Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

pc 2 - infected because setup of weird site + problems on zalman ve350 & usb key


  • This topic is locked This topic is locked
6 replies to this topic

#1 emig-tea

emig-tea

  • Banned
  • 22 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 05 August 2017 - 01:54 AM

Hello,

 

i'm back on bleepingcomputer,

 

since  this topic locked here:

 

https://www.bleepingcomputer.com/forums/t/652529/windows-7-10-infecte-problems-on-xubuntu-live-usb-and-sd-cards/

 

because one topic by each pc, i retry again to post 2 topics: one by pc/one for each pc,

to make coherence,

 

i uninstalled the "dll care" & "smart pc utilities" optimizers,

 

i installed RegCure and Anvisoft apps on C:/program files/pc optimizer pro sub-directory, and copied that accidentally on downloads folder, it's theorical and bad intuitional, i go to begin clean now please;

 

my pc #2 is a Compaq Desktop by HP,

Antivirus/firewall: Ad-Aware Personnal Security + Comodo Firewall Free

System: Win 10 x64

i have this pc since 2011 (win 8 pre-installed)

 

i have followed instructions on my other topics: adwcleaner/mbam/frst, but a improvization for mbam, because mbam don't launches on my pc (bug) in normal, safe mode, before, after reinstall, before and after use mbam cleaning tool, the problems persists,

 

i have now mb clean results, adwcleaner and frst logs,

 

****

 

 
I Have a desktop compaq pc since 2011 with Windows 8 installed,
This pc not formated/resetted since 2011 ( 6 years) and i have also installed in marsh 2014 reimage repair and freeven because of fake java/Dropbox installations by a suspicious sites,
 
In 2015 we are infected respectively by Filefact smart file advisor, alcoholsoft/filefacts toolbar with hxxp://start.filefacts.com in default homepage in marsh 2015, then Fix-It Registry Optimizer in October 2015, and ZoneAlarm Toolbar in december 2015,
 
After installations on december 31th 2015 i have installed Abbyy Finereader 12 Trial version and Daemon Tools Lite, but with a suspicious site and one Boxore icon appears on desktop,
 
One day later late in evening, i have installed all Avanuest Trial version, one of theses is the malicious Registry First Aid rogue installed,
 
After purchased a logitec webcam on Amazon at marsh, i go to download the new Cyberlink VideoMeeting+ on a curious site and the Systweak suite comes on my desktop/Windows explorer with regcleanpro and advanced systemprotector,
 
In rage, i go take multiples scans, disinfections apps and logs during all the marsh 2016 month, and now her results:
Adsfix: http://www.cjoint.com/doc/16_03/FCgsgvvNhzn_AdsFix-04-03-2016-01-59-32.txt
Zhpdiag: http://www.cjoint.com/c/FCbl3bGfEcD
Malwarebytes Anti-Malware: http://www.cjoint.com/c/FCftwZZNGXn
Roguekiller: http://www.cjoint.com/c/FCit2fnqxbn
Pre_scan: http://www.cjoint.com/doc/16_03/FCgshkgXs2n_Pre-Scan-06-03-2016-12-20-12.txt
and now, on year later,
my parents goes to computer repair services in a shop to repair my Archos PC Stick, zalman VE-350, usb keys (wintobootic, frama asso/salix, multibootables sardu/yumi, sandisk connect, virtualbox portable of Cubuntu live Toshiba drive...),

 

for my portableapps companion drbl bootable usb drive/network disk(s):
and my trouble on network device, the CustomUSB PortableApps.Com DRBL bootable Companion blue 32 GB stick plugged on my Orange Livebox, is actually the (Y:/) partition on my laptop, if i copy/modify/move a file/folder on it i have this error message in french:
Accès au dossier de destination refusé: Vous devez disposer d'une autorisation pour effectuer cette action",
On compaq pc, this network device is the (Z:\) disk , i clicked on it on my compaq pc, a error messages says "denied access", ora error message in french with "Restauration des connexions réseau: Erreur lors de la connexion de Z: à \\Livebox\COMPANION Microsoft Windows Network: Le chemin réseau n'as pas été trouvé - Cette connexion n'as pas été restaurée" displayed on this

 

and my desktop pc since the july 5th infected by pc clean plus & hd wallpapers
and july 5th at evening i have installed and used paragon extfs for windows to assign letter/mount the ubuntu mate of dualboot's partition on win 10, it's the D letter on my quickdiag logs
i wait help

 

 

I have also bugs on zalman ve350 and usb keys:

 

Theses devices are inspected from june 21th to july 19th on computer repair shop for 70$, and no résolvez the problêms,

 

M'y wintobootic win8. 1 windows2go SanDisk reversible micro-usb/usb disk have infinité looping at boot, Block m'y accès to w8.1 configuration

 

M'y customusb.com Fold-it 16 gb/emtech reversible micro usb usb mobile & go 64 gb three disks are multibootables but boot error at sardu/yumi menus

 

M'y framakey asso 64 verbatim usb key/memtest86 nano 128 usb are now 50 mb partitions/disks, suspicions boot errors, and à "no partition table on thèses disks" error messages when'i try to résine to 64 and 128 gb original sizes when I use im-magic résizer,  paragon, etc...

 

M'y hdd zalman external ve350 are no Iso file on lcd screen but this device contains dozen Iso files, lire aviser,  on respective "_iso" folder, this device are no boot

 

M'y others verbatim store 'n' go disk is à 32 gb framakey salix, with at every logo on salix thé " firefox doesn't close properly, please restant firefox" error message persiste at every try to open firefox, internet and thunderbird on salix

 

Thèses sd/devices/usb/hdd scannéd with ad-aware, Comodo,  ccleaner,  but thèses problêms persists,  thanks. ..

 

****

 

Thanks...

 

and now the adwcleaner, mbam cleanup log, and frst logs:

 

Attached Files



BC AdBot (Login to Remove)

 


#2 emig-tea

emig-tea
  • Topic Starter

  • Banned
  • 22 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 05 August 2017 - 11:47 PM

And à New bug appears on evening of august 5th, 2017:

In august 5th 2017 I have on ubuntu mate live in usb live surfer on Firefox and I tried to download portable apps on unknowns Website with adwares at 8:47 P.M. and multiples malicious popup on ubuntu's firefox (same thing like windows, prove in ubuntu the adwares on firefox goes in ubuntu),
one seconde later the ubuntu's screen/desktop/firefox freezer and goes slow, I force exit ubuntu mate live with the desktop pc's power buttons

Thanks...

#3 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:03 PM

Posted 07 August 2017 - 09:15 AM


Hi.

It's me again.

Both of these topic have the same FRTS log.

https://www.bleepingcomputer.com/forums/t/653539/pc-1-infected-by-adwares-rogues-problems-on-sdsdxcmicro-sd-cards-xubunt/

https://www.bleepingcomputer.com/forums/t/653540/pc-2-infected-because-setup-of-weird-site-problems-on-zalman-ve350-usb-key/

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 31-07-2017
Exécuté par jean- (administrateur) sur DESKTOP-37KC94K (04-08-2017 12:20:03)
Exécuté depuis C:\Users\jean-\Desktop
Profils chargés: jean- (Profils disponibles: jean- & MSSQL$ADK)
Platform: Windows 10 Home Version 1607 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Opera)
Mode d'amorçage: Safe Mode (with Networking)

Résultats d'analyse de Farbar Recovery Scan Tool (FRST) (x64) Version: 31-07-2017
Exécuté par jean- (administrateur) sur DESKTOP-37KC94K (04-08-2017 12:20:03)
Exécuté depuis C:\Users\jean-\Desktop
Profils chargés: jean- (Profils disponibles: jean- & MSSQL$ADK)
Platform: Windows 10 Home Version 1607 (X64) Langue: Français (France)
Internet Explorer Version 11 (Navigateur par défaut: Opera)
Mode d'amorçage: Safe Mode (with Networking)


If these topic are for the same one will be closed.

If not the run the Farbar tool in Normal mode and submit fresh FRST and Addition.txt logs for my review.

#4 emig-tea

emig-tea
  • Topic Starter

  • Banned
  • 22 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 07 August 2017 - 02:09 PM

hello, sorry of this erratum and posted 2 times same frst:

 

1) pc 1 is not compaq desktop, but is acer w7 laptop

 

2) because of this erratum i ran the frst fix on two computers, the fix done succesfull

y on my other pc 5pc 2) but blocks on pc 1 here (w7 acer) but i have fixlog file

 

3) the usb framakey asso/salix, memtest86, multibootables drives, windows2go drive, and zalman ve350 drive and also the network drive:

~~~~~~~~~~~~

for my portableapps companion drbl bootable usb drive/network disk(s):
and my trouble on network device, the CustomUSB PortableApps.Com DRBL bootable Companion blue 32 GB stick plugged on my Orange Livebox, is actually the (Y:/) partition on my laptop, if i copy/modify/move a file/folder on it i have this error message in french:
Accès au dossier de destination refusé: Vous devez disposer d'une autorisation pour effectuer cette action",
On compaq pc, this network device is the (Z:\) disk , i clicked on it on my compaq pc, a error messages says "denied access", ora error message in french with "Restauration des connexions réseau: Erreur lors de la connexion de Z: à \\Livebox\COMPANION Microsoft Windows Network: Le chemin réseau n'as pas été trouvé - Cette connexion n'as pas été restaurée" displayed on this

 

I have also bugs on zalman ve350 and usb keys:

 

Theses devices are inspected from june 21th to july 19th on computer repair shop for 70$, and no résolvez the problêms,

 

M'y wintobootic win8. 1 windows2go SanDisk reversible micro-usb/usb disk have infinité looping at boot, Block m'y accès to w8.1 configuration

 

M'y customusb.com Fold-it 16 gb/emtech reversible micro usb usb mobile & go 64 gb three disks are multibootables but boot error at sardu/yumi menus

 

M'y framakey asso 64 verbatim usb key/memtest86 nano 128 usb are now 50 mb partitions/disks, suspicions boot errors, and à "no partition table on thèses disks" error messages when'i try to résine to 64 and 128 gb original sizes when I use im-magic résizer,  paragon, etc...

 

M'y hdd zalman external ve350 are no Iso file on lcd screen but this device contains dozen Iso files, lire aviser,  on respective "_iso" folder, this device are no boot

 

M'y others verbatim store 'n' go disk is à 32 gb framakey salix, with at every logo on salix thé " firefox doesn't close properly, please restant firefox" error message persiste at every try to open firefox, internet and thunderbird on salix

 

Thèses sd/devices/usb/hdd scannéd with ad-aware, Comodo,  ccleaner,  but thèses problêms persists,  thanks. ..

 

and now the fixlog/frst/addition/shortcuts 4 logs:

Attached Files



#5 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:03 PM

Posted 08 August 2017 - 07:02 AM

Hi.

Repair these services.

Boot with Safe Mode with Networking. Execute the following.

Please Download Tweaking.com - Windows Repair from Here
  • Install and then run the program
  • Execute the instructions on Step 1 Important
  • Click Next on Step 2 Optional, do the Pre Scan skip Step 3 and 4 Optional for now.
  • On Step 5 Backup System Restore Do a Registry backup. When you have completed this click Next
  • Click Repairs - Open Repairs in the bottom right corner
  • Uncheck the All repair button then select just the item(s) listed below

  • 01 - Repair Registry Permissions
    03 - Reset Service permissions
    04 - Register System Files
    05 - Repair WMI
    10 - Remove Policies Set By Infections
    17 - Repair Windows Updates
    21 - Repair MSI (Windows Installer)
    26 - Restore Important Windows Services
    27 - Set Windows Service to Default Startup
  • Click the Start button and let the process run to completion. Copy any error messages into Notepad, Save it on your Desktop. ( Reboot if asked to do so)
  • Please copy and paste the Contents of this file on your next reply.
===

Restart the computer normally.

How is the computer running now?

#6 emig-tea

emig-tea
  • Topic Starter

  • Banned
  • 22 posts
  • OFFLINE
  •  
  • Local time:05:03 AM

Posted 08 August 2017 - 11:46 AM

pre_scan:

┌────────────────────────────────────────────────────────────────────────────────┐
│ Tweaking.com - Windows Repair 2018 (v4.0.1) - Pre-Scan
│ Computer: DESKTOP-37KC94K (Windows 10 Home 10.0.14393.105 ) (64-bit)
│ [Started Scan - 08/08/2017 16:39:40]
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Scanning Windows Packages Files.
│ Started at (08/08/2017 16:39:40)

│ No problems were found with the Packages Files.

│ Files Checked & Verified: 9 542

│ Done Scanning Windows Packages Files.(08/08/2017 18:15:42)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Scanning Reparse Points.
│ Started at (08/08/2017 18:15:42)

Reparse Point: (Type: SYMLINK) (Name: cclog) (Original Path: C:\SYSTEM.SAV\LOGS\SymLogs\cclog) (Target Path: C:\Users\Public\Symantec\SymSilent\cclog) (Creation Time: 05/03/2013 01:49:08)
Target Path doesn't exist!

│ Missing Default Reparse Point: (Original Path: C:\ProgramData\Desktop) (Target Path: C:\Users\Public\Desktop)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\ProgramData\Start Menu) (Target Path: C:\ProgramData\Microsoft\Windows\Start Menu)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\ProgramData\Templates) (Target Path: C:\ProgramData\Microsoft\Windows\Templates)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\AppData\Local\History) (Target Path: C:\Users\Default\AppData\Local\Microsoft\Windows\History)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\Documents\My Music) (Target Path: C:\Users\Default\Music)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\Documents\My Pictures) (Target Path: C:\Users\Default\Pictures)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\Documents\My Videos) (Target Path: C:\Users\Default\Videos)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\My Documents) (Target Path: C:\Users\Default\Documents)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\NetHood) (Target Path: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\PrintHood) (Target Path: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\Start Menu) (Target Path: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Default\Templates) (Target Path: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Public\Documents\My Music) (Target Path: C:\Users\Public\Music)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Public\Documents\My Pictures) (Target Path: C:\Users\Public\Pictures)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\Public\Documents\My Videos) (Target Path: C:\Users\Public\Videos)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\AppData\Local\History) (Target Path: C:\Users\jean-\AppData\Local\Microsoft\Windows\History)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\Documents\My Music) (Target Path: C:\Users\jean-\Music)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\Documents\My Pictures) (Target Path: C:\Users\jean-\Pictures)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\Documents\My Videos) (Target Path: C:\Users\jean-\Videos)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\My Documents) (Target Path: C:\Users\jean-\Documents)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\NetHood) (Target Path: C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Network Shortcuts)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\PrintHood) (Target Path: C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Printer Shortcuts)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\Start Menu) (Target Path: C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Start Menu)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\jean-\Templates) (Target Path: C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Templates)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\AppData\Local\History) (Target Path: C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\History)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\INetCache\Content.IE5) (Target Path: C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\INetCache\IE)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\Documents\My Music) (Target Path: C:\Users\MSSQL$ADK\Music)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\Documents\My Pictures) (Target Path: C:\Users\MSSQL$ADK\Pictures)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\Documents\My Videos) (Target Path: C:\Users\MSSQL$ADK\Videos)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\My Documents) (Target Path: C:\Users\MSSQL$ADK\Documents)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\NetHood) (Target Path: C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Network Shortcuts)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\PrintHood) (Target Path: C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Printer Shortcuts)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\Start Menu) (Target Path: C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Missing Default Reparse Point: (Original Path: C:\Users\MSSQL$ADK\Templates) (Target Path: C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Templates)
│ A Default Reparse Point is missing and this can cause problems on the system.

│ Problems were found with the Reparse Points.
│ You can use the Repair Reparse Points Tool at the bottom of this Window to try and fix these problems.

│ Files & Folders Searched: 405 868
│ Reparse Points Found: 83

│ Done Scanning Reparse Points.(08/08/2017 18:24:56)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ Checking Environment Variables.
│ Started at (08/08/2017 18:24:57)

│ This folder in the 'Path' variable doesn't exist: C:\PROGRA~1\CONDUS~1\DISKEE~1\

│ This folder in the 'Path' variable doesn't exist:

│ Problems were found with the Environment Variables.
│ You can use the Repair Environment Variables Tool at the bottom of this Window to try and fix these problems.

│ Done Checking Environment Variables. (08/08/2017 18:24:57)
└────────────────────────────────────────────────────────────────────────────────┘
┌────────────────────────────────────────────────────────────────────────────────┐
│ [Finished Scan - 08/08/2017 18:24:57]

│ [x] Scan Complete - Problems Found!
│ [x]
│ [x] You can use the Repair Reparse Points or Repair Environment Variables tools at the bottom of this Window if needed.
│ [x]
│ [x] While problems have been found, you can still run the repairs in the program.
│ [x] But for the best results it is recommended to fix the problems reported in this scan if possible.
└────────────────────────────────────────────────────────────────────────────────┘

reparse points:

┌───────────────────────────────┐
│[STARTED] [08/08/2017 18:36:06]│
└───────────────────────────────┘
Running Repair on C:\SYSTEM.SAV\LOGS\SymLogs\cclog

   [x] Command to Run: Create Target Path/Folder C:\Users\Public\Symantec\SymSilent\cclog
   [x] Calling SHCreateDirectoryExW
   [x] Create Target Path/Folder Done.

Running Repair on C:\ProgramData\Desktop

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\ProgramData\Desktop" "C:\Users\Public\Desktop"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\ProgramData\Desktop

Running Repair on C:\ProgramData\Start Menu

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\ProgramData\Start Menu" "C:\ProgramData\Microsoft\Windows\Start Menu"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\ProgramData\Start Menu

Running Repair on C:\ProgramData\Templates

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\ProgramData\Templates" "C:\ProgramData\Microsoft\Windows\Templates"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\ProgramData\Templates

Running Repair on C:\Users\Default\AppData\Local\History

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\AppData\Local\History" "C:\Users\Default\AppData\Local\Microsoft\Windows\History"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\AppData\Local\History

Running Repair on C:\Users\Default\Documents\My Music

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\Documents\My Music" "C:\Users\Default\Music"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\Documents\My Music

Running Repair on C:\Users\Default\Documents\My Pictures

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\Documents\My Pictures" "C:\Users\Default\Pictures"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\Documents\My Pictures

Running Repair on C:\Users\Default\Documents\My Videos

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\Documents\My Videos" "C:\Users\Default\Videos"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\Documents\My Videos

Running Repair on C:\Users\Default\My Documents

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\My Documents" "C:\Users\Default\Documents"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\My Documents

Running Repair on C:\Users\Default\NetHood

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\NetHood" "C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\NetHood

Running Repair on C:\Users\Default\PrintHood

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\PrintHood" "C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\PrintHood

Running Repair on C:\Users\Default\Start Menu

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\Start Menu" "C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\Start Menu

Running Repair on C:\Users\Default\Templates

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Default\Templates" "C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Default\Templates

Running Repair on C:\Users\Public\Documents\My Music

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Public\Documents\My Music" "C:\Users\Public\Music"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Public\Documents\My Music

Running Repair on C:\Users\Public\Documents\My Pictures

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Public\Documents\My Pictures" "C:\Users\Public\Pictures"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Public\Documents\My Pictures

Running Repair on C:\Users\Public\Documents\My Videos

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\Public\Documents\My Videos" "C:\Users\Public\Videos"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\Public\Documents\My Videos

Running Repair on C:\Users\jean-\AppData\Local\History

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\AppData\Local\History" "C:\Users\jean-\AppData\Local\Microsoft\Windows\History"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\AppData\Local\History

Running Repair on C:\Users\jean-\Documents\My Music

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\Documents\My Music" "C:\Users\jean-\Music"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\Documents\My Music

Running Repair on C:\Users\jean-\Documents\My Pictures

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\Documents\My Pictures" "C:\Users\jean-\Pictures"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\Documents\My Pictures

Running Repair on C:\Users\jean-\Documents\My Videos

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\Documents\My Videos" "C:\Users\jean-\Videos"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\Documents\My Videos

Running Repair on C:\Users\jean-\My Documents

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\My Documents" "C:\Users\jean-\Documents"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\My Documents

Running Repair on C:\Users\jean-\NetHood

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\NetHood" "C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Network Shortcuts"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\NetHood

Running Repair on C:\Users\jean-\PrintHood

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\PrintHood" "C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Printer Shortcuts"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\PrintHood

Running Repair on C:\Users\jean-\Start Menu

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\Start Menu" "C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Start Menu"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\Start Menu

Running Repair on C:\Users\jean-\Templates

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\jean-\Templates" "C:\Users\jean-\AppData\Roaming\Microsoft\Windows\Templates"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\jean-\Templates

Running Repair on C:\Users\MSSQL$ADK\AppData\Local\History

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\AppData\Local\History" "C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\History"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\AppData\Local\History

Running Repair on C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\INetCache\Content.IE5

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Calling SHCreateDirectoryExW To Create Target Folder: C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\INetCache\IE
   [x] Create Target Path/Folder Done.
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\INetCache\Content.IE5" "C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\INetCache\IE"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\AppData\Local\Microsoft\Windows\INetCache\Content.IE5

Running Repair on C:\Users\MSSQL$ADK\Documents\My Music

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\Documents\My Music" "C:\Users\MSSQL$ADK\Music"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\Documents\My Music

Running Repair on C:\Users\MSSQL$ADK\Documents\My Pictures

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\Documents\My Pictures" "C:\Users\MSSQL$ADK\Pictures"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\Documents\My Pictures

Running Repair on C:\Users\MSSQL$ADK\Documents\My Videos

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\Documents\My Videos" "C:\Users\MSSQL$ADK\Videos"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\Documents\My Videos

Running Repair on C:\Users\MSSQL$ADK\My Documents

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\My Documents" "C:\Users\MSSQL$ADK\Documents"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\My Documents

Running Repair on C:\Users\MSSQL$ADK\NetHood

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\NetHood" "C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Network Shortcuts"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\NetHood

Running Repair on C:\Users\MSSQL$ADK\PrintHood

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\PrintHood" "C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Printer Shortcuts"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\PrintHood

Running Repair on C:\Users\MSSQL$ADK\Start Menu

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\Start Menu" "C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Start Menu"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\Start Menu

Running Repair on C:\Users\MSSQL$ADK\Templates

   [x] Command to Run: Create Default Reparse Point (This Is A Default Windows Reparse Point, Lets Put It Back The Way It Should Be)
   [x] Calling Checking If Link Folder Exists
   [x] Type is JUNCTION, Calling: mklink /J "C:\Users\MSSQL$ADK\Templates" "C:\Users\MSSQL$ADK\AppData\Roaming\Microsoft\Windows\Templates"
   [x] Setting Owner To System And Everyone Read Access To Denied (This Is The Default) To The Link Folder: C:\Users\MSSQL$ADK\Templates

┌────────────────────────────────┐
│[FINISHED] [08/08/2017 18:37:10]│
└────────────────────────────────┘

 

repairs:

Log:
Tweaking.com - Windows Repair 2018 (v4.0.1)
────────────────────────────────────────────────────────────────────────────────

System Variables
────────────────────────────────────────────────────────────────────────────────
OS: Windows 10 Home
OS Architecture: 64-bit
OS Version: 10.0.14393.105
OS Service Pack:
Computer Name: DESKTOP-37KC94K
Windows Drive: C:\
Windows Path: C:\WINDOWS
Program Files: C:\Program Files
Program Files (x86): C:\Program Files (x86)
Current Profile: C:\Users\jean-
Current Profile SID: S-1-5-21-4265624635-2019933758-61733912-1001
Current Profile Classes: S-1-5-21-4265624635-2019933758-61733912-1001_Classes
Profiles Location: C:\Users
Profiles Location 2: C:\WINDOWS\ServiceProfiles
Local Settings AppData: C:\Users\jean-\AppData\Local
────────────────────────────────────────────────────────────────────────────────

System Information
────────────────────────────────────────────────────────────────────────────────
System Up Time: 0 Days 10:01:34

Process Count: 49
Commit Total: 8,91 GB
Commit Limit: 11,20 GB
Commit Peak: 9,19 GB
Handle Count: 20648
Kernel Total: 381,20 MB
Kernel Paged: 306,04 MB
Kernel Non Paged: 75,16 MB
System Cache: 776,29 MB
Thread Count: 767
────────────────────────────────────────────────────────────────────────────────

Memory Before Cleaning with CleanMem
────────────────────────────────────────────────────────────────────────────────
Memory Total: 3,57 GB
Memory Used: 2,99 GB(83,7679%)
Memory Avail.: 594,05 MB
────────────────────────────────────────────────────────────────────────────────

Cleaning Memory Before Starting Repairs...

Memory After Cleaning with CleanMem
────────────────────────────────────────────────────────────────────────────────
Memory Total: 3,57 GB
Memory Used: 3,00 GB(83,8787%)
Memory Avail.: 590,00 MB
────────────────────────────────────────────────────────────────────────────────

Starting Repairs...
   Started at (08/08/2017 18:40:34)

The current repair has failed to start for over 30 sec.
Trying Again....

The current repair has failed to start for over 30 sec.
Trying Again....

The current repair has failed to start for over 30 sec.
Trying Again....

   Done, but failed, at (08/08/2017 18:42:35)
   Total Repair Time: 00:02:04

The current repair has failed to start 4 times.
Something is keeping the repair from running.

Try running the repairs in Windows Safe Mode. (This will keep 3rd party programs from getting in the way of the repairs)
If the repairs still fail then please post in the Tweaking.com forums for support.

-----------

-------------

i have tonight used the repairs in safe mode,

Thanks...



#7 nasdaq

nasdaq

  • Malware Response Team
  • 38,933 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Montreal, QC. Canada
  • Local time:11:03 PM

Posted 09 August 2017 - 08:40 AM

Hi,

I Have been made aware of all you other topics and activities in this Forum and others.

I'm discontinuing the help on this topic.

My time and that of the other helpers is limited and will be well used to help others in need.

As far as I'm concerned, your repetitive actions and ignorance of the rules led to many forums to stop offering you assistance. This is the same here with me.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users