correctly, MemTest86+ will start to run automaticly, as shown below:

memtestStart.png

  • If you want to be reasonably certain your RAM is OK, then allow MemTest to run until you see this message:

memtestFinished.png

  • On the other hand, if you want to be completely sure your RAM is OK, allow MemTest to run overnight. Memtest will run forever until power is pulled on the machine.
  • Check the MemTest screen for any reported errors. Errors will appear as RED warnings at the bottom of the screen, similar to the following screenshot:

memtestFail.png

  • Press the reset button on the computer, removing the MemTest disk in the process
  • Report the results
===================================================

Seagate Seatools for DOS

----------
  • Please download SeaTools for DOS and create a bootable CD as instructed here and save it to your desktop
  • NOTE: If you have any difficulty booting up with this version, please use one of the legacy versions of SeaTools for DOS
  • If you do not have ISO burning software on your computer download and install Active@ ISO Burner then create a bootable disk with the downloaded file
  • Boot your computer using the CD you just created. If necessary see [url=http://www.hiren.info/pages/bios-boot-cdrom]here for instructions about how to boot to CD
  • After the program loads click I Accept
  • Left Click on your hard drive listed under Drive List (if you have a Seagate hard drive take special note of the caution below)
  • Click Basic Tests, then select Long Generic
  • Allow the process to run, which may take up to 3 hours, and report the findings in your reply
  • If the results indicate your hard drive failed the test and you have a Seagate hard drive installed DO NOT follow up on the suggestion to allow the program to attempt to resolve the issue. Doing so may cause permanent loss of data
===================================================

Things I would like to see in your next reply. Please be sure to copy and paste any requested log information unless you are asked to attach it. :thumbsup2:
  • MemTest results
  • Seatools results

Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#12 wukassa

wukassa
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 17 February 2015 - 10:17 AM

Can I use a bootable usb drive instead?



#13 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,374 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:57 PM

Posted 17 February 2015 - 10:38 AM

Yes, you certainly can.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."

#14 wukassa

wukassa
  • Topic Starter

  • Members
  • 20 posts
  • OFFLINE
  •  
  • Local time:12:57 AM

Posted 17 February 2015 - 12:28 PM

Ok,

Memtest gives me no errors (2 passes completed)

 

SeaTools tells me: No hard drives found.

 

I took the hard drive out and I'm testing it with seatools for windows via usb.

 

I'll let you know the results.

 

Thanks 


Edited by wukassa, 17 February 2015 - 01:31 PM.


#15 Oh My!

Oh My!

    Adware and Spyware and Malware.....


  • Malware Response Instructor
  • 37,374 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:California
  • Local time:04:57 PM

Posted 17 February 2015 - 01:47 PM

Very good, thanks.
Gary
 
If I do not reply within 24 hours please send me a Personal Message.

"May you be richly rewarded by the Lord, the God of Israel, under whose wings you have come to take refuge."




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users